On October 6, 2026, Anthropic expanded its Cyber Verification Program (CVP). The program now has three access tiers and folds the former Project Glasswing and the existing security-team CVP into one flow. Applications are open to professionals and organizations that pass verification.
Each tier includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and future models. The company says generally available models keep conservative cybersecurity blocks, because the same capability that helps fix a flaw can also be used to exploit it.
What changes at each tier
- Defense Access covers security operations, incident response, malware analysis and vulnerability validation on systems the organization owns or maintains. Anthropic says it expects to reply within a few days. It includes company teams, hospitals, municipal utilities, open-source maintainers and researchers with a record of reported flaws.
- Red Team Access adds authorized penetration testing and red teaming, only against systems the organization is allowed to test. Review is expected to take a few weeks. Applicants stay on the defensive tier in the meantime. Individual researchers are not eligible. Real-time blocks remain for actions that could cause physical harm or mass disruption, such as ransomware or tests of high-risk safety systems.
- Specialized Access has the fewest blocks and is limited to organizations authorized to test systems whose failure could affect lives or markets, such as flight operations, power grids, telecom and interbank transfers. Anthropic says it reviews each case in depth, in collaboration with the US government. Current Project Glasswing members move to this tier without reapproval for models already cleared.
Organizations already in Glasswing or the CVP do not need to apply again to keep current access. Anthropic automatically evaluates the move to Opus 5.5, Sonnet 5.5 and Mythos 5.1. The program is on the Claude Platform, Google Cloud Vertex AI and Microsoft Foundry. On Amazon Bedrock it is only for customers eligible for Enterprise Frontier Safeguards, expected later this fall in the Northern Hemisphere.
What Anthropic measured
On CyScenarioBench with Opus 5.5, Anthropic reports that without the CVP every task was blocked on the first prompt. In Defense Access, 46 of 50 trials were blocked at some point and four completed. In Red Team Access there were no blocks, and the model completed 34 of 50 tasks, a rate the company compares with 67.6% with no safeguards.
In Project Glasswing, partners reportedly found at least 129,000 verified vulnerabilities between April and July 2026. Anthropic adds 5,500 more from its own open-source scans between April and October. More than 33,000 of those flaws were rated critical or high severity. The company treats the figure as a lower bound, based on part of its partners, and estimates the real impact could be at least five times higher. That projection is Anthropic's, not an independent audit.
Data retention is required to monitor misuse, with a temporary exception for organizations that already had zero data retention on Fable 5.1 or Mythos 5.1. Enterprise Frontier Safeguards is meant to later allow data to stay in customer-controlled infrastructure.
The announcement does not release these models to the general public. Access remains tied to verification, security controls and the type of work authorized.
Sources
- Anthropic: Expanding the Cyber Verification Program
- Anthropic post on X
- Help Center: Cyber Verification Program
- Claude Mythos page
Transparency: This content was created, edited or reviewed with the aid of artificial intelligence. Information was cross-checked with public posts on X and sources available on the internet. Check the original sources for the full context.
Por GeekikiBot