AI News Feed
Market watch
Cybersecurity

Anthropic Expands Cyber Verification Program Into Three Tiers, Absorbs Project Glasswing

Anthropic expands its Cyber Verification Program to three tiers and folds Project Glasswing into it.

The overhaul addresses a restriction Anthropic built into its own products. Because the company treats cybersecurity as dual use, its generally available models carry conservative classifiers that block most cyber work. When Claude Opus 5.5 launched Sept. 22, most security tasks sent to it were routed to the older Opus 4.8.

Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1 are available at every tier of the new structure, and later models will be added as they ship. Project Glasswing, which since April has given Claude Mythos access to organizations securing critical software and was widened to 150 more organizations in June, is absorbed into the program.

Defense Access is the entry tier, meant for defensive jobs such as incident response and malware reverse engineering. Security teams defending systems they own or maintain qualify, whether they work for a company, a university or a government body. Individual researchers with a record of reported vulnerabilities can apply as well, along with critical infrastructure operators as small as a regional hospital. Anthropic said it expects many organizations doing defensive work to qualify and is aiming to respond to applications within a few days.

Red Team Access opens up authorized penetration testing and red-teaming against systems an organization has permission to test. Even at this level, Anthropic's classifiers block requests in real time when the work moves toward something like deploying ransomware. Applicants wait a few weeks for a review and sit in the Defense Access tier in the meantime, and individual researchers are shut out of the tier for now.

Specialized Access carries the fewest cyber blocks of the three. Only organizations cleared to test safety systems such as power grids and telecom networks qualify, since failures there could put lives at risk or disrupt markets. Anthropic vets each of them in depth with the U.S. government, and existing Glasswing members move straight into the tier without reapproval for current models.

Enrolled organizations must allow data retention so Anthropic can watch for misuse. Enterprise Frontier Safeguards, due later this year, will let eligible customers keep that data in cloud infrastructure they control.

Anthropic tested the tiers on the multistage cyber operations benchmark CyScenarioBench, with Claude Opus 5.5 running each of its 10 challenges five times. Every attempt without program access was blocked on the first prompt. Because the scenarios are offensive, Anthropic had expected heavy blocking in the Defense Access tier, where 46 of the 50 runs were stopped at some point. At the Red Team level nothing was blocked and the model finished 34 of its 50 runs. Anthropic said that result is effectively the same as the model's 67.6% success rate with no safeguards applied.

Outside the lab, the argument for widening access comes from the Mythos program the new structure absorbs. Partners in Project Glasswing found at least 129,000 verified vulnerabilities between April and July, and Anthropic's own scanning of open-source code turned up 5,500 more through October. Of that combined total, more than 33,000 have been rated critical or high severity. The figures draw on just 33 partner reports, and the company said the true impact is likely at least five times higher. Fewer than half of the partners disclosed patch counts, often because fixes were still underway.

The program is available through the Claude Platform, Google LLC's Vertex AI and Microsoft Corp.'s Foundry service. On Amazon Web Services Inc.'s Bedrock, it is limited to customers eligible for Enterprise Frontier Safeguards.

Editor's Summary

Anthropic has recast its Cyber Verification Program as a three-tier system that gates access to its Claude models for vetted security work, absorbing Project Glasswing's critical-infrastructure partners in the process. Internal testing showed the tiers remove blocking on offensive scenarios at the Red Team level while still stopping most Defense Access runs, and program partners reported at least 129,000 verified vulnerabilities between April and July.