Anthropic has expanded its Cyber Verification Program on 6 October, giving vetted security teams broader access to its most capable AI models with reduced safeguards after its Project Glasswing partners identified more than 129,000 software vulnerabilities.
The expanded programme combines Project Glasswing with Anthropic’s existing Cyber Verification Program into three access tiers, each with different verification requirements and restrictions. All three provide access to Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and future models.
Anthropic said the Defense Access tier is intended for defensive cybersecurity work including incident response, malware analysis and vulnerability validation. Security teams defending systems they own or maintain, critical infrastructure operators, open-source maintainers and individual researchers with a track record of reporting vulnerabilities can apply.
The company said Red Team Access adds authorised penetration testing and red-teaming, but is restricted to organisations and only permits testing against systems they are authorised to assess. Anthropic said safeguards will continue to block actions that could cause physical harm or mass disruption, including ransomware deployment.
Specialized Access has the fewest cyber restrictions and is reserved for organisations authorised to test safety-critical systems such as power grids, flight operating systems, telecoms networks and interbank transfer infrastructure. Anthropic said it reviews every organisation in this tier in collaboration with the US government, while existing Glasswing members will transition without reapproval for current models.
Anthropic said its evaluation of Claude Opus 5.5 using the CyScenarioBench benchmark found that all 50 tests were blocked without Cyber Verification Program access, while 46 of 50 were blocked under Defense Access. Under Red Team Access, none were blocked and the model completed 34 of 50 tests, matching its reported 67.6 per cent completion rate without safeguards.
The company said Project Glasswing partners identified at least 129,000 verified vulnerabilities between April and July, while Anthropic’s own open-source scanning found a further 5,500 between April and October. More than 33,000 of the vulnerabilities identified across those efforts have so far been classified as critical or high severity.
Anthropic said the figures are likely to underestimate the programme’s impact because they are based on reports from 33 partners, with fewer than half disclosing patch numbers. The company expects the true impact to be at least five times higher, although it said differences in triage methods and incomplete patch data limit the findings.
Organisations enrolled in the programme must permit data retention so Anthropic can monitor for cyber misuse, while the company said its Enterprise Frontier Safeguards service will eventually allow eligible customers to keep data in cloud infrastructure they control.






.png)