Anthropic PBC has broadened its Cyber Verification Program into a three-tier structure that grants vetted security teams progressively fewer restrictions on cybersecurity work. The change responds to limits Anthropic built into its own products: because the company classifies cybersecurity as dual-use, its generally available models use conservative classifiers that block most cyber tasks. When Claude Opus 5.5 shipped on Sept. 22, most security requests sent to it were redirected to the older Opus 4.8.

At the same time, Anthropic is absorbing Project Glasswing into the program. Since April, Glasswing has provided Claude Mythos access to organizations that secure critical software, and in June Anthropic extended it to 150 additional organizations. Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1 are offered at all three tiers, and Anthropic said future models will be added as they are released.

The entry level, Defense Access, covers defensive work including incident response and malware reverse engineering. Teams protecting systems they own or maintain can qualify, whether they work at a company, a university or a government body. Individual researchers with a record of reported vulnerabilities may also apply, along with critical infrastructure operators as small as a regional hospital. Anthropic said it expects many defensive organizations to qualify and aims to answer applications within a few days.

Red Team Access permits authorized penetration testing and red-teaming against systems an organization has permission to test. At this tier Anthropic's classifiers still block requests in real time when work shifts toward activity such as deploying ransomware. Applicants wait a few weeks for review and remain in Defense Access during that period, and individual researchers are currently excluded from this tier.

Specialized Access carries the fewest cyber restrictions of the three. It is limited to organizations cleared to test safety systems such as power grids and telecom networks, where failures could endanger lives or disrupt markets. Anthropic vets each of these organizations in depth with the U.S. government, and existing Glasswing members move directly into the tier without reapproval for current models.

Enrolled organizations must permit data retention so Anthropic can monitor for misuse. Enterprise Frontier Safeguards, scheduled for later this year, will allow eligible customers to keep that data in cloud infrastructure they control. The program is available through the Claude Platform, Google LLC's Vertex AI and Microsoft Corp.'s Foundry service, while on Amazon Web Services Inc.'s Bedrock it is limited to customers eligible for Enterprise Frontier Safeguards.

Anthropic tested the tiers on the multistage cyber operations benchmark CyScenarioBench, running each of its 10 challenges five times with Claude Opus 5.5. Every attempt without program access was blocked on the first prompt. Because the scenarios are offensive, Anthropic had expected heavy blocking in Defense Access, where 46 of 50 runs were stopped at some point. At the Red Team level nothing was blocked and the model completed 34 of 50 runs, which Anthropic said is effectively the same as the model's 67.6% success rate without safeguards.

The case for wider access comes from the Mythos program the new structure absorbs. Project Glasswing partners identified at least 129,000 verified vulnerabilities between April and July, and Anthropic's own scanning of open-source code found 5,500 more through October. More than 33,000 of that combined total were rated critical or high severity. The figures rest on just 33 partner reports, and the company said the real impact is likely at least five times higher. Fewer than half of the partners disclosed patch counts, often because fixes were still in progress.

More cybersecurity news from TechManNews.