Anthropic has launched an expanded version of its Cyber Verification Program (CVP), introducing a three-tier access structure designed to provide qualifying security professionals with advanced cyber capabilities and reduced blocking classifiers on its most capable models.
What Happened
The new CVP framework consolidates Anthropic’s previous initiatives, including Project Glasswing and the original CVP, into a unified offering. The program grants access to models such as Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, with safeguards adjusted based on the applicant's role and verification level. The tiers include Defense Access, which supports defensive tasks like malware reverse-engineering and vulnerability analysis for organizations such as critical infrastructure operators and open-source maintainers; Red Team Access, which permits authorized penetration testing and adversarial red-teaming but retains real-time blocks on actions that could cause physical harm or mass disruption; and Specialized Access, which offers the fewest cyber blocks for a limited set of verified organizations testing safety-critical systems like flight operating systems and power grids.
Anthropic reports that the program aims to balance the dual-use nature of AI in cybersecurity, where capabilities useful for defense can also be exploited by malicious actors. Generally available models maintain conservative safeguards to limit harmful activities, while the CVP provides vetted defenders with the tools necessary to secure their systems. Data retention is currently required for enrolled organizations to monitor for misuse, though a new Enterprise Frontier Safeguards (EFS) solution combining zero data retention with robust safeguards is expected to be available later this fall.
Why It Matters
This expansion represents a significant shift in how AI providers manage the deployment of frontier models in high-stakes security environments. By integrating Project Glasswing into the broader CVP, Anthropic is extending the impact of its earlier pilot program to a larger number of cyber defenders. The company cites data from Project Glasswing, stating that partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026, with Anthropic’s own open-source scanning efforts identifying an additional 5,500 verified vulnerabilities between April and October 2026. More than 33,000 of these vulnerabilities were rated as critical or high-severity. Anthropic notes that these figures are likely an undercount, based on partial survey data, and estimates the true impact could be at least five times higher.
To validate the efficacy of the new tiers, Anthropic evaluated Claude Opus 5.5 using CyScenarioBench, an evaluation measuring the model’s ability to plan and execute multi-stage cyber operations. The company reports that without CVP access, every task was blocked on the first prompt. In the Defense Access tier, 46 of 50 trials were blocked at some point, while the Red Team Access tier resulted in no blocks and successfully completed 34 of 50 tasks. Anthropic states this completion rate is effectively equivalent to the model’s 67.6% success rate on the evaluation when no safeguards are applied, suggesting that the tiered approach can safely unlock advanced capabilities for authorized users.
The Bottom Line
Anthropic’s updated Cyber Verification Program now offers a structured pathway for security organizations to access advanced AI capabilities with tailored safeguards. The integration of Project Glasswing and the introduction of three distinct access tiers aim to provide defenders with a permanent advantage in identifying and mitigating software vulnerabilities while maintaining controls against potential misuse. Existing Project Glasswing members will transition to the Specialized Access tier, while new applicants can apply for Defense or Red Team Access through the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry.