Anthropic has expanded its Cyber Verification Program, creating three levels of vetted access for security professionals who need Claude to perform work that generally available models may block. Announced on 6 October, the structure brings Anthropic’s earlier Project Glasswing initiative and its existing cyber program into one offering, with access shaped around the sensitivity and scope of each team’s work.

Why Anthropic is separating cyber access

Cybersecurity is a classic dual-use area. The same reasoning and tool-use capabilities that help defenders analyse malware, validate vulnerabilities or respond to incidents can also help an attacker. Anthropic says its standard models therefore use conservative cyber safeguards. Those protections reduce misuse risk, but can also interrupt legitimate defensive workflows or create false positives for authorised practitioners.

The revised program attempts to manage that tension through verification rather than a single global setting. Security organisations apply for the level that matches their use case and must demonstrate relevant controls. Anthropic can then provide stronger capabilities or less restrictive classifiers within a more closely governed environment. For buyers, the important distinction is that this is controlled access, not a general relaxation of Claude’s cyber safety policies.

Three tiers for different kinds of work

Anthropic describes three access tiers, beginning with defensive work such as security operations, incident response, malware reverse engineering and vulnerability analysis. Higher-access categories are intended for more intensive evaluation and red-team work, where models may need to plan and execute realistic multi-stage activity against authorised targets. Each tier carries different verification requirements and security controls.

Eligible participants can use Anthropic’s most capable model families, including Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, with future models expected to be considered as well. Existing members retain their current settings for older models and will be assessed for access to the newer models. Administrators must still assign access to specific workspaces, keeping deployment decisions inside the customer organisation.

Controls remain part of the product

Data retention is normally required so Anthropic can monitor for cyber misuse. The company says its forthcoming Enterprise Frontier Safeguards will combine stronger privacy options with robust controls, including infrastructure managed by eligible customers. Until that system is available, some organisations already using zero-data-retention configurations for Mythos or Fable may be able to participate under equivalent arrangements.

Anthropic also tested tier-specific safeguards using CyScenarioBench, an evaluation built around realistic multi-stage cyber operations. It reported that the defensive tier blocked 46 of 50 tasks, while its red-team configuration allowed Claude Opus 5.5 to attempt the full set and complete 34. These results do not establish real-world safety on their own, but they show that the company is tuning controls for the purpose of each tier rather than treating every verified user identically.

Evidence from Project Glasswing

The announcement includes unusually concrete figures from Anthropic’s earlier work. Partners using Project Glasswing reported at least 129,000 verified software vulnerabilities between April and July 2026. Anthropic’s open-source scanning added another 5,500 verified issues between April and October, and more than 33,000 of the combined findings were rated critical or high severity.

Anthropic cautions that these figures are incomplete. They rely on reports from only part of the partner group, organisations used different triage methods, and fewer than half disclosed patching totals because remediation was still under way. The company nevertheless believes the true effect could be substantially larger. That claim will warrant scrutiny, particularly around how findings are validated and whether the program improves remediation as well as discovery.

Availability across cloud channels

The expanded program is available through the Claude Platform, Google Cloud Vertex AI and Microsoft Foundry. Amazon Bedrock access is narrower and tied to eligibility for Enterprise Frontier Safeguards. Applicants must provide evidence of the security controls required for their chosen tier, and Anthropic says it will continue adjusting the classifiers as it learns from participating teams.

For security leaders, the launch signals a broader pattern in frontier AI distribution: sensitive capabilities may increasingly be delivered through identity, assurance and monitoring layers rather than a single public model policy. The practical test will be whether the verification burden is workable for legitimate defenders, and whether Anthropic can detect misuse without undermining the confidentiality that enterprise security teams require.

Teams considering an application should map their intended tasks to the published tiers, document who can use the access and decide how model-generated findings enter an existing vulnerability-management process. They should also plan for false positives, escalation and responsible disclosure. Powerful discovery is useful only when findings can be verified, prioritised and remediated without creating unnecessary exposure.

Procurement teams should confirm which deployment channel supports the required privacy settings and models. Availability differs between Anthropic’s platform and the three cloud routes, so the commercial contract, data path and technical controls should be reviewed together before access is assigned.