Anthropic Unveils 3-Tier Cyber Verification Program for AI Access
Share
Anthropic, a leading AI safety and research company, has announced a significant revamp of its Cyber Verification Program (CVP), integrating it with Project Glasswing into a unified, three-tiered offering. This new structure is designed to provide controlled access to Anthropic’s most capable AI models for critical cybersecurity tasks, while maintaining safeguards against malicious use.
The company acknowledges that the powerful capabilities of its generally available models, such as Claude Opus 5.5, Sonnet 5.5, and Fable 5.1, while beneficial for defensive cybersecurity work, could also be exploited by attackers. These models currently include built-in safeguards that restrict most cyber-related activities.
Unified Access for Cybersecurity Operations
Previously, the CVP and Project Glasswing operated as separate initiatives. Project Glasswing provided select organisations with access to Claude Mythos for securing critical software, while the original CVP offered approved teams greater access to Opus and Sonnet models by loosening standard safeguards.
Under the new integrated system, all three tiers now include access to Opus 5.5, Sonnet 5.5, Mythos 5.1, and future models. Each tier comes with distinct verification requirements and security controls tailored to the sensitivity of the work involved.
Three Tiers of Access
The new program features:
- Defense Access: This tier supports essential cybersecurity functions such as Security Operations Centre (SOC) and incident response work, malware reverse engineering, and vulnerability analysis and validation. Eligibility extends to security teams defending their own systems, critical infrastructure operators, small security firms, open-source maintainers, and individual researchers with a track record of reporting vulnerabilities. Anthropic aims to process these applications within a few days.
- Red Team Access: Building on Defense Access, this tier permits authorised penetration testing and red teaming, strictly limited to systems an organisation has explicit permission to test. Activities that could cause physical harm or widespread disruption, such as deploying ransomware, remain blocked in real-time. This tier is currently exclusive to organisations, with individual researchers not eligible. Reviews are expected to take several weeks, during which qualifying applicants will receive Defense Access.
- Specialized Access: Offering the fewest cyber blocks, this top tier is reserved for a select number of organisations authorised to test safety-critical systems. This includes highly sensitive infrastructure like power grids, flight systems, telecom networks, and interbank transfer systems. Anthropic collaborates with the US government to vet applicants for this tier, and existing Project Glasswing members are transitioning into this category.
Impact and Data Handling
Between April and July, Project Glasswing partners identified at least 129,000 verified vulnerabilities. Additionally, Anthropic’s own open-source scanning efforts uncovered 5,500 more vulnerabilities between April and October. Over 33,000 of these were rated as critical or high severity, with Anthropic estimating the true impact to be at least five times higher, as these figures represent only a subset of participants.
Organisations participating in the new Cyber Verification Program must agree to data retention, allowing Anthropic to monitor for potential misuse. However, Anthropic plans to introduce Enterprise Frontier Safeguards later this autumn, which will enable eligible customers to store data in their own controlled cloud infrastructure. Until then, organisations with zero data retention access to Fable 5.1 or Mythos 5.1 can continue using the CVP with zero data retention.
The CVP is available on the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry. For Amazon Bedrock customers, access is currently limited to those eligible for Enterprise Frontier Safeguards. Existing CVP members will retain their current settings for previous models and will undergo automatic evaluation for access to the new, more advanced models.




Leave a Reply