Anthropic announced on October 6, 2026 that it is expanding its Cyber Verification Program into three access tiers (Defense, Red Team and Specialized) and merging Project Glasswing into the same program. All three tiers cover Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, and applications go through a single portal.
If you do security work with Claude and have been annoyed by refusals on legitimate tasks, this is the most concrete answer Anthropic has given so far. It is also a policy shift: instead of one blunt classifier setting for everyone, access now scales with who you are and what you are authorized to test.
TL;DR: the three tiers at a glance
| Question | Defense Access | Red Team Access | Specialized Access |
|---|---|---|---|
| Who is it for? | Defenders: SOC teams, IR, malware analysts, open-source maintainers, researchers | Authorized offensive teams: in-house, government and pen-test firms | Verified orgs testing safety-critical systems |
| Individuals eligible? | Yes, with a vulnerability-disclosure track record | No, organizations only | No, organizations only |
| Typical review time | Days | Weeks | Run with the US government |
| What it adds | Defensive cyber work such as vulnerability analysis and reverse engineering | Authorized penetration testing and red-teaming | Fewest cyber blocks |
| Still blocked? | Offensive abuse | Physical harm or mass disruption (ransomware, damaging physical systems) | Case by case; reviewed with government |
The details above come from Anthropic's announcement. The table compresses it; read the original for exact eligibility language before you apply.
What changed compared with the earlier program
Before this change there were two separate things. The Cyber Verification Program let qualifying security professionals reduce the blocking classifiers on Claude, and Project Glasswing gave a select set of organizations access to Claude Mythos for finding bugs in critical software. We covered the original Glasswing launch in our Mythos Preview and Glasswing explainer.
The expansion does three things:
- One front door. Glasswing and the verification program become a single offering with three levels.
- A ladder instead of a switch. Defense, then Red Team, then Specialized, each with progressively fewer cyber blocks and progressively stricter vetting.
- Model coverage that follows releases. The announcement says new models are included going forward, so you should not need to re-apply each time a model ships.
Anthropic also says the program operates on the Claude Platform, Google Cloud Vertex AI and Microsoft Foundry. That matters for enterprises that buy Claude through a cloud marketplace rather than directly.
Tier one: Defense Access
Defense Access is aimed at the broadest group. Anthropic names company security teams, nonprofits, universities, government bodies, critical infrastructure operators, smaller security firms, open-source maintainers and individual researchers who have a vulnerability-disclosure track record. The covered work includes security operations center tasks, incident response, malware reverse engineering and vulnerability analysis.
Two things stand out. First, individuals can qualify, which is rare in programs like this. If you maintain an open-source library or have published coordinated disclosures, you are the target audience. Second, review is quick: Anthropic says days, not weeks.
What this does not do is turn Claude into an offensive tool. The tier is framed around defensive outcomes.
Tier two: Red Team Access
Red Team Access adds authorized penetration testing and red-teaming on top of the defensive uses. It is organizations-only: in-house red teams, government red teams, and security or penetration-testing firms. Individual researchers are not eligible, and Anthropic says the review takes weeks.
The condition that matters most is authorization. Testing has to target systems the organization is authorized to assess. Anthropic also keeps real-time blocks for actions that could cause physical harm or mass disruption, with ransomware, physical system damage and high-risk safety-system testing given as examples.
For a pen-test firm that has been routing around refusals by splitting tasks into innocuous-looking pieces, this is a clearer path: apply, document your engagement controls, and work inside a defined boundary.
Tier three: Specialized Access
Specialized Access has the fewest cyber blocks and is reserved for verified organizations authorized to test safety-critical systems. Anthropic gives flight operating systems, power grids, telecom networks, interbank infrastructure and government networks as examples. Today it is reviewed in collaboration with the US government.
Existing Project Glasswing members transition into this tier automatically without being reapproved. That is the clearest signal that Glasswing is no longer a separate brand with its own gate.
The numbers Anthropic published about Glasswing
The announcement includes results from the Glasswing period. Partners identified at least 129,000 verified vulnerabilities between April and July 2026, and Anthropic's open-source efforts found an additional 5,500 between April and October 2026. More than 33,000 have been rated critical or high severity. One partner said discovery would have taken "months or even years" longer without the technology.
Treat these as Anthropic-reported figures. The post does not break down how severity was assigned or how many of the findings have patches. For independent context on how many AI-found bugs become exploitable, see our VulnCheck exploit-rate analysis.
Why this matters now
Cyber access has been a recurring fault line in 2026. Open-weight models posted Mythos-class cyber evaluation scores, which undercuts the idea that closed-model guardrails alone keep capability away from attackers. Critics argued the same guardrails block US defenders while doing little to slow determined offensive actors. OpenAI has taken a parallel route with its defense factory of cyber agents.
A tiered verification program is Anthropic's attempt to answer both complaints. It keeps the strongest capabilities behind identity and authorization checks, while giving defenders a faster lane. Whether it works depends on two things nobody outside Anthropic can measure yet: how often legitimate teams are rejected, and how many bad actors pass vetting.
There is also a political layer. Anthropic recently barred the UK AI Security Institute from pre-release testing of Mythos 5.1, and the company's security and alignment update described real incidents involving its own models. Routing the riskiest tier through the US government fits that pattern of selective, government-adjacent access.
How to apply
Anthropic says organizations apply through its portal at portal.anthropic.com/programs/cvp and that verification and security-control documentation is required. Before you start, gather:
- Proof of who you are: legal entity, security team charter, or for individuals a public disclosure history.
- A scope statement: what systems you defend or test, and who authorized the testing.
- Security controls: how you protect API keys, logs and any vulnerable code the model sees.
- A use-case list: SOC triage, malware analysis, patch generation, authorized red-team ops.
If you buy Claude through a cloud, check whether your enterprise agreement needs the program enabled at the platform level. The announcement lists Vertex AI and Foundry alongside Anthropic's own platform.
What people are likely to ask next
Does a verified account make Claude write working exploits? Anthropic does not say that in the announcement. It describes fewer blocks on authorized work, not a promise of unlimited output, and the Red Team tier keeps hard stops on harmful actions.
Do I lose access if I misuse it? The post describes verification and security-control documentation as requirements, which implies the status can be revoked. Read the program terms in the portal for the exact consequences before you build a workflow that depends on it.
Is this a replacement for responsible disclosure? No. Finding more bugs faster only helps if maintainers can triage them. The Glasswing figures above are a reminder that the bottleneck is increasingly patching, not discovery.
Where this connects to data handling
Cyber access is only half of the enterprise story. Anthropic's earlier Enterprise Frontier Safeguards announcement describes a solution that combines zero data retention with misuse detection, letting customers keep data in their own cloud accounts. Anthropic's CVP announcement adds that Amazon Bedrock access requires Enterprise Frontier Safeguards eligibility. For a security team, the practical reading is that sensitive vulnerability data can stay in your environment while you use a less restricted model tier. Rollout of that safeguard is described as phased starting fall 2026.
What to watch
- Rejection rates and turnaround. Days for Defense and weeks for Red Team are Anthropic's stated expectations; real-world experience will tell.
- Whether other labs copy the ladder. OpenAI and Google both gate cyber-capable models in different ways, as in our Fable 5.1 versus Astra comparison.
- Government involvement. If the Specialized tier stays tied to US government review, non-US critical infrastructure operators may face a gap, a theme that also showed up in Mythos 5 EU access.
- Model coverage. The announced set (Opus 5.5, Sonnet 5.5, Mythos 5.1) is where you can test now; see the Mythos 5.1 launch benchmarks for what the strongest model can do.
Practical advice for builders
If you build security products on Claude, do not assume your customers have access. Your end users' classifier settings follow the account making the API call, so a product that proxies requests may still hit blocks unless the underlying organization is verified. Ask your design partners whether they plan to apply, and document which tier your features require.
If you are a solo researcher, start with Defense Access and a clean disclosure record. If you run a pen-test practice, begin collecting engagement paperwork now, because Red Team review takes weeks.
Details reflect Anthropic's October 6, 2026 announcement and may change as the program rolls out.
Related reading
- Claude Mythos Preview and Project Glasswing
- Mythos 5.1 and Fable 5.1 launch benchmarks and pricing
- Claude Opus 5.5 launch, benchmarks and pricing
- VulnCheck: AI-found bugs and exploit rates
- Open-weight GLM-5.3 and Mythos-class cyber evals
- AI cyber guardrails and US defenders
- OpenAI's defense factory of cyber agents
