Anthropic opens its most dangerous cyber capabilities to more security teams, in three tiers
On Tuesday, Oct. 6, 2026, Anthropic folded Project Glasswing and its Cyber Verification Program into one program with three levels of access, so many more verified defenders can use Claude models with fewer cyber safety blocks. Its own test shows how much the tier matters: the same model was blocked on every attack task without access and on none at the Red Team level.
AI models are now good enough at hacking that the companies building them lock most of that ability away from the public. This decides who gets the key. Opening it to regional hospitals, small utilities and open-source maintainers is a real step, because those are exactly the places that get hit and can't afford big security teams. But Anthropic's own test shows the stakes: at the Red Team level the model ran through two-thirds of realistic attack scenarios with nothing stopping it. That makes the vetting the whole ballgame, and right now the public has to take Anthropic's word that it's checking applicants carefully.
On Tuesday, 6 October 2026, Anthropic published “Expanding the Cyber Verification Program.” The page prints Oct 6, 2026. It does not print an hour. Anthropic says it is opening an expanded version of that program, so qualifying security professionals can use stronger cyber tools with fewer automatic blocks. The program now has three levels of access. Each level includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models after these. Those lines are Anthropic’s.
Why the models most people can use stay locked down. Cybersecurity is dual use. The same skill that lets a security team find and fix a flaw can help an attacker use that flaw. Anthropic’s regular Claude models, including Claude Opus 5.5, Claude Fable 5.1, and Claude Sonnet 5.5, have conservative cyber safeguards that block most cyber work. A safeguard, here, is an automatic stop on a request the model treats as too risky. Anthropic says the point is to limit what a malicious actor can do, while it keeps working so those stops do not catch ordinary secure coding. Those lines are Anthropic’s.
For six months, trusted access ran through two programs. Project Glasswing gave a group of organizations securing the most critical software access to Claude Mythos. The Cyber Verification Program gave vetted security teams reduced safeguards on Claude Opus and Claude Sonnet. Anthropic is merging them into one expanded program. Those lines are Anthropic’s.
Defense Access is the first level. It covers defensive work: security operations, incident response, reverse-engineering malware, and checking that a reported vulnerability is real. Reverse-engineering malware means taking a malicious program apart to see what it does. A vulnerability is a flaw someone could use to break in. Anthropic says this level is open to security teams at companies, nonprofits, universities, and government bodies that are defending systems they own or maintain. It is also open to critical-infrastructure operators of any size. Anthropic’s examples are a regional hospital and a municipal utility. Smaller security firms, open-source maintainers, and individual researchers with a track record of reported vulnerabilities can apply too. Anthropic says it expects many defensive teams to qualify, and it aims to answer applications within a few days. Those lines are Anthropic’s.
Red Team Access adds authorized penetration testing and red-teaming on top of that defensive work. A penetration test is a permitted attempt to break into a system so the holes show up before an attacker finds them. Red-teaming is the same idea pointed at an organization or a model: testers try the attack the defender has to stop. Anthropic limits this level to organizations. Individual researchers are not eligible. The testing has to be against systems the organization is authorized to test. Anthropic says reviews should take a few weeks, and that an organization waiting on this level is enrolled in Defense Access in the meantime. Users are still blocked in real time on actions that could cause physical harm or mass disruption. Anthropic’s examples are deploying ransomware, damaging physical systems, or penetration-testing high-risk safety systems. Ransomware is software that locks someone’s files and demands payment. Those lines are Anthropic’s.
Specialized Access has the fewest cyber blocks. Anthropic reserves it for a limited set of verified organizations that are allowed to test systems where a mistake could hurt people or disrupt markets. The examples on the page are flight operating systems, power grids, telecom networks, interbank transfer systems, and government networks. Anthropic says it reviews every organization for this level in depth, together with the U.S. government. Existing Project Glasswing members move into this level. They do not need a new approval for the current models. Those lines are Anthropic’s.
Organizations in the program must let Anthropic keep their data, so Anthropic can watch for misuse. Anthropic states one exception. Organizations that already have zero data retention on Claude Fable 5.1 or Claude Mythos 5.1 can use the program without that data being stored. Zero data retention means the company does not keep the contents of the requests. A planned option called Enterprise Frontier Safeguards is due later this fall. Anthropic describes it as a way to keep the safeguards while the customer stores the data in cloud infrastructure they control. Until that option arrives, the retention rule is the default for everyone else. Those lines are Anthropic’s.
Anthropic tested Claude Opus 5.5 on CyScenarioBench, a set of 10 multi-stage cyberattack scenarios, five tries each. That is 50 trials. A scenario here is a realistic attack with more than one step. Without program access, every task was blocked on the first prompt. In Defense Access, 46 of the 50 trials were blocked at some point, and 4 succeeded. In Red Team Access there were no blocks, and the model completed 34 of the 50 tasks. Thirty-four out of fifty is 68 percent, about two in three. Anthropic says that result is effectively the same as the model’s 67.6 percent success rate on this test with no safeguards at all, and that the no-safeguards run stands in for Specialized Access. Those figures are Anthropic’s.
What the older program already found, as Anthropic states it. Project Glasswing partners found at least 129,000 verified software vulnerabilities between April and July 2026. Verified, in that sentence, is Anthropic’s word for a flaw a partner confirmed. Anthropic’s own open-source scanning found another 5,500 between April and October 2026. More than 33,000 of them were rated critical or high severity. Critical or high means a flaw that can do serious damage, not a minor bug. Anthropic says the total is likely an undercount, because it comes from survey data from only some partners. The page says the third-party count rests on partial data from 33 partner reports. Anthropic says it expects the true impact to be at least five times higher. Several partners told Anthropic that finding the same number of flaws without Claude Mythos would have taken months or years longer. Those lines are Anthropic’s.
Where someone approved for the program can use it. Anthropic says it is available on the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry. On Amazon Bedrock, it is available only for customers eligible for Enterprise Frontier Safeguards. People already in the older Cyber Verification Program keep their current settings on earlier models. Anthropic says they will be evaluated automatically for Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1. Those lines are Anthropic’s.
Reuters reported the same announcement on Tuesday. It says Glasswing partners found at least 129,000 verified vulnerabilities between April and July, and that Anthropic’s own scanning found 5,500 more between April and October, with more than 33,000 rated critical or high severity. It describes the three levels in the same shape as Anthropic’s post. Defense work is open to security teams, infrastructure operators, open-source maintainers, and researchers with a record of reported flaws. Red-team work is for organizations only. The specialized level, reviewed with the U.S. government, is for systems such as power grids, flight systems, and interbank transfers, and existing Glasswing members move there. The byline is Anzar Mehraj in Bengaluru and Jeffrey Dastin in San Francisco. Those lines are Reuters’.
The picture is a chart of the three access levels and of Anthropic’s CyScenarioBench results for Claude Opus 5.5. Three columns name Defense, Red Team, and Specialized access, with who can apply and what each level still blocks. A bar panel beside them shows the block results: all 50 trials blocked with no program access, 46 of 50 blocked in Defense Access, and none blocked in Red Team Access, where the model finished 34 of 50. It is a summary of the announcement. It is not a photograph of a security team or a hospital.
In plain terms, Anthropic on Tuesday folded Project Glasswing and the Cyber Verification Program into one program with three levels. Hospitals, utilities, open-source maintainers, and individual researchers with a record of reported flaws can apply for the defensive level, which Anthropic aims to answer in a few days. Organizations can apply for a red-team level that still blocks ransomware and physical harm. The loosest level is a short list, reviewed with the U.S. government, and today’s Glasswing members move there. On Anthropic’s own test, the same model was stopped on every attack trial with no access, on 46 of 50 in Defense Access, and on none at the Red Team level, where it finished 34 of 50.
