Artificial Intelligence

Anthropic Introduces 3-Tier Cyber Verification Program for AI Access

Anthropic is integrating the CVP and Project Glasswing into a single offering, with three levels of access to its most capable AI models.

Anthropic

Anthropic on Tuesday announced a revamped Cyber Verification Program (CVP), integrating the CVP and Project Glasswing into a single offering, with three levels of access to its most capable AI models.

Anthropic’s generally available models, including Claude Opus 5.5, Sonnet 5.5 and Fable 5.1, ship with cyber safeguards that block most cyber work. The company says this is because the same capabilities that help defenders find and fix flaws can also help attackers exploit them.

Until now, CVP and Glasswing ran as separate programs: Glasswing gave organizations securing critical software access to Claude Mythos, while the original CVP loosened safeguards on Opus and Sonnet models for approved teams.

Under the new structure, all three tiers include Opus 5.5, Sonnet 5.5, Mythos 5.1 and future models. Each tier comes with its own verification requirements and security controls.

The Defense Access tier covers SOC and incident response work, malware reverse engineering, and vulnerability analysis and validation. Eligible applicants include security teams defending their own systems, critical infrastructure operators, small security firms, open source maintainers, and individual researchers with a history of reported vulnerabilities. Anthropic aims to respond to these applications within a few days.

Red Team Access adds authorized penetration testing and red teaming, limited to systems the organization is permitted to test. Actions that could cause physical harm or mass disruption, such as deploying ransomware, are still blocked in real time.

Advertisement. Scroll to continue reading.

“Currently, this tier is for organizations only; individual researchers are not eligible,” Anthropic said. Reviews are expected to take a few weeks, and qualifying applicants get Defense Access in the meantime.

Specialized Access has the fewest cyber blocks. It’s reserved for a small number of organizations authorized to test safety-critical systems such as power grids, flight systems, telecom networks, and interbank transfer infrastructure. Anthropic currently vets these applicants in collaboration with the US government, and existing Glasswing members are moving into this tier.

Glasswing partners found at least 129,000 verified vulnerabilities between April and July, and Anthropic’s own open source scanning turned up 5,500 more between April and October. More than 33,000 of them are rated critical or high severity. Anthropic says the true impact is likely at least five times higher, as the figures come from only a subset of Glasswing participants.

Organizations in the new program must accept data retention so that Anthropic can monitor for misuse. Later this fall, Enterprise Frontier Safeguards will let eligible customers store data in cloud infrastructure they control. Until then, organizations with zero data retention access to Fable 5.1 or Mythos 5.1 can use CVP with zero data retention.

CVP is available on the Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry. On Amazon Bedrock, it’s only available to customers eligible for Enterprise Frontier Safeguards. Existing CVP members keep their current settings for previous models and will be automatically evaluated for access to the new ones.

Related: Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development

Related: Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

Related: Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion

Related Content

Artificial Intelligence

Wikimedia looked into whether its own websites had seen activity like that disclosed by other organizations

Artificial Intelligence

Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP).

Artificial Intelligence

The announcement comes after Trump hosted top executives of AI companies at the White House last week.

Cybersecurity Funding

doxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority.

Artificial Intelligence

The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI.

Artificial Intelligence

Fifteen years after coining the framework, John Kindervag insists zero trust still works in the AI era—if you get the implementation right.

Data Protection

PwC’s survey found that only 22% of leaders would use fully autonomous AI for cyber defense, while just 21% are implementing quantum-resistant security measures.

Artificial Intelligence

As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version