Anthropic on Tuesday announced a revamped Cyber Verification Program (CVP), integrating the CVP and Project Glasswing into a single offering, with three levels of access to its most capable AI models.
Anthropic’s generally available models, including Claude Opus 5.5, Sonnet 5.5 and Fable 5.1, ship with cyber safeguards that block most cyber work. The company says this is because the same capabilities that help defenders find and fix flaws can also help attackers exploit them.
Until now, CVP and Glasswing ran as separate programs: Glasswing gave organizations securing critical software access to Claude Mythos, while the original CVP loosened safeguards on Opus and Sonnet models for approved teams.
Under the new structure, all three tiers include Opus 5.5, Sonnet 5.5, Mythos 5.1 and future models. Each tier comes with its own verification requirements and security controls.
The Defense Access tier covers SOC and incident response work, malware reverse engineering, and vulnerability analysis and validation. Eligible applicants include security teams defending their own systems, critical infrastructure operators, small security firms, open source maintainers, and individual researchers with a history of reported vulnerabilities. Anthropic aims to respond to these applications within a few days.
Red Team Access adds authorized penetration testing and red teaming, limited to systems the organization is permitted to test. Actions that could cause physical harm or mass disruption, such as deploying ransomware, are still blocked in real time.
“Currently, this tier is for organizations only; individual researchers are not eligible,” Anthropic said. Reviews are expected to take a few weeks, and qualifying applicants get Defense Access in the meantime.
Specialized Access has the fewest cyber blocks. It’s reserved for a small number of organizations authorized to test safety-critical systems such as power grids, flight systems, telecom networks, and interbank transfer infrastructure. Anthropic currently vets these applicants in collaboration with the US government, and existing Glasswing members are moving into this tier.
Glasswing partners found at least 129,000 verified vulnerabilities between April and July, and Anthropic’s own open source scanning turned up 5,500 more between April and October. More than 33,000 of them are rated critical or high severity. Anthropic says the true impact is likely at least five times higher, as the figures come from only a subset of Glasswing participants.
Organizations in the new program must accept data retention so that Anthropic can monitor for misuse. Later this fall, Enterprise Frontier Safeguards will let eligible customers store data in cloud infrastructure they control. Until then, organizations with zero data retention access to Fable 5.1 or Mythos 5.1 can use CVP with zero data retention.
CVP is available on the Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry. On Amazon Bedrock, it’s only available to customers eligible for Enterprise Frontier Safeguards. Existing CVP members keep their current settings for previous models and will be automatically evaluated for access to the new ones.
Related: Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development
Related: Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says
Related: Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion
