Anthropic Opens Claude Access to Verified Cyber Defenders

Anthropic has significantly expanded its Cyber Verification Program, introducing new access tiers that grant verified cybersecurity professionals looser restrictions when using its Claude models. The rollout, announced October 6, 2026, includes three distinct permission levels: Defense Access, Red Team Access, and Specialized Access. These adjustments are designed to match each team’s security role with appropriate access privileges.

What’s new in Anthropic’s Cyber Verification Program

The upgraded program now covers Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and will extend to future models. It unifies prior programs—including ‘Project Glasswing’—into a single framework where permissions align with actual task types. Public versions of Claude still feature tight cyber safeguards, while verified users can perform broader, higher-risk experiments under controlled conditions.

The Three Access Tiers in Detail

Defense Access is tailored for entities like corporate security teams, academic institutions, government bodies, hospitals, utilities, smaller security firms, open-source maintainers, and researchers with credible vulnerability disclosure histories. It covers work like incident response, malware reverse engineering, vulnerability analysis, and security operations. Anthropic aims for approval within a few days.

Red Team Access grants permission for authorized penetration testing and red-teaming. This level is limited to organizations—including internal red teams, government-sponsored test teams, or external security firms—with explicit permission to evaluate their targets. While controls remain in place to prevent misuse—such as blocking ransomware deployment or harmful intrusions into safety-critical systems—Red Team Access allows more hands-on testing. Defenders receiving this access may already receive Defense Access to begin their work sooner while their Red Team review is underway.

Specialized Access is the most permissive tier, reserved for organizations that require deep access to test infrastructures like power grids, aviation systems, telecom networks, interbank systems, or core government infrastructure. Anthropic conducts rigorous review in partnership with U.S. government bodies. Members of the former Glasswing cohort are automatically migrated into this tier without needing to reapply for current model access.

Testing Results and Transparency

Anthropic used CyScenarioBench, a benchmark assessing multi-stage cybersecurity operations, to test Opus 5.5. With public access, every malicious task was blocked at the first prompt. Under Defense Access, 46 out of 50 attempts were blocked, while four succeeded. In the Red Team tier, none of the controls blocked testing, and 34 out of 50 tasks were completed—approaching the roughly 67.6% success rate seen without any safeguards. These results stem from company benchmarks, not proof of invulnerability.

Between April and July 2026, Glasswing partners reported over 129,000 verified vulnerabilities. An additional 5,500 vulnerabilities were flagged through open-source scanning between April and October. Of all findings, more than 33,000 were judged to be high or critical risk. However, fewer than half of discoveries revealed closure statistics, so the overall number of resolved issues remains unclear.

Anthropic’s program requires data retention for misuse monitoring, except in certain zero-retention cases. A planned initiative called Enterprise Frontier Safeguards will let eligible organizations host monitoring data in cloud environments they control. Applicants can apply for access through Claude Platform, Google Cloud Vertex AI, and Microsoft Foundry; Amazon Bedrock is available for those who meet its specific EFS requirements. Existing participants maintain their prior access settings and are automatically evaluated for newer models.

This matters because developers need balance: enabling thorough testing without opening the door for misuse. Anthropic’s tiered approach gives more flexibility—and risk—to verified defenders under oversight, while keeping the public-facing model restrained.