Skip to content
Wednesday, 7 October 2026
Tenesys AI News
Subscribe
Cyber Security· Important

Anthropic expands Cyber Verification Program with three access tiers for security teams

In short: Anthropic has merged its Project Glasswing and Cyber Verification Program into a single, expanded CVP with three access tiers: Defense Access, Red Team Access, and Specialized Access. Each tier unlocks progressively fewer safety blocks on cyber-related tasks in Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1 for vetted security organizations. Anthropic also published benchmark results and vulnerability-discovery numbers from the earlier Glasswing program to justify the expansion.

Source: AnthropicAnthropicClaude Opus 5.5Original article ↗

This summary was generated automatically by AI from Anthropic's publication. It is our own text, not a copy of the original — facts, figures and quotes belong to the source, linked above and below.

What changed?

  • 1Three tiers: Defense Access (SOC/incident response/malware analysis), Red Team Access (adds authorized pen testing), Specialized Access (critical infrastructure testing, reviewed with the US government)
  • 2Access applies to Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and future models
  • 3Data retention required for monitoring; zero-data-retention option available via Claude Fable 5.1/Mythos 5.1 until Enterprise Frontier Safeguards (EFS) launches later this fall
  • 4CyScenarioBench results: 0/50 tasks succeeded without CVP, 4/50 in Defense Access, 34/50 in Red Team Access (matching the 67.6% unrestricted success rate)
  • 5Project Glasswing partners found at least 129,000 verified vulnerabilities (April–July 2026), plus 5,500 more via Anthropic's own open-source scanning, with over 33,000 rated critical/high severity
  • 6CVP available on Claude Platform, Google Vertex AI, Microsoft Foundry, and Amazon Bedrock (for EFS-eligible customers only)

Why it matters

This shows Anthropic actively tuning the dual-use trade-off in frontier models for cybersecurity: generally available Claude models stay heavily restricted on offensive/defensive cyber tasks, while vetted organizations can unlock near-unrestricted capability for vulnerability research and red-teaming. It signals that AI-assisted vulnerability discovery at scale is becoming normalized for security teams with proper vetting.

What it means for AI agents and contact centers

This program targets dedicated security teams doing malware analysis, penetration testing, or critical-infrastructure defense — not typical API users building voice agents or automation. If your stack relies on Claude APIs through general availability, nothing changes for your current usage; this is relevant only if you run a formal security/red-team function and want reduced safeguards for vulnerability research on your own infrastructure.

Sources

  • AnthropicOfficialPrimary source
    „Oct 6, 2026 Announcements Expanding the Cyber Verification Program“
    6 Oct 2026, 22:00
    Original article →
Published by source
6 Oct 2026, 22:00
Found by our system
6 Oct 2026, 22:05
Summary generated
6 Oct 2026, 22:06

This article was written by AI from the original source. Facts, numbers and prices come from the source; missing values are marked “Not specified”. Legal notice, copyright and privacy

Anthropic expands Cyber Verification Program with three access tiers for security teams · TENESYS AI NEWS