explainx.ai0k
TrendingAI News TodayPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

follow on google

Add explainx.ai as a preferred source

corporate training

support@explainx.ai

get started

Find your pathTake Free Evaluation

community

Join the community

learn

mind: share how you thinkpathways — start freeworkshopsbootcampscoursescompare Explainxcertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsmdx readeragentsllmsdesignsdictionarypeopleagi trackerfelony benchranks

company

aboutvisionmissionteaminstructorsteach on explainxpartnershipscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource libraryfor LLMsexplainx.ai kids

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportcontactprivacytermsdata rightshow we create contentsubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

explainx.ai

On this page

  • TL;DR: the three tiers at a glance
  • What changed compared with the earlier program
  • Tier one: Defense Access
  • Tier two: Red Team Access
  • Tier three: Specialized Access
  • The numbers Anthropic published about Glasswing
  • Why this matters now
  • How to apply
  • What people are likely to ask next
  • Where this connects to data handling
  • What to watch
  • Practical advice for builders
  • Related reading
← Back to blog

explainx / blog

Anthropic Expands Its Cyber Verification Program Into Three Tiers

Anthropic, Cybersecurity, Claude, Project Glasswing, AI Safety

Anthropic merged Project Glasswing into a three-tier Cyber Verification Program with Defense, Red Team and Specialized access. Eligibility and steps.

Oct 7, 2026·8 min read·Yash Thakker
add explainx.ai
go deep
Anthropic Expands Its Cyber Verification Program Into Three Tiers

Anthropic announced on October 6, 2026 that it is expanding its Cyber Verification Program into three access tiers (Defense, Red Team and Specialized) and merging Project Glasswing into the same program. All three tiers cover Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, and applications go through a single portal.

If you do security work with Claude and have been annoyed by refusals on legitimate tasks, this is the most concrete answer Anthropic has given so far. It is also a policy shift: instead of one blunt classifier setting for everyone, access now scales with who you are and what you are authorized to test.

Weekly digest3.5k readers

Catch up on AI

Curated AI updates on agents, skills, and MCP — delivered to your inbox. Unsubscribe anytime.

TL;DR: the three tiers at a glance

table · 4 cols
QuestionDefense AccessRed Team AccessSpecialized Access
Who is it for?Defenders: SOC teams, IR, malware analysts, open-source maintainers, researchersAuthorized offensive teams: in-house, government and pen-test firmsVerified orgs testing safety-critical systems
Individuals eligible?Yes, with a vulnerability-disclosure track recordNo, organizations onlyNo, organizations only
Typical review timeDaysWeeksRun with the US government
What it addsDefensive cyber work such as vulnerability analysis and reverse engineeringAuthorized penetration testing and red-teamingFewest cyber blocks
Still blocked?Offensive abusePhysical harm or mass disruption (ransomware, damaging physical systems)Case by case; reviewed with government

The details above come from Anthropic's announcement. The table compresses it; read the original for exact eligibility language before you apply.

What changed compared with the earlier program

Before this change there were two separate things. The Cyber Verification Program let qualifying security professionals reduce the blocking classifiers on Claude, and Project Glasswing gave a select set of organizations access to Claude Mythos for finding bugs in critical software. We covered the original Glasswing launch in our Mythos Preview and Glasswing explainer.

The expansion does three things:

  1. One front door. Glasswing and the verification program become a single offering with three levels.
  2. A ladder instead of a switch. Defense, then Red Team, then Specialized, each with progressively fewer cyber blocks and progressively stricter vetting.
  3. Model coverage that follows releases. The announcement says new models are included going forward, so you should not need to re-apply each time a model ships.

Anthropic also says the program operates on the Claude Platform, Google Cloud Vertex AI and Microsoft Foundry. That matters for enterprises that buy Claude through a cloud marketplace rather than directly.

Tier one: Defense Access

Defense Access is aimed at the broadest group. Anthropic names company security teams, nonprofits, universities, government bodies, critical infrastructure operators, smaller security firms, open-source maintainers and individual researchers who have a vulnerability-disclosure track record. The covered work includes security operations center tasks, incident response, malware reverse engineering and vulnerability analysis.

Two things stand out. First, individuals can qualify, which is rare in programs like this. If you maintain an open-source library or have published coordinated disclosures, you are the target audience. Second, review is quick: Anthropic says days, not weeks.

What this does not do is turn Claude into an offensive tool. The tier is framed around defensive outcomes.

Tier two: Red Team Access

Red Team Access adds authorized penetration testing and red-teaming on top of the defensive uses. It is organizations-only: in-house red teams, government red teams, and security or penetration-testing firms. Individual researchers are not eligible, and Anthropic says the review takes weeks.

The condition that matters most is authorization. Testing has to target systems the organization is authorized to assess. Anthropic also keeps real-time blocks for actions that could cause physical harm or mass disruption, with ransomware, physical system damage and high-risk safety-system testing given as examples.

For a pen-test firm that has been routing around refusals by splitting tasks into innocuous-looking pieces, this is a clearer path: apply, document your engagement controls, and work inside a defined boundary.

Tier three: Specialized Access

Specialized Access has the fewest cyber blocks and is reserved for verified organizations authorized to test safety-critical systems. Anthropic gives flight operating systems, power grids, telecom networks, interbank infrastructure and government networks as examples. Today it is reviewed in collaboration with the US government.

Existing Project Glasswing members transition into this tier automatically without being reapproved. That is the clearest signal that Glasswing is no longer a separate brand with its own gate.

The numbers Anthropic published about Glasswing

The announcement includes results from the Glasswing period. Partners identified at least 129,000 verified vulnerabilities between April and July 2026, and Anthropic's open-source efforts found an additional 5,500 between April and October 2026. More than 33,000 have been rated critical or high severity. One partner said discovery would have taken "months or even years" longer without the technology.

Treat these as Anthropic-reported figures. The post does not break down how severity was assigned or how many of the findings have patches. For independent context on how many AI-found bugs become exploitable, see our VulnCheck exploit-rate analysis.

Why this matters now

Cyber access has been a recurring fault line in 2026. Open-weight models posted Mythos-class cyber evaluation scores, which undercuts the idea that closed-model guardrails alone keep capability away from attackers. Critics argued the same guardrails block US defenders while doing little to slow determined offensive actors. OpenAI has taken a parallel route with its defense factory of cyber agents.

A tiered verification program is Anthropic's attempt to answer both complaints. It keeps the strongest capabilities behind identity and authorization checks, while giving defenders a faster lane. Whether it works depends on two things nobody outside Anthropic can measure yet: how often legitimate teams are rejected, and how many bad actors pass vetting.

There is also a political layer. Anthropic recently barred the UK AI Security Institute from pre-release testing of Mythos 5.1, and the company's security and alignment update described real incidents involving its own models. Routing the riskiest tier through the US government fits that pattern of selective, government-adjacent access.

How to apply

Anthropic says organizations apply through its portal at portal.anthropic.com/programs/cvp and that verification and security-control documentation is required. Before you start, gather:

  • Proof of who you are: legal entity, security team charter, or for individuals a public disclosure history.
  • A scope statement: what systems you defend or test, and who authorized the testing.
  • Security controls: how you protect API keys, logs and any vulnerable code the model sees.
  • A use-case list: SOC triage, malware analysis, patch generation, authorized red-team ops.

If you buy Claude through a cloud, check whether your enterprise agreement needs the program enabled at the platform level. The announcement lists Vertex AI and Foundry alongside Anthropic's own platform.

What people are likely to ask next

Does a verified account make Claude write working exploits? Anthropic does not say that in the announcement. It describes fewer blocks on authorized work, not a promise of unlimited output, and the Red Team tier keeps hard stops on harmful actions.

Do I lose access if I misuse it? The post describes verification and security-control documentation as requirements, which implies the status can be revoked. Read the program terms in the portal for the exact consequences before you build a workflow that depends on it.

Is this a replacement for responsible disclosure? No. Finding more bugs faster only helps if maintainers can triage them. The Glasswing figures above are a reminder that the bottleneck is increasingly patching, not discovery.

Where this connects to data handling

Cyber access is only half of the enterprise story. Anthropic's earlier Enterprise Frontier Safeguards announcement describes a solution that combines zero data retention with misuse detection, letting customers keep data in their own cloud accounts. Anthropic's CVP announcement adds that Amazon Bedrock access requires Enterprise Frontier Safeguards eligibility. For a security team, the practical reading is that sensitive vulnerability data can stay in your environment while you use a less restricted model tier. Rollout of that safeguard is described as phased starting fall 2026.

What to watch

  • Rejection rates and turnaround. Days for Defense and weeks for Red Team are Anthropic's stated expectations; real-world experience will tell.
  • Whether other labs copy the ladder. OpenAI and Google both gate cyber-capable models in different ways, as in our Fable 5.1 versus Astra comparison.
  • Government involvement. If the Specialized tier stays tied to US government review, non-US critical infrastructure operators may face a gap, a theme that also showed up in Mythos 5 EU access.
  • Model coverage. The announced set (Opus 5.5, Sonnet 5.5, Mythos 5.1) is where you can test now; see the Mythos 5.1 launch benchmarks for what the strongest model can do.

Practical advice for builders

If you build security products on Claude, do not assume your customers have access. Your end users' classifier settings follow the account making the API call, so a product that proxies requests may still hit blocks unless the underlying organization is verified. Ask your design partners whether they plan to apply, and document which tier your features require.

If you are a solo researcher, start with Defense Access and a clean disclosure record. If you run a pen-test practice, begin collecting engagement paperwork now, because Red Team review takes weeks.

Details reflect Anthropic's October 6, 2026 announcement and may change as the program rolls out.

Related reading

  • Claude Mythos Preview and Project Glasswing
  • Mythos 5.1 and Fable 5.1 launch benchmarks and pricing
  • Claude Opus 5.5 launch, benchmarks and pricing
  • VulnCheck: AI-found bugs and exploit rates
  • Open-weight GLM-5.3 and Mythos-class cyber evals
  • AI cyber guardrails and US defenders
  • OpenAI's defense factory of cyber agents
Spotted something out of date? Let us know.
Yash Thakker

Written by

Yash Thakker

Yash is an AI expert with over 300K learners. Join his workshops →

View Yash Thakker in People in AI →

Related posts

Sep 11, 2026

Anthropic Threat Intelligence Report: Claude Misuse Across Cyber, Weapons, Bio, and Distillation

On September 10, 2026 Anthropic published its most detailed Threat Intelligence report yet — case studies of Claude misuse disrupted between December 2025 and August 2026 across seven harm areas. explainx.ai separates what is in the primary report (including China-linked anti-torpedo work and Alibaba's 151M+ distillation campaign) from claims circulating on X and prediction markets.

Sep 10, 2026

Anthropic Says Claude Models Were Used in 15 Real-World System Breaches

Anthropic disclosed that Claude models were used as part of the toolchain in 15 separate real-world security incidents, described as the first time the company has reported model involvement in confirmed breaches at this scale. explainx.ai walks through what "used in a breach" actually means, how it fits Anthropic's own alignment reporting this year, and what it means for anyone running Claude in production.

Sep 1, 2026

Anthropic's September Update: Securing Evals After the Cyber Incidents

Anthropic published a follow-up to July's three cybersecurity-evaluation incidents, detailing new sandbox and monitoring defenses, practices asked of external eval partners, reward-hacking research, and the security hardening done ahead of Mythos-class models. explainx.ai unpacks the specifics and the "without safeguards" confusion in the reactions.