Cybersecurity

Anthropic Expands Cyber Verification Program with Three Access Levels for Defenders

Anthropic announced the expansion of its Cyber Verification Program to provide advanced cyber capabilities and reduced safeguards to verified security teams through three access levels. The company’s tests show that restricted access kept most offensive scenarios blocked while allowing greater capabilities for authorized testing teams.

2026-10-06
4 min read
4 views
certi.news Editorial Team
Anthropic Expands Cyber Verification Program with Three Access Levels for Defenders

On October 6, 2026, Anthropic announced the expansion of the Cyber Verification Program (CVP), enabling qualified security organizations to use advanced cyber capabilities and less restrictive classification safeguards according to the nature of their work. The program includes the Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1 models, as well as future models.

Three Levels Based on the Type of Work

The program begins with the Defense Access level, designated for defensive operations such as security operations center and incident response tasks, malware reverse engineering, and vulnerability analysis and validation. Potential organizations include security teams at companies, universities, and government agencies; critical infrastructure operators; smaller security companies; open-source project maintainers; and individual researchers with a documented record of reporting vulnerabilities. Anthropic expects to respond to applications within days.

Red Team Access adds penetration testing and adversary simulation teams, provided that testing is limited to systems the applicants are authorized to test. Actions such as deploying ransomware, damaging physical systems, or testing high-risk safety systems remain categorically prohibited. This level is currently limited to organizations, and its review may take weeks, with qualified applicants temporarily enrolled in Defense Access.

Specialized Access is reserved for a limited number of verified organizations authorized to test systems whose disruption could affect people’s lives or markets, such as aircraft operating systems, power grids and telecommunications networks, interbank transfer infrastructure, and government networks. Anthropic reviews every organization at this level in cooperation with the U.S. government. Current Project Glasswing members will also move to the new level without re-certification for the current models.

Testing the Balance Between Utility and Prevention

Anthropic tested the Claude Opus 5.5 model using CyScenarioBench, an evaluation that measures the planning and execution of multi-stage cyber operations in realistic conditions. Without CVP access, all ten tasks were blocked on the first attempt. In Defense Access, 46 of 50 attempts were blocked at some point, while four attempts succeeded. In Red Team Access, no blocking occurred, and the model completed 34 of 50 tasks—the same result, approximately, that it recorded when run without safeguards, with a success rate of 67.6%.

What Changes in Practice?

The fundamental change is not opening cyber capabilities to everyone, but separating them from generally available models through multilevel verification that links the model’s power to the type of authorization and the required controls. General models remain suitable for code review, patching known issues, finding vulnerabilities in owned code, and triaging security alerts.

Anthropic says that Project Glasswing partners discovered at least 129,000 documented software vulnerabilities between April and July 2026, while the company’s open-source scanning operations found an additional 5,500 vulnerabilities between April and October. More than 33,000 of them have so far been classified as critical or high-risk, with the company warning that the figures may be lower than the actual number because they rely in part on scanning data from a sample of partners.

Joining the program requires retaining data to monitor cyber misuse. Anthropic says eligible organizations will later be able to use Enterprise Frontier Safeguards, which combines zero data retention with safety controls and stores data in a cloud infrastructure controlled by the organization. Until it becomes available, some users of Claude Fable 5.1 or Claude Mythos 5.1 with zero data retention can use CVP under this policy.

certi.news analysis: The program reflects a practical attempt to solve the dual-use dilemma in artificial intelligence models: preventing general offensive use without depriving defense teams of tools that could accelerate vulnerability discovery. However, the test results were produced by Anthropic itself, and moving to higher access levels requires institutional verification and ongoing oversight, while the timing of EFS availability and the detailed eligibility assessment mechanism remain open questions.

News source
Anthropic Newsroom
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news