AI News: Anthropic Opens Three-Tier Claude Access for Verified Cyber Teams

Anthropic expanded its Cyber Verification Program on October 6, 2026, giving vetted security professionals broader access to Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1 with fewer cyber-related blocking controls. The move is the latest AI news development to treat advanced models as tools for controlled defensive research as well as authorized offensive testing.
What changed in Anthropic’s cyber program?
Anthropic replaced separate access paths with a three-tier program that matches model permissions to a team’s role and the potential consequences of its work. The company said the revised structure combines its original Cyber Verification Program with Project Glasswing, an initiative focused on testing critical software.
- Defense Access: intended for incident response, malware analysis, vulnerability research and defensive work on systems the applicant owns or maintains.
- Red Team Access: adds authorized penetration testing and red-team exercises. Organizations, rather than individual applicants, are eligible for this level.
- Specialized Access: reserved for a smaller group testing safety-critical systems, including power grids, flight systems and interbank transfer infrastructure.
According to Anthropic, every tier includes access to Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and future models, although the safeguards and verification requirements differ by tier.
Why is Anthropic reducing some safeguards?
Cybersecurity testing can resemble malicious activity when an AI system examines malware, writes exploit code or probes a network. Anthropic’s program is designed to reduce false refusals for verified professionals while retaining controls around who can use the models, what they can test and how high-risk activity is reviewed.
The company described the expanded program as a way to make advanced cyber capabilities available to qualifying security teams. Anthropic wrote, “We’re launching a new, expanded version of our Cyber Verification Program (CVP), which makes advanced cyber capabilities and reduced blocking classifiers available to qualifying security professionals.”
The distinction matters because unrestricted access could help defenders and attackers alike. Anthropic is therefore tying access to identity checks, organizational responsibility and the intended environment. The structure does not make advanced cyber assistance available to the public at large.
Who can apply for access?
Anthropic’s stated target group includes security teams, critical-infrastructure operators, open-source maintainers and researchers with a record of reporting vulnerabilities. Applicants must show that their work is authorized and that they can operate the models within the required security controls.
- Security operations and incident-response teams can seek defensive access.
- Organizations conducting authorized penetration tests can seek Red Team Access.
- Teams working on safety-critical infrastructure face the narrowest eligibility rules.
- Existing Project Glasswing members are moving into the Specialized Access tier, according to Anthropic’s program description.
Anthropic has not publicly stated how many organizations will receive each tier or how many applications it expects to approve. That leaves the program’s eventual scale unclear.
What did Project Glasswing find?
Project Glasswing provides the main evidence behind Anthropic’s decision to widen access. Reuters reported on October 6, 2026, that the initiative helped uncover more than 100,000 software vulnerabilities during 2026. The figure refers to findings associated with the project, not to the number of confirmed exploitable flaws in critical infrastructure.
The earlier effort had operated for roughly six months before Anthropic folded it into the expanded program, according to Reuters’ report. Anthropic’s own Glasswing page describes the initiative as an effort to secure critical software for the AI era.
That history also explains the new specialized tier. Testing a consumer application carries different risks from testing systems that control electricity, aircraft or financial transfers. Anthropic’s framework separates those activities instead of applying one permission level to every security researcher.
How does the new structure compare with the previous program?
The earlier version covered Claude Opus and Claude Sonnet through a single access level, according to Anthropic’s support documentation updated in October 2026. The revised framework introduces three levels and adds Claude Mythos 5.1 to the listed model lineup.
- Previous structure: one principal access level for verified cyber work.
- New structure: Defense, Red Team and Specialized tiers.
- Model access: Opus 5.5, Sonnet 5.5, Mythos 5.1 and future models are listed across the new tiers.
- Program scope: the former CVP and Project Glasswing now sit under one framework.
The revised design gives Anthropic more room to distinguish routine defensive analysis from work that could affect public safety or financial stability. It also gives security organizations a defined route to request capabilities that ordinary users cannot access.
What risks remain for security teams?
Fewer blocking controls can improve the usefulness of a model for legitimate testing, but the same capability can produce harmful instructions if a user misrepresents an authorization. The program’s protection therefore depends on verification, monitoring and the applicant’s ability to contain testing inside approved systems.
Specialized Access carries the highest potential impact. Anthropic says reviews for work involving critical systems are currently handled in collaboration with the U.S. government, according to reporting published by AI Weekly on October 6, 2026. Anthropic has not disclosed the complete review criteria or the government agencies involved.
Model access also does not replace professional judgment. A generated exploit may be inaccurate, unsafe or unsuitable for a live environment. Security teams still need change controls, testing boundaries and human approval before applying model output to production systems.
What happens next?
Anthropic will process applications under the three-tier model and transition existing Glasswing participants into Specialized Access. The company’s announcement says new models will be added to the program in the future, but it does not provide a timetable or promise access to every applicant.
The next test will be operational. Anthropic will need to show that broader access improves vulnerability discovery without allowing unauthorized intrusion or dangerous experimentation. Independent reporting will also be needed to assess the reported findings, the number of approved teams and any security incidents linked to the program.
For defenders, the expansion creates a controlled path to use frontier models in incident response and authorized testing. For model providers, it raises a harder question: how much capability can be released safely when the work itself requires bypassing some of the restrictions designed to prevent cyber abuse?


