metir
metir
Docs
Download on App StoreGet it on Google PlayLog inSign up
Back to Blog
Anthropic
Cybersecurity
Project Glasswing
AI Safety
Claude Opus 5.5

Anthropic Cyber Verification Program: 3 Tiers, 129,000 Bugs

Anthropic folded Project Glasswing into an expanded Cyber Verification Program with three access tiers. What each tier unlocks, and what the 129,000 figure covers.

Metir AI TeamOctober 7, 20268 min read
Anthropic Cyber Verification Program: 3 Tiers, 129,000 Bugs

On October 6, 2026, Anthropic announced an expanded Cyber Verification Program (CVP), a structure that lets vetted security teams use its Claude models with fewer cyber-related safeguards. The program now has three access tiers, and it absorbs Project Glasswing, the invitation-only effort that gave a limited group of defenders access to Claude Mythos models. Anthropic also published a headline number: its partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026.

This piece walks through what Anthropic actually said, separates the figures it measured from the ones it estimated, and looks at the larger design question: how an AI lab should gate capabilities that help defenders and attackers alike.

Anthropic logoAnthropic
Anthropic's Cyber Verification Program now covers Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1.
129,000Verified vulnerabilities found by Glasswing partnersApril to July 2026
33,000+Rated critical or high severityof the verified vulnerabilities, so far
5,500Found by Anthropic's own open-source scanningApril to October 2026
3Access tiersDefense, Red Team, Specialized

What the Anthropic Cyber Verification Program changes

Before this announcement, Anthropic ran two separate efforts. Project Glasswing gave critical-software defenders access to Claude Mythos, and the original CVP offered reduced safeguards to vetted security teams. According to Anthropic's post, the two are now one program with a single application path, and Glasswing members move into the top tier without being reapproved.

The structural change is that "vetted" is no longer a single yes-or-no status. Anthropic says the framing it uses is dual use: "the same capabilities that enable a security team to find and fix a vulnerability can also help a malicious actor exploit it." A tiered model lets the company match how many safeguards it removes to how much it knows about who is asking.

Cyber Verification Program: three access tiers

Each step up removes more cyber blocks and adds eligibility requirements.

1. Defense AccessReview: A few days

Unlocks: SOC and incident response, malware reverse engineering, vulnerability analysis and validation

Who: Company security teams, universities, nonprofits, government bodies, infrastructure operators, open-source maintainers, individual researchers with disclosure history

2. Red Team AccessReview: A few weeks

Unlocks: Everything in Defense, plus authorized penetration testing and red-teaming

Who: In-house and government red teams, penetration testing firms (organizations only)

3. Specialized AccessReview: Case by case

Unlocks: Fewest cyber blocks, for testing safety-critical systems (flight systems, power grids, telecom)

Who: Limited verified organizations, reviewed with the US government; Glasswing members move over automatically

Source: Anthropic, Expanding the Cyber Verification Program, October 6, 2026.

The three tiers, in plain terms

Defense Access is the entry tier. It is meant for security operations center and incident response work, reverse-engineering malware, and analyzing and validating vulnerabilities. Anthropic lists a wide eligibility pool: company security teams, nonprofits, universities, government bodies, critical infrastructure operators, smaller security firms, open-source maintainers, and individual researchers with a vulnerability disclosure history. The company says it aims to respond to applications within a few days.

Red Team Access adds authorized penetration testing and red-teaming. Eligibility is narrower: in-house red teams, government red teams, and security or penetration-testing firms. Per the information Anthropic published, this tier is open to organizations rather than individuals, and reviews are expected to take a few weeks given "increased eligibility requirements and security controls." Real-time blocks remain on actions that could cause physical harm or mass disruption.

Specialized Access has the fewest cyber blocks. It is reserved for organizations authorized to test safety-critical systems such as flight operating systems, power grids and telecom networks, and Anthropic says it reviews these applicants in collaboration with the US government.

All three tiers cover Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, with future models to be added.

A US Army National Guard cyber analyst pointing at a monitor while a partner-nation officer works at a computer during cyber skills training
A US Army National Guard cyber threat intelligence analyst works alongside a partner-nation officer during a multinational cyber training exercise. Illustrative of defensive security work generally; it does not depict the Cyber Verification Program. U.S. Air National Guard photo, public domain.

Reading the 129,000 figure carefully

The number is large, so the wording matters. Anthropic's post says: "Through the program, our partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026." Three details deserve attention.

  • Source and window. The count is attributed to Glasswing partners over four months. A separate 5,500 verified vulnerabilities came from Anthropic's own open-source scanning between April and October.
  • Severity. Anthropic says more than 33,000 of the verified vulnerabilities have so far been rated critical or high severity.
  • Undercount, by design. The company says the figure is likely an undercount because it rests on survey data from only a subset of Glasswing partners, and it expects the true impact to be "at least five times higher." That multiple is an estimate, not a measurement.

Some early coverage of the announcement attributed the 129,000 to the new Red Team tier. Anthropic's own wording ties it to Glasswing partners' work before the expansion, so the tier name should not be read as the source of the discovery count.

Partners such as Booz Allen and Comcast are cited in the announcement as reporting that Claude Mythos models shortened vulnerability discovery timelines by months or even years. As with any vendor-published testimonial, independent replication of those timelines is not yet available.

What the safeguards test shows

Anthropic also published results from CyScenarioBench, an evaluation of multi-stage cyber operations. Claude Opus 5.5 attempted 10 challenges five times each, giving 50 trials per setting.

Trials blocked by safeguards, by tier

Claude Opus 5.5 on CyScenarioBench, 50 trials per tier.

No program (generally available)50 of 50 blocked
Defense Access46 of 50 blocked
Red Team Access0 of 50 blocked

At Red Team Access, no trials were blocked and 34 of 50 were completed (67.6%). Source: Anthropic, October 2026.

Without program access, all 50 trials were blocked. At Defense Access, 46 of 50 were still blocked. At Red Team Access, none were blocked and the model completed 34 of 50 tasks, a 67.6% success rate that, as reported by SiliconANGLE, Anthropic describes as effectively equivalent to the model with no safeguards applied. Two readings are reasonable. One is that the tiers work as intended: the same prompts produce very different outcomes depending on verified status. The other is that Red Team Access exposes the full offensive capability of the model to anyone who clears the review, which is why the identity and monitoring layers carry so much weight. Both can be true at once.

“

Cybersecurity is inherently dual use: the same capabilities that enable a security team to find and fix a vulnerability can also help a malicious actor exploit it.

Anthropic, October 6, 2026

Tiered verification versus open access

The CVP sits on a spectrum. At one end is fully open release, where any API key holder gets the same model behavior. At the other is a named-customer model, where capability is available only to organizations a lab has vetted directly. Anthropic's design takes a middle path: general-purpose models stay broadly available with cyber safeguards on, and verification unlocks more behavior in steps.

According to SiliconANGLE and Beri, enrollment also requires data retention so Anthropic can monitor for misuse, with exceptions for organizations that already have retention exemptions or that qualify for Enterprise Frontier Safeguards, which Anthropic has said will let eligible customers keep data in their own cloud. That is a real trade: a defender gets fewer blocks, and the lab gets visibility. Organizations handling sensitive incident data will weigh that differently, which is part of why Anthropic's separate customer-data safeguards matter here (see our earlier post on Enterprise Frontier Safeguards).

The tradeoffs, in short:

  • Open access maximizes reach and reproducibility but gives the lab little ability to separate a researcher from an attacker.
  • Tiered verification scales with identity evidence and can add monitoring, but it creates review queues, and the definition of "defender" decides who is left out. Individual researchers, for instance, can join the entry tier but not Red Team Access.
  • Government-only release offers the tightest control and the least breadth, as covered in our look at approval-gated security models.

How this compares with OpenAI's approach

OpenAI built a structurally similar ladder under its Daybreak effort: a standard model for common defensive work, a Trusted Access for Cyber tier for verified defenders, and a more permissive cyber-specific model for authorized work such as red-teaming. Our earlier coverage details that design, and its follow-up on Daybreak for frontline defenders describes OpenAI's critical-infrastructure push. The notable convergence is the shape, not the details: both labs now stage cyber permissiveness by verified identity rather than offering one setting for everyone. The differences, including review times, retention terms and which systems qualify for the top tier, would need a side-by-side reading of each lab's current policy documents, and we have not attempted a point-by-point comparison here.

What defenders actually get

For a security team, the practical changes are concrete:

  • A defined route to fewer refusals on malware analysis, vulnerability validation and incident response, with a stated turnaround of days rather than an open-ended request.
  • A path for smaller organizations, open-source maintainers and individual researchers, groups that were not part of the original invitation-only Glasswing cohort.
  • Access to Opus 5.5, Sonnet 5.5 and Mythos 5.1 through one program, with new models to follow. SiliconANGLE reports availability through Claude Platform, Google Vertex AI and Microsoft Foundry, with Amazon Bedrock limited to Enterprise Frontier Safeguards-eligible customers.

What to watch

Several questions remain open. Anthropic's 129,000 figure is partner-reported and survey-based, so the eventual breakdown by severity, software type and fix rate will say more than the headline. The review queue for Red Team Access will show whether a few-weeks timeline holds as applications scale. It is also unclear how retention requirements will sit with regulated industries, and how the government-reviewed Specialized tier will be run in practice. Finally, as other labs ship stronger cyber models, expect pressure for tier definitions to converge, or for governments to set them.

Teams that work across several AI vendors, including through model-agnostic tools like Metir, will likely face a patchwork of verification requirements, one per provider, for the foreseeable future.

Sources:

  • Expanding the Cyber Verification Program | Anthropic
  • Anthropic folds Project Glasswing into an expanded three-tier Cyber Verification Program | SiliconANGLE
  • Anthropic Lifts Cyber Blocks for Pen Testers Who Let It Keep Logs | Beri

Image credits

Header and in-body photographs: a US Army National Guard cyber threat intelligence analyst working with a partner-nation officer during a multinational cyber exercise, U.S. Air National Guard photos, public domain, via Wikimedia Commons (header, in-body). Both are illustrative and do not depict the Cyber Verification Program.

Ready to experience AI that adapts to you?

metir brings together the world's best AI models in one seamless experience. Start for free today.

Get Started Free
metir

Agentic Operating System for Professionals buried in meetings, emails and docs.

© 2026 metir. All rights reserved.

Product

  • Features
  • Pricing
  • Research
  • Docs
  • Blog
  • Enterprise

Company

  • Docs
  • Support
  • Careers

Legal

  • Terms of service
  • Privacy policy

Personalisation is powerful. Privacy is non-negotiable.

Status: All systems operational