On October 6, 2026, Anthropic announced an expanded Cyber Verification Program (CVP), a structure that lets vetted security teams use its Claude models with fewer cyber-related safeguards. The program now has three access tiers, and it absorbs Project Glasswing, the invitation-only effort that gave a limited group of defenders access to Claude Mythos models. Anthropic also published a headline number: its partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026.
This piece walks through what Anthropic actually said, separates the figures it measured from the ones it estimated, and looks at the larger design question: how an AI lab should gate capabilities that help defenders and attackers alike.
AnthropicWhat the Anthropic Cyber Verification Program changes
Before this announcement, Anthropic ran two separate efforts. Project Glasswing gave critical-software defenders access to Claude Mythos, and the original CVP offered reduced safeguards to vetted security teams. According to Anthropic's post, the two are now one program with a single application path, and Glasswing members move into the top tier without being reapproved.
The structural change is that "vetted" is no longer a single yes-or-no status. Anthropic says the framing it uses is dual use: "the same capabilities that enable a security team to find and fix a vulnerability can also help a malicious actor exploit it." A tiered model lets the company match how many safeguards it removes to how much it knows about who is asking.
Cyber Verification Program: three access tiers
Each step up removes more cyber blocks and adds eligibility requirements.
Unlocks: SOC and incident response, malware reverse engineering, vulnerability analysis and validation
Who: Company security teams, universities, nonprofits, government bodies, infrastructure operators, open-source maintainers, individual researchers with disclosure history
Unlocks: Everything in Defense, plus authorized penetration testing and red-teaming
Who: In-house and government red teams, penetration testing firms (organizations only)
Unlocks: Fewest cyber blocks, for testing safety-critical systems (flight systems, power grids, telecom)
Who: Limited verified organizations, reviewed with the US government; Glasswing members move over automatically
Source: Anthropic, Expanding the Cyber Verification Program, October 6, 2026.
The three tiers, in plain terms
Defense Access is the entry tier. It is meant for security operations center and incident response work, reverse-engineering malware, and analyzing and validating vulnerabilities. Anthropic lists a wide eligibility pool: company security teams, nonprofits, universities, government bodies, critical infrastructure operators, smaller security firms, open-source maintainers, and individual researchers with a vulnerability disclosure history. The company says it aims to respond to applications within a few days.
Red Team Access adds authorized penetration testing and red-teaming. Eligibility is narrower: in-house red teams, government red teams, and security or penetration-testing firms. Per the information Anthropic published, this tier is open to organizations rather than individuals, and reviews are expected to take a few weeks given "increased eligibility requirements and security controls." Real-time blocks remain on actions that could cause physical harm or mass disruption.
Specialized Access has the fewest cyber blocks. It is reserved for organizations authorized to test safety-critical systems such as flight operating systems, power grids and telecom networks, and Anthropic says it reviews these applicants in collaboration with the US government.
All three tiers cover Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, with future models to be added.

Reading the 129,000 figure carefully
The number is large, so the wording matters. Anthropic's post says: "Through the program, our partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026." Three details deserve attention.
- Source and window. The count is attributed to Glasswing partners over four months. A separate 5,500 verified vulnerabilities came from Anthropic's own open-source scanning between April and October.
- Severity. Anthropic says more than 33,000 of the verified vulnerabilities have so far been rated critical or high severity.
- Undercount, by design. The company says the figure is likely an undercount because it rests on survey data from only a subset of Glasswing partners, and it expects the true impact to be "at least five times higher." That multiple is an estimate, not a measurement.
Some early coverage of the announcement attributed the 129,000 to the new Red Team tier. Anthropic's own wording ties it to Glasswing partners' work before the expansion, so the tier name should not be read as the source of the discovery count.
Partners such as Booz Allen and Comcast are cited in the announcement as reporting that Claude Mythos models shortened vulnerability discovery timelines by months or even years. As with any vendor-published testimonial, independent replication of those timelines is not yet available.
What the safeguards test shows
Anthropic also published results from CyScenarioBench, an evaluation of multi-stage cyber operations. Claude Opus 5.5 attempted 10 challenges five times each, giving 50 trials per setting.
Trials blocked by safeguards, by tier
Claude Opus 5.5 on CyScenarioBench, 50 trials per tier.
At Red Team Access, no trials were blocked and 34 of 50 were completed (67.6%). Source: Anthropic, October 2026.
Without program access, all 50 trials were blocked. At Defense Access, 46 of 50 were still blocked. At Red Team Access, none were blocked and the model completed 34 of 50 tasks, a 67.6% success rate that, as reported by SiliconANGLE, Anthropic describes as effectively equivalent to the model with no safeguards applied. Two readings are reasonable. One is that the tiers work as intended: the same prompts produce very different outcomes depending on verified status. The other is that Red Team Access exposes the full offensive capability of the model to anyone who clears the review, which is why the identity and monitoring layers carry so much weight. Both can be true at once.
Cybersecurity is inherently dual use: the same capabilities that enable a security team to find and fix a vulnerability can also help a malicious actor exploit it.
Anthropic, October 6, 2026
Tiered verification versus open access
The CVP sits on a spectrum. At one end is fully open release, where any API key holder gets the same model behavior. At the other is a named-customer model, where capability is available only to organizations a lab has vetted directly. Anthropic's design takes a middle path: general-purpose models stay broadly available with cyber safeguards on, and verification unlocks more behavior in steps.
According to SiliconANGLE and Beri, enrollment also requires data retention so Anthropic can monitor for misuse, with exceptions for organizations that already have retention exemptions or that qualify for Enterprise Frontier Safeguards, which Anthropic has said will let eligible customers keep data in their own cloud. That is a real trade: a defender gets fewer blocks, and the lab gets visibility. Organizations handling sensitive incident data will weigh that differently, which is part of why Anthropic's separate customer-data safeguards matter here (see our earlier post on Enterprise Frontier Safeguards).
The tradeoffs, in short:
- Open access maximizes reach and reproducibility but gives the lab little ability to separate a researcher from an attacker.
- Tiered verification scales with identity evidence and can add monitoring, but it creates review queues, and the definition of "defender" decides who is left out. Individual researchers, for instance, can join the entry tier but not Red Team Access.
- Government-only release offers the tightest control and the least breadth, as covered in our look at approval-gated security models.
How this compares with OpenAI's approach
OpenAI built a structurally similar ladder under its Daybreak effort: a standard model for common defensive work, a Trusted Access for Cyber tier for verified defenders, and a more permissive cyber-specific model for authorized work such as red-teaming. Our earlier coverage details that design, and its follow-up on Daybreak for frontline defenders describes OpenAI's critical-infrastructure push. The notable convergence is the shape, not the details: both labs now stage cyber permissiveness by verified identity rather than offering one setting for everyone. The differences, including review times, retention terms and which systems qualify for the top tier, would need a side-by-side reading of each lab's current policy documents, and we have not attempted a point-by-point comparison here.
What defenders actually get
For a security team, the practical changes are concrete:
- A defined route to fewer refusals on malware analysis, vulnerability validation and incident response, with a stated turnaround of days rather than an open-ended request.
- A path for smaller organizations, open-source maintainers and individual researchers, groups that were not part of the original invitation-only Glasswing cohort.
- Access to Opus 5.5, Sonnet 5.5 and Mythos 5.1 through one program, with new models to follow. SiliconANGLE reports availability through Claude Platform, Google Vertex AI and Microsoft Foundry, with Amazon Bedrock limited to Enterprise Frontier Safeguards-eligible customers.
What to watch
Several questions remain open. Anthropic's 129,000 figure is partner-reported and survey-based, so the eventual breakdown by severity, software type and fix rate will say more than the headline. The review queue for Red Team Access will show whether a few-weeks timeline holds as applications scale. It is also unclear how retention requirements will sit with regulated industries, and how the government-reviewed Specialized tier will be run in practice. Finally, as other labs ship stronger cyber models, expect pressure for tier definitions to converge, or for governments to set them.
Teams that work across several AI vendors, including through model-agnostic tools like Metir, will likely face a patchwork of verification requirements, one per provider, for the foreseeable future.
Sources:
- Expanding the Cyber Verification Program | Anthropic
- Anthropic folds Project Glasswing into an expanded three-tier Cyber Verification Program | SiliconANGLE
- Anthropic Lifts Cyber Blocks for Pen Testers Who Let It Keep Logs | Beri
Image credits
Header and in-body photographs: a US Army National Guard cyber threat intelligence analyst working with a partner-nation officer during a multinational cyber exercise, U.S. Air National Guard photos, public domain, via Wikimedia Commons (header, in-body). Both are illustrative and do not depict the Cyber Verification Program.
