Anthropic Adds Three Security Access Tiers With Fewer Claude Restrictions
The updated program separates defensive work from authorized attack testing. Anthropic’s benchmark shows sharply different blocking behavior, while enrollment brings verification and monitoring requirements.
Anthropic’s consolidated Cyber Verification Program sets three permission tiers for vetted security work, from defensive analysis to limited testing of safety-critical infrastructure. In the company’s 50-trial-per-tier evaluation, Red Team Access removed blocks from all trials and completed 34, while Defense Access blocked 46; the result measures benchmark task completion, not real-world misuse. Access still requires verification and monitoring, and safeguards against ransomware and potentially disruptive physical-system tests remain in place.
01
Without Cyber Verification Program access, all 50 offensive-task trials were blocked on the first prompt; with Defense Access, four succeeded despite 46 encountering blocks.
02
Specialized Access is limited to verified organizations testing safety-critical systems, with Anthropic reviewing applicants alongside the U.S. government.
03
Anthropic expects to respond to Defense Access applicants within days and to review Red Team Access applications over a few weeks.
Anthropic is giving vetted security teams fewer restrictions on Claude—but not the same freedom to act. Its expanded Cyber Verification Program, announced October 6, 2026, promises broader access for defenders. In the company’s offensive-task evaluation, however, Defense Access blocked most trials, while Red Team Access allowed every trial to proceed without a block.
The update combines the previous program and Project Glasswing into one offering. All three tiers include advanced models such as Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1. Permissions, verification requirements and security controls differ by the work an applicant needs to do.
Permission follows the kind of security work
Defense Access covers incident response, malware analysis and vulnerability validation. Potential applicants include company security teams, hospitals, utilities, open-source maintainers and individual researchers with a record of reported vulnerabilities. Anthropic aims to respond within a few days.
Red Team Access adds penetration testing—authorized attempts to break into systems—and other adversarial testing. It is currently limited to organizations, excluding individual researchers. Reviews are expected to take a few weeks; qualifying applicants receive Defense Access during that review.
Specialized Access has the fewest cyber blocks. It is reserved for a limited set of verified organizations authorized to test safety-critical systems, including power grids and flight operating systems. Anthropic reviews each organization with the U.S. government. Existing Glasswing members transition without reapproval for current models.
Red Team Access is not unrestricted. Anthropic says real-time blocks still apply to actions that could cause physical harm or mass disruption, including ransomware deployment and testing high-risk safety systems.
The benchmark measures the permission boundary
Anthropic tested Opus 5.5 on CyScenarioBench, which measures planning and execution of multistage cyber operations under realistic constraints. It ran five attempts on each of 10 challenges per tier. These were complex offensive scenarios, so the company expected blocks under Defense Access.
The company described Red Team Access performance as effectively equivalent to its 67.6% success rate without safeguards. That comparison concerns completion of these challenges, not a measured rate of real-world misuse.
Broader access comes with monitoring
Enrollment generally requires data retention so Anthropic can monitor misuse. Its planned Enterprise Frontier Safeguards solution, due later this fall, would let eligible organizations store data in cloud infrastructure they control. Until then, organizations already using Fable 5.1 or Mythos 5.1 with zero data retention can retain that arrangement in the program.
Applicants must provide proof of the security controls required for their tier. The program is available through the Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry. Amazon Bedrock access is limited to customers eligible for Enterprise Frontier Safeguards.
Sources
anthropic.comExpanding the Cyber Verification Program
Reader comments
Newest comments first. Replies stay oldest first.