Anthropic Adds Three Security Access Tiers With Fewer Claude Restrictions
The updated program separates defensive work from authorized attack testing. Anthropic’s benchmark shows sharply different blocking behavior, while enrollment brings verification and monitoring requirements.
Anthropic’s consolidated Cyber Verification Program sets three permission tiers for vetted security work, from defensive analysis to limited testing of safety-critical infrastructure. In the company’s 50-trial-per-tier evaluation, Red Team Access removed blocks from all trials and completed 34, while Defense Access blocked 46; the result measures benchmark task completion, not real-world misuse. Access still requires verification and monitoring, and safeguards against ransomware and potentially disruptive physical-system tests remain in place.
01
Without Cyber Verification Program access, all 50 offensive-task trials were blocked on the first prompt; with Defense Access, four succeeded despite 46 encountering blocks.
02
Specialized Access is limited to verified organizations testing safety-critical systems, with Anthropic reviewing applicants alongside the U.S. government.
03
Anthropic expects to respond to Defense Access applicants within days and to review Red Team Access applications over a few weeks.
Anthropic is giving vetted security teams fewer restrictions on Claude—but not the same freedom to act. Its expanded Cyber Verification Program, announced October 6, 2026, promises broader access for defenders. In the company’s offensive-task evaluation, however, Defense Access blocked most trials, while Red Team Access allowed every trial to proceed without a block.
The update combines the previous program and Project Glasswing into one offering. All three tiers include advanced models such as Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1. Permissions, verification requirements and security controls differ by the work an applicant needs to do.
Permission follows the kind of security work
Defense Access covers incident response, malware analysis and vulnerability validation. Potential applicants include company security teams, hospitals, utilities, open-source maintainers and individual researchers with a record of reported vulnerabilities. Anthropic aims to respond within a few days.
Red Team Access adds penetration testing—authorized attempts to break into systems—and other adversarial testing. It is currently limited to organizations, excluding individual researchers. Reviews are expected to take a few weeks; qualifying applicants receive Defense Access during that review.
Specialized Access has the fewest cyber blocks. It is reserved for a limited set of verified organizations authorized to test safety-critical systems, including power grids and flight operating systems. Anthropic reviews each organization with the U.S. government. Existing Glasswing members transition without reapproval for current models.
Red Team Access is not unrestricted. Anthropic says real-time blocks still apply to actions that could cause physical harm or mass disruption, including ransomware deployment and testing high-risk safety systems.
The benchmark measures the permission boundary
Anthropic tested Opus 5.5 on CyScenarioBench, which measures planning and execution of multistage cyber operations under realistic constraints. It ran five attempts on each of 10 challenges per tier. These were complex offensive scenarios, so the company expected blocks under Defense Access.
The company described Red Team Access performance as effectively equivalent to its 67.6% success rate without safeguards. That comparison concerns completion of these challenges, not a measured rate of real-world misuse.
Broader access comes with monitoring
Enrollment generally requires data retention so Anthropic can monitor misuse. Its planned Enterprise Frontier Safeguards solution, due later this fall, would let eligible organizations store data in cloud infrastructure they control. Until then, organizations already using Fable 5.1 or Mythos 5.1 with zero data retention can retain that arrangement in the program.
Applicants must provide proof of the security controls required for their tier. The program is available through the Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry. Amazon Bedrock access is limited to customers eligible for Enterprise Frontier Safeguards.
A security flaw can hide between software components that each appear sound on their own. In customer findings published October 6, Anthropic described how Comcast and Booz Allen used Claude Mythos Preview through Project Glasswing to trace those connections. Comcast says it fixed a critical authentication flaw before observing evidence of exploitation.
The mechanism is an exploit chain: an attacker connects smaller weaknesses into a route to a more serious breach. Anthropic says Mythos can examine source code, configuration settings and application behavior together, rather than treating each file or component as a separate security problem.
Comcast’s assessment covered 258 business-critical systems and approximately 170 million lines of code. The authentication weakness appeared in a public-facing platform and could have let an attacker bypass its login controls. According to the customer account, the problem came from interactions between systems—not one defective component.
Engineers then tested the finding against the running application and confirmed that the security gap was reachable in practice. They traced the root cause, implemented a fix and checked for prior exploitation. That sequence separates a plausible AI finding from a vulnerability a team can demonstrate and repair.
Booz Allen used Mythos Preview to examine more software during time-limited security assessments and identify weaknesses that could be linked together. Sahil Sanghvi, its vice president of AI engineering, said the model connected application behavior, configuration, identity, permissions and deployment context into coherent security hypotheses.
Brad Medairy, Booz Allen’s president of national cybersecurity, said one analyst reviewed eight production systems across 138 repositories in 12 days. He estimated that the same portfolio review would otherwise have taken several months with a larger team. That comparison is the customer’s estimate, not a measured side-by-side trial.
The model also helped draft fixes and assemble evidence for engineers responsible for the affected systems. Medairy said teams still needed to validate findings, remove duplicate patterns and send issues to the right owners. The reported speedup therefore concerns review capacity, not the removal of human judgment.
For broader Project Glasswing context, Anthropic’s October 6 program update says partners found at least 129,000 verified software vulnerabilities between April and July 2026. Its impact figures draw on partial data from 33 partner reports and open-source partnerships. Organizations used different triage approaches, and fewer than half of partners disclosed patch totals, often because fixes remained underway. Those figures show reported discovery volume; they do not establish how much of the exposed software has been repaired.
Reader comments
Newest comments first. Replies stay oldest first.