If you run a security team, the default posture of frontier models has been frustrating: safeguards tuned to block malicious actors also block defensive work like malware reverse-engineering or vulnerability validation. On October 6, 2026, Anthropic announced an expanded Cyber Verification Program that restructures trusted access into three tiers, merging the earlier Project Glasswing and CVP pilots into one application path.
Why tiers instead of a single gate
Cybersecurity is dual-use by nature — the same capability that finds a vulnerability can exploit it. Anthropic’s generally available models, including Claude Opus 5.5 and Claude Sonnet 5.5, ship with conservative cyber safeguards that block most cyber work by default. That protects against misuse but slows down defenders. The tiered structure is an attempt to match safeguards to the actual scope of an organization’s authorization, rather than applying one blunt policy to everyone.
What each tier unlocks
- Defense Access covers defensive work: SOC and incident response, malware reverse-engineering, and analyzing or validating vulnerabilities. Anthropic expects many defensive organizations to qualify — including critical infrastructure operators, open-source maintainers, and individual researchers with a track record of reported vulnerabilities — and aims to respond within days.
- Red Team Access adds authorized penetration testing. Real-time blocks remain on actions that could cause physical harm or mass disruption, such as deploying ransomware or testing high-risk safety systems. Organizations only, a few weeks to review, and you’re enrolled in Defense Access while you wait.
- Specialized Access has the fewest cyber blocks and is reserved for verified organizations authorized to test systems where failure affects lives or markets — flight operating systems, power grids, telecom networks. Anthropic reviews each applicant in collaboration with the US government; existing Glasswing members transition here without reapproval.
All tiers include access to the most capable models, including Claude Mythos 5.1. One practical note: data retention is required for misuse monitoring, though organizations with Claude Fable 5.1 or Claude Mythos 5.1 on zero data retention can keep that setup, and an upcoming Enterprise Frontier Safeguards option will let eligible orgs store data in their own cloud infrastructure.
Do the tiered classifiers actually work?
Anthropic ran Claude Opus 5.5 through CyScenarioBench, which measures multi-stage cyber operations, with safeguards tuned per tier. The reported results: without CVP access, every task was blocked on the first prompt; in Defense Access, 46 of 50 trials hit a block at some point; in Red Team Access, no blocks occurred and the model completed 34 of 50 tasks — matching its 67.6% unsafeguarded success rate.
That’s the design intent working as described, but it comes from Anthropic’s own evaluation. Independent verification of tier-based classifier behavior would be the more useful signal, and the company says it will keep refining the classifiers.
The evidence that trusted access matters
The strongest argument for the program comes from Project Glasswing’s track record. Between April and July 2026, partners uncovered at least 129,000 verified vulnerabilities using Claude Mythos models, plus 5,500 more from Anthropic’s own open-source scanning — over 33,000 rated critical- or high-severity. Anthropic itself flags these as undercounts based on partial reporting from 33 partners, with fewer than half disclosing patch numbers.
The pattern here — verified identity, scoped capability, monitoring in exchange for reduced restrictions — is the same governed-access tradeoff playing out across enterprise AI. I’ve written about a similar dynamic in Cohere’s North 2 approach to agents enterprises can govern.
What to do with this
If your team is blocked on legitimate defensive work, applying is the direct next step — applications are open, and existing CVP members keep current settings while being automatically evaluated for the new models. Full tier details live in Anthropic’s Help Center. The honest caveat: your team’s access level will shape what your workflows can automate, so plan your tooling around the tier you actually qualify for, not the one you want.
