Anthropic has taken a significant step to enhance cybersecurity by expanding access to its sophisticated Claude models. This expansion, announced on October 6, 2026, is part of the Cyber Verification Program, which now allows verified security professionals to engage with Claude models under fewer cybersecurity restrictions. The update introduces three distinct access tiers, catering to defensive research, authorized penetration testing, and critical system testing where failures could have severe consequences.
Integration and Access Tiers
The expansion incorporates models such as Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, among others yet to be released. By integrating the Project Glasswing with the previous verification program, Anthropic offers a streamlined approach, aligning permissions with the specific needs of each security team.
One of the core challenges this update addresses is the dual-use nature of advanced cybersecurity tools. While these tools are vital for identifying vulnerabilities, they also pose a risk if exploited by malicious actors. To mitigate this, public models maintain stringent security measures, while verified professionals are granted fewer restrictions, tailored to their verified activities.
Detailed Overview of Access Tiers
Defense Access caters to security operations, incident response, malware analysis, and vulnerability assessments. Eligible participants include corporate security teams, academic institutions, government entities, and small security firms. Individual researchers with a track record of reporting vulnerabilities may also apply, with Anthropic aiming to process applications within a few days.
Red Team Access is designated for authorized penetration testing and red-teaming, available to organizations like internal red teams, government bodies, and specialized security firms. This access requires permission to test specific targets and maintains real-time controls to prevent actions like ransomware deployment. Reviews for this tier can extend over several weeks, during which applicants receive provisional Defense Access.
Specialized Testing and Future Prospects
Specialized Access, offering the least cyber restrictions, is reserved for testing critical infrastructure such as power grids and telecom networks. Organizations in this category undergo evaluation in collaboration with the US government. Existing members of Project Glasswing transition to this tier seamlessly, leveraging prior expansions.
In recent testing, Anthropic used the CyScenarioBench to evaluate Opus 5.5, observing that public access blocked all tasks initially. Defense Access managed to block 46 out of 50 attempts, while Red Team Access successfully completed 34 tasks without blocks, closely aligning with previously reported success rates.
Conclusion and Application Process
Anthropic reports that partners within Glasswing identified over 129,000 verified vulnerabilities between April and July 2026. Additional open-source scanning revealed 5,500 vulnerabilities from April to October, with a substantial portion rated as high or critical. However, these findings are based on partial data, and complete patch implementations are not fully reported.
Organizations interested in the Cyber Verification Program must provide evidence of necessary security controls. Access to these models is facilitated through the Claude Platform, Google Cloud Vertex AI, and Microsoft Foundry, with Amazon Bedrock access requiring specific eligibility criteria. Existing members automatically undergo evaluation for newer models, ensuring continuity and adaptation to the latest security advancements.
