On Tuesday, Anthropic unveiled an upgraded Cyber Verification Program (CVP), merging it with Project Glasswing to introduce a comprehensive three-tier access system for its advanced AI models. This initiative aims to bolster cybersecurity by integrating diverse levels of access and protection.
Enhanced Security with Integrated Models
Anthropic’s new framework includes models like Claude Opus 5.5, Sonnet 5.5, and Fable 5.1, all designed with cyber defenses that prevent potential misuse. The company’s approach acknowledges that while AI can aid in identifying and rectifying vulnerabilities, it also poses risks of exploitation if not properly safeguarded.
Previously, CVP and Glasswing operated independently: Glasswing provided access to Claude Mythos for securing critical software, while CVP allowed controlled access to Opus and Sonnet models for approved entities. The unified structure now ensures that all tiers comprise these models and any future developments, each with specific verification and security protocols.
Three Tiers of Access Explained
The first level, Defense Access, is designed for security operations centers, incident responders, malware analysts, and vulnerability assessors. Eligible participants include security teams, infrastructure operators, and individual researchers with verified vulnerability reporting experience. Anthropic commits to processing applications for this tier within a few days.
Red Team Access permits authorized penetration testing but restricts activities that could lead to physical harm or widespread disruption. This tier is exclusive to organizations, with reviews taking a few weeks. Applicants receive temporary Defense Access during the evaluation period.
The final tier, Specialized Access, features minimal cyber restrictions and is reserved for organizations allowed to test critical systems like power grids and telecom networks. Anthropic collaborates with the US government to vet these applicants, with existing Glasswing members transitioning to this level.
Impact and Future Developments
From April to July, Glasswing partners identified over 129,000 verified vulnerabilities, with Anthropic’s open-source scanning revealing an additional 5,500 from April to October. Over 33,000 were deemed critical or high severity, and Anthropic suggests the actual impact could be significantly greater.
Participants in this new program must agree to data retention policies for monitoring misuse. Later this year, the Enterprise Frontier Safeguards will allow some customers to manage data in their cloud infrastructure. Until then, organizations with zero data retention access to Fable 5.1 or Mythos 5.1 can operate under CVP guidelines.
CVP is accessible via the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry, with limited availability on Amazon Bedrock for those eligible for Enterprise Frontier Safeguards. Current CVP members will retain their existing settings for previous models and be considered for the new program automatically.
