Enterprise & Security

Cyber Verification Program: Anthropic now loosens its cyber blocks in three tiers

4 min read AI-generated

Without access, Opus 5.5 is stopped on the first prompt of all ten CyScenarioBench challenges. In the Red Team tier nothing is blocked at all — and it solves 34 of 50 attempts.

Featured image for "Cyber Verification Program: Anthropic now loosens its cyber blocks in three tiers"

On October 6, Anthropic rebuilt its Cyber Verification Program and folded Project Glasswing into it. Two programs become one, with three access tiers. Every tier carries the strongest models: Opus 5.5, Sonnet 5.5, Mythos 5.1, and whatever comes next.

The reason for the blocks hasn’t changed. The same capability that lets a security team find and close a hole helps an attacker walk through it. So the generally available models refuse most cyber work.

Three tiers, three review processes

Defense Access covers defensive work: SOC tasks, incident response, reverse-engineering malware, analyzing and validating vulnerabilities. Qualifying applicants include security teams at companies, nonprofits, universities and government bodies defending systems they own, critical infrastructure operators of any size — Anthropic names the regional hospital and the municipal utility explicitly — smaller security firms, open-source maintainers, and individual researchers with a track record of reported vulnerabilities. Answer within a few days.

Red Team Access adds authorized penetration testing and red-teaming, only against systems you have permission to test. Real-time blocks stay on anything that could cause physical harm or mass disruption: deploying ransomware, damaging physical systems, pen testing high-risk safety systems. Review takes weeks, and you sit in Defense Access while it runs. Individuals aren’t eligible here.

Specialized Access has the fewest blocks and stays with a small set of verified organizations — flight operating systems, power grids, telecom networks, interbank transfer infrastructure, government administrative networks. Anthropic reviews each one in depth and does it with the US government. Existing Glasswing members move here and don’t reapply for current models.

Anthropic measured how far apart the tiers actually are

Opus 5.5 ran through CyScenarioBench, an evaluation of multi-stage cyber operations: ten challenges, five attempts per challenge per tier.

With no CVP access, every task ended on the first prompt. In Defense Access, 46 of 50 trials were stopped somewhere along the way and four ran through. In Red Team Access nothing was blocked, and Opus 5.5 completed 34 of 50 — effectively the 67.6% the model reaches with no safeguards at all.

That’s the most useful number of the day, because it makes the tiers comparable. Defense Access isn’t a watered-down Red Team tier. It is something else.

What Glasswing turned up in four months

Closing out the program, Anthropic put numbers on it: partners found at least 129,000 verified software vulnerabilities between April and July 2026, and Anthropic’s own open-source scanning found 5,500 more between April and October. Over 33,000 of those are rated critical or high severity.

The figures rest on 33 partner reports, and fewer than half the partners said how much was already patched. Anthropic believes the real number is at least five times higher — an estimate, and worth reading as one.

Comcast and Booz Allen describe the same problem

Alongside the announcement, Anthropic let two participants speak, and neither names discovery as the bottleneck. Both name verification.

Comcast had Mythos Preview work through 258 business-critical systems and roughly 170 million lines of code, and it surfaced a critical authentication vulnerability in a public-facing platform. It didn’t come from one broken component but from several systems interacting, each of which looked correct on its own. “Discovery is becoming faster. Discovery is becoming easier. The volume of findings is enormous. Validation of these volumes of findings is the new bottleneck,” says Noopur Davis, Comcast’s chief information security officer.

At Booz Allen, a Mythos model found a flaw in the code that runs when a device powers on, before the operating system loads. That code decides whether the device locks itself or wipes its data, and it leans on a key stored on the machine. The key was left unprotected, so the very operating system it was meant to restrain could swap in one of its own. A lost or stolen device would have stayed open indefinitely. Claude got there by following a single setting through two programs written in two languages.

“One analyst reviewed eight production systems across 138 repositories in twelve days,” says Brad Medairy, who runs National Cybersecurity at Booz Allen. “Without Mythos, a portfolio review at that scale would have taken us several months with a larger team.”

Checking the findings is the new bottleneck

Two companies, one observation: the models make finding cheap, which moves the work to validating, deduplicating and routing. Anyone hoping a CVP tier is a shortcut mostly gets more candidates to review.

One condition is easy to miss. Program members have to allow data retention so Anthropic can watch for misuse. Only until Enterprise Frontier Safeguards ships later this fall may organizations with zero data retention on Fable 5.1 or Mythos 5.1 use CVP without it. And one gap stays open, the one Nathan Lambert’s objection from the same day lands on: a tiered model with verification helps whoever can get verified. Whoever can’t reaches for open weights, and nobody there asks.

Sources

AnthropicSecurityCyber Verification ProgramProject GlasswingClaude Mythos