Anthropic announced on 6 October 2026 an expanded Cyber Verification Program (CVP) with three access tiers: Defense Access, Red Team Access and Specialized Access. It says each tier includes its most capable models, including Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, with reduced blocking classifiers for qualifying security professionals.
The company says it is folding its two trusted-access programs into one. Project Glasswing gave a group of organizations access to Claude Mythos, and the CVP gave vetted security teams reduced safeguards on Opus and Sonnet. Existing Glasswing members move to Specialized Access and, Anthropic says, do not require reapproval for current models.
Business Pill · ATTACKING YOUR OWN SYSTEM
A one-minute explainer of red teaming: a team is given permission to attack a system the way an adversary would, so its owner can find the weak points first. It teaches the general idea only and says nothing about any company in this story.
The key insight: Anthropic is selling the same model with different brakes. Every tier includes Claude Mythos 5.1; what changes is how often the classifiers block cyber work and how much verification and security control the customer must accept. As we read it, access is priced in controls, not in model choice.
The Three Tiers
Defense Access, Anthropic says, covers security operations center and incident response work, reverse-engineering malware, and analyzing and validating vulnerabilities. Its examples of qualifying applicants include company and government security teams, operators of critical infrastructure of any size, smaller security firms, open-source maintainers and individual researchers with a track record of reported vulnerabilities. It says it aims to respond within a few days.
Red Team Access adds authorized penetration testing and red-teaming. Anthropic says users will still experience real-time blocks on actions that could cause physical harm or mass disruption, such as deploying ransomware, damaging physical systems, or pen testing high-risk safety systems. It expects reviews to take a few weeks, and says the tier is for organizations only.
Specialized Access has the fewest cyber blocks. Anthropic says it is reserved for a limited set of verified organizations authorized to test systems such as flight operating systems, power grids, telecom networks, interbank transfer infrastructure and government administrative networks. It says it currently reviews every organization for this tier in depth in collaboration with the US government.

What the Public Models Still Block
Anthropic writes that “Cybersecurity is inherently dual use: the same capabilities that enable a security team to find and fix a vulnerability can also help a malicious actor exploit it.”
It says its generally available models, such as Claude Opus 5.5, Claude Fable 5.1 and Claude Sonnet 5.5, have conservative cyber safeguards that block most cyber work. It says those models can continue to be used for code review, patching known issues, vulnerability finding in owned source code, and triage of security alerts.
The Conditions Attached
Data retention is required for organizations in the program so that Anthropic can monitor for cyber misuse, the announcement says. It says Enterprise Frontier Safeguards, which it describes as combining the privacy of zero data retention with safeguards, is due later this fall and will let eligible organizations store data in cloud infrastructure they control.
The security requirements article sets controls per tier. For Defense Access, it says all accounts must use phishing-resistant multi-factor authentication by 15 December 2026, and long-lived static credentials, including API keys, must not be used after that date. Until then, it says, an API key must be replaced at least every seven days.
For Red Team Access, the article limits a granted workspace to 25 Approved Users, requires managed devices and background checks, and requires outbound traffic to be limited to an allow-list wherever the model performs offensive or agentic work. For all tiers, it says customers must report suspected breaches or misuse within 72 hours, or within 24 hours for a security incident.
Anthropic’s Own Test
Anthropic says it ran Claude Opus 5.5 through CyScenarioBench, an evaluation that measures whether models can plan and execute multi-stage cyber operations, with safeguards tuned for each tier. It ran five attempts at each of 10 challenges, 50 trials per tier.
It reports that without CVP access every task was blocked on the first prompt. In Defense Access, 46 of the 50 trials were blocked at some point and four succeeded. In Red Team Access no blocks occurred and the model completed 34 of the 50, which Anthropic calls effectively equivalent to its 67.6% success rate with no safeguards applied, representative of Specialized Access.
The Glasswing Figures
Anthropic says Glasswing partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026, and its own open-source scanning found an additional 5,500 between April and October 2026. It says more than 33,000 of these have so far been rated critical- or high-severity.
The company says these figures are based on partial data from 33 partner reports and are likely an undercount, and that it expects the true impact to be at least five times higher. That multiplier is Anthropic’s estimate.
Anthropic says the CVP is available on the Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry, and on Amazon Bedrock only for customers eligible for Enterprise Frontier Safeguards.
The Structural Read
Anthropic says it ran the test to assess the efficacy of its CVP protections. On that evaluation, Claude Opus 5.5 without CVP access was blocked on the first prompt, Defense Access completed 4 of 50 tasks, and Red Team Access completed 34 of 50, which Anthropic calls effectively equivalent to the model with no safeguards. The numbers are Anthropic’s, from an evaluation it ran.
The controls scale with the access. For Defense Access, the security requirements article sets a 15 December 2026 deadline for phishing-resistant multi-factor authentication and an end to long-lived API keys. For Red Team Access, it caps a workspace at 25 Approved Users and requires managed devices, background checks and an egress allow-list.
Monitoring is part of the deal. The announcement says data retention is required so Anthropic can monitor for misuse. It says that once Enterprise Frontier Safeguards is available later this fall, eligible organizations will be able to store data in cloud infrastructure they control, and that until then organizations with zero-data-retention access to Claude Fable 5.1 or Claude Mythos 5.1 can also use CVP with zero data retention. On the top tier, Anthropic says every organization is reviewed in collaboration with the US government.
Anthropic, announcing the expanded Cyber Verification Program
“Cybersecurity is inherently dual use: the same capabilities that enable a security team to find and fix a vulnerability can also help a malicious actor exploit it.”
Three Implications
SAME MODELS, TIERED BLOCKING Anthropic says every tier includes Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1; the tiers differ in which cyber tasks the classifiers block and in the verification required.
SECURITY TEAMS INHERIT A COMPLIANCE LIST The requirements article sets per-tier controls, from phishing-resistant MFA by 15 December 2026 for Defense Access to a 25-user cap, managed devices and background checks for Red Team Access.
GLASSWING BECOMES A TIER Anthropic says existing Glasswing members move to Specialized Access without reapproval for current models, and that this tier is reviewed in collaboration with the US government.
The Business Engineer Lens
This story maps onto the Business Engineer framework Inside Anthropic’s Permission Layer.
The framework’s starting point: “It is becoming the first major AI lab actively attempting to define the governance layer of the AI stack.”
The tiered Cyber Verification Program is a concrete case: Anthropic says every tier includes the same models, while access is graded by verification, security controls and, for the top tier, review with the US government. As we read it, what is being productised here is permission itself.
What Is Not Established
We read the announcement, the Glasswing page, the CVP Help Center article and the security requirements article as text copies. The announcement’s tier overview is an image, and we worked from the text articles instead.
CyScenarioBench results are Anthropic’s own and were not independently run. The Glasswing vulnerability counts come from partner reports Anthropic describes as partial. We did not read the Booz Allen or Comcast accounts the announcement links, or any wire coverage, and we did not contact Anthropic.
The Bottom Line
Anthropic has replaced its single-level CVP and the separate Project Glasswing with three access tiers that all include Claude Mythos 5.1, with fewer cyber blocks and tighter verification at the higher tiers, as Anthropic describes them. On Anthropic’s test of Claude Opus 5.5, Red Team Access completed 34 of 50 tasks, Defense Access 4, and access without CVP none.
94,000+ executives read Business Engineer for the AI strategy frameworks cited by ChatGPT, Claude, and Perplexity.
A note on sourcing. We read Anthropic’s announcement of 6 October 2026, its Project Glasswing page, and the Claude Help Center articles on the Cyber Verification Program and its security requirements, all as text copies. The benchmark and vulnerability figures are Anthropic’s own. We did not read the partner accounts it links or wire coverage, and we did not contact Anthropic. Nothing here is a forecast, and nothing here is financial or investment advice.
Sources: Anthropic: Expanding the Cyber Verification Program (6 Oct 2026) · Anthropic: Project Glasswing · Claude Help Center: Cyber Verification Program · Claude Help Center: CVP Security Requirements









