Franklin AI News Brief

Anthropic expands cyber verification into three tiers for defenders and authorized testers

Key Takeaways

  • The revised program combines CVP and Project Glasswing, with different eligibility, safeguards and data-retention requirements for defensive work, red teaming and safety-critical.
  • The revised program combines CVP and Project Glasswing, with different eligibility, safeguards and data-retention requirements for defensive work, red teaming and safety-critical systems.
  • Anthropic has expanded its Cyber Verification Program into three access tiers, combining the earlier CVP and Project Glasswing programs.
  • The change gives qualifying security professionals routes to advanced cyber capabilities and reduced blocking classifiers, with eligibility and safeguards tied to the work they intend to perform.
  • The October 6 announcement names Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1 among the models available through the tiers.

Anthropic has expanded its Cyber Verification Program into three access tiers, combining the earlier CVP and Project Glasswing programs. The change gives qualifying security professionals routes to advanced cyber capabilities and reduced blocking classifiers, with eligibility and safeguards tied to the work they intend to perform.

The October 6 announcement names Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1 among the models available through the tiers. Access still requires verification. The program is not a blanket removal of safeguards for the generally available versions of those models.

Defense Access covers owned and maintained systems

Defense Access supports incident response, security operations, malware reverse-engineering and vulnerability analysis or validation. Anthropic lists company security teams, nonprofits and universities among potential applicants, along with government bodies defending systems they own or maintain.

The tier also includes critical-infrastructure operators of any size, smaller security firms, open-source maintainers and individual researchers with a track record of reported vulnerabilities. Anthropic expects many defensive organizations to qualify and aims to respond within a few days. Those are the company's application targets, rather than a guaranteed approval deadline.

Generally available models remain usable for code review, patching known issues, finding vulnerabilities in owned source code and triaging security alerts. Teams do not need to assume that every software-security task requires a higher-access tier.

Red teaming requires authorization

Red Team Access adds authorized penetration testing and red-team work to the defensive uses. It is currently for organizations, not individual researchers. Applicants can include in-house or government red teams and penetration-testing firms. They may test only systems they have permission to assess.

Anthropic says real-time blocks remain for actions that could cause physical harm or mass disruption, including deploying ransomware, damaging physical systems and penetration testing high-risk safety systems. Reviewing Red Team applications may take a few weeks; qualifying organizations receive Defense Access while that review proceeds.

Specialized Access has the fewest cyber blocks and is limited to verified organizations authorized to test safety-critical systems. Examples include flight operating systems, power grids and interbank transfer infrastructure. Anthropic says it currently reviews these organizations in depth with the US government. Existing Glasswing members transition to this tier without reapproval for current models.

Safeguards change the meaning of a cyber score

Anthropic evaluated Claude Opus 5.5 across ten CyScenarioBench challenges, with five attempts per challenge in each tier. It reports that the generally available model blocked every task at the first prompt. Defense Access blocked 46 of 50 trials at some stage; the other four succeeded.

Red Team Access produced no blocks and completed 34 of 50 trials. Anthropic describes that as equivalent to the model's 67.6% success rate without safeguards in the evaluation. These controlled results describe the tested scenarios and tier settings. They do not establish that a particular security team will reproduce the same completion rate.

The importance of access settings also appears in Anthropic's earlier assessment of GLM-5.3 cyber capabilities, which discusses comparisons with safeguards disabled and models restricted to vetted users. Cyber capability and the policy that permits its use need to be read together.

Retention and platform availability need checking

Program participants generally need data retention so Anthropic can monitor cyber misuse. The company plans Enterprise Frontier Safeguards later in the fall, combining zero-retention privacy with safeguards and allowing eligible organizations to store data in cloud infrastructure they control. Until then, it describes a zero-retention exception for organizations already accessing Claude Fable 5.1 or Mythos 5.1 with that arrangement.

CVP is available through the Claude Platform, Google Cloud Vertex AI and Microsoft Foundry. Amazon Bedrock access is limited to customers eligible for Enterprise Frontier Safeguards. Existing CVP members keep earlier-model settings and receive automatic evaluation for the newly named models, but administrators still need to assign access to workspaces.

Anthropic also reports at least 129,000 verified vulnerabilities found by partners between April and July, plus 5,500 from its open-source scanning through October. Its account notes incomplete partner data and patch reporting. Discovery counts should therefore remain separate from the number of fixes completed or systems secured.

Our read

Franklin AI Take

Teams should choose access around the systems they are authorized to test and the data-handling requirements they can meet. Anthropic allows individual researchers with a vulnerability-reporting history in Defense Access, while Red Team Access is currently organization-only. That distinction will matter more to applicants than the model names. The evaluation also shows why an unqualified cyber leaderboard can mislead: changing safeguards changed which operations Claude attempted in the same set of challenges.