
The Claude logo. Image: Anthropic
Anthropic will now let vetted security teams use Claude for hacking work its public models refuse to touch. The company announced on Tuesday an expanded Cyber Verification Program with three tiers of access, from defensive work up to authorised attacks on power grids and banking systems, and it is folding its invitation-only Project Glasswing into the same scheme.
Each tier covers Anthropic’s most capable models, including Claude Opus 5.5, Claude Sonnet 5.5 and the restricted Claude Mythos 5.1, plus future models. Organisations apply through a portal, and Anthropic says it will verify every applicant and ask for proof of the security controls each tier needs.
Three levels of access
Anthropic says its generally available models carry “conservative cyber safeguards that block most cyber work”, to limit what attackers can do with them. The program loosens those blocks in steps:
- Defense Access covers security operations, incident response, reverse-engineering malware and validating vulnerabilities. Company, university, nonprofit and government security teams, critical infrastructure operators “of any size”, smaller security firms, open-source maintainers and individual researchers with a record of reported bugs can qualify. Anthropic aims to answer within a few days.
- Red Team Access adds authorised penetration testing and red-teaming, but only against systems the organisation is allowed to test. It is for organisations only, not individuals, and reviews take a few weeks. Claude will still block actions that could cause physical harm or mass disruption, such as deploying ransomware.
- Specialized Access, with the fewest blocks, is for a small set of organisations authorised to test systems such as flight operating systems, power grids, telecoms networks, interbank transfers and government networks. Anthropic says it reviews each one “in collaboration with the US government”. Existing Glasswing members move straight into this tier.
Members must let Anthropic keep their data so it can watch for misuse. Organisations already using Claude Fable 5.1 or Mythos 5.1 with zero data retention can keep that arrangement, and Anthropic says a new option called Enterprise Frontier Safeguards will let firms store the data on their own cloud later this autumn. The program runs on the Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry, and on Amazon Bedrock only for customers eligible for that new option.
How much the blocks change
Anthropic tested the tiers on CyScenarioBench, an evaluation of multi-stage cyberattacks, running Opus 5.5 five times on each of 10 challenges. Without the program, every task was blocked on the first prompt. At Defense Access, 46 of the 50 runs were blocked at some point. At Red Team Access, nothing was blocked and Claude completed 34 of the 50, which Anthropic says matches the model’s 67.6% success rate with no safeguards at all.
These are Anthropic’s own figures, and nobody outside the company has checked them yet.
Glasswing’s bug count
Anthropic also gave its first big tally from Glasswing, which has given Mythos to a group of organisations securing critical software for the past six months. It says partners found at least 129,000 verified vulnerabilities between April and July, and its own open-source scanning found another 5,500 between April and October, with more than 33,000 rated critical or high severity. It calls that an undercount, based on survey data from 33 partner reports, and says the true figure is likely “at least five times higher”. Fewer than half of partners said how many bugs they had patched.
The move comes on the same day that Mistral pitched its new open model on doing the security work that Claude and OpenAI’s GPT-6 Astra refuse. Last week Anthropic warned that a Chinese open-weight model can now build working hacks with no such safeguards at all.
Why it matters
Anthropic is betting it can hand its strongest hacking abilities to more defenders by checking who they are, rather than by blocking the work outright. If the vetting holds, far more security teams get Mythos-level tools; if it doesn’t, the company has widened the door it spent six months guarding.
Sources: Anthropic: Expanding the Cyber Verification Program; Claude Help Center: real-time cyber safeguards.


