
Anthropic Cyber Verification Program: Which Tier Fits You?
Anthropic split its Cyber Verification Program into 3 tiers, Defense, Red Team and Specialized, giving vetted defenders broader Claude access for security.
Security teams want frontier AI on their side, but the same capabilities that help a defender reverse-engineer malware could help an attacker. Anthropic's answer, announced on October 6, 2026, is a reorganized Cyber Verification Program (CVP) with three clearly defined tiers. Verified defenders get broader access to Claude for security work, while the safeguards that block genuinely dangerous actions stay in place. It is a practical step toward putting AI security tools in the right hands.
- Tiers: Defense Access, Red Team Access and Specialized Access.
- Models: Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and future models.
- Review times: a few days for Defense Access and a few weeks for Red Team Access, according to Anthropic.
- Project Glasswing: partners found more than 129,000 verified vulnerabilities from April to July 2026, with over 33,000 rated critical or high severity.
Why Did Anthropic Change the Cyber Verification Program?
Anthropic says its generally available models ship with conservative cyber safeguards that block most security work beyond everyday tasks like code review, patching your own code and triaging alerts. That is sensible for the general public, but it slows down professionals. The new structure matches access to the work people actually do. It also folds in Project Glasswing, Anthropic's vulnerability-hunting initiative, whose members move automatically into the highest tier.
Which CVP Tier Fits Your Security Team?
Here is how the three tiers break down:
- Defense Access covers security operations center and incident response work, malware reverse-engineering and vulnerability analysis. It is open to company and nonprofit security teams, universities, government bodies, critical infrastructure operators, smaller security firms, open-source maintainers and individual researchers with a history of vulnerability disclosure.
- Red Team Access adds authorized penetration testing and red-teaming against systems you are allowed to test. It is for organizations only, such as in-house red teams, government red teams and pen-testing firms.
- Specialized Access is for a small number of verified organizations testing safety-critical systems like flight software, power grids, telecom networks and interbank infrastructure. Anthropic reviews these applications together with the US government.
What Safeguards Stay in Place?
Even Red Team Access keeps real-time blocks on actions that could cause physical harm or mass disruption. SecurityWeek's report lists ransomware deployment among the blocked activities. Specialized Access has the fewest blocks, which is why it carries the strictest vetting.
How Do You Apply?
Applications go through Anthropic's CVP portal, and applicants must show proof of their security controls. Access works on the Claude Platform, Google Cloud Vertex AI and Microsoft Foundry, and on Amazon Bedrock for Enterprise Frontier Safeguards customers. Existing CVP members are evaluated for new models automatically.
For background on how this started, see our explainer on Project Glasswing and AI vulnerability discovery. More defensive AI news lives in our AI security section.
Sources: Anthropic — October 6, 2026; SecurityWeek — October 7, 2026.
More Ai Security Stories

SailPoint Autonomous Agents: Identity Security for AI Agents
SailPoint launched Autonomous Agents and just-in-time access at Navigate 2026, citing a survey where 79% of firms run AI agents but only 2% govern them.

Apple Full Disk Access Changes: What Mac Users Should Know
Apple says new macOS controls will make Full Disk Access require very explicit user action as AI agents grow more capable. Here is what is known so far.

Thales Sentinel Envelope Plus: Shielding Code From AI Agents
Thales Sentinel Envelope Plus hardens compiled apps against AI reverse engineering. In tests, an AI agent found 0 of 10 bugs after using 970x more tokens.
