Anthropic Launches Tiered Cyber Verification Program for Claude AI Models
In a significant development within the realm of artificial intelligence and cybersecurity, Anthropic has introduced a restructured Cyber Verification Program. This innovative initiative delineates access to its Claude AI models into three distinct tiers, effectively tailoring each level to the user’s trustworthiness and the security tasks they intend to perform. The new framework replaces Anthropic’s previous model, which utilized an all-or-nothing approach that primarily restricted offensive security capabilities in its standard models, including Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1. The redefined tier system combines two earlier initiatives, Project Glasswing and the original Cyber Verification Program, into a cohesive strategy designed to balance the advantages of AI-assisted cybersecurity operations with the risks of potential misuse.
Overview of the Tiers
The newly introduced tiers are designed to provide varied levels of access based on the nature of the security work being conducted. The first tier, known as Defense Access, targets activities such as security operations, incident response, malware reverse engineering, and vulnerability validation. This entry-level access is designed for a range of entities, including regional hospitals, municipal utilities, open-source maintainers, and individual researchers who have demonstrated established track records. Notably, Anthropic aims to process applications for this tier within a matter of days, allowing quicker access to essential tools for those needing it.
The second tier, termed Red Team Access, allows authorized penetration testing for organizations that have the legal clearance to evaluate the systems they are targeting. However, this access comes with caveats: real-time blocks remain in place for activities that have the potential to inflict physical harm or cause mass disruption, such as ransomware deployments or attacks on critical safety systems. Applications for this tier require a more extensive review process, often taking several weeks.
Lastly, the Specialized Access tier is the highest level and is strictly reserved for entities authorized to conduct tests on critical infrastructure, where potential errors could result in physical harm or significant market disruption. This includes vital systems responsible for flights, power grids, and interbank transfer networks. All applicants in this category must undergo a comprehensive review process that includes collaboration with the US government. Importantly, those who were previously involved in Project Glasswing will automatically transition into this tier, eliminating the need for reapplication.
Performance Insights from Internal Testing
Internal assessments utilizing Anthropic’s CyScenarioBench benchmark revealed that Claude Opus 5.5 exhibited an impressive performance, completing 34 out of 50 realistic multi-step cyber operations in the Red Team Access mode without encountering any blocks. This completion rate is noteworthy, especially when compared to the results achieved in scenarios where no safeguards were in place. Meanwhile, the Defense Access tier proved more restrictive, as it blocked 46 of the 50 trials, allowing just four particularly challenging tasks to proceed.
Impact on Cybersecurity Vulnerabilities
Between April and July of 2026, partners utilizing the Cyber Verification Program successfully unearthed a staggering 129,000 verified software vulnerabilities. Of these, over 33,000 were classified as critical or high severity. Anthropic has acknowledged that these figures likely represent an undercount of the actual vulnerabilities found, attributing this to partial survey responses from a limited subset of partners. Furthermore, the company’s own open-source scanning efforts identified an additional 5,500 verified vulnerabilities between April and October of the same year. Notably, various partners reported that Claude models significantly accelerated the process of vulnerability identification, reducing what could have taken months or even years to mere weeks.
Application and Future Considerations
Organizations interested in accessing the tiered Cyber Verification Program are encouraged to apply through Anthropic’s verification portal, ensuring they select the tier that aligns with their operational needs and authorization level. For those already engaged with Project Glasswing, their Specialized Access status will remain intact. This shift from a binary access model to one that incorporates graduated permissions based on potential impact signifies a substantial evolution in Anthropic’s approach to cybersecurity. The success of this new framework will ultimately hinge on real-world adoption, as well as its effectiveness beyond the promising benchmark results that Anthropic has published to date.
As Anthropic continues to navigate the challenges of AI in cybersecurity, this new framework may serve as a model for other organizations looking to enhance their security measures while responsibly managing the risks associated with advanced technologies.
