TL;DR

Anthropic announced on Tuesday 6 October that it has rebuilt its Cyber Verification Program (CVP) around three access tiers, giving vetted security teams versions of Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1 that block less cyber work. The programme absorbs Project Glasswing, the scheme that has given a select group of organisations Mythos access over the past half-year.

Why a separate route

Anthropic’s general models, Opus 5.5, Fable 5.1 and Sonnet 5.5, carry cautious cyber safeguards that stop most security tasks, because the skills that help a defender fix a flaw can help an attacker exploit it. The CVP is the company’s answer for defenders who need more. Applicants are verified, must show they have the required security controls, and must accept data retention so Anthropic can watch for misuse.

The three tiers are:

  • Defense Access: incident response, malware analysis and vulnerability validation, open to in-house security teams, critical infrastructure operators of any size, smaller security firms, open-source maintainers and researchers with a record of reported vulnerabilities. Anthropic aims to reply within days.
  • Red Team Access: adds authorised penetration testing for organisations only, with reviews taking a few weeks. Live blocking still applies to anything that risks physical damage or widespread disruption, ransomware deployment included.
  • Specialized Access: the fewest blocks, for a small number of organisations cleared to test systems such as power grids, telecoms networks and interbank payment infrastructure. For now, Anthropic reviews each one in depth together with the US government, and Glasswing members move here.

Testing the tiers

Anthropic ran Opus 5.5 five times through each of the 10 challenges in CyScenarioBench, its test of multi-stage cyber operations. With no CVP access, each task was stopped at the first prompt. At Defense Access, 46 of 50 runs were blocked at some stage. At Red Team Access nothing was blocked, and the model completed 34 of 50, in line with its 67.6% unrestricted success rate.

The company says that from April to July, Glasswing partners turned up no fewer than 129,000 confirmed software flaws, and its own open-source scanning added 5,500 more by October. Over 33,000 of the combined total have been rated critical or high severity so far. Because only some partners were surveyed, Anthropic reckons the true impact is at least fivefold.

Looking forward

Customers can join through Anthropic’s own Claude Platform, Microsoft Foundry or Vertex AI on Google Cloud. In our view, UK security teams at hospitals and utilities look likely to meet the Defense Access criteria as written. The harder question for British operators of national infrastructure is the top tier, where vetting currently runs through the US government. Anthropic’s announcement does not say how a UK grid, telecoms or payments operator would qualify, and that is worth asking before relying on it.