Anthropic expanded its Cyber Verification Program on October 6, 2026, creating three access tiers for security professionals. The company’s announcement brings the earlier program and Project Glasswing into a broader offering with different verification requirements and safeguards.
The change concerns who can use advanced cybersecurity capabilities and under what controls. Applying to the program is separate from receiving approval; access is not an unrestricted release to every Claude user.
On this page
Three scopes of security work
Defense Access covers work such as incident response, malware analysis and vulnerability validation. Anthropic lists security teams defending systems they own or maintain, critical infrastructure operators, open-source maintainers and individual researchers with a vulnerability-reporting record among potential applicants.
Red Team Access adds authorized penetration testing. It is currently limited to organizations, excluding individual researchers. Anthropic says applicants can receive Defense Access while their Red Team application is reviewed. Testing still requires authorization, and the company says controls remain for activities that could cause physical harm or widespread disruption.
Specialized Access is reserved for a limited set of verified organizations testing systems whose failure could affect lives or markets. Anthropic says it reviews these organizations in cooperation with the US government. Existing Project Glasswing participants move into this tier without reapproval for their current models.
These are eligibility descriptions, rather than a guarantee that any particular applicant will be accepted.
Privacy controls are part of enrollment
Anthropic says program enrollment generally requires data retention to support misuse monitoring. It plans Enterprise Frontier Safeguards later in the fall, allowing eligible organizations to retain data in cloud infrastructure they control while using safeguards.
The announcement also describes an interim exception for organizations already accessing Claude Fable 5.1 or Claude Mythos 5.1 with zero data retention. That exception should not be read as a general zero-retention promise to new applicants.
According to Anthropic, CVP is available through the Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry. Amazon Bedrock access is restricted to customers eligible for Enterprise Frontier Safeguards.
What the evaluation establishes
Anthropic tested Claude Opus 5.5 across ten CyScenarioBench challenges, with five attempts per challenge at each access tier. It reports that Defense Access blocked 46 of 50 trials at some point, while Red Team Access blocked none and completed 34.
Those results describe Anthropic’s evaluation of its own safeguards. They do not independently establish that misuse is impossible or predict success on every security task. Our AI benchmark coverage explains why test conditions matter, while AI lab news follows changes to access and deployment policies.
Source: Anthropic, “Expanding the Cyber Verification Program,” October 6, 2026. Checked October 7, 2026.




