Anthropic announced on Tuesday a major expansion of its security-focused model access efforts, restructuring its vetted-access initiative into a formal Cyber Verification Program (CVP) with three distinct tiers for cybersecurity professionals. The move comes as the company disclosed that its Project Glasswing initiative has uncovered at least 129,000 verified software vulnerabilities since April.
The restructured program allows vetted security teams to run Anthropic's most capable models — including Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1 — with reduced safeguards and blocking classifiers, permissions that are normally unavailable to general users. According to Anthropic, the goal is to put frontier AI capabilities into the hands of defenders before malicious actors weaponize the same tools. For more context on this story, see our ongoing latest AI developments.
Three Access Tiers, Three Threat Scenarios
The new program is organized around three access levels, each tailored to a different type of security work:
- Defense Access covers defensive operations such as incident response, malware reverse engineering, and vulnerability analysis and validation.
- Red Team Access adds authorized penetration testing and red-teaming to the defensive use cases, allowing simulated attacks against systems that organizations have permission to test.
- Specialized Access carries the fewest safeguards and is reserved for a limited set of verified organizations that are authorized to test AI safety systems themselves.
Organizations and individual security teams apply for the tier that matches their work, and Anthropic reviews each application before granting access. The company said all three tiers include access to its current flagship models as well as new models released going forward.
Safeguards Still Bite — Selectively
Anthropic paired the announcement with evaluation data meant to show that the tier system separates benign defensive work from genuinely dangerous capability. In a CyScenarioBench evaluation on Claude Opus 5.5, the company reported that safeguards blocked 46 of 50 tasks in the Defense Access tier. In the Red Team Access tier on the same model, none of the tasks were blocked, and the model completed 34 of 50 — the same completion rate recorded when no safeguards were applied at all.
By contrast, without CVP access, every task was blocked on the first prompt, according to Anthropic.
"These evaluations give us confidence that we can make advanced cyber capabilities safely available to a broader set of defenders, expanding the defensive efforts we began with Project Glasswing," the company said in its announcement, which was widely reported by The Hacker News, Reuters and SecurityWeek.
The design reflects a bet that most defensive security work — patching, log analysis, malware triage — can proceed under strict guardrails, while legitimate offensive testing needs a wider corridor. It also mirrors how the security industry has long handled dual-use tooling: vet the practitioner, not just the tool.
Glasswing's Expanding Footprint
The program expansion is tightly coupled to Project Glasswing, Anthropic's initiative to apply its models to hardening critical software. The company said Glasswing uncovered at least 129,000 verified software vulnerabilities between April and July 2026, and an additional 5,500 verified vulnerabilities between April and October through open-source scanning efforts.
Of the verified vulnerabilities, more than 33,000 have so far been rated as critical or high severity — a figure Anthropic describes as likely a significant undercount, since it draws on survey data from only a subset of Glasswing partners. The company estimates the true impact could be at least five times higher.
A Measured View of AI-Driven Vulnerability Discovery
Independent analysis suggests the flood of AI-found flaws does not translate directly into a matching wave of exploited breaches. In an analysis published late last month, VulnCheck researcher Patrick Garrity found that only 2 of the 300 vulnerabilities discovered by Anthropic or Project Glasswing — roughly 0.67 percent — have been exploited in the wild.
The two exploited flaws are CVE-2026-26980, an SQL injection vulnerability in Ghost CMS, and CVE-2026-61500, a session forgery flaw in Rejetto HTTP File Server. The data supports a nuance that security researchers have been emphasizing: AI is lowering the barrier to vulnerability discovery, but most of the flaws it surfaces were never on attackers' radars.
The announcement also lands amid broader debate about AI-generated security work. Research from 1Password and Veracode has shown that AI-written vulnerability patches can themselves introduce new flaws, underscoring that automation assists but does not replace human verification.
What It Means for the Security Industry
For security teams, the CVP lowers the activation energy for using frontier models on real defensive work. Incident responders gain a sanctioned path to malware analysis assistance; penetration testers get a governed environment for AI-assisted attacks; and the small set of organizations auditing AI safety systems themselves receive the least restricted access.
For Anthropic, the program is both a safety strategy and a commercial one. It concretizes the company's position that powerful cyber capabilities should be released deliberately, to vetted defenders, rather than suppressed entirely — a contrast with rivals who have faced scrutiny over models with weaker cyber controls. It also deepens Anthropic's relationships with the enterprises most likely to pay for frontier model access: governments, critical infrastructure operators and large security vendors.
The company did not announce pricing changes tied to the program, and applications are processed through Anthropic's existing vetted-access channels. Given the scale of what Glasswing has already surfaced — and the company's own admission that the numbers likely understate reality — the security industry will be watching how many of those 129,000 findings get fixed before attackers find them first.
---
Stay Ahead of AIGet the latest AI news, analysis, and breakthroughs — all in one place.
Read more AI news →