Anthropic is expanding access to powerful cyber capabilities on its most advanced AI models for approved security organizations, with reduced safeguards tailored to the type of work they're authorized to perform. The company announced an expansion of its Cyber Verification Program that creates three distinct access levels based on whether teams are doing defensive security work, authorized penetration testing, or evaluating high-stakes systems like power grids and financial infrastructure. The move combines two pilot initiatives Anthropic has run over the past six months and comes as security partners using the technology have already identified more than 129,000 verified software vulnerabilities.

The expanded program grants vetted organizations access to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, along with future releases, each with varying levels of cyber restrictions. Defense Access targets tasks like security operations, incident response, malware reverse engineering, and vulnerability analysis. Red Team Access adds authorized penetration testing and red-team operations, though users can test only systems they have permission to assess. Specialized Access has the lightest cyber restrictions and is limited to a small group of verified organizations authorized to test systems including flight operating systems, power grids, telecommunications networks, interbank transfer infrastructure, and government administrative networks. Anthropic reviews organizations seeking Specialized Access in partnership with the US government. The company tested the different access levels using CyScenarioBench, an evaluation measuring whether AI models can plan and execute multistage cyber operations. Running Claude Opus 5.5 through 10 challenges with five attempts each per tier, all 50 trials without CVP access were blocked at the first prompt. Under Defense Access, 46 of 50 trials were blocked at some stage while four succeeded. Under Red Team Access, none of the 50 trials was blocked and Claude completed 34, matching its 67.6% success rate when no safeguards were applied.

According to Anthropic, Project Glasswing partners identified at least 129,000 verified software vulnerabilities between April and July 2026, while its own open-source scanning efforts found another 5,500 between April and October. More than 33,000 of those vulnerabilities have been rated critical or high severity. The company said "defenders also need access to the best tools and most powerful capabilities to secure their systems," adding that its generally available models use conservative cyber safeguards blocking most cyber attacks. The company noted the vulnerability count is "likely an undercount, as it is based on survey data from only a subset of Glasswing partners," and expects the true impact to be at least five times higher.

Industry analysts emphasized that reduced safeguards require additional controls beyond the AI model itself. Sakshi Grover, research director at IDC, said the evaluation should be viewed in context as "a vendor-run test, not an independent one," while noting the results show why authorization and scope matter when AI is used for security testing. Grover recommended enterprises give each agent a distinct identity, use short-lived privileges for specific tasks, independently check targets and actions, and test containment and recovery mechanisms. Deepika Giri, vice president of Asia/Pacific artificial intelligence platforms and advisory at IDC, said the tiered approach can work if access is continuously reviewed, noting "it only works if the vetting is real and access keeps being checked after it is granted, because an agent's behavior can change over time." Cybersecurity researcher Vibhum Dubey added that organizations need to define who is accountable for actions taken by the AI. Organizations enrolled in CVP will be subject to data retention so Anthropic can monitor for cyber misuse, though the company said its forthcoming Enterprise Frontier Safeguards service will allow eligible organizations to combine zero-data-retention capabilities with additional safeguards and store data in cloud infrastructure they control. The tiered structure balances giving security professionals the offensive capabilities they need to find vulnerabilities before attackers do, while creating accountability checkpoints that matter most when the systems being tested directly affect public safety or financial stability.