Anthropic has expanded its Cyber Verification Program, folding in a previous invitation-only effort called Project Glasswing to produce a single scheme with three tiers of access. The premise is that its generally available models carry conservative cyber safeguards which block most offensive security work, and in doing so block the people paid to defend systems.
Defence Access covers security teams at companies, nonprofits, universities and government bodies, operators of critical infrastructure, smaller security firms, open-source maintainers and individual researchers with a track record of reported vulnerabilities, with review in a few days. Red Team Access adds authorised penetration testing and red-teaming, takes a few weeks to review and is open to organisations only. Specialised Access is reserved for a limited set of verified organisations testing things such as power grids, telecom networks and interbank transfer infrastructure.
The useful disclosure is what the tiers actually change. On Anthropic’s own CyScenarioBench, Defence Access was blocked on 46 of 50 trials, while Red Team Access completed 34 of the 50 tasks. Red Team users still hit real-time blocks on actions such as deploying ransomware or damaging physical systems.
Anthropic reports that Glasswing partners found at least 129,000 verified software vulnerabilities between April and July 2026, more than 33,000 of them critical or high severity. Data retention is required across the tiers for now.
Source: Anthropic, Expanding the Cyber Verification Program.
