Anthropic has expanded its Cyber Verification Program, giving qualifying security teams access to cyber capabilities and reduced blocking safeguards through three tiers. The key change is a broader route to powerful tools for defensive work, with tighter checks as permitted activity moves towards authorised red-teaming and sensitive systems.
Anthropic Watch analysis
What happened
Anthropic says the expanded programme combines its Cyber Verification Program with Project Glasswing. Defense Access covers work such as incident response, malware analysis and vulnerability validation. Red Team Access adds authorised penetration testing and red-teaming; Specialized Access, for a limited set of verified organisations, covers testing safety-critical or market-sensitive systems. Applicants must provide verification and show the security controls required for their tier.
The company says Defense Access applications should receive a response within a few days, while Red Team Access reviews may take a few weeks. Applicants for the latter are placed in Defense Access while their application is considered. Individual researchers are not eligible for Red Team Access, though Anthropic lists researchers with a track record of reported vulnerabilities among potential Defense Access applicants. The programme is available through the Claude Platform, Vertex AI and Microsoft Foundry, with Amazon Bedrock access limited to customers eligible for Enterprise Frontier Safeguards.
Anthropic’s own evaluation illustrates the intended distinction between tiers. Across 50 attempts at 10 CyScenarioBench challenges, it says all tasks were blocked on the first prompt without programme access; Defense Access blocked 46 of 50 at some point; and Red Team Access blocked none, with 34 tasks completed. Anthropic says that completion rate matched the evaluation with no safeguards applied. These are the company’s results on its chosen test, not an independent assessment of real-world risk.
Why it matters
The programme makes access to advanced cyber capabilities conditional on who is using them, what work they are authorised to do and what controls they can demonstrate. That is a consequential distinction: the same tools that can help find and fix vulnerabilities can also assist attacks. Anthropic says real-time blocks remain in place for actions such as deploying ransomware, damaging physical systems or testing high-risk safety systems.
The practical details matter to applicants, too. Data retention is required for enrolled organisations to monitor for misuse, although Anthropic says some customers with zero-data-retention access to specified models can use the programme that way. It says a separate solution combining zero data retention with safeguards is expected later this autumn.
Our read
This is a substantial access-policy change, not simply a new badge for security teams. The tier structure gives defenders a defined path to more capable models while recognising that authorised testing of a company’s own systems is not the same as probing a power grid or flight system. Anthropic’s benchmark figures are useful evidence of how its controls behave in that test, but they do not settle how well the tiers will work in practice. Security teams considering an application should check the scope, eligibility and data terms for the tier they need.
What to watch
- How many organisations qualify for each tier, and how long applications actually take.
- Whether independent testing or later disclosures support Anthropic’s account of the safeguards.
- When the promised zero-data-retention option becomes available to eligible organisations.
- What Anthropic shares about vulnerabilities found through the expanded programme.
Discussion spark: Should access to advanced cyber AI be widened through verified tiers like these, or do the benchmark results show that the most capable access needs stronger independent oversight first?
Sources and evidence
- Source update (6 October 2026, 19:00 UTC)
Anthropic Watch is independently operated by WittyWires. It is not affiliated with, endorsed by, or operated by Anthropic.