Anthropic is expanding access to its most capable AI models for selected cybersecurity organisations, including teams permitted to conduct high-risk offensive testing. The move brings more testing of AI’s cyber capabilities into a US-government partnership, while keeping access restricted and reviewed.
Anthropic Watch analysis
What happened
Bloomberg reports that verified organisations can apply to use Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and future models through the programme. New organisations will be reviewed in partnership with the US government, and existing Project Glasswing members are included.
The access levels differ by team. Red teams conducting authorised security testing will have broader permissions, including offensive testing. Verified defensive teams will have a narrower tier for work such as malware reverse engineering and incident response. Anthropic says it will still block activity that could cause physical harm or mass disruption. Read the report.
Why it matters
This is a controlled expansion of access to models Anthropic presents as having significant cybersecurity capabilities, not a general release for anyone to try. The practical distinction is who gets to test what: authorised red teams can probe more aggressively, while defenders get tools aimed at understanding and responding to threats.
The programme also makes government involvement part of the access-review process. That could help direct testing towards organisations responsible for critical infrastructure, but it leaves important questions about who qualifies, what oversight looks like and how results will be shared.
Our read
Giving vetted security teams room to test powerful models is more useful than pretending the capability can be put back in the box. The safeguards and tiered access matter, though: “high-risk offensive testing” is not a phrase that should come with a casual sign-up button. The test now is whether controlled access produces practical defensive knowledge without widening the circle faster than oversight can keep up.
What to watch
- Which organisations are approved and how Anthropic and the US government describe the review process.
- What limits apply to red-team testing and how blocked behaviour is enforced.
- Whether participants publish useful findings for critical-infrastructure defenders.
Discussion spark: Should access to powerful AI cyber models be expanded to vetted red teams under government review, or do the risks justify keeping testing narrower?
Sources and evidence
- Anthropic Expands Access to Latest AI Models for Cyber Firms – Yahoo Finance UK (6 October 2026, 18:58 UTC)
Anthropic Watch is independently operated by WittyWires. It is not affiliated with, endorsed by, or operated by Anthropic.