Anthropic announced a revamped Cybersecurity Verification Program (CVP) on Tuesday, integrating CVP and Project Glasswing into a single offering, with three levels of access to its most capable AI models. Anthropic’s generally available models, including Claude Opus 5.5, Sonnet 5.5 and Fable 5.1, feature cyber safeguards that block the majority of cyber operations.
See also: Florida woman arrested after Anthropic reports Claude chat

The company says the same capabilities that help defenders identify and fix vulnerabilities can also help attackers exploit them. Previously, CVP and Glasswing operated as separate programs: Glasswing provided organizations with critical software access to Claude Mythos, while the original CVP loosened security controls on the Opus and Sonnet models for approved groups.
Under the new structure, all three tiers include Opus 5.5, Sonnet 5.5, Mythos 5.1 , and future models. Each tier comes with its own verification requirements and security checks. The Defense Access tier covers SOC and incident response tasks, malware reverse engineering, and vulnerability analysis and validation. Eligible applicants include security teams defending their own systems, critical infrastructure operators, small security companies, open source maintainers, and individual researchers with a history of reporting vulnerabilities.
Anthropic aims to respond to these requests within a few days. Red Team Access adds authorized penetration testing and red teaming, limited to systems that the organization is authorized to test. Actions that could cause physical damage or mass disruption, such as ransomware deployment, are still blocked in real time.
See also: Anthropic IPO: Warns of 'catastrophic' AI risks

Currently, this level is only for organizations; individual researchers are not eligible. Reviews are expected to take a few weeks, and eligible applicants will receive Defense Access in the meantime. Specialized Access has the fewest cybersecurity safeguards and is intended for a small number of organizations authorized to test safety-critical systems such as power grids, flight systems, telecommunications networks, and interbank transportation infrastructure.
Anthropic is currently reviewing these applicants in collaboration with the U.S. government, and existing Glasswing members are moving to this level. Glasswing partners identified at least 129,000 verified vulnerabilities between April and July, and Anthropic’s own open source scanning identified 5,500 more between April and October. More than 33,000 of these vulnerabilities are rated critical or high severity.
Anthropic suggests that the true impact is likely at least five times higher, as the data comes from only a subset of Glasswing participants.
Organizations in the new program must opt in to data retention so Anthropic can monitor for misuse. Later this fall, Enterprise Frontier Safeguards will allow eligible customers to store data in cloud infrastructure they control. Until then, organizations with zero data retention access to Fable 5.1 or Mythos 5.1 can use CVP with zero data retention.
See also: Anthropic and OpenEvidence offer free medical AI in nearly 100 countries

CVP is available on the Claude Platform, Google Cloud Vertex AI, and Microsoft Foundry. On Amazon Bedrock, it is only available to customers eligible for Enterprise Frontier Safeguards. Existing CVP members retain their current settings for previous models and will be automatically assessed for access to the new ones.
