AIToday
Large Language ModelsAI Safety & AlignmentImpress WatchPublished: Oct 7, 2026, 19:01 JST

Anthropic opens Claude Mythos 5.1 to wider security audience with 3-tier CVP

Anthropic opens Claude Mythos 5.1 to wider security audience with 3-tier CVP

3 Key Points

  1. What happened

    Anthropic merged its Project Glasswing and CVP programs into three access levels — Defense Access, Red Team Access, and Specialized Access — letting more approved security experts use Claude Mythos 5.1.

  2. Why it matters

    Verified defenders and red teams gain access to Anthropic's top model, while actions that could cause large-scale disruption remain blocked, so the expansion appears aimed at security work rather than general release.

  3. What to watch

    The loosest tier, Specialized Access, is limited to select organizations testing systems like power grids and interbank transfer infrastructure, so broader availability hinges on who passes review.

WHO IT HITSApproved security teams doing incident response, malware reverse engineering, vulnerability analysis, and sanctioned penetration testing are the direct beneficiaries, while organizations running critical infrastructure such as power grids and interbank transfer systems are the narrow group eligible for the least-restricted tier.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

Anthropic had been running two separate efforts: Project Glasswing, which gave Claude Mythos to organizations protecting critical software, and the Cyber Verification Program, which gave vetted organizations versions of Claude Opus and Sonnet with relaxed cyber-related restrictions. The new move folds both into a single structure with three tiers — Defense Access, Red Team Access, and Specialized Access — defined by what each type of user is allowed to do.

The tiering is the notable part. Defense Access covers incident response, malware reverse engineering, and vulnerability analysis. Red Team Access adds approved penetration testing and red-team activity, but still blocks operations that could cause large-scale disruption, such as ransomware deployment or damage to physical systems. Specialized Access, the least restricted, is reserved for select organizations permitted to test systems including aviation operations, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks.

Alongside Claude Mythos 5.1, the tiers also draw on Claude Opus 5.5 and Claude Sonnet 5.5. How much this actually widens access is likely to depend on how Anthropic reviews applicants, since the most sensitive capabilities remain gated behind approval rather than being opened outright.

FAQ
Where can organizations use the Cyber Verification Program?
It is available on Claude Platform, Google Cloud's Vertex AI, and Microsoft Foundry. On Amazon Bedrock it is only available to users covered by Enterprise Frontier Safeguards (EFS).
What data rules apply to participating organizations?
Participants are required to retain data so misuse can be monitored. When EFS launches later this autumn, covered organizations will be able to store data in cloud infrastructure they manage themselves.
What happens to existing Project Glasswing members?
They move to Specialized Access without needing re-review.

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleAI makes 95% of China's 120,000 microdramas