AIToday
AI Safety & AlignmentAI Regulation & PolicyAI Watch (Impress)Published: Oct 7, 2026, 13:00 JST

Anthropic expands Cyber Verification Program to three tiers

Anthropic expands Cyber Verification Program to three tiers

3 Key Points

  1. What happened

    Anthropic is releasing an expanded Cyber Verification Program with three access levels — Defense, Red Team, and Special Access. Users apply via the Verification Portal and can pick models like Claude Opus 5.5 and Claude Mythos 5.1.

  2. Why it matters

    Each tier carries different vetting requirements and security controls, so vetted security teams at nonprofits, universities, government bodies, hospitals, and utilities gain advanced cybersecurity features and relaxed blocking that ordinary users do not get.

  3. What to watch

    Special Access, the tier with the fewest cyber blocks, is reviewed in cooperation with the U.S. government, so the highest-risk permissions hinge on government screening. Watch for Enterprise Frontier Safeguards later this autumn.

WHO IT HITSVetted security teams — SOC and incident-response staff, malware reverse engineers, vulnerability analysts, internal and government red teams, and penetration-testing firms — gain tiered access to Claude models with relaxed blocking, while participating organizations must accept data retention rules.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

Anthropic's Cyber Verification Program is not new, but the expansion reshapes it into a graduated system. The three tiers — Defense Access, Red Team Access, and Special Access — are meant to match the scope of a security team's work, with different verification requirements and security controls applied at each level. Defense Access covers defensive work such as security operations centers, incident response, malware reverse engineering, and vulnerability analysis, and is aimed at nonprofits, universities, government security teams, and operators of critical infrastructure like regional hospitals and local government utilities.

Red Team Access goes further, permitting approved penetration testing and red team activities in addition to defensive use, for internal red teams, government red teams, and security and penetration-testing firms. Even there, operations that could cause harm or widespread disruption — deploying ransomware, damaging physical systems, or penetration-testing high-risk safety systems — remain blocked in real time, and testing is limited to authorized systems such as IT systems in critical industries. The third tier, Special Access, carries the fewest cyber blocks and is reserved for a limited set of verified organizations testing safety systems tied to aviation operations, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks. Reviews for this level are conducted in cooperation with the U.S. government.

Organizations in the program are required to retain data in order to monitor cyber misuse, which sets up the coming change: Enterprise Frontier Safeguards, described as combining zero data retention with robust security, is slated for availability later this autumn, at which point eligible organizations will be able to store data in cloud infrastructure they manage themselves. Until then, organizations with access to zero-data-retention Claude Fable 5.1 or Claude Mythos 5.1 can use a zero-data-retention version of the program. The balance the program strikes is likely to be tested at the Special Access tier, where the fewest blocks meet the most sensitive targets, and where government screening is the gate.

FAQ
How do I apply for Anthropic's Cyber Verification Program?
Users who want to join apply through the Verification Portal, which handles applications and management for Claude trust programs.
Which Claude models can participants use?
Each tier lets users choose among models such as Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, plus new AI models added later.
What is Enterprise Frontier Safeguards?
It is a new solution combining zero data retention with robust security, available later this autumn. It will let eligible organizations store data in cloud infrastructure they manage themselves.
AI Watch (Impress)Read Original Article

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleGoogle rolls out Gemini Live "シンプルガイド" for seniors