AIToday
Large Language ModelsAI Safety & AlignmentAI Regulation & PolicyTHE DECODERPublished: Oct 7, 2026, 22:01 JST

Anthropic widens Cyber Verification Program access

Anthropic widens Cyber Verification Program access

3 Key Points

  1. What happened

    Anthropic is opening its Cyber Verification Program to far more groups — corporate security teams, government agencies, universities, critical infrastructure operators, open-source developers, and individual researchers. It splits access into Defense, Red Team, and Specialized tiers, and vets Specialized applicants together with the US government.

  2. Why it matters

    The program gives vetted security professionals access to the company's most powerful models with reduced safety filters because the publicly available versions block most vulnerability research, malware analysis, incident response, and penetration testing — work that could also help attackers.

  3. What to watch

    The tiering is the test — Red Team Access is limited to organizations only, and Specialized Access requires joint vetting with the US government, so the pace of expansion hinges on how those gates are applied.

WHO IT HITSVetted security researchers, corporate security teams, and government agencies gain access to models whose safety filters normally block vulnerability research. Individual researchers and open-source developers qualify only for the Defense Access tier.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

Anthropic's expansion of the Cyber Verification Program follows its earlier, narrower effort under the name Project Glasswing. According to Anthropic, partners in that predecessor program found at least 129,000 confirmed vulnerabilities between April and July 2026, with more than 33,000 rated high-severity or critical. Those figures come from surveys of a subset of partners, and Anthropic says the real-world impact is at least five times higher.

The structure of the new program reflects the tension at its center: the same capabilities that help defenders also help attackers, which is why Anthropic kept the publicly available models blocked for most security work. The three tiers draw a line between defensive and offensive uses, and the Specialized Access tier goes furthest by requiring joint vetting with the US government for applicants testing systems like flight controls, power grids, or banking infrastructure.

What the expansion ultimately delivers hinges on how those gates are applied in practice. For Anthropic, the surveys suggest partners saw their work accelerated by months or even years, but the tiering and the joint vetting process may shape how quickly the wider pool of security professionals can actually take part.

FAQ
What can security professionals do with the reduced-filter access?
Anthropic lists vulnerability research, malware analysis, incident response, and penetration testing as the permitted uses. Basic tasks like code review or patching known flaws are still possible without special access.
Who can apply for each tier?
Defense Access is open to corporate security teams, government agencies, universities, critical infrastructure operators, open-source developers, and individual researchers. Red Team Access allows authorized attack simulations but is limited to organizations only, and Specialized Access is reserved for testing systems like flight controls, power grids, or banking infrastructure.
What results did the predecessor program produce?
Partners in Project Glasswing found at least 129,000 confirmed vulnerabilities between April and July 2026, with more than 33,000 classified as high-severity or critical. Anthropic says the real-world impact is at least five times higher.

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleClaude Docs task ledger keeps parallel work on one page