Anthropic Opens Its Most Powerful Models to Vetted Cyber Teams
Anthropic unveiled an expanded Cyber Verification Program on Tuesday, giving vetted security teams access to its most capable AI models with fewer safeguards — after partners found at least 129,000 software vulnerabilities in three months.

Anthropic is handing hackers its best tools. The AI company said Tuesday it will open its most capable models to vetted cybersecurity teams with far fewer restrictions than the public versions get.
The expanded Cyber Verification Program, or CVP, merges two programs Anthropic has run for six months. One, Project Glasswing, gave organizations guarding critical software access to Claude Mythos. The other gave vetted security teams reduced safeguards on Claude Opus and Sonnet. Both now fold into a single program with three access tiers.
The reason, Anthropic says, is results. Partners in Project Glasswing found at least 129,000 verified software vulnerabilities between April and July, the company said. More than 33,000 were rated critical or high severity. Anthropic’s own open-source scanning turned up another 5,500 between April and October.
The company called those figures an undercount. The survey covered only a subset of its partners, it said, and the real impact could be at least five times higher.
Three levels of access
The Defense tier is the broadest. Security teams, critical infrastructure operators, open-source maintainers and researchers with a record of reporting vulnerabilities can apply. It covers defensive work like incident response, malware reverse-engineering and validating suspected flaws.
The Red Team tier adds authorized penetration testing and red-teaming. Only organizations can apply, and only against systems they are allowed to assess.
The Specialized tier has the fewest restrictions. It is reserved for organizations authorized to test safety-critical systems like power grids, flight operating systems, telecom networks and interbank transfer infrastructure. Anthropic says it reviews each applicant in collaboration with the U.S. government.
All three tiers get access to Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1, plus future models. Existing Glasswing members move over without reapplying.
Powerful, with limits
Anthropic measured what the relaxed rules change. In 50 simulated cyber scenarios, the standard model was blocked on every task. With Red Team access, it completed 34 — about the same rate the company records with no safeguards applied at all.
The loosened rules are not total. Anthropic says safeguards still block actions that could cause physical harm or mass disruption, including ransomware deployment.
The announcement follows fears raised in April, when the unveiling of Claude Mythos sparked concern that AI could find software flaws faster than people could fix them. Booz Allen and Comcast contributed case studies on scanning their own codebases through the program.


