Anthropic expands its Cyber Verification Program (CVP), giving verified security teams access to advanced AI capabilities through three different access tiers. Anthropic cyber verification program was announced on October 6, 2026. The program provides qualifying organizations with reduced cyber safeguards on models including Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1. Anthropic says its partners already uncovered at least 129,000 verified software vulnerabilities between April and July 2026, showing how quickly AI can assist with security testing.
Anthropic Creates Three Cybersecurity Access Tiers
Anthropic cyber verification program has separated the expanded program into a tiered structure with three different access levels. The three are defense access, Red Team access, and specialized access.
- Defense Access: Focuses on security operations, incident response, malware reverse engineering, and vulnerability analysis. Entities that may be eligible for Defense Access include companies, non-profits, universities, government organizations, open-source maintainers, and individual researchers with reported vulnerabilities. Anthropic anticipates that many organizations engaged in defensive security work will qualify.
- Red Team Access: It introduces paid-for pentesting and red-team operations. It requires organizations to gain authorization before conducting tests on the relevant systems, as well as on systems used by vital sectors. Anthropic continues to prevent attempts at physical or widespread disruption, such as deploying ransomware or targeting high-risk safety systems.
- Narrow Utilization: It is under the strictest of cyber controls. Anthropic limits use to a small set of authenticated entities that experiment with systems where a malfunction could potentially harm humans or critical infrastructure systems such as airport systems, power grids, cell networks, bank networks, or government installations.
AI Finds More Than 129,000 Verified Vulnerabilities
Anthropic says Project Glasswing partners uncover at least 129,000 verified software vulnerabilities between April and July 2026 using Claude Mythos models. The company also identifies another 5,500 verified vulnerabilities through its own open-source scanning efforts between April and October.
More than 33,000 of the reported vulnerabilities receive critical- or high-severity ratings. Anthropic says these figures likely represent only a fraction of the total impact because the data comes from a subset of partners. The company estimates that the true impact could be at least five times higher. The speed of vulnerability discovery is one of the most important parts of the announcement. Several Project Glasswing partners tell Anthropic that finding the same number of vulnerabilities without Claude Mythos would take months or even years.
Anthropic Tests How Much Access Each Tier Provides

Anthropic tests the new safeguards using CyScenarioBench, an evaluation designed to measure whether AI models can plan and execute multi-stage cyber operations. Without CVP access, Claude Opus 5.5 blocks every task in the company’s test. In the Defense Access tier, safeguards block 46 of 50 trials. The remaining four tasks succeed.
The Red Team Access tier produces a different result. Anthropic reports no blocks across the 50 trials, and Claude Opus 5.5 successfully completes 34 of them. That matches the model’s 67.6% success rate when no safeguards apply in the evaluation. These results show why Anthropic separates access into different levels. Defensive teams need powerful AI to inspect systems and identify weaknesses, while unrestricted cyber capabilities can also create risks when used for harmful purposes.
Anthropic Keeps Safeguards for High-Risk Cyber Actions
The larger program doesn’t have any exemptions from all cybersecurity restrictions. Since the same AI efficiency can make it easier to patch holes or be exploited to make them, Anthropic is concerned with cybersecurity as both an offensive and a defensive area.
“Red Team” users, for instance, can perform pen testing in accordance with this authority, but continued moratoriums remain in place for attempts to cause physical harm or significantly disrupt other problematic acts. Customized Access is far less restricted because it is limited to entities that undergo more rigorous verification and are permitted to perform testing on higher-risk systems.
The company also needs to hold onto data for the companies that enroll in Anthropic cyber verification program, so it can track cyber abuse. At a later date, the company introduces Enterprise Frontier Safeguards, which permits participating organizations to mix stronger safeguards with zero retention of data in their own cloud.
AI Security Changes the Pressure on Unpatched Systems
For businesses, this creates a simple question: If AI can uncover vulnerabilities at this pace, how long can an unpatched website, application, or CRM remain safe?
Three checks make sense this week:
- Review exposed systems: Check websites, applications, APIs, and other internet-facing services for known vulnerabilities.
- Prioritize critical fixes: Focus first on high- and critical-severity issues that affect customer data, authentication, payments, or business operations.
- Test third-party software: Review Cloud Security Tools, plugins, integrations, libraries, and open-source components because vulnerabilities can enter a system through dependencies.
Anthropic cyber verification program shows that AI-assisted security is moving toward continuous vulnerability discovery. As these tools become more capable and available to verified defenders, organizations may need to shorten the gap between finding a security flaw and fixing it.