HyperAIHyperAI

Command Palette

Search for a command to run...

Anthropic Expands Cyber Verification Program With New Security Tiers

Anthropic has officially expanded its Cyber Verification Program, introducing a tiered access framework designed to equip vetted security professionals with advanced artificial intelligence capabilities while maintaining rigorous safeguards against malicious use. The updated program consolidates previous initiatives, including Project Glasswing, into a unified structure comprising three distinct access levels. Each tier grants qualifying organizations varying degrees of access to the company’s latest language models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and Claude Fable 5.1, with the stringency of cyber safeguards calibrated to the specific scope of the applicant’s defensive operations. The Defense Access tier targets foundational security work such as incident response, malware reverse engineering, and vulnerability analysis. It caters to corporate security teams, critical infrastructure operators, open-source maintainers, and independent researchers, with applications typically processed within days. The Red Team Access tier extends these capabilities to authorized penetration testing and adversarial simulations for in-house and government red teams, as well as specialized security firms. This tier enforces stricter review processes, taking several weeks to approve, and maintains real-time blocks on actions that could cause physical harm or widespread disruption. Specialized Access, the least restricted tier, is reserved for a limited group of organizations vetted in coordination with U.S. government authorities. These entities are authorized to conduct safety testing on critical life-saving and market-impacting systems, such as aviation networks, power grids, and interbank infrastructure. Current members of Project Glasswing will seamlessly transition into this highest tier without requiring reapproval. To validate the program’s efficacy, Anthropic evaluated the tiered safeguards using CyScenarioBench, a benchmark measuring multi-stage cyber operational capabilities. Results indicate that while the Defense tier effectively blocks complex offensive scenarios, the Red Team and Specialized tiers permit advanced testing comparable to unrestricted model usage, demonstrating a calibrated balance between operational utility and risk mitigation. Data retention policies remain mandatory for CVP participants to enable misuse monitoring, though upcoming Enterprise Frontier Safeguards will offer zero-retention options controlled by participating organizations. The expansion builds on the measurable success of the company’s initial security initiatives, which facilitated the discovery of over 129,000 verified software vulnerabilities across critical and high-severity categories within a six-month period. Partner organizations reported that AI assistance accelerated their vulnerability identification processes by months or years. The CVP is now available through the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry, with limited availability on Amazon Bedrock for Enterprise Frontier Safeguards participants. Organizations may submit tier-specific applications, after which verification and security control assessments will be conducted before access is granted. Full tier specifications and application procedures are publicly accessible through the platform.

Related Links