Anthropic expands Cyber Verification Program with three access tiers for security professionals using Claude with reduced safety filters
Anthropic opened its Cyber Verification Program to a wider pool of vetted organizations and individual researchers, giving access to Claude's most powerful models with reduced safety filters for vulnerability research, malware analysis, incident response and penetration testing. Access is split into three tiers: Defense Access (corporate security teams, government agencies, universities, critical infrastructure operators, open-source developers, individual researchers), Red Team Access (organizations only, authorized attack simulations), and Specialized Access (testing systems such as flight controls, power grids, banking infrastructure; applicants vetted together with the US government).
Entities: Anthropic, Claude, Cyber Verification Program, Project Glasswing, US government, The Decoder
0 primary
What happened
Anthropic has widened its Cyber Verification Program, which gives vetted users access to its most powerful Claude models with reduced safety filters for vulnerability research, malware analysis, incident response and penetration testing. Access now comes in three tiers. Defense Access covers corporate security teams, government agencies, universities, critical infrastructure operators, open-source developers and individual researchers. Red Team Access is for organisations only and covers authorised attack simulations. Specialized Access covers testing of systems such as flight controls, power grids and banking infrastructure, with applicants vetted together with the US government. The source is an Anthropic announcement as reported by The Decoder. The extraction found no primary links, and the article gives no dates or participant numbers for the new tiers.
Why it matters
Security teams, universities and independent researchers who were previously blocked by Claude's dual-use refusals can now apply for less restricted access. That could speed up defensive work such as triaging vulnerabilities and analysing malware. The US government's role in vetting the Specialized tier is the most notable detail, because it ties access to critical infrastructure testing to a state process. The practical impact is still uncertain. We don't know how many applicants will be accepted, how long vetting takes, or exactly which safeguards are loosened. Attackers will also be watching for ways to get into the programme or imitate vetted users.
What is noise
The headline figures (129,000 confirmed vulnerabilities, over 33,000 high or critical, and the claim that real impact is "at least five times higher") come from Anthropic's own surveys of a subset of Project Glasswing partners. They are unaudited and cannot be checked, and they describe the predecessor programme rather than this expansion. "Months or years of work saved" is also self-reported. Raw vulnerability counts say nothing about severity, whether the findings were new, or how many were fixed.
Watch next
- 01Independent verification of the Glasswing figures, for example CVE records crediting Claude-assisted discovery, or vendor and open-source maintainer statements on report volume and quality, over the next one to two quarters.
- 02Published details of vetting: acceptance rates, turnaround times, which safeguards are actually relaxed in each tier, and how Anthropic monitors and revokes access.
- 03Evidence of misuse or leakage, such as reports of verified accounts being abused or stolen, plus any regulatory or congressional response to the US government's role in the Specialized tier. Also watch whether OpenAI or Google announce comparable tiered programmes.
Coverage
1 storyMore distribution signals
Full feed →- NYT-led publishers file summary judgment brief citing internal OpenAI/Microsoft messages calling AI training "astonishing theft" and admitting chatbots substitute for journalism18 Sept 202686
- Deepseek releases V4.1-Flash, an open-source model that sharply cuts KV cache memory and input-processing compute for AI agents10 Sept 202682
- OpenAI launches GPT-6 Sol and Luna at half the token price of GPT-5.6, with roughly flat intelligence scores per independent analysis22 Sept 202680
- Anthropic threat report: Claude abused for malware, drone/missile software, mass surveillance, and industrial-scale distillation by Chinese AI labs11 Sept 202680