Eigen RadarAI
Analysis

Anthropic splits cyber model access into three verification tiers

Anthropic has expanded its cyber verification program with separate access conditions for defense, authorized red teaming and testing critical systems. Individual researchers can apply for defense access, while broader capabilities are reserved for verified organizations. Project Glasswing partners join the same program. Participants must retain data for misuse monitoring, with transition arrangements preserved for certain existing customers.

Artificial Intelligence··Evening
A metal network appliance connected by a short cable to a laptop on a bright workbench, with a spare cable and closed equipment case behind.

Glasswing and cyber verification join one program

Anthropic expanded its Cyber Verification Program, which verifies access to AI models for cybersecurity work, on 6 October. Defense, red-team and specialized access carry different application requirements. Project Glasswing, which provides the Mythos model to organizations protecting critical software, joins the same program. Existing Glasswing partners move into specialized access without another approval process for their current models.[1], [2]

The three tiers include Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1. Anthropic attributes the restrictions to the use of these capabilities both for finding and repairing flaws and for conducting attacks. It says generally available models remain usable for ordinary code review and security patching.[1]

Individuals can seek defense access while red teaming is for organizations

The defense tier covers security operations, incident response, malware analysis and vulnerability validation. Companies, universities, nonprofits and government bodies protecting their own systems can apply. Critical-infrastructure operators, smaller security firms, open-source maintainers and individual researchers with a history of reporting vulnerabilities are also eligible. Anthropic aims to respond within a few days.[1], [2]

Red teams test defenses using an attacker’s methods on systems they are authorized to assess. This tier is open only to organizations conducting authorized penetration tests; individual researchers cannot apply. Reviews may take weeks. Qualifying applicants can receive defense access while waiting. Real-time blocks remain on activities capable of causing physical harm or mass disruption.[1], [2]

Critical-system access requires detailed review and data retention

Specialized access is reserved for a limited set of organizations authorized to test high-impact systems, including flight operations, power grids, telecom networks and interbank transfer infrastructure. Anthropic reviews these applicants in detail with the US government. Participants must accept data retention for monitoring misuse.[1], [2]

Anthropic plans to offer Enterprise Frontier Safeguards, its enterprise protection arrangement, later in the autumn. Eligible customers will be able to retain data in cloud infrastructure they control. Organizations already using Fable 5.1 or Mythos 5.1 with zero data retention can preserve that arrangement during the transition. The program is available through Claude Platform, Google Cloud Vertex AI and Microsoft Foundry; Amazon Bedrock access is limited to customers eligible for the enterprise safeguards.[1], [2]

References

  1. News sourceAnthropicAnthropic expands cyber access through three verification tiers↩1↩2↩3↩4↩5↩6
  2. News sourceSecurityWeekAnthropic’s cyber program divides access into three tiers↩1↩2↩3↩4↩5