Anthropic Opens Cyber Verification Program to More Security Teams With Reduced Claude Safety Filters
Anthropic is expanding its Cyber Verification Program (CVP) to a much larger pool of vetted security professionals, giving them access to Claude's most powerful models with reduced safety filters. Access is split into three tiers: Defense, Red Team, and Specialized. Anthropic claims partners in its predecessor program, Project Glasswing, found at least 129,000 confirmed vulnerabilities between April and July 2026.
Anthropic is opening its Cyber Verification Program (CVP) to a much wider pool of security professionals, giving vetted organizations and individual researchers access to Claude's most powerful models with reduced safety filters, according to The Decoder, which cites Anthropic's announcement.
The reduced restrictions cover vulnerability research, malware analysis, incident response, and penetration testing. Publicly available Claude models block most of that work because the same capabilities could assist attackers. Basic tasks such as code review or patching known flaws remain available without special access.
Three access tiers
The CVP divides access into three levels:
- Defense Access: Open to corporate security teams, government agencies, universities, critical infrastructure operators, open-source developers, and individual researchers.
- Red Team Access: Allows authorized attack simulations. Limited to organizations only; individuals are excluded.
- Specialized Access: Reserved for testing systems such as flight controls, power grids, and banking infrastructure. Anthropic vets every applicant for this tier together with the US government.
Project Glasswing results
The CVP follows Project Glasswing, a predecessor program. According to Anthropic, Glasswing partners found at least 129,000 confirmed vulnerabilities between April and July 2026. More than 33,000 were classified as high-severity or critical.
These figures come from surveys of a subset of partners, not an independent audit. Anthropic claims the real-world impact is at least five times higher. Several partners reported that the AI accelerated their work by months or even years, per the company.
What is not disclosed
The source does not specify which Claude models are included, the exact filters relaxed at each tier, pricing, or application timelines. No new model or model version is part of this announcement; it changes access policy for existing models.
What this means
This is a tiered, identity-based access model for dual-use capability, and it formalizes a practice that frontier labs have handled informally. Rather than setting one global refusal threshold, Anthropic is shifting the control point from the model's behavior to the verification of the user. The Specialized tier, with US government co-vetting, signals that Anthropic treats attacks on physical and financial infrastructure as a category requiring state-level involvement.
The Glasswing numbers should be read cautiously. They are self-reported, drawn from a subset of partners, and the "five times higher" estimate is Anthropic's own extrapolation. Confirmed-vulnerability counts also say nothing about exploitability or remediation rates. Still, if even the confirmed figure holds, it indicates that AI-assisted vulnerability discovery is operating at a scale that strains triage and patching capacity on the defender side.
The open question is leakage: a wider verified pool raises the risk of credential misuse or insider abuse, and Anthropic has not detailed monitoring or revocation mechanisms. Competitors with similar trusted-access programs will face the same trade-off between defender utility and misuse risk.
Related Articles
Anthropic launches Claude for Google Workspace add-on in public beta, adding sidebars to Docs, Sheets and Slides
Anthropic has released the Claude for Google Workspace add-on in public beta, placing a Claude sidebar inside Google Docs, Sheets, and Slides. It is available to all paid Claude users through the Google Workspace Marketplace, and includes an "ask before edits" preview mode.
Cline v4.1.23 fixes Claude 400 errors on custom Anthropic URLs, changes defaults for 19 providers
Cline v4.1.23 fixes a 4.1.22 regression that caused 400 errors when using Claude through custom Anthropic base URLs such as Azure AI Foundry. It also changes default models for 19 providers and adds GPT-6.1 Sol to the recommended list.
Cline CLI v3.0.69 raises MCP startup timeout from 3 to 10 seconds, fixing silently dropped Windows servers
Cline CLI v3.0.69 raises the default MCP server startup timeout from 3 seconds to 10 seconds. On Windows, servers launched via npx or uvx were being silently dropped. The release also fixes Claude requests through custom Anthropic base URLs, reasoning-level mismatches, and a broken `cline config --json` command.
OpenAI to watermark ChatGPT and Codex text in the EU under AI Act; API opt-in available worldwide
OpenAI will add an invisible watermark to text generated by ChatGPT and Codex in the European Union to comply with the EU AI Act's transparency rules. Developers anywhere can enable it on select API models starting today, but it is off by default. OpenAI's own tests show detection falling from about 92% to 66% after 10% of words are replaced with synonyms.
Comments
Loading...