# Anthropic Expands Cyber Verification Program for Claude Access

> Source: <https://insideai.news/news/cybersecurity-ai/anthropic-cyber-verification-program/13739/>
> Published: 2026-10-07 07:07:25+00:00

**October 7, 2026, (Inside AI) —** Anthropic on Tuesday expanded its [Cyber Verification Program](https://www.anthropic.com/news/cyber-verification-program), creating a three-tier system that grants vetted security professionals access to advanced Claude models with fewer safety restrictions. The program merges the former Project Glasswing and the earlier Cyber Verification Program into one unified offering.

The move follows a period of rapid adoption of AI in cybersecurity, with Anthropic reporting that its partners identified more than **129,000** verified vulnerabilities between April and July 2026. That figure, combined with Anthropic's own open-source scanning that found over **5,500** vulnerabilities, underscores the growing role of AI in both defense and offense.

The new program offers three tiers: Defense Access, Red Team Access, and Specialized Access. Each requires different verification levels and security controls. Defense Access targets security teams at companies, nonprofits, universities, governments, critical infrastructure operators, smaller security firms, open-source maintainers, and individual researchers with vulnerability disclosure track records. At this tier, Claude still blocks **46 out of 50** complex cyber tasks but allows defensive operations. Applications typically receive responses within days.

Red Team Access serves in-house red teams, government red teams, and professional penetration testing firms. This tier removes all blocks on offensive security scenarios and is limited to organizations only. The verification process takes weeks to complete. Specialized Access provides minimal safeguards for verified organizations authorized to test safety-critical systems such as flight operating systems and power grids. Anthropic reviews these applications in collaboration with the U.S. government. Existing Project Glasswing members transition to this tier automatically without reapproval.

All three tiers include access to Claude Opus 5.5, Claude Sonnet 5.5, [Claude Mythos 5.1](https://insideai.news/news/cybersecurity-ai/z-ais-glm-5-3-nears-anthropics-mythos-5-in-cyber-defence-tests/7816/), and future models.

Security vendors including Wiz, [Palo Alto Networks](https://insideai.news/news/cybersecurity-ai/palo-alto-networks-ai-cybersecurity-service/12614/), CrowdStrike, and Accenture have already built cyber products on Claude Opus since May 2026. CrowdStrike's consulting chief said that **"frontier models like Anthropic's Claude Opus are giving defenders a capability advantage that didn't exist a year ago."** (CrowdStrike consulting chief)

Anthropic also announced a **$35 million** Defender Advantage Fund (0xDAF) that distributes Claude credits for patching live vulnerabilities in open-source projects, automating scanning approaches, and developing attack-resistant capabilities. Initial grant recipients will be named in the coming weeks.

## Balancing Offense And Defense

The expansion raises questions about how AI companies manage dual-use risks. By providing tiered access, Anthropic aims to support legitimate security work while preventing misuse. The company has not disclosed how it verifies organizations or what safeguards prevent rogue actors from abusing Red Team Access. Inside AI could not independently verify the verification process.

The program's success will depend on its ability to attract top security talent and demonstrate tangible results. With cyber threats growing in sophistication, AI-assisted defense could become a standard tool. However, critics may argue that loosening restrictions on offensive capabilities could backfire if not properly controlled.

Anthropic's move follows similar efforts by other AI firms to engage with the security community. OpenAI and Google have also launched programs to provide AI models for cybersecurity research, though with varying levels of access. The industry is still grappling with how to balance openness with safety.

As AI models become more capable, the line between defensive and offensive use blurs. Anthropic's tiered approach represents a pragmatic attempt to navigate this complexity. The coming months will reveal whether it sets a precedent or faces challenges.
