Anthropic's Cyber Verification Program now has 3 tiers — and Mythos for open-source maintainers
On October 6, 2026, Anthropic folded Project Glasswing into its Cyber Verification Program (CVP), the scheme that relaxes cyber safeguards for vetted security professionals, and rebuilt it as three tiers: Defense, Red Team and Specialized. The biggest change is that Claude Mythos 5.1, Anthropic's top security-capable model, previously limited to Glasswing's critical-software partners, is now included in all three tiers. Defense Access, the broadest tier, is open to security teams protecting their own systems, small security firms, open-source maintainers and individual researchers with a record of reported vulnerabilities. Red Team Access, which adds authorized penetration testing, is for organizations only, and Specialized Access for power grids, aviation and interbank systems is vetted together with the U.S. government
The three lines
- Structure — Defense, Red Team, Specialized; all three include Opus 5.5, Sonnet 5.5 and Mythos 5.1
- Wider door — open-source maintainers and proven individual researchers can apply; review in days
- Rationale — Glasswing partners found 129,000+ verified vulnerabilities April–July; 33,000+ critical or high
Key questions
- Who can apply for Anthropic Cyber Verification Program
- **It depends on the tier; only Defense Access takes individuals.** | Tier | Eligible | Review | |---|---|---| | Defense | In-house security teams, critical infrastructure operators, small security firms, open-source maintainers, individuals with reported vulnerabilities | A few days (target) | | Red Team | Organizations only | A few weeks; Defense Access meanwhile | | Specialized | Organizations testing grids, flight systems, telecom, interbank transfers | Vetted with the U.S. government |
- Who can use Claude Mythos
- **Since October 6, participants in all three CVP tiers.** | Period | Mythos access | |---|---| | Before Oct 6 | Project Glasswing partners only | | After Oct 6 | All CVP tiers (Mythos 5.1) | | General public | Still not available |
- Why are AI cybersecurity models restricted
- **The skill that finds a flaw is the skill that exploits it.** | Item | Detail | |---|---| | Default models | Opus 5.5, Sonnet 5.5, Fable 5.1 block most cyber work | | Approach | Loosen safeguards step by step for verified users | | Condition | Data retention required so misuse can be monitored | | Still blocked | Ransomware deployment and other mass-harm actions, even for Red Team |
Who should get the AI model a company considers its most dangerous? Anthropic has answered with a three-column table. On October 6, 2026, it merged two programs: the Cyber Verification Program (CVP), which loosened safeguards for approved security teams, and Project Glasswing, which gave a small set of critical-software organizations its top model. The new CVP has three tiers — Defense, Red Team and Specialized — and all three now include Claude Mythos 5.1. Open-source maintainers and individual researchers with a track record can apply.
1. Why the gate exists
Anthropic's general models — Opus 5.5, Sonnet 5.5 and Fable 5.1 — ship with safeguards that block most cyber work. The company's reasoning: the capabilities that help defenders find and fix flaws also help attackers exploit them. So the locks open only for verified people, and only so far.
This continues a pattern from early September, when Anthropic, OpenAI and Google each released cyber-focused models and all three kept them gated. The new structure decides how many keys to cut and for whom.
| Period | Program | Models |
|---|---|---|
| Before | Project Glasswing | Claude Mythos, critical-software organizations only |
| Before | Original CVP | Relaxed Opus and Sonnet for approved teams |
| From Oct 6, 2026 | Unified CVP, three tiers | Opus 5.5, Sonnet 5.5, Mythos 5.1 and future models, in every tier |
2. How the tiers differ
| Defense | Red Team | Specialized | |
|---|---|---|---|
| Allowed work | SOC and incident response, malware reverse engineering, vulnerability analysis and validation | Defense + authorized penetration testing and red teaming | Fewest cyber blocks |
| Who | In-house security teams, critical infrastructure operators, small security firms, open-source maintainers, individuals with reported vulnerabilities | Organizations only | A few organizations authorized to test power grids, flight systems, telecom networks, interbank transfers |
| Review | Days (target) | Weeks; Defense Access meanwhile | With the U.S. government; Glasswing members move here |
| Still blocked | — | Real-time blocks on ransomware and other mass-disruption actions | — |
Red Team work is limited to systems the organization is permitted to test. Every participant must accept data retention so Anthropic can watch for misuse. Later this fall, "Enterprise Frontier Safeguards" will let eligible customers keep that data in cloud infrastructure they control; until then, organizations with zero-data-retention access to Fable 5.1 or Mythos 5.1 can use CVP under ZDR.
| Channel | Availability |
|---|---|
| Claude Platform | Yes |
| Google Cloud Vertex AI | Yes |
| Microsoft Foundry | Yes |
| Amazon Bedrock | Only for Enterprise Frontier Safeguards customers |
| Existing CVP members | Keep current settings; auto-evaluated for new models |
3. The case for widening: plenty found, little fixed
| Metric | Figure (Anthropic) |
|---|---|
| Verified vulnerabilities found by Glasswing partners, April–July | 129,000+ |
| Additional finds from Anthropic's own open-source scanning, April–October | 5,500 |
| Rated critical or high | 33,000+ |
| Anthropic's estimate of true impact | At least five times higher |
One report said only 516 of 5,674 confirmed open-source findings had been patched. Discovery is far outpacing repair. Opening Defense Access to maintainers reads as putting the tool in the hands of the people who actually fix code.
4. What remains unconfirmed
- Outlets describe Glasswing's tier differently; what agrees across reports is that every tier includes Mythos 5.1 and Glasswing members move to Specialized.
- The vulnerability counts and the five-fold estimate are Anthropic's; the patch figure comes from one report.
- Whether non-U.S. organizations can join the U.S.-vetted Specialized tier was not stated.
- Mistral also announced a less restricted security edition of Large 4 for vetted users the same week, a sign that tiered access to cyber capability may become an industry norm.
Sources
- SecurityWeek — Anthropic Introduces 3-Tier Cyber Verification Program for AI Access
- Quartz — Anthropic expands cyber AI access program to more security firms
- Technology.org — Anthropic Opens Mythos-Class AI to More Defenders
- Digital Today — Anthropic overhauls cybersecurity program, expands Mythos access to all participants