무슨 일이 일어났나요?
Anthropic launched an expanded Cyber Verification Program (CVP) that integrates its previous Project Glasswing and CVP initiatives into a single framework with three access tiers: Defense Access, Red Team Access, and Specialized Access. This program grants qualifying security professionals access to advanced AI models, including Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, with reduced cyber-blocking classifiers tailored to the specific scope of their work. The tiers range from defensive operations and malware analysis to authorized penetration testing and specialized testing of critical safety systems, with verification requirements and security controls scaling according to the tier's risk profile.
Anthropic has unified its Project Glasswing and Cyber Verification Program into a new, expanded Cyber Verification Program (CVP). This consolidated program introduces three distinct access tiers designed to match the scope of security work: Defense Access, Red Team Access, and Specialized Access. Each tier provides access to Anthropic's most capable models, including Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, but with varying levels of cyber-blocking safeguards.
The Defense Access tier is intended for defensive work such as security operations, incident response, and malware reverse-engineering. It is open to a broad range of entities, including corporate security teams, nonprofits, universities, government bodies, critical infrastructure operators, and individual researchers with a track record of reporting vulnerabilities. Anthropic states it aims to respond to applications for this tier within a few days.
Red Team Access adds authorized penetration testing and red-teaming capabilities to the defensive uses. This tier is restricted to organizations, such as in-house red teams and security firms, and requires a more rigorous review process that may take several weeks. Users in this tier are still subject to real-time blocks on actions that could cause physical harm or mass disruption, such as deploying ransomware or testing high-risk safety systems.
Specialized Access is the most restricted tier, reserved for a limited set of verified organizations authorized to test safety-critical systems like flight operating systems, power grids, and interbank transfer infrastructure. This tier has the fewest cyber blocks and requires in-depth review in collaboration with the US government. Existing members of Project Glasswing will transition to this tier without reapproval for current models.
To ensure safety, Anthropic requires data retention for all enrolled organizations to monitor for misuse, although it notes that organizations with access to Claude Fable 5.1 or Claude Mythos 5.1 with can use the CVP with zero data retention until the Enterprise Frontier Safeguards (EFS) are available later this fall. The program is available on the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry, with limited availability on Amazon Bedrock for EFS-eligible customers.
왜 중요한가요?
This development addresses the dual-use nature of AI in cybersecurity by creating a structured pathway for defenders to access powerful offensive capabilities without exposing them to the general public. By formalizing access tiers, Anthropic aims to balance the need for robust defensive tools against the risk of malicious exploitation. The program is significant because it operationalizes the use of advanced AI for vulnerability discovery and incident response, potentially accelerating the patching of critical software flaws and strengthening the security posture of critical infrastructure, while maintaining strict oversight through data retention and government collaboration for the highest-risk activities.
The expansion of the CVP is significant because it formalizes the use of advanced AI for offensive cybersecurity tasks, which are typically restricted in generally available models due to dual-use risks. By creating tiered access, Anthropic allows defenders to utilize the full potential of models like Claude Mythos 5.1 for vulnerability discovery and penetration testing, which can significantly accelerate the identification and remediation of security flaws.
Anthropic cites data from Project Glasswing, where partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026, with over 33,000 rated as critical or high-severity. The company claims that these models increased the rate of vulnerability finding by months or even years compared to manual efforts. This suggests that the new CVP could have a substantial impact on the overall security of software ecosystems and critical infrastructure.
The program also highlights the evolving landscape of and security. By implementing strict verification processes, data retention requirements, and real-time blocking for high-risk actions, Anthropic is attempting to mitigate the risks associated with providing powerful cyber capabilities to a broader audience. This approach may set a precedent for how other AI companies manage dual-use capabilities in the future.
For security professionals, the CVP offers a legitimate and supported pathway to access advanced AI tools for their work, reducing the need to rely on potentially unsafe or unauthorized methods. This could lead to a more robust and collaborative security community, where defenders are better equipped to protect against increasingly sophisticated cyber threats.
대화형 메커니즘: 실제로 작동하는 방식
이 개발의 이면에 있는 기본 기술을 대화식으로 살펴보세요.
Why can ethical evaluation not be reduced to one model score?
다음에 무엇을 볼 것인가
Monitor the adoption rates of the new CVP tiers among critical infrastructure operators and government agencies. Watch for the release of Enterprise Frontier Safeguards (EFS) later this fall, which will allow eligible organizations to use while maintaining robust safeguards. Additionally, track the reported impact of the program on vulnerability discovery rates, as Anthropic claims partners have already identified over 129,000 verified vulnerabilities through similar initiatives.
The rollout and adoption of the three CVP tiers will be a key indicator of the program's success. Watch for announcements from major critical infrastructure operators, government agencies, and large security firms regarding their enrollment in the program and their experiences with the new access levels.
The release of Enterprise Frontier Safeguards (EFS) later this fall is another important development to monitor. EFS will combine with robust safeguards, addressing privacy concerns for organizations that are hesitant to share data with Anthropic. The availability of EFS could expand the pool of eligible organizations for the CVP.
Anthropic has stated that it will share more about its efforts to secure open-source software and critical infrastructure in the coming weeks. These updates may provide further insights into the practical impact of the CVP and the specific vulnerabilities discovered through the program.
The response from the cybersecurity community and regulatory bodies to the CVP will also be worth watching. The program's tiered approach and strict verification processes may be viewed as a positive step in responsible AI deployment, or it may face scrutiny over the potential for misuse despite the safeguards in place.