Anthropic Launches 3-Tier Cybersecurity Verification Program for AI Access Control
Anthropic has launched a revised Cyber Verification Program (CVP), merging its existing CVP and Project Glasswing into a unified framework offering three distinct access levels for its advanced AI models.
Three-Level Cybersecurity Verification Framework
Anthropic has launched a revised Cyber Verification Program (CVP), merging its existing CVP and Project Glasswing into a unified framework offering three distinct access levels for its advanced AI models. The initiative aims to balance AI utility with security by implementing tiered verification processes and safeguards. The company’s widely available models, including Claude Opus 5.5, Sonnet 5.5, and Fable 5.1, incorporate built-in restrictions to prevent misuse in cyber operations. These safeguards are designed to mitigate risks associated with the dual-use nature of AI capabilities, which can be leveraged by both defenders and adversaries.
Previous CVP and Glasswing Integration
Previously, the CVP and Glasswing operated as separate initiatives. Glasswing provided select organizations with access to Claude Mythos for critical software security tasks, while the original CVP allowed approved teams to bypass certain restrictions on Opus and Sonnet models. The updated structure consolidates these programs, ensuring all three tiers include access to Opus 5.5, Sonnet 5.5, Mythos 5.1, and future models. Each tier requires specific verification steps and enforces unique security protocols.
Defense Access Tier
The Defense Access tier is intended for entities engaged in cybersecurity operations such as security operations center (SOC) activities, incident response, malware reverse engineering, and vulnerability analysis. Eligible applicants include internal security teams, critical infrastructure operators, small security firms, open-source maintainers, and researchers with a track record of vulnerability disclosures. Anthropic pledges to process applications within days.
Red Team Access Tier
The Red Team Access tier grants authorized penetration testing capabilities, limited to systems explicitly permitted for evaluation. Real-time restrictions prevent actions that could cause physical harm or large-scale disruptions, such as ransomware deployment. This tier is currently restricted to organizational applicants, with individual researchers excluded. Review timelines for this level extend to several weeks, during which qualifying entities may receive temporary Defense Access.
Specialized Access Tier
The Specialized Access tier imposes minimal cybersecurity restrictions and is reserved for a select group of organizations tasked with testing safety-critical systems. These include power grids, aviation systems, telecommunications networks, and interbank transfer infrastructure. Anthropic collaborates with U.S. government agencies to vet applicants for this tier, with existing Glasswing participants transitioning to this level.
Data Retention and Enterprise Frontier Safeguards
Data retention requirements are mandatory for all program participants, enabling Anthropic to monitor for potential misuse. A forthcoming feature called Enterprise Frontier Safeguards will allow eligible customers to store data in their own cloud infrastructure later this year. Until then, organizations using Fable 5.1 or Mythos 5.1 without data retention access can utilize the CVP under zero-retention conditions.
CVP Accessibility and Vulnerability Metrics
The CVP is accessible via the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry. On Amazon Bedrock, access is limited to customers meeting Enterprise Frontier Safeguards criteria. Current CVP members retain their existing settings for older models and will be automatically assessed for access to newer versions. Glasswing partners have identified over 129,000 verified vulnerabilities between April and July, with Anthropic’s open-source scanning initiatives uncovering an additional 5,500 vulnerabilities by October. Over 33,000 of these are classified as critical or high severity, though the company estimates the actual impact could be up to five times higher due to incomplete participation data.
