Anthropic Opens Its Strongest AI Models To More Cyber Defenders Through Cyber Verification Programme
Hyderabad: Anthropic is expanding its Cyber Verification Programme (CVP) so that more security professionals can use its most capable Artificial Intelligence (AI) models, including Claude Mythos 5.1, Claude Opus 5.5, and Claude Sonnet 5.5. Each model comes with safeguards designed for defensive work.
The company says cybersecurity personnel require the best tools to protect their systems. This is because cybersecurity has inherent dual use: capabilities to help fix a vulnerability, and also help a cybercriminal exploit it.
Three levels of access
Anthropic says the new programme has three levels of access, allowing teams to apply the level that suits their work.
- Defence Access - It covers defensive tasks such as security operations centre, incident response tasks, reverse-engineering malware, and analysing vulnerabilities. The company says applications sent by organisations that conduct defensive cybersecurity work would be responded to within a few days.
- Red Team Access- It adds approved penetration testing. It is for organisations only, and the company says applications would take a few weeks.
- Specialised Access- It has the fewest cyber blocks. This access is limited to verified organisations that test safety systems, such as power grids, telecom networks, flight operating systems, interbank transfer infrastructure, and government administrative networks.
- Anthropic
says each organisation applying for this access will be reviewed in collaboration with the United States (US) government.
How safe is the new cybersecurity programme?
Anthropic tested Claude Opus 5.5 on CyScenarioBench to check the efficacy of this new programme. This test measures whether an AI model can plan and carry out cyber operations that take several stages. Each tier was given five attempts at each of the 10 challenges, making 50 trials per tier.
- No CVP access: Every task was blocked at the first prompt.
- Defence Access: 46 out of 50 trials were blocked at some point. The other four succeeded.
- Red Team Access: No cyber blocks occurred, and the Opus 5.5 model completed 34 out of the 50 tasks. The Red Team result is effectively the same as the model's 67.6 per cent success rate with no safeguard at all, which represents Specialised Access.
Anthropic says this gives it confidence that it can share advanced cyber skills safely with more defenders. It adds that it will keep refining its safeguards over time.
Finding vulnerabilities faster
The CVP builds on Project Glassing, an earlier scheme that gave selected organisations access to Claude Mythos models. Anthropic says the results were striking.
With the help of this new programme, the AI company's partners found at least 129,000 verified software vulnerabilities between April and July 2026. Anthropic's own scans of open-source software found another 5,500 verified software vulnerabilities between April and October 2026. More than 33,000 of these have been rated critical or high severity.
Anthropic believes the true figures are higher. They come from survey data covering only some partners, from 33 reports in total. Organisations also sorted their findings in different ways, and fewer than half shared how many flaws they had patched, often because repairs were still underway. The AI company expects the real impact to be at least five times greater.
Several partners said the models saved them months, or even years, of work in finding the same number of flaws.
How to join the programme?
Anthropic says CVP is available on the Claude Platform, Google Cloud's Vertex AI, and Microsoft Foundry. Moreover, the new programme is available only on Amazon Bedrock for customers eligible for Enterprise Frontier Safeguards.
Organisations can apply to the programme, and Anthropic will check every applicant and ask for proof of the right security controls. Current CVP members will keep their settings for older models and be assessed automatically for the new ones.
Data retention is required so that Anthropic can watch for misuse. A new option called Enterprise Frontier Safeguards, due later this autumn, will let eligible organisations store data on their own cloud systems.