
Anthropic is opening a wider path for security researchers to use its most capable Claude models without giving the same level of access to everyone. Its expanded Cyber Verification Program, announced October 6, creates three vetted tiers for defensive research, authorized red teaming and especially sensitive work on critical systems.
The distinction matters because the same model that can find a weakness in software may also help someone exploit it. Anthropic has been restricting some advanced cyber capabilities in generally available Claude products. The new program is an attempt to let legitimate defenders move faster while retaining a review process and limits around who receives additional access. It is a controlled-access policy, not a public release of unrestricted hacking tools.
The first tier, Defense Access, is intended for a broad pool of vetted defensive teams and individual researchers. Red Team Access is aimed at organizations conducting authorized penetration testing. Specialized Access is narrower still, reserved for a small number of vetted groups protecting critical infrastructure and other high-risk systems, in collaboration with the US government. The available models can vary by tier and include Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1.
Applicants will not necessarily receive a decision at the same speed. Anthropic says reviews for Defense Access may take days, while Red Team Access applications may take weeks. Those delays could frustrate smaller researchers trying to respond to a live incident, but they are also part of the company’s answer to the obvious question: how do you distinguish a defender from a capable attacker asking for the same assistance?
Anthropic published tests to explain the trade-off. In one set of 50 trials, the unrestricted comparison model blocked the first prompt in every case. Defense Access blocked 46 of the 50 trials at some point, while the more permissive Red Team Access completed 34 of 50. Those are company-reported results from a particular evaluation, not a guarantee that harmful use will always be stopped or that legitimate work will always succeed. The widening access comes with a measurable increase in capability and risk.
The company also says its security collaborations identified at least 129,000 vulnerabilities between April and July, with another 5,500 findings from its own scans through October; about 33,000 of the combined findings were rated high or critical. A finding is not the same as a fixed vulnerability. The useful measure over time will be whether affected maintainers can verify, prioritize and patch the issues before attackers benefit.
The shift adds another layer to Anthropic’s debate over how to release Mythos-class security capabilities. Strong AI could make defensive auditing cheaper for organizations that cannot afford large specialist teams. It could also compress the time between discovering a flaw and weaponizing it. Anthropic’s tiered system acknowledges both possibilities, but its credibility will rest on how carefully it vets access, monitors misuse and reports outcomes beyond headline vulnerability counts.







