Business & Industry

Anthropic Opens Claude Cyber Access in Three Tiers

Anthropic is handing its strongest security tools to the defenders who need them, with conditions attached. The company folded two older programs into one three-tier system, and every tier now requires data retention.

Evan BrooksEvan Brooks
Heat: 1,200
Anthropic Opens Claude Cyber Access in Three Tiers

Anthropic is handing its strongest security tools to the defenders who need them, with conditions attached. The company folded two older programs into one three-tier system, and every tier now requires data retention.

Anthropic's Cyber Verification Program, Explained

Anthropic expanded its Cyber Verification Program on October 6, opening advanced cyber capabilities and looser blocking filters to vetted security professionals. The program now runs on three access tiers. Teams apply for the level that matches the scope of their work, and every tier includes Anthropic's most capable models: Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models as they arrive.

The reason the company gates this at all comes down to a single word: dual-use. The same ability that helps a defender find and patch a vulnerability can help an attacker exploit it. So Anthropic's general models ship with conservative cyber safeguards. Those safeguards block most security work by default. Who gets past them? That's what the program decides.

The Three Anthropic Access Tiers, Side by Side

Here's where the tiers diverge. Defense Access covers defensive work: security operations centers, incident response, reverse-engineering malware, and analyzing and validating vulnerabilities. Qualifying groups include security teams at companies, nonprofits, universities, and government bodies defending their own systems. Critical infrastructure operators like regional hospitals and municipal utilities fit too, as do smaller security firms, open-source maintainers, and individual researchers with a record of reported vulnerabilities. Anthropic aims to answer these applications within a few days.

Red Team Access takes the defensive list and adds authorized penetration testing and red-teaming. In-house red teams, government red teams, and security and pen-testing firms qualify. The limit is explicit: testing is allowed only on systems the org is authorized to touch. Even here, Anthropic keeps real-time blocks on actions that could cause physical harm or mass disruption. Deploying ransomware counts. So does damaging physical systems or pen-testing high-risk safety systems. Reviews here take a few weeks, and the tier is for organizations only. Individuals don't qualify.

Specialized Access is the deepest tier, with the fewest cyber blocks. It's reserved for a small set of verified organizations cleared to test safety-critical systems like flight operating systems, power grids, telecom networks, and interbank transfer infrastructure. Anthropic reviews every applicant in depth in collaboration with the US government, and existing Project Glasswing members move straight into this tier.

What Each Anthropic Tier Opens Up, and Where Blocks Remain

The headline feature is a drop in the blocking classifiers that trip up legitimate security work. During its evaluation, Anthropic expected heavy blocks on the generally available model and the Defense tier, and no blocks on Red Team and Specialized. The numbers back that up: in the Red Team tier, Claude Opus 5.5 completed 34 of 50 tasks, roughly matching its 67.6% success rate with safeguards off. That's the point of the program, and it shows the gap between a blocked model and an open one.

The hidden condition is data retention. Every organization enrolled in the program has to let Anthropic keep logs so it can watch for misuse. That's the trade: fewer blocks in exchange for visibility. For a security team chasing a live incident, that's a fair deal. For firms that can't hand over client data, it's a hard limit.

Anthropic says a fix is coming. Later this fall it plans to ship Enterprise Frontier Safeguards, a setup that pairs zero data retention with its safety monitoring. Eligible groups will then be able to keep data in cloud infrastructure they control. Until that lands, the tighter rule holds.

How Anthropic's Program Compares to OpenAI's

Anthropic isn't alone in opening the door. OpenAI runs a similar effort, Trusted Access for Cyber, aimed at the same problem: trusted defenders need fewer guardrails than the public. The two approaches differ in shape. Anthropic's version is tiered by the type of work, with government review at the highest level and logging across the board.

Both programs are wrestling with the same tension. Cybersecurity is one of the clearest cases where a model's danger and its usefulness come from the same capability, so the choice isn't whether to gate access but how tightly. Anthropic's answer is to gate by scope, verify the organization, and keep a record.

Who Should Apply to the Anthropic Program

The expanded Cyber Verification Program is live now, and applications run through Anthropic's CVP portal. If your team does defensive security work, Defense Access is the entry point and the fastest one to clear. If you run authorized offensive tests, Red Team Access is the target, with a longer review. Specialized Access stays narrow. It's reserved for the systems where a mistake could hurt people or markets.

The practical takeaway: if your general Claude model keeps blocking legitimate security tasks, this program exists to fix that, as long as you accept the data retention that comes with it.

Share This Story

Mentioned products

Sources

Related AI News

Google Cloud's Gemini Agent Takes on Work Tasks
Product

Google Cloud's Gemini Agent Takes on Work Tasks

Google's Gemini just got a promotion from answering questions to finishing work. Businesses get it first, and the model picker reaches outside Google on day one.

Heat: 820
Anthropic's New Usage Policy Bans Model Abuse
Business & Industry

Anthropic's New Usage Policy Bans Model Abuse

Anthropic rewrote its rules for the first time in a year. The headline change protects the model itself, and the election section got a more careful rewrite than most people expected.

Heat: 780
Anthropic's Free OSS Scanner Hunts Open-Source Bugs
Product

Anthropic's Free OSS Scanner Hunts Open-Source Bugs

Anthropic is handing open-source maintainers a free bug-hunting service run by its strongest models. No human checks the reports first, which is both the appeal and the catch.

Heat: 700
Anthropic's $100M Plan to Train 10,000 AI Engineers
Business & Industry

Anthropic's $100M Plan to Train 10,000 AI Engineers

Anthropic is spending $100 million to build a specific kind of engineer, one who can move AI from a slide deck into a working system. The catch: you can't apply, and the first badges won't exist until 2027.

Heat: 1,050