Anthropic folds Project Glasswing into an expanded three-tier Cyber Verification Program

Associated Writers

Anthropic Expands Cyber Verification Program with New Access Tiers

Anthropic PBC has announced an expansion of its Cyber Verification Program, introducing three distinct tiers designed for vetted security teams. This restructuring aims to reduce access restrictions at each successive level, enhancing the company’s collaboration with cybersecurity professionals.

The update addresses a significant limitation previously built into Anthropic’s AI products. The company considers cybersecurity to be a dual-use field; consequently, its widely available AI models employ conservative classifiers that inhibit most cyber-related tasks. Following the launch of Claude Opus 5.5 on September 22, many security operations were redirected to the older Opus 4.8 model.

In addition to the tiered access structure, Anthropic is integrating its existing Project Glasswing initiative into the Cyber Verification Program. Since its inception in April, Project Glasswing has enabled Claude Mythos to collaborate with organizations focused on securing critical software. In June, the program was expanded to include an additional 150 organizations, offering enhanced cybersecurity capabilities. All tiers in the new program will include access to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, with future models being introduced as they are released.

The initial tier, known as Defense Access, is tailored for defensive roles, encompassing incident response and malware reverse engineering. Organizations that qualify for this tier include those that maintain the systems they protect, such as corporate entities, universities, and government agencies. Individual researchers with a history of reporting vulnerabilities can also apply, as can operators of critical infrastructure, such as regional hospitals. Anthropic anticipates that a substantial number of organizations engaging in defensive cybersecurity efforts will qualify, with a goal of processing applications within a few days.

The next tier, Red Team Access, permits authorized penetration testing and red teaming against systems where the organization has received permission. At this level, however, Anthropic’s classifiers will still prevent requests that veer into potentially harmful territory, such as ransomware deployment. Applicants to this tier can expect a review process lasting several weeks, during which individual researchers will not be eligible to apply.

Specialized Access, the highest tier, imposes the fewest cybersecurity restrictions. Only organizations cleared for testing critical safety systems, such as power grids and telecommunications networks, can access this tier due to the potential life-threatening risks involved. Anthropic conducts comprehensive vetting of these organizations in collaboration with U.S. government entities. Existing members of Project Glasswing will transition directly into this tier without requiring additional approvals for current models.

Organizations enrolled in the Cyber Verification Program will be required to allow data retention, enabling Anthropic to monitor for any misuse. Additionally, the forthcoming Enterprise Frontier Safeguards will provide eligible customers the ability to store data in controlled cloud infrastructure.

Anthropic tested the new access tiers against the CyScenarioBench, a multi-stage benchmark for cyber operations. The Claude Opus 5.5 model was engaged in each of the benchmark’s ten challenges multiple times, with all attempts without program access impeded at the first prompt. Given that the scenarios were offensive in nature, substantial blocking was expected in the Defense Access tier; indeed, 46 of 50 attempts were halted at some point. In contrast, the Red Team Access tier experienced no blocks, with the model completing 34 of its 50 runs—a performance level comparable to the model’s overall 67.6% success rate without imposed safeguards.

The justification for expanding access is supported by insights from the Mythos initiative, which the new program assimilates. During the period from April to July, partners in Project Glasswing identified over 129,000 verified vulnerabilities, with Anthropic’s own examination of open-source code revealing an additional 5,500 vulnerabilities by October. Of this cumulative total, more than 33,000 were categorized as critical or high severity. However, these figures are derived from just 33 partner reports, with the company indicating that the actual impact could be significantly greater, as fewer than half of the partners disclosed the counts of patch implementations due to ongoing efforts to address these vulnerabilities.

The Cyber Verification Program is accessible via the Claude Platform, as well as through Google LLC’s Vertex AI and Microsoft Corp.’s Foundry service. However, on Amazon Web Services Inc.’s Bedrock, access is restricted to those customers qualified for Enterprise Frontier Safeguards.

[gspeech type=full]

Share This Article
Leave a comment