✉ The Friday AI Brief: the week's 5 best AI stories, tools & comparisons — in your inbox every Friday morning.

Anthropic logo

Anthropic Opens Its Most Cyber-Capable Models to More Security Teams — With Fewer Safeguards

Anthropic Opens Its Most Cyber-Capable Models to More Security Teams — With Fewer Safeguards

October 6, 2026 — After its Glasswing partners found over 129,000 verified software vulnerabilities in four months, Anthropic is expanding the program into a three-tier Cyber Verification Program.

What happened

Anthropic announced Tuesday that it is expanding a program that gives vetted cybersecurity professionals access to its most powerful AI models with reduced safeguards. The revamped Cyber Verification Program (CVP) merges two efforts the company has run for the past six months: Project Glasswing, which gave organizations securing critical software access to Claude Mythos, Anthropic’s most cyber-capable model family, and the original CVP, which gave vetted security teams relaxed restrictions on Claude Opus and Sonnet models.

All three tiers of the new program include access to Claude Opus 5.5, Sonnet 5.5, and Mythos 5.1, plus future models.

The results so far are staggering

The expansion comes with a number Anthropic clearly wanted in the spotlight: Glasswing partners found at least 129,000 verified vulnerabilities between April and July of this year. Anthropic’s own open-source scanning turned up 5,500 more between April and October. More than 33,000 of the findings were rated critical or high severity.

Anthropic says those figures are probably an undercount — they come from a survey of a limited number of partners — and expects the true impact to be at least five times higher. In other words, AI-assisted vulnerability hunting is already working at a scale that dwarfs traditional human-led disclosure.

The three tiers

The new program splits access by use case, with verification requirements and security controls tightening as the permissions grow:

  • Defense tier: Covers incident response and malware analysis. Security teams, critical-infrastructure operators, open-source maintainers, and researchers with a track record of reported vulnerabilities can apply.
  • Red Team tier: Adds authorized penetration testing and red-teaming — but only organizations can apply, not individuals.
  • Specialized tier: The fewest restrictions, reserved for a small group of organizations authorized to test safety-critical systems like power grids, flight systems, and interbank transfer infrastructure. Anthropic vets members alongside the U.S. government, and existing Glasswing members will move into this tier.

The tension at the heart of this

Anthropic is explicit about the trade-off. When it unveiled Claude Mythos Preview in April, the announcement raised fears that AI could be used to hack software before it gets secured — the classic dual-use dilemma. The company’s answer is gating: powerful cyber capabilities exist, the question is only who gets them and under what controls.

This move also mirrors Mistral’s approach revealed today — giving cybersecurity leaders and state authorities access to a version of its new Large 4 model with fewer safety restrictions for real-world red-teaming. The industry’s most capable cyber models are being opened to defenders first, under controlled conditions, while public access stays locked down.

Why it matters

If you’re responsible for any software that other people depend on, this is one of the most consequential announcements in AI safety this year. The defender’s playbook just got a serious upgrade: 129,000 verified vulnerabilities in four months suggests AI-assisted auditing is finding problems human teams were missing — including 33,000 critical and high-severity ones.

The uncomfortable flip side: the same capabilities are being deliberately kept from public release because they’d be devastating in the wrong hands. The gap between what these models can find and what ordinary users can access is now an explicit policy choice, managed by Anthropic with the U.S. government looking over its shoulder.

Frequently asked questions

What is Anthropic’s Cyber Verification Program?

It’s a program giving vetted cybersecurity professionals access to Anthropic’s most powerful AI models — including Claude Opus 5.5, Sonnet 5.5, and Mythos 5.1 — with reduced safeguards, so defenders can find vulnerabilities before attackers do.

How many vulnerabilities did the program find?

Project Glasswing partners found at least 129,000 verified vulnerabilities between April and July 2026, with over 33,000 rated critical or high severity. Anthropic believes the true figure is at least five times higher.

Who can join the program?

It depends on the tier: the Defense tier is open to security teams, critical-infrastructure operators, open-source maintainers, and proven researchers; Red Team and Specialized tiers are limited to organizations, with the Specialized tier vetted alongside the U.S. government.

Why aren’t these models publicly available with the same capabilities?

Anthropic restricts access because the cyber capabilities are dual-use — the same model that finds vulnerabilities for defenders could help attackers exploit them.

Sources: Reuters; Anthropic.

Leave a Comment

Your email address will not be published. Required fields are marked *

Get the 5 best AI tools every week

Top AI news, tools, and prompts — one short email. Free, unsubscribe anytime.

Scroll to Top