On 6 October 2026 Anthropic merged Project Glasswing and its Cyber Verification Program into one program with three access tiers. Generally available Claude models keep conservative cyber safeguards that block most cyber work. More capability depends on who the organization is verified to be, what it is authorized to test, and whether it accepts ongoing monitoring.
The Three Tiers
Anthropic's announcement says each tier includes its most capable models and has its own verification requirements and security controls.
- Defense Access covers security operations, incident response, malware reverse-engineering, and analyzing and validating vulnerabilities. Qualifying applicants include company, nonprofit, university and government security teams defending systems they own or maintain, critical infrastructure operators of any size, smaller security firms, open-source maintainers, and individual researchers with a track record of reported vulnerabilities. Anthropic aims to answer applications within a few days.
- Red Team Access adds authorized penetration testing and red-teaming, only against systems the organization is authorized to test. It is for organizations only. Real-time blocks stay on for actions that could cause physical harm or mass disruption, such as deploying ransomware. Reviews are expected to take a few weeks, and applicants get Defense Access in the meantime.
- Specialized Access has the fewest cyber blocks and is limited to verified organizations authorized to test safety systems such as flight operating systems, power grids, telecom networks and interbank transfer infrastructure. Anthropic reviews each organization in depth with the US government.
Generally available models can still be used for code review, patching known issues, finding vulnerabilities in source code you own, and triaging security alerts.
Verification Is Followed By Monitoring
Enrolled organizations must accept data retention so Anthropic can monitor for cyber misuse. Anthropic says Enterprise Frontier Safeguards, due later this fall, will let eligible organizations keep that data in cloud infrastructure they control. Anthropic verifies every applicant and asks for proof of the security controls each tier requires. Users who hit a block they think their tier should allow can report it.
How Anthropic Tested The Tiers
Anthropic ran Claude Opus 5.5 through CyScenarioBench, five attempts at each of 10 challenges per tier:
- Without program access, every task was blocked on the first prompt.
- In the Defense Access tier, 46 of 50 trials were blocked at some point.
- In the Red Team Access tier, nothing was blocked and the model completed 34 of 50 tasks, which Anthropic says matches its success rate with no safeguards applied.
These are Anthropic's own results on its own evaluation.
What Operators Should Change
An agent company that does security work for itself or for clients needs an organizational identity a model provider can vet, a written authorization for every system its agents test, and a decision on whether it can accept data retention. Without verification, the generally available models block most cyber work. Keep the authorization records where the agents cannot edit them.
Related: The agent identity (KYA) playbook covers verified operator identity for agents. See also our notes on Enterprise Frontier Safeguards and on OpenAI's critical cyber gate for Astra.