Anthropic Cyber Verification: Three Access Tiers

Anthropic Cyber Verification expanded on October 6, 2026 into three access tiers for qualifying security professionals. The company’s announcement brings its earlier verification program and Project Glasswing into a combined offering, with access conditions tailored to different kinds of security work.
Event date: October 6, 2026 · Sources checked: October 7, 2026
The Anthropic Cyber Verification tiers
Defense Access covers defensive activity such as incident response and vulnerability analysis. Red Team Access adds authorized adversarial testing, with additional requirements. Specialized Access is reserved for a narrower group working on sensitive systems. Existing Glasswing members move into that specialized tier for current models.
Anthropic names Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1 among the models covered by the expanded program. Access is conditional on verification and controls. This is not an unrestricted public release of the most capable cyber functionality.
Authorization and safeguards remain part of access
Anthropic says teams must stay within the systems they are authorized to test. Its announcement also describes continuing blocks on some harmful actions and different review expectations across tiers. Reduced blocking does not remove the need for a defined engagement scope or internal oversight.
The program documentation should be checked for current eligibility, workspace setup and retention requirements. Those conditions can affect procurement and implementation as much as model capabilities.
Anthropic Cyber Verification — xpu live analysis: choose access around the task
A useful application starts with the work a team needs to perform, rather than the highest tier it might obtain. Incident triage, authorized penetration testing and work on safety-critical infrastructure involve different permissions. Treating them as interchangeable can create avoidable confusion about what an agent is allowed to do.
For a deployment review, record the approved organization, workspace and target systems. Keep a clear owner for each engagement and retain an account of actions taken. Even when a model helps identify a flaw, a human process still needs to verify the finding and manage remediation.
The wider significance is a shift toward differentiated access to powerful AI tools. Our view is that evaluation should examine both useful defensive performance and the effectiveness of the surrounding controls. A program announcement establishes its design; independent evidence and operational experience will help establish how well that design works.
Sources and further reading
Related on xpu live: AI agents and permissions guide.