Anthropic Opens Claude's Cyber Verification Program to More Defenders
Anthropic merged its Cyber Verification Program with Project Glasswing into three vetted-access tiers for security teams using Claude.
Anthropic just handed its most capable AI models a permission slip to go looking for trouble — but only to a short, vetted list of security teams. On October 6, the company folded its existing Cyber Verification Program together with a pilot it had been running quietly called Project Glasswing, and relaunched the whole thing as a single three-tier access system for anyone doing real, authorized hacking work with Claude.
What actually changed
Here's the context: Claude, like most consumer AI models, is built to refuse requests that look like they could help someone break into a system — writing exploit code, reverse-engineering malware, probing a live network for weaknesses. That's sensible for the general public, but it's also exactly the kind of work a legitimate security team does every day. Anthropic's answer has been a verification system: prove who you are and what you're authorized to test, and the model's guardrails relax accordingly for your account.
What's new is that this used to be two separate, overlapping efforts — the standard Cyber Verification Program and the more experimental Project Glasswing — and now it's one program with three clearly defined tiers:
- Defense Access — for security operations center (SOC) analysts, incident responders, malware reverse engineers and vulnerability researchers defending their own systems. Anthropic says these reviews are turned around in days.
- Red Team Access — everything in Defense Access, plus authorized penetration testing and "red teaming" (simulated attacks a company hires someone to run against its own systems, with permission, to find holes before real attackers do). This tier takes several weeks to approve.
- Specialized Access — the narrowest tier, reserved for organizations cleared to test safety-critical systems, with reviews currently run in coordination with the US government.
All three tiers plug into Anthropic's current model lineup — Opus 5.5, Sonnet 5.5, and a dedicated security-tuned model called Claude Mythos 5.1 — plus whatever the company ships next.
The numbers behind the decision
Anthropic isn't just doing this as a goodwill gesture. The company says partners already running under the Project Glasswing pilot turned up roughly 129,000 verified software vulnerabilities between April and July 2026, more than 33,000 of them rated critical or high severity. That's a meaningful chunk of real-world bug-hunting happening with an AI model in the loop, and it's the kind of evidence Anthropic is using to justify loosening restrictions for a defined group rather than for everyone.
An AI model that can find a critical vulnerability in your codebase can, in the wrong hands, also find one to exploit — which is exactly why access to the sharper version of that capability is now a membership, not a toggle.
What this means for Indian security teams
India has one of the largest pools of security researchers and bug-bounty hunters anywhere, and a genuine shortage of SOC staff to match the scale of attacks hitting Indian banks, telcos and government systems. A program like this is relevant here in a very practical way: an Indian security firm or an independent researcher with a track record of responsibly disclosed vulnerabilities could realistically qualify for Defense Access and get a faster, less-restricted Claude to work with. The catch is the top tier — Specialized Access is explicitly being run in collaboration with the US government for now, which means India's own cyber establishment, including CERT-In (the Indian Computer Emergency Response Team that coordinates national incident response) and MeitY, has no formal seat at that table yet. If Anthropic's gated-access model becomes the template other AI labs follow for sensitive capabilities, where India's regulators and researchers sit in that verification chain is worth watching closely, especially as the DPDP Act tightens rules around who gets to touch sensitive data during a security investigation in the first place.
The bigger shift
This is part of a wider pattern: AI companies are increasingly building tiered, permissioned access into their most powerful models instead of a single public release. It's a reasonable response to a real problem — a model good enough to find a zero-day (a previously unknown, unpatched software flaw) is good enough to help someone write one. But it also means the most capable version of these tools is quietly becoming something you have to apply for, not something you can just sign up and pay for.
- Expect other AI labs to introduce similar vetted-access tiers for security-sensitive use cases.
- Expect the application and review process itself to become a competitive differentiator — speed of approval matters to a SOC team mid-incident.
- Expect questions about fairness and geography to keep coming up as long as the top tier runs through a single government's clearance process.
For now, the practical takeaway for any Indian security team reading this is simple: if your organization already has a disclosure history or runs authorized penetration tests, it's worth checking whether you qualify for Defense or Red Team Access rather than assuming the sharper tools are off-limits.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0