◈AI Codex
Security & Complianceupdate

The Cyber Verification Program now has three tiers, and it absorbs Project Glasswing

In brief

On October 6, 2026 Anthropic merged Project Glasswing into the Cyber Verification Program and split access into Defense, Red Team, and Specialized tiers. Who qualifies for each, which models they unlock, and how to apply.

5 min read·Guardrails

Contents

♡Sign in to save

On October 6, 2026, Anthropic combined Project Glasswing and the Cyber Verification Program (CVP) into one program and replaced the old two-tier system with three tiers. Verified organizations get Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1 with reduced cyber safeguards, scaled to the tier.

Claude's cyber safeguards can interrupt legitimate security work: exploit analysis, malware reverse engineering, penetration testing. The CVP is the way security professionals get those safeguards relaxed after Anthropic verifies who they are. The Life Sciences Verification Program does the same for biology.

The three tiers

Tier Who qualifies
Defense Security teams at companies, nonprofits, universities, and government bodies; critical infrastructure operators; smaller security firms; open-source maintainers; individual researchers with a vulnerability disclosure history
Red Team In-house red teams, government red teams, and penetration testing firms. Organizations only, not individuals
Specialized A limited set of verified organizations testing safety-critical systems such as flight operating systems and power grids, reviewed together with the US government

Why Anthropic merged the programs

Anthropic says Claude Mythos models raised the rate at which organizations find vulnerabilities, and that partners uncovered at least 129,000 verified vulnerabilities between April and July 2026. The expansion widens that group beyond the original Glasswing partners. On the same day Anthropic published a customer story on how Comcast and Booz Allen use Mythos to find exploit chains.

How to apply

Organizations apply at portal.anthropic.com/programs/cvp. Anthropic says Defense Access applications typically get a response within days and Red Team Access within weeks.

What to do

  • Security leads: decide which tier matches the work. Most internal security teams belong in Defense. Only teams that run offensive testing belong in Red Team.
  • Open-source maintainers: Defense is open to you, which is new for people outside a company.
  • Builders on the API: if your product triggers cyber refusals for a security customer, send them to this program rather than working around the safeguards. Claude Opus 5.5 explains how refusals surface in the API response.
  • Admins: the safeguard relaxation attaches to the verified organization. Keep a record of who in your company is using the verified access.

Source: Expanding the Cyber Verification Program (Anthropic, October 6, 2026).

Weekly brief

For people actually using Claude at work.

Each week: one thing Claude can do in your work that most people haven't figured out yet — plus the failure modes to avoid. No tutorials. No hype.

No spam. Unsubscribe anytime.

What to read next

Picked for where you are now

All articles →