More Defenders Get Access to Claude’s Cybersecurity Tools

Anthropic is widening its Cyber Verification Program, giving vetted security professionals access to Claude models with fewer safety filters for defensive work. The program has three access tiers, while results reported by partners in its predecessor program point to both large-scale vulnerability discoveries and the need to interpret those figures carefully.

WTF Index TERMINATOR
◄ Terminator 3 Idiocracy 0 ►

Expanded access to powerful models with fewer safeguards creates some potential for misuse, though the program is aimed at vetted defensive security work.

More Defenders Get Access to Claude’s Cybersecurity Tools

Anthropic is expanding access to Claude for cybersecurity work through its Cyber Verification Program (CVP). Vetted organizations and individual researchers can use the company’s most powerful AI models with reduced safety filters for vulnerability research, malware analysis, incident response, and penetration testing.

Why access is being widened

Claude’s publicly available models block most of this kind of work because the same capabilities could also help attackers. That creates a challenge for security professionals: tools that could help identify or investigate a weakness may also be misused to exploit systems.

Anthropic’s program is designed to give approved users access for specified security work. The distinction matters because ordinary access remains available for basic tasks such as code review and patching known flaws. Those tasks do not require special approval, according to the source article.

With the CVP, Anthropic is widening the pool of people and organizations that may qualify for more capable tools. The program covers defensive research and response, as well as authorized attack simulations. Access is divided into three tiers, each with different eligible users and uses.

Three tiers set different boundaries

“Defense Access” is available to corporate security teams, government agencies, universities, critical infrastructure operators, open-source developers, and individual researchers. This tier is the broadest described in the program and includes both organizations and individuals.

“Red Team Access” is for authorized attack simulations, but is limited to organizations. That distinction keeps this tier focused on institutional testing rather than individual applicants, while recognizing that simulations can be part of security work.

“Specialized Access” covers testing systems such as flight controls, power grids, or banking infrastructure. Anthropic vets every applicant for this tier together with the US government. The source describes this joint review as a feature of the specialized tier, which focuses on systems where security failures could have wider consequences.

Earlier program results offer a measure of scale

The CVP follows Project Glasswing, a predecessor program. According to Anthropic, partners in that program found at least 129,000 confirmed vulnerabilities between April and July 2026. More than 33,000 were classified as high-severity or critical.

Those figures are based on surveys of a subset of partners, rather than a complete count across all participants. Anthropic says the real-world impact is at least five times higher. That estimate is the company’s characterization of the results; the source does not provide a separate full tally to verify it.

Several partners also reported that AI sped up their work by months or even years. The reports suggest that the tools may help security teams move through research more quickly, but they do not establish that every team or task will see the same gains.

Broader access brings both opportunity and oversight

The expanded program puts more security professionals in a position to use models that are otherwise subject to stricter filters for cyber-related work. Its tier structure reflects the range of activities involved, from individual vulnerability research to organizational simulations and testing of critical infrastructure.

For security teams, the practical change is a route to apply for access matched to their work. For Anthropic, widening access means evaluating who can use these capabilities and for what purpose. The reported Project Glasswing findings provide a reason for defenders to seek such tools, while the program’s eligibility rules and review process show that access remains controlled.

The source leaves open how many applicants will qualify or how the expanded program will perform over time. For now, the stated design pairs broader cybersecurity access with distinct limits for each tier, and the earlier partner reports offer an initial, qualified account of what AI-assisted security work may achieve.