Anthropic is expanding a program that lets vetted cybersecurity professionals use its most powerful AI models with fewer safeguards, Reuters reported on Tuesday, folding its Project Glasswing initiative into a revamped Cyber Verification Program with three tiers of access.
Anthropic said Glasswing partners found at least 129,000 verified software vulnerabilities between April and July, and that its own open-source scanning turned up 5,500 more between April and October. More than 33,000 have been rated critical or high severity, the company said. Anthropic called the figures likely an undercount, since they come from a survey of a limited number of partners, and said it expects the true impact to be at least five times higher.
Until now the company ran two programs. Glasswing gave organizations securing critical software access to Claude Mythos, Anthropic’s most cyber-capable family of models, while the original Cyber Verification Program gave vetted security teams reduced safeguards on Claude Opus and Sonnet. All three new tiers include Claude Opus 5.5, Sonnet 5.5, Mythos 5.1 and future models, according to Reuters.
The Defense tier covers work such as incident response and malware analysis and is open to security teams, critical infrastructure operators, open-source maintainers and researchers with a record of reported vulnerabilities. The Red Team tier adds authorized penetration testing and red-teaming, and only organizations can apply. The Specialized tier, which has the fewest restrictions, is reserved for a small group of organizations authorized to test safety-critical systems such as power grids, flight systems and interbank transfer infrastructure. Anthropic vets each Specialized member together with the US government, Reuters reported, and existing Glasswing members will move into that tier.
Anthropic said enrolled organizations generally must allow data retention so it can monitor for misuse, and Red Team users will still hit real-time blocks on actions such as deploying ransomware. The program runs on the Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry, and on Amazon Bedrock only for customers eligible for Enterprise Frontier Safeguards, a privacy option the company said will be available later this fall.
Access has widened in steps since Anthropic unveiled Claude Mythos Preview in April, a release that raised fears AI could hack software before it had been secured. On September 1 the company launched Claude Fable 5.1 alongside a trusted-access Mythos 5.1, and the EU cybersecurity agency ENISA later began testing Mythos 5. On Monday, a Defense Department official told the BBC the Pentagon had stopped using Anthropic products.