Anthropic Expands Access to Its Most Powerful AI Models for Cybersecurity Teams

Anthropic cybersecurity, Anthropic AI security, Claude cybersecurity, Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, AI cybersecurity, AI security tools, AI vulnerability detection, cybersecurity AI, cyber defense AI, Anthropic Cyber Verification Program, Cyber Verification Program, Project Glasswing, AI vulnerability research, software security, critical infrastructure security, AI safety, cybersecurity news, artificial intelligence news, latest AI news

Oct 7, 2026 - 03:30
 0  0
Anthropic Expands Access to Its Most Powerful AI Models for Cybersecurity Teams

Anthropic Opens Its Most Powerful AI Models to More Cybersecurity Defenders

Anthropic is widening access to some of its most capable AI systems for cybersecurity work, taking a significant step toward putting frontier AI directly in the hands of the people responsible for defending software and critical infrastructure.

The company announced an expanded Cyber Verification Program (CVP) on October 6, bringing together two programs it has operated over the past six months: the Cyber Verification Program and Project Glasswing. The expanded system gives qualifying security professionals access to advanced cyber capabilities and reduced blocking safeguards, but access is not being opened to everyone. Organizations and researchers must go through verification and are placed into different access tiers depending on the type and sensitivity of their work.

At the center of the new program are Anthropic's most capable models for complex work, including Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1. The company says future models will also be incorporated into the program. That makes the announcement more than a simple expansion of an existing security research program: Anthropic is building a controlled channel through which highly capable AI can be used for defensive cybersecurity work before similar capabilities become broadly available.

Why Anthropic Is Giving Security Teams Fewer AI Restrictions

The decision comes from a basic problem with powerful AI: the same capabilities that help a security researcher find a vulnerability can potentially be used by someone trying to exploit it.

Anthropic's regular Claude models therefore operate with conservative cybersecurity safeguards designed to block many high-risk activities. Those restrictions are useful for preventing misuse, but they can also get in the way when legitimate defenders are investigating malware, validating vulnerabilities or conducting authorized security testing.

The new program attempts to solve that tension through verified access rather than unrestricted access. Anthropic says the expanded CVP uses different levels of verification and security controls depending on the work being performed. In other words, a security team investigating an incident does not automatically receive the same level of access as an organization conducting authorized red-team testing against sensitive systems.

That distinction is becoming increasingly important as AI models become better at understanding large codebases, tracing vulnerabilities and carrying out long sequences of technical tasks.

Three Access Levels for Different Security Jobs

Anthropic has divided the expanded program into three access tiers: Defense Access, Red Team Access and Specialized Access.

Defense Access is aimed at defensive cybersecurity work. Anthropic specifically lists areas such as security operations center activities, incident response, malware reverse engineering, and analyzing and validating vulnerabilities. Security teams, critical-infrastructure operators, open-source maintainers and researchers with a history of reporting vulnerabilities can apply for this level.

Red Team Access goes further by allowing authorized penetration testing and red-team activities. This level is restricted to organizations rather than individual applicants, reflecting the greater risk involved when AI is being used to actively test systems.

The most tightly controlled level is Specialized Access. Anthropic says this tier is reserved for a small number of organizations working on particularly sensitive systems, including areas such as power grids, flight systems and interbank transfer infrastructure. Existing Project Glasswing members will transition into this tier.

Anthropic also says members are vetted together with the U.S. government, adding another layer of oversight to access involving particularly sensitive cybersecurity capabilities.

Project Glasswing Found Far More Vulnerabilities Than Anthropic Expected

The expansion is closely tied to what Anthropic has learned through Project Glasswing, which began in April as a collaboration involving major technology, finance and infrastructure organizations.

The results have been striking. Anthropic says Glasswing partners identified at least 129,000 verified software vulnerabilities between April and July 2026. Anthropic's own open-source scanning efforts identified another 5,500 verified vulnerabilities between April and October. More than 33,000 of those vulnerabilities have so far been classified as critical or high severity.

The company cautions that these numbers are likely an undercount because the figures come from only a subset of Glasswing partners. Anthropic estimates the overall impact could eventually be at least five times larger.

That matters because traditional security teams face a problem that is becoming increasingly difficult to solve manually: there is simply too much software and too much code for human researchers to examine line by line. AI can operate across enormous codebases and investigate potential weaknesses much faster, giving defenders a way to expand the amount of security research they can perform.

Claude Mythos Is Still Not a Normal Consumer AI Model

The most important model in Anthropic's cybersecurity strategy is the Claude Mythos family.

Anthropic describes Mythos 5.1 as its most capable model for cybersecurity and biology research. Because of the potential for misuse, access remains restricted to vetted organizations through trusted-access programs. Anthropic has also introduced Fable 5.1, which uses the same underlying model as Mythos 5.1 but applies stronger safeguards for cybersecurity and biology use cases.

This controlled approach reflects Anthropic's concern that highly capable cyber AI could become dangerous if released without restrictions. The company has previously said that Mythos-class systems can find vulnerabilities at a level that could fundamentally change the economics of cybersecurity.

Rather than waiting for offensive use to catch up, Anthropic is attempting to give defenders access first.

Opus 5.5 Makes the Expansion Even More Significant

Anthropic's recently introduced Claude Opus 5.5 adds another dimension to the program.

The company describes Opus 5.5 as its strongest model to date, with major improvements in complex coding and long-running tasks. Anthropic says external testers have used it for large software migrations and difficult engineering workflows, while its own evaluations showed improvements in safety and resistance to prompt injection compared with earlier models.

Anthropic has already said Opus 5.5 is comparable to Claude Mythos 5.1 in cybersecurity and biology capabilities. As a result, the company is applying safeguards similar to those used for Fable 5.1 while preparing to expand Opus 5.5 access to verified cybersecurity professionals.

That is an important change in the AI security landscape. Advanced cybersecurity capability is no longer limited to specialized security software or isolated research systems. Increasingly, general-purpose frontier AI models are becoming capable enough to participate directly in sophisticated security workflows.

The Bigger Race Is Between AI Defenders and AI Attackers

Anthropic's move also highlights a larger problem facing the cybersecurity industry.

AI can reduce the amount of time required to discover a software weakness, understand unfamiliar code or investigate an incident. Those same advantages could eventually be used by attackers. As models improve, the question is increasingly shifting from whether AI can perform advanced cybersecurity tasks to who gets access to those capabilities and under what controls.

Anthropic's approach is essentially a controlled race: give trusted defenders increasingly powerful tools, measure what happens, and strengthen safeguards as the technology develops.

That philosophy was already visible when Project Glasswing launched. Anthropic described the initiative as an effort to use frontier AI capabilities defensively before comparable systems become widely available to malicious actors.

What This Means for the Future of Cybersecurity

The practical significance of Anthropic's announcement goes beyond its own Claude models.

If AI can reliably identify large numbers of vulnerabilities, security teams may eventually use AI as a continuous layer of software defense rather than as an occasional research assistant. Instead of waiting for a vulnerability disclosure, teams could have AI systems constantly inspect code, investigate suspicious behavior and prioritize weaknesses for human review.

But that future also requires stronger controls. Giving an AI system more freedom to test software creates a much higher consequence if the system misunderstands authorization or acts outside its intended environment. Anthropic's tiered approach is therefore as much about controlling powerful AI as it is about making cybersecurity faster.

For now, Anthropic is keeping its most sensitive capabilities behind verification rather than releasing them broadly. The company believes the benefits to defenders are significant enough to justify expanding access, but the restrictions show that it still considers these models powerful enough to require careful handling.

The result is an unusual moment in cybersecurity: AI is becoming powerful enough to uncover vulnerabilities at a scale humans cannot easily match, while the companies building these systems are simultaneously trying to ensure that the same capabilities do not become an easy advantage for attackers.

Sources

  • Anthropic — Expanding the Cyber Verification Program
  • Anthropic — Project Glasswing: Securing Critical Software for the AI Era
  • Anthropic — Claude Mythos 5.1
  • Anthropic — Claude Opus 5.5
  • Reuters — Anthropic opens its most powerful AI models to more security teams
  • VentureBeat — Anthropic's Project Glasswing and AI cybersecurity research

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
jajoy39 I’m Nahid Hasan Joy, a technology writer, web developer, and digital enthusiast with a strong interest in the ever-changing world of technology.