FINANCE, POLICY & MARKETSPublished by Paul Ivinskas
fc.The Financial CurrentDAILY INTELLIGENCEWhat matters across finance
Back to newsfeed
News

Anthropic expands advanced AI access for verified cybersecurity teams

Three access tiers broaden Anthropic’s cybersecurity program, with tighter checks for sensitive infrastructure work. Reported vulnerability findings remain company claims.

0% through article

Analysis

Anthropic expanded its Cyber Verification Program on October 6, giving vetted cybersecurity professionals access to its strongest models with fewer cyber-related blocks. It combines the earlier program with Project Glasswing, which provided Claude Mythos to organizations securing critical software. [2]

Access depends on the work

Defense Access covers work such as incident response and malware analysis. Red Team Access adds authorized penetration testing, where specialists probe systems with the owner’s permission; only organizations can apply. All three tiers include Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1, Reuters reported. [2]

Specialized Access is reserved for a smaller group authorized to test sensitive systems, including power grids, flight systems and interbank-transfer infrastructure. Anthropic reviews these organizations with the U.S. government. Existing Glasswing members move into this tier. [2]

Verification and safeguards remain

Applicants must describe their security work and attest to required controls. Independent researchers on paid plans can apply for Defense Access; higher tiers are organization-only. Approval can be narrowed or withdrawn, and Anthropic’s usage policy still applies. [3]

Defense Access users have until December 15, 2026 to adopt phishing-resistant multifactor authentication and stop using API keys. Until then, some multifactor authentication is required and keys expire every seven days. Existing participants retain their current access and corresponding requirements under existing terms. [3]

Generally available models still support code review, patching known problems and finding weaknesses in source code users own. The verified program permits additional security work rather than removing every safeguard. [1]

Findings are not completed repairs

Anthropic says Glasswing partners found at least 129,000 verified software vulnerabilities between April and July 2026, while its open-source scans found another 5,500 between April and October. More than 33,000 were rated high or critical severity. [1]

The company says its figures draw on partial reports from 33 partners and its open-source partnerships. Organizations used different triage approaches, and fewer than half the partners disclosed patch totals, often because fixes were unfinished. The findings therefore do not establish how many problems have been repaired. [1]

Monitoring comes with access

The program generally requires data retention to monitor misuse. The help page allows an interim exception for organizations already granted zero-data-retention access to Fable or Mythos. The forthcoming Enterprise Frontier Safeguards offering would let eligible organizations store data in cloud infrastructure they control. [3]

What remains uncertain

Access remains conditional. Company-reported vulnerability counts do not establish an independently audited patch rate or prevention of misuse.

Sources

Flag an error or suggest a correction →Public corrections log →

AI-generated researchMethodology