Analysis
Anthropic on Tuesday announced an expanded, three-tier Cyber Verification Program (CVP) that folds in Project Glasswing and gives vetted cybersecurity professionals reduced safeguards on Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1, plus future models. Anthropic disclosed that Glasswing partners alone found 129,000 verified vulnerabilities between April and July, with the company's own open-source scanning turning up another 5,500 โ more than 33,000 of the combined total rated critical or high-severity.
Three Tiers, Three Risk Levels
The program splits access by what a verified organization is allowed to do with a less-restricted Claude:
โExisting Project Glasswing members move into this tier automatically.โ
- Defense Access โ defensive work only (SOC monitoring, incident response, malware reverse-engineering), open to company security teams, nonprofits, universities, government bodies, critical infrastructure operators and even individual researchers, with a review turnaround of a few days.
- Red Team Access โ adds authorized penetration testing and red-teaming on systems an organization has permission to test, open only to organizations (not individuals), with real-time blocks still in place for anything that could cause physical harm or mass disruption, and a multi-week review.
- Specialized Access โ the fewest cyber blocks of the three, reserved for a limited set of organizations testing safety-critical systems like flight-operating software, power grids, telecom networks, interbank transfer infrastructure and government administrative networks, reviewed in collaboration with the US government. Existing Project Glasswing members move into this tier automatically.
Anthropic itself flagged the vulnerability count as incomplete: the combined figure is based on just 33 partner reports, a fraction of the full Glasswing roster, and the company said plainly, "This is likely an undercount... we expect the true impact to be at least five times higher." One quote from partners stood out: several told Anthropic that Claude's Mythos-class models had "increased their rate of vulnerability finding by months or even years" compared with working without it.
Anthropic previously leaned hard into AI-safety messaging in its own IPO filing, and this expansion cuts the other direction โ loosening restrictions, not tightening them, for a credentialed subset of users. That's a deliberate signal to the security industry that Anthropic sees defenders, not only attackers, as the group that most needs an uncensored Claude.
The obvious limitation: a verification program is only as strong as its vetting, and Anthropic has not disclosed exactly how it screens applicants for Defense- or Red Team-tier access, or what stops a credentialed account from being compromised and misused by someone who was never vetted at all. The vulnerability count is also explicitly partial and self-reported by partners who have a commercial reason to showcase strong results, which is a different kind of number than an independently audited total.
For security teams, the practical takeaway is narrower than the headline: this expands who can ask Claude harder questions, not what Claude is newly capable of doing.

