TLDR
Anthropic’s expanded Cyber Verification Program is an application desk for its strongest models: verified security professionals get Claude Mythos 5.1, Opus 5.5 and Sonnet 5.5 with fewer safeguards, in three tiers up to government co-review. It enables vetted defenders to run exploit validation and red-team work on the same models that refuse those tasks on the public API. The difference between the vetted model and the one you can buy is the refusal behavior, which means the version everyone evaluated is not the version anyone can use without an approval.
Caption: five labs, five gates. The cyber-capable tier is reachable by application (OpenAI, Google, Anthropic), by contract (Microsoft), or by waiting two weeks (Z.ai, the only open-weights row).
What Anthropic actually announced
The October 6 post folds two six-month-old programs into one. Project Glasswing, which gave critical-software organizations access to Claude Mythos, and the earlier Cyber Verification Program, which gave vetted teams reduced safeguards on Opus and Sonnet, now form a single offering with three tiers. Defense Access covers SOC work, incident response, malware reverse engineering and vulnerability validation; qualifying applicants include open-source maintainers and individual researchers with a track record of reported vulnerabilities. Red Team Access adds authorized penetration testing, organizations only. Specialized Access, the tier with the fewest blocks, is reviewed “in collaboration with the US government,” and existing Glasswing members move into it without reapproval.
The company’s own benchmark states the gap between tiers without decoration. On CyScenarioBench, a test of multi-stage offensive operations, the generally available Opus 5.5 blocked every task at the first prompt. The Defense tier blocked 46 of 50 trials. The Red Team tier blocked nothing and completed 34 of 50, which is the model’s 67.6% unsafeguarded rate. The tiers are not marketing lines; they are the difference between a model that cannot start the task and one that runs it at full capability.
The receipt Anthropic offers for why: partners in Project Glasswing reported 129,000 verified vulnerabilities between April and July, with more than 33,000 rated critical or high severity, and the company estimates the true count at five times higher because most partners did not report patched numbers. Anthropic is arguing the same capability, pointed at defenders, scales defensive throughput by years. The argument is credible, and the data is company-collected.
The gate, as a product structure
Reading the Help Center terms is where the arrangement stops being a press release and starts being a contract. One application per organization. Admins assign seats. Individual applicants are limited to the lowest tier. Data retention is required, with zero retention promised only through Enterprise Frontier Safeguards, a product Anthropic says arrives later this fall. On Amazon Bedrock, access requires EFS eligibility first. Anthropic “may review, narrow, or withdraw a grant.” A webinar on October 14 walks applicants through the portal.
The arrangement is a vetting desk in the plain sense: identity verification, an attestation of security controls, a description of the work, and a grant that can be narrowed. The company is explicit about the reasoning, and the reasoning is not unreasonable: models that can chain zero-day discovery into working exploits, which OpenAI’s system card documents for Astra, are genuinely dangerous as open API features. The CSA research note accepts the premise. Its objection is distribution: vetting criteria “appear to favor organizations that are already well resourced”, a regional hospital or a small MSSP is “structurally less likely to qualify” than a national cyber authority, and only two of eight surveyed programs publish pricing at all.
The version mismatch underneath
The benchmarked model and the purchasable model have quietly diverged. Anthropic’s vulnerability-discovery figures come from Mythos through Glasswing. OpenAI’s ExploitBench results come from Astra through Daybreak. Google’s 70-percent vulnerability-discovery rate comes from Gemini 3.8 Flash Cyber through Fairwind. The publicly served variants refuse the same tasks by design. TrustList states the consequence plainly: “the benchmarked model may not be the purchasable one”. A security team comparing a vendor’s headline number against its own results on the public endpoint is comparing two different products.
Defenders have noticed the friction on their side of the desk. A Hacker News thread from September carries an organization already allow-listed under the old CVP reporting that it still gets downgraded to an older model when asking Claude to check its own code for security problems. Earlier this year, bug-bounty operators reported that cyber policy changes “break authorized bug bounty workflows”. Anthropic’s answer to that friction is the expansion: more organizations qualify, the tiers map to actual work, Defense decisions land in days. The open question is whether the desk scales at the speed the capability is spreading.
The open-weights row
One lab in the map released the same capability to everyone. Z.ai shipped GLM-5.3 with a two-week safety delay and then published the weights, which puts the strongest open-weights cyber model one download away from any security team that cannot clear a vetting application, and one download away from everyone else too. Tokenstead has tracked the same model’s defensive ledger since August: a running vulnerability hunt that sends findings to maintainers privately and free, now past 4,200 verified findings. The rescue story from the Hugging Face breach, where the defender self-hosted an open-weights model after commercial models declined the forensic work, is the pattern in miniature.
Open weights make defensive capability un-gateable and make misuse un-gateable with it; an audited openness is what made GLM-5.3’s bypassable safeguards a measurable fact rather than a vendor assurance. The vetted-access model keeps misuse out by identity and keeps concentration in; it also puts a desk between a defender and the tool, and the desk answers to terms that can change. Which arrangement a security team prefers depends on whether its constraint is qualification or cash, and for most of the market today neither path is available on the public API.
What to watch
- Whether Defense Access review actually holds at days when application volume follows the October expansion; the queue is the gate’s real shape.
- The Enterprise Frontier Safeguards ship date: the zero-retention promise is what turns CVP from an enterprise pilot into deployable infrastructure, and it has a date attached only as “this fall”.
- The October 14 webinar: a vetting program doing marketing is a program mid-funnel; watch what changes in the terms afterward.
- Any non-US organization report of Mythos access: the CSA note’s framing was US-only as of September; the expansion’s geography is stated nowhere on the announcement page, which is itself information.
- Whether pricing for the gated tiers is ever published. Two of eight programs publish pricing today.
Sources: Anthropic announcement · Claude Help Center terms · CSA research note · TrustList listing · The Hacker News coverage · HN: CVP experience thread
Related on this site: GLM-5.3 found 4,249 vulnerabilities, for maintainers, free
Discussion
Be the first to commentStart a discussion
Got a take on this, a rig to show off, or a benchmark that says otherwise? Sign up and start the thread - your comment publishes instantly once you're in.