← All posts / Policy

Three Tiers, One Program: Anthropic Opens Mythos-Class Cyber Models to Vetted Defenders

Anthropic has rebuilt its Cyber Verification Program into three access tiers — Defense, Red Team, and Specialized — folding in Project Glasswing and opening Claude Mythos 5.1 to security teams, alongside the first hard numbers: 129,000+ verified vulnerabilities found since April.

Three Tiers, One Program: Anthropic Opens Mythos-Class Cyber Models to Vetted Defenders

On October 6, 2026, Anthropic quietly redrew the map of who gets to use frontier AI for offensive-security work. The company expanded its Cyber Verification Program (CVP) into a three-tier system — Defense, Red Team, and Specialized Access — and folded Project Glasswing, its invite-only program for securing critical software, into the new structure. Existing Glasswing members transition to the Specialized Access tier, the least-restricted level, which is reviewed in coordination with the US government.

The models on offer are the point: every tier now includes Anthropic’s most capable systems, including Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1 — the cyber-specialized lineage that Glasswing partners have been using behind closed doors since April. For the security industry, this is the first general-purpose pathway to Mythos-class capabilities that doesn’t require an invitation.

Why the program exists

Anthropic’s framing is blunt: its generally available models ship with “conservative cyber safeguards that block most cyber work.” Ask vanilla Claude to reverse-engineer malware or write an exploit, and a blocking classifier stops the conversation. That default is safe for the public — and unusable for the people whose job is to find and fix vulnerabilities before attackers do.

The tension has been building all year. When Project Glasswing launched on April 7, 2026, it brought together AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks around a stark admission: Claude Mythos Preview had demonstrated it could “surpass all but the most skilled humans at finding and exploiting software vulnerabilities,” uncovering high-severity flaws in every major operating system and web browser. Anthropic committed up to $100 million in usage credits to put those capabilities to defensive use rather than let them leak to adversaries first.

The CVP expansion is the industrialization of that idea. Instead of hand-picking partners, Anthropic now runs an application-based pipeline with graduated levels of trust — and graduated levels of unblocking.

The three tiers

Defense Access covers security operations, incident response, malware reverse engineering, and analyzing and validating vulnerabilities. It’s aimed at security teams at companies, nonprofits, universities, and governments; critical infrastructure operators of any size; smaller security firms; open-source maintainers; and individual researchers with a track record of disclosed vulnerabilities. Anthropic aims to review applications within a few days.

Red Team Access adds authorized penetration testing and red teaming on top of everything in Defense. It’s open to in-house and government red teams and to security and penetration-testing firms — organizations only, no individuals. Review takes a few weeks, and applicants receive Defense Access while they wait. Even at this tier, real-time blocks remain on “actions that could cause physical harm or mass disruption, such as deploying ransomware, damaging physical systems, or pen testing high-risk safety systems.”

Specialized Access carries the fewest cyber blocks of all. It exists for the work that sounds most alarming in a policy document: testing safety systems in flight software, power grids, telecom networks, and interbank transfer infrastructure. Access is limited to a verified set of organizations and is reviewed with the US government. This is where Glasswing members land.

The benchmark behind the tiers

To show the tiers actually work as designed, Anthropic ran Claude Opus 5.5 through CyScenarioBench, its internal evaluation of multi-stage cyber operations — five attempts at each of ten challenges per tier. The results sketch the gradient precisely:

  • No program: 0 of 50 tasks completed. Every offensive scenario was blocked on the first prompt.
  • Defense Access: 4 of 50 completed, with 46 of 50 trials blocked at some point.
  • Red Team Access: 34 of 50 completed, no blocks encountered — matching the model’s 67.6% unsafeguarded success rate.

The numbers are Anthropic’s own, from Anthropic’s own benchmark, and the company is candid about that. But the shape is informative: the tiers aren’t marketing — they measurably gate capability. Red Team Access restores essentially the full offensive capability of the model, which is exactly what a licensed penetration tester needs and exactly what an anonymous API caller never gets.

The first Glasswing numbers

Alongside the CVP expansion, Anthropic published the first aggregate results from Project Glasswing’s first phase, covering April through October 2026:

  • At least 129,000 verified vulnerabilities found by Glasswing partners from April to July — over 33,000 of them rated critical or high severity.
  • 5,500 additional verified vulnerabilities found by Anthropic’s own open-source scanning efforts between April and October.
  • These figures draw on reports from 33 partners, and Anthropic calls them “likely an undercount,” suggesting the true impact is “at least five times higher.”

Fewer than half of partners disclosed how many issues they had actually patched, so no patch-rate figure exists yet — a gap that reflects a hard truth of the AI-vulnerability era: discovery has become cheap, and remediation has not.

What stays the same — and what changes

Anthropic is explicit that ordinary development work needs no program at all: standard models still handle code review, patching known issues, vulnerability finding in owned source code, and triage of security alerts. The CVP matters for teams whose legitimate work looks offensive to a classifier.

The program runs on the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry; Amazon Bedrock support is limited to customers eligible for Enterprise Frontier Safeguards, a zero-retention option Anthropic says is coming later this fall. Every enrolled organization must permit data retention so Anthropic can monitor for misuse — the price of admission is visibility.

The bigger signal is structural. The most capable cyber models now arrive wrapped in use-based access tiers, verified organizational identities, and retained logs — not as a single open API. Six months after Glasswing’s launch turned “AI can find zero-days” from a hypothesis into a quarterly report, Anthropic has decided the way to keep frontier cyber capability out of the wrong hands is to make the right hands easier to verify.

For defenders, that’s an offer with a queue measured in days. For everyone else, the blocking classifier remains very much on.