Signal

Anthropic integrates its Cyber Verification Program and Project Glasswing into a new, expanded version of CVP, with three tiers and access to its latest models

First reported by Anthropic ·

The signal ●●●○ Compiled by AI from Anthropic, Techmeme and Bloomberg
Why you might care

Access to advanced AI models for cybersecurity tasks now has tiered availability, enabling deeper vulnerability research.

What happened

Anthropic has launched an expanded version of its Cyber Verification Program (CVP), integrating its previous Cyber Verification Program and Project Glasswing. This new CVP offers three access tiers: Defense Access, Red Team Access, and Specialized Access, each with specific verification requirements and security controls. The program provides qualifying security professionals with access to Anthropic's most capable AI models, including Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, with reduced cyber safeguards. Defense Access is for defensive tasks like incident response and vulnerability analysis. Red Team Access adds authorized penetration testing, while Specialized Access, reserved for a limited set of verified organizations, allows testing of safety-critical systems with minimal restrictions. Anthropic's evaluations show significant reductions in model blocks for cyber tasks across these tiers, with no blocks occurring in the Red Team Access tier. The program aims to provide cybersecurity defenders with advanced tools while maintaining necessary safety measures. Data retention is required, but Anthropic is developing Enterprise Frontier Safeguards for zero data retention options.

What it means

The consolidation of Project Glasswing and the Cyber Verification Program into a unified, tiered offering signifies Anthropic's strategic move to broaden access to powerful AI tools for cybersecurity professionals. By segmenting access based on defined roles and security protocols, Anthropic aims to balance the need for robust defensive capabilities with the inherent risks of dual-use AI technology. This approach allows for tailored model performance, addressing the specific requirements of defensive operations, penetration testing, and the assessment of highly critical systems, thereby potentially accelerating vulnerability discovery and remediation across various sectors.

The tiered structure and explicit evaluation benchmarks like CyScenarioBench suggest a maturing market for specialized AI applications in cybersecurity, indicating that AI providers are developing more granular control mechanisms to cater to diverse industry needs. The emphasis on data retention, with a future transition to zero-retention options via Enterprise Frontier Safeguards, highlights ongoing industry efforts to reconcile AI utility with data privacy and security compliance. This evolution could set new standards for how AI is deployed in sensitive security contexts, impacting how organizations evaluate and integrate AI into their cybersecurity strategies.

AI-written summary. May contain errors.