Anthropic reconfigures its cool kids security program
First reported by The Register ·
Access to advanced AI models for security testing now comes with tiered restrictions based on use case.
Anthropic has reconfigured its Project Glasswing and Cyber Verification Program (CVP) into a new three-tiered security program. The original programs, launched in April 2026 alongside the Mythos frontier model, aimed to provide partners early access to identify vulnerabilities. The new structure includes Defense Access, Red Team Access, and Specialized Access tiers, with varying levels of access and restrictions on security-related tasks. Anthropic reports that its security programs have helped partners identify over 129,000 verified software vulnerabilities between April and July 2026, with an additional 5,500 identified through its own open-source scanning. Of these, over 33,000 were rated critical or high-severity. The company also noted a significant gap between identified and patched vulnerabilities, with only 516 of 5,674 true positive vulnerabilities having been patched at the time of reporting.
The consolidation and tiering of Anthropic's security programs suggest a market maturation where AI capabilities are being more carefully segmented for enterprise use. By offering different levels of access, Anthropic is attempting to balance the utility of its frontier models for threat hunting with its ongoing safety and ethical considerations. This move could set a precedent for how other AI labs manage access to their most powerful models for security-focused applications, potentially leading to more specialized and controlled offerings across the industry.
The significant number of identified but unpatched vulnerabilities highlights a bottleneck in the cybersecurity response chain, even with advanced AI tools. This gap between vulnerability discovery and remediation is a persistent challenge that AI alone may not solve, indicating a continued need for robust human oversight and efficient patching processes. As AI models become more adept at finding flaws, the industry will need to adapt its remediation strategies to keep pace, or the value of AI-driven vulnerability discovery will be diminished.
AI-written summary. May contain errors.