Anthropic is widening access to some of its most capable Claude models for cybersecurity work, giving more vetted security teams a way to use advanced AI tools with fewer restrictions. This expansion comes as part of the Anthropic Cyber Verification Program, which supports trusted professionals in their security efforts.
The company announced an expanded Cyber Verification Program, bringing several earlier initiatives under one structure. The goal is to give legitimate defenders stronger AI capabilities without making those same capabilities broadly available to anyone who wants them.
That balance is getting harder to manage. The same model that helps a security researcher uncover a serious software flaw can also help an attacker understand how to exploit it.
Anthropic Expands Access to Advanced Cybersecurity Models
Anthropic’s expanded Cyber Verification Program is designed to give approved security professionals access to Claude models under different levels of verification and control.
The programme includes access to Claude Opus, Claude Sonnet and Claude Mythos models, depending on the type of work being carried out. Anthropic is not simply removing its safeguards. Instead, it is creating different access levels based on who is using the model and what kind of cybersecurity activity they are authorised to perform.
The approach reflects a growing problem for frontier AI companies. Cybersecurity capabilities are becoming powerful enough that restricting them too aggressively could disadvantage defenders, while releasing them too broadly could create obvious misuse risks.
Claude Has Already Found Thousands of Serious Vulnerabilities
Anthropic says its earlier security programmes have already produced substantial results.
Through Project Glasswing, participating organisations identified at least 129,000 verified software vulnerabilities over several months. Anthropic also reported thousands of additional findings through its own scanning work.
A significant number of those vulnerabilities were classified as high or critical severity. That matters because it moves the conversation away from theoretical benchmark scores. Anthropic is pointing to real software flaws found with AI assistance, giving it a stronger argument for why security teams should have access to more capable models.
Defense Access Targets Everyday Security Work
The first level of Anthropic’s programme is aimed at defensive cybersecurity work.
That includes activities such as incident response, malware analysis, vulnerability research and security operations. Corporate security teams, government agencies, universities, nonprofits and critical infrastructure operators may be able to qualify.
Anthropic also plans to make this level available to selected independent researchers and open-source maintainers with a proven history of responsible vulnerability disclosure. The idea is relatively simple. More defenders get access to stronger AI tools, but access still depends on verification.
Red Team Access Allows More Aggressive Testing
A second level is designed for red teams and organisations conducting authorised penetration testing.
This tier gives approved users more freedom to simulate attacks against systems they have permission to test. That could include internal enterprise environments, government systems or client infrastructure being assessed by professional security firms. The safeguards are looser than they are under the defensive tier, but they are not removed completely.
Anthropic still restricts activities that could create widespread disruption, physical harm or serious damage to critical infrastructure. This tier makes the dual-use nature of advanced AI particularly obvious. The techniques used by a red team to find weaknesses can look very similar to the techniques used by a real attacker.
Specialized Access Reaches Critical Infrastructure
Anthropic is keeping its most permissive access level much more tightly controlled.
This tier is intended for organisations working with safety-critical systems such as energy infrastructure, aviation and financial networks. The company is taking a cautious approach because the potential consequences are much higher in these environments.
A vulnerability in an ordinary application can be damaging. A vulnerability in a power grid, aviation system or major financial network can have far more serious consequences. Anthropic’s decision to limit this level to highly vetted organisations shows how seriously it is treating the risk.
Claude Mythos Sits at the Center of Anthropic’s Strategy
Claude Mythos is one of the models at the heart of Anthropic’s controlled-access approach. The model is designed for advanced work in sensitive areas including cybersecurity and biology. Anthropic sees those capabilities as valuable, but also potentially dangerous if released without restrictions.
That is why Mythos is being made available through trusted-access programmes rather than being opened broadly. This creates an interesting model for future AI deployment. Instead of giving every user the same capabilities, AI companies may increasingly decide access based on identity, purpose and the level of risk attached to the task.
Security Teams Could Fall Behind Without Better AI Tools
Anthropic’s argument is that restricting powerful cyber capabilities too aggressively could create a different kind of problem. Attackers are already experimenting with AI. If defenders are forced to work with weaker systems while adversaries gain access to increasingly capable tools elsewhere, the imbalance could become difficult to manage.
Giving security teams better AI models may help them find vulnerabilities faster, review code more efficiently and respond to attacks before the damage spreads. That does not remove the danger. It simply changes the question from whether powerful cyber AI should exist to who should be allowed to use it.
AI Cybersecurity Remains a Difficult Risk to Control
The biggest challenge is that cybersecurity work does not divide neatly into good and bad categories. Finding a vulnerability is useful if the person discovering it intends to fix the problem. The same discovery can be harmful if someone uses it to break into a system.
AI cannot always tell the difference based on the technical request alone. That means Anthropic has to rely on verification, access controls, monitoring and restrictions around how its models are used. Those systems may become just as important as the models themselves.
Anthropic Has Already Seen the Limits of Controlled Testing
Anthropic has previously disclosed incidents in which Claude models interacted with real systems during cybersecurity evaluations that were intended to be contained.
Those incidents highlighted how quickly testing environments can become risky when powerful models are given broad permissions.
The company later strengthened its controls and reviewed a large number of transcripts to check whether similar incidents had occurred elsewhere.
That history gives additional context to the expanded Cyber Verification Program. Anthropic wants to give defenders more capability, but it also knows that access controls can fail if the surrounding environment is not carefully managed.
Anthropic Is Betting on Controlled Access Instead of Full Restriction
Anthropic’s new programme reflects a broader shift in how frontier AI companies may handle powerful cybersecurity capabilities. Keeping the strongest tools completely locked away could slow down legitimate security work. Releasing them without restrictions would create an entirely different set of risks.
Anthropic is choosing a middle path. The company is expanding access, but only to verified users and under different levels of control. That approach may become more common as AI systems improve.
The more useful these models become for finding security flaws, the harder it will be to justify keeping them away from defenders. The harder problem will be making sure they do not become just as useful to attackers.
Sources
Reuters — Anthropic Opens Its Most Powerful AI Models to More Security Teams
https://www.reuters.com/legal/litigation/anthropic-opens-its-most-powerful-ai-models-more-security-teams-2026-10-06/
Anthropic — Cyber Verification Program
https://www.anthropic.com/news/cyber-verification-program

