Skip to content
important Security verified update

Anthropic opens access to Claude models with lighter filtering to individual security researchers

independently confirmed updated 3 h ago

The expanded Cyber Verification Program allows vetted individuals to obtain Defense Access to Claude models with lighter safety filtering. Red Team Access remains limited to organizations; Anthropic vets Specialized Access applicants jointly with the US government.

Anthropic is expanding access to Claude models with reduced safety filtering for security work. Individual researchers with a documented track record of reporting vulnerabilities can also obtain Defense Access. Red Team Access is reserved for organizations and allows attack simulations only on systems they are authorized to test. Specialized Access serves a limited group of organizations testing sensitive systems, such as flight control systems or power grids; the company vets applicants jointly with the US government.

The expanded Cyber Verification Program brings together the existing Cyber Verification Program and Project Glasswing. All three tiers include Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1. Defense Access covers defensive tasks, incident response, malware analysis and vulnerability verification. Red Team Access adds authorized penetration testing. The company aims to respond to Defense Access applications within a few days; it says reviewing a Red Team Access application should take several weeks; eligible organizations receive Defense Access in the meantime.

Lighter filtering does not mean all controls are removed. Red Team Access continues to block activities that could cause physical harm or large-scale disruption. The program requires participating organizations to retain data to monitor abuse, with a temporary exception for organizations that have access to Claude Fable 5.1 or Claude Mythos 5.1 with zero data retention. According to the company, Enterprise Frontier Safeguards is intended to enable eligible organizations to store data in their own cloud infrastructure later in the autumn.

According to Anthropic, Project Glasswing partners found at least 129 000 confirmed vulnerabilities from April to July 2026, including over 33 000 of high or critical severity. The figures come from a survey of some partners; they are neither an independent verification of the results nor a complete accounting of the program.

What changed

Why it matters

Vetted participants can use the models for security tasks that generally available versions often block. However, generally available models can still be used without special access to review code, fix known bugs or triage security alerts.

What was added since the original report

Verified updates

  1. New verified information

    The access allows the use of models with reduced safety filtering.; Defense Access is also available to individual security researchers.; Red Team Access is reserved exclusively for organizations.; Anthropic vets Specialized Access applicants jointly with the US government.

    • The access allows the use of models with reduced safety filtering.
    • Defense Access is also available to individual security researchers.
    • Red Team Access is reserved exclusively for organizations.
    • Anthropic vets Specialized Access applicants jointly with the US government.

Two audiences, two different impacts

What this means

01

For individuals

An independent security researcher with a track record of reporting vulnerabilities can apply for Defense Access. Individuals are not eligible for authorized attack simulations under Red Team Access.

What to do If you have a documented track record of reporting vulnerabilities, apply for Defense Access.
More practical updates →
02

For a business

The security team must align its access tier with the scope of its work and data retention policies. According to the company, approval for Red Team Access can take several weeks, which affects penetration testing schedules.

Risks and compliance
What to decide Before applying, check whether the selected tier and data retention conditions match your planned testing and company policies.
More business impacts →
Anthropic Claude Claude Mythos 5.1 Claude Opus 5.5 Claude Sonnet 5.5 Cyber Verification Program

Check the original

Event sources

independently confirmed · 2 publishers, 1 independent. We count feeds from the same owner only once.

2
Anthropic News primary source · first detected Expanding the Cyber Verification Program The Decoder (daily AI news) independent context Anthropic gives more security teams access to Claude with fewer safety restrictions