Anthropic Loosens AI Safety Access With Three-Tier System, Giving Security Experts Early Access to Opus 5.5

Anthropic has expanded its Cyber Verification Program into a three-tier access framework, opening early access to Claude Opus 5.5 and other unreleased mode

On October 6, 2026, Anthropic formally expanded its Cyber Verification Program into a three-tier access system, granting qualified security professionals early access to models including Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1. Over the past six months, the program has identified more than 129,000 vulnerabilities, 33,000 of which were critical or high severity.

Facts

According to Anthropic's official announcement, the update merges the former Project Glasswing and CVP into a single three-tier framework. Tier one, Defense Access, is aimed at defensive work including security operations centers, incident response, malware reverse engineering, and vulnerability validation; tier two, Red Team Access, adds authorized penetration testing and red team exercises; tier three, Specialized Access, targets power grids, financial systems, and core government systems, and involves the strictest review. All three tiers can access unreleased models such as Claude Opus 5.5, while generally available models retain conservative cybersecurity protections.

How It Works

The announcement notes that cybersecurity capabilities are dual-use: the same tools that fix vulnerabilities can be turned to malicious ends. Generally available models therefore block most cyber tasks, while CVP uses tiered vetting to reduce false positives while keeping real-time blocks on behavior that causes physical harm or mass destruction. Defense Access is expected to complete review within days, Red Team Access takes weeks, and Specialized Access involves deep collaboration with the U.S. government. Data retention requirements run through the entire process until the Enterprise Frontier Safeguards program is introduced.

Industry Impact

The program lets security teams use stronger models for vulnerability discovery and system hardening, with more than 129,000 vulnerabilities found cumulatively over the past six months. Defense Access covers enterprises, nonprofits, universities, and critical infrastructure operators, while Red Team Access is limited to authorized organizations; individual researchers are not yet included. Specialized Access is restricted to a small number of cleared entities and covers high-risk scenarios such as flight operating systems and power networks. The move institutionalizes tiered AI safeguards and could change how security practitioners gain access to frontier models.

Strategic Assessment

(The following is analysis, not fact.) By combining vetting thresholds with real-time blocking, the three-tier system attempts to strike a balance between lowering safeguards and preventing abuse; its correspondence with WDCD compliance evaluations suggests that professional security credentials are increasingly viewed as a potential justification for AI to lower its own safeguards, though the actual effects remain to be seen.