Anthropic has expanded its Cyber Verification Program, creating tiered access to advanced model capabilities for qualified security professionals. The programme is designed to reduce blocking for legitimate defensive work while keeping the most sensitive capabilities behind organisational verification.
The new structure distinguishes vulnerability research and incident response from authorised penetration testing and red-team activity. The latter tier is limited to organisations that apply and are accepted. Anthropic says the programme grew out of Project Glasswing, an industry initiative involving technology companies, financial institutions and open-source organisations.
The company reports that partner work associated with the initiative has helped identify more than 100,000 software vulnerabilities this year, while Anthropic's own open-source scanning found another 5,500 verified issues between April and October. Those figures are company-reported and reflect a mix of partner activity and Anthropic scanning, not a controlled benchmark of model performance.
The development sharpens a central governance problem for frontier models: the same capabilities that help defenders reproduce and patch vulnerabilities can also lower barriers for attackers. Verification, permitted-use controls, logging and rapid revocation therefore become part of the product itself. Enterprises assessing cyber-capable models should examine not only benchmark scores, but also who receives elevated access and how misuse is detected.
