Anthropic has expanded its Cyber Verification Program (CVP) to provide qualifying cybersecurity professionals with greater access to advanced AI capabilities and models with reduced cyber safeguards.
The expanded programme introduces three access tiers: Defense Access, Red Team Access and Specialized Access, enabling security organisations to apply for access based on the nature and scope of their cybersecurity activities. Eligible users across the tiers will have access to Anthropic’s advanced models, including Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, along with future models.
Anthropic said the move addresses the dual-use nature of cybersecurity AI, where capabilities that help defenders identify vulnerabilities can also potentially be used for malicious exploitation. Its generally available models therefore operate with conservative cyber safeguards designed to block most potentially harmful cyber activities while reducing false positives affecting legitimate secure coding.
Under Defense Access, organisations can use advanced capabilities for defensive activities such as security operations, incident response, malware reverse engineering, and vulnerability analysis and validation. Eligible applicants can include corporate, nonprofit, university and government security teams, critical infrastructure operators, smaller security firms, open-source maintainers and individual security researchers with established vulnerability-reporting records.
Red Team Access extends these capabilities to authorised penetration testing and red-team operations. It is intended for in-house and government red teams, as well as security and penetration-testing firms. However, testing must be conducted only against systems for which users have authorisation. Real-time safeguards will continue to block activities that could cause physical harm or mass disruption, including ransomware deployment and testing of high-risk safety systems.
The highest tier, Specialized Access, will be limited to verified organisations authorised to test safety-critical or market-sensitive systems. These may include flight operating systems, power grids, telecommunications networks, interbank transfer infrastructure and government administrative networks.
Anthropic said Defense Access applications are expected to be reviewed within a few days, while Red Team Access applications may take several weeks because of additional verification and security controls.

