Anthropic has expanded its Cyber Verification Program into three access tiers for qualifying security professionals. Announced on 6 October, the change gives applicants a route to advanced cyber capabilities under different verification requirements and controls.
What you need to know
Individual researchers can apply for Defense Access on a paid plan. Red Team and Specialized Access are for organisations. Approval depends on verification and the work being proposed; an ordinary subscription does not automatically enable the program.
The three tiers have different jobs
Defense Access covers activities such as incident response, malware analysis and vulnerability validation.
Red Team Access adds authorised penetration testing and red-teaming. It does not authorise testing systems without permission.
Specialized Access is reserved for a limited group of verified organisations working on high-consequence safety systems, including telecommunications networks.
Anthropic says Red Team Access retains blocks against activities that could cause physical harm or large-scale disruption. The tier names describe approved scope, rather than a general switch that removes every restriction.
Source: Anthropic: expanded Cyber Verification Program
Our earlier Fable and Mythos report provides background on the models and their access boundaries.
How to begin an application
Anthropic directs applicants to its Verification Portal. Organisations apply once and administrators designate access. Individual applicants are limited to Defense Access. The application asks for identity details, a description of the work and confirmation of the required security controls.
The help page says review may produce a request for more information. Treat submission, approval and access being enabled in the correct account or workspace as separate steps.
Source: Anthropic: Cyber Verification Program help
Before applying, prepare a plain-language description of the security work. State which systems you own or maintain, who authorises testing and which tasks are being blocked. That gives the reviewer a clearer scope than a request for unrestricted model access.
Check data handling and account controls
Anthropic’s guidance describes retention for misuse monitoring, with exceptions for certain existing Fable or Mythos zero-data-retention arrangements. It also describes Enterprise Frontier Safeguards as a future option. Check the terms that actually apply to your account before submitting sensitive material.
Source: Anthropic: Cyber Verification Program help
Our recommendation is to review the access arrangement with the people responsible for security and data handling. Decide what material can be sent, who can use the grant and how completed work will be reviewed. Do that before turning a successful trial into a recurring process.
What ordinary users can still do
Anthropic says generally available models remain usable for tasks such as secure code review, patching and finding vulnerabilities in source code the user owns. The expanded program is aimed at work requiring a different cyber access level.
Source: Anthropic: expanded Cyber Verification Program
For a small development task, begin by defining what you want checked and reviewing the suggested changes. Receiving an answer from a model does not establish that the code is secure or that a proposed test is authorised.
Sources and further reading
Anthropic: expanded Cyber Verification Program6 October expansion, three tiers, permitted scope and continued cyber safeguards.www.anthropic.com
Anthropic: Cyber Verification Program helpApplication route, individual paid-plan eligibility, security controls, retention exceptions and admin provisioning.support.claude.com
Spotted something wrong? Corrections are recorded in the open. Report a correction






