AI-generated editorial illustration of a security professional reviewing screens; not an actual Claude interface.
AI · News

Claude’s Cyber Verification Program: who can apply?

Anthropic has expanded verified cybersecurity access into three tiers. Individual researchers and organisations have different routes, controls and limits.

AI-generated editorial illustration. Conceptual scene; not an actual site, event or product screenshot.
Michel ElijahPublished 10 October 2026 Checked 10 October 2026 3 min read

Anthropic has expanded its Cyber Verification Program into three access tiers for qualifying security professionals. Announced on 6 October, the change gives applicants a route to advanced cyber capabilities under different verification requirements and controls.

What you need to know

Individual researchers can apply for Defense Access on a paid plan. Red Team and Specialized Access are for organisations. Approval depends on verification and the work being proposed; an ordinary subscription does not automatically enable the program.

Source: Anthropic: expanded Cyber Verification Program

Source: Anthropic: Cyber Verification Program help

The three tiers have different jobs

  • Defense Access covers activities such as incident response, malware analysis and vulnerability validation.

  • Red Team Access adds authorised penetration testing and red-teaming. It does not authorise testing systems without permission.

  • Specialized Access is reserved for a limited group of verified organisations working on high-consequence safety systems, including telecommunications networks.

Anthropic says Red Team Access retains blocks against activities that could cause physical harm or large-scale disruption. The tier names describe approved scope, rather than a general switch that removes every restriction.

Source: Anthropic: expanded Cyber Verification Program

Our earlier Fable and Mythos report provides background on the models and their access boundaries.

How to begin an application

Anthropic directs applicants to its Verification Portal. Organisations apply once and administrators designate access. Individual applicants are limited to Defense Access. The application asks for identity details, a description of the work and confirmation of the required security controls.

The help page says review may produce a request for more information. Treat submission, approval and access being enabled in the correct account or workspace as separate steps.

Source: Anthropic: Cyber Verification Program help

Before applying, prepare a plain-language description of the security work. State which systems you own or maintain, who authorises testing and which tasks are being blocked. That gives the reviewer a clearer scope than a request for unrestricted model access.

Check data handling and account controls

Anthropic’s guidance describes retention for misuse monitoring, with exceptions for certain existing Fable or Mythos zero-data-retention arrangements. It also describes Enterprise Frontier Safeguards as a future option. Check the terms that actually apply to your account before submitting sensitive material.

Source: Anthropic: Cyber Verification Program help

Our recommendation is to review the access arrangement with the people responsible for security and data handling. Decide what material can be sent, who can use the grant and how completed work will be reviewed. Do that before turning a successful trial into a recurring process.

What ordinary users can still do

Anthropic says generally available models remain usable for tasks such as secure code review, patching and finding vulnerabilities in source code the user owns. The expanded program is aimed at work requiring a different cyber access level.

Source: Anthropic: expanded Cyber Verification Program

For a small development task, begin by defining what you want checked and reviewing the suggested changes. Receiving an answer from a model does not establish that the code is secure or that a proposed test is authorised.

Our coverage of OpenAI’s false-front operations concerns a different form of AI misuse: deceptive identities and sources.

Our Australian AI hearing report covers the separate debate over incident-reporting and governance obligations.

Michel ElijahContent Advisor

Michel Elijah covers technology, streaming and online security for Tech X Telco. He writes practical how-to guides on everything from email troubleshooting to spotting the latest scams doing the rounds in Australia, with a focus on clear steps anyone can follow.

Spotted something wrong? Corrections are recorded in the open. Report a correction

Keep reading
All stories

One useful thing a week.

One setting worth changing, one service or AI change that matters, and one practical guide. No spam, unsubscribe any time.

Newsletter archive

Free · Australian · Unsubscribe any timeWe email a confirmation link first. Your address is stored only to send this newsletter.