Anthropic is letting more security teams use its AI with fewer restrictions

More than 33,000 critical or high-severity software vulnerabilities. That’s what vetted security researchers found using Anthropic’s AI models in just four months. It’s a striking number, and Anthropic is now using it to justify expanding access to its most powerful models for cybersecurity professionals. The question worth asking is: who decides who gets in, and what happens when things go wrong?

According to Reuters, Anthropic has combined two existing programs into a revamped Cyber Verification Program, or CVP. The original CVP gave vetted security teams access to Claude Opus and Sonnet models with reduced safeguards. The other program, Project Glasswing, gave organizations working on critical software access to Claude Mythos, the company’s most security-focused model family. The new CVP merges both and creates three access tiers, each with different verification requirements.

The numbers behind the expansion are hard to ignore. Glasswing partners found at least 129,000 verified vulnerabilities between April and July. Anthropic’s own open-source scanning added another 5,500 between April and October. And the company says these figures are almost certainly an undercount, estimating the real impact could be five times higher because the data only covers a limited number of partners. That’s a lot of uncertainty baked into the headline statistic.

The three tiers work like this:

  • Defense tier: covers incident response and malware analysis. Open to security teams, critical infrastructure operators, open-source maintainers, and researchers with a track record of disclosed vulnerabilities.
  • Red Team tier: adds authorized penetration testing and red-teaming. Organizations only, not individuals.
  • Specialized tier: fewest restrictions, reserved for a small group cleared to test safety-critical systems like power grids, flight systems, and interbank transfer infrastructure. Existing Glasswing members move here automatically.

All three tiers include access to Claude Opus 5.5, Sonnet 5.5, Mythos 5.1, and future models. Anthropic says it vets each member in coordination with the US government, which is worth pausing on. Government involvement in deciding who gets reduced-restriction access to powerful AI is not a small thing. There’s no public detail about what that vetting actually looks like, what data is shared with government agencies during the process, or what oversight exists if a vetted organization misuses access.

The timing also matters. When Anthropic released Claude Mythos Preview back in April, security researchers raised real concerns that AI capable of finding vulnerabilities at scale could just as easily be pointed at systems before defenders had a chance to act. Anthropic’s answer is essentially: trust the vetting process. But the company also admits its own vulnerability numbers are probably a significant undercount, which suggests the program’s reach is already larger and messier than the data shows.

For privacy and security advocates, the core tension here is familiar. More powerful tools in the hands of defenders sounds good. But fewer safeguards, coordinated with government agencies, and applied to infrastructure like power grids and financial systems, with limited public transparency about the rules of engagement, is exactly the kind of arrangement that deserves more scrutiny than a press release typically invites.