Anthropic Overhauls AI Security Access Programs, Merging Initiatives into Three Tiers
Anthropic has consolidated its Cyber Verification Program (CVP) and Project Glasswing into a new three-tiered structure to provide tiered access to its AI models for security research and vulnerability discovery.

Anthropic, a prominent AI safety and research company, has announced a significant reconfiguration of its security access programs. The company has merged its Cyber Verification Program (CVP) and Project Glasswing into a unified, three-tiered system designed to offer varying levels of access to its advanced AI model capabilities for security organizations.
Previously, Project Glasswing provided partners with early access to Anthropic's frontier models, such as Mythos, to proactively identify vulnerabilities within their own systems. The CVP, on the other hand, was aimed at broader security organizations. The integration aims to streamline these offerings and provide a more structured approach to how security professionals can leverage Anthropic's AI for defensive and offensive security research.
Anthropic claims that these combined programs have been instrumental in helping partners discover a substantial number of software vulnerabilities. Between April and July 2026, partners reportedly identified over 129,000 verified software vulnerabilities, with more than 33,000 classified as critical or high severity. The company also noted an additional 5,500 vulnerabilities found through its own open-source scanning efforts.
Despite these reported successes, the article points to a potential gap between vulnerability discovery and remediation. Anthropic's own figures indicate that out of thousands of identified high-severity and critical vulnerabilities, only a fraction have been patched, suggesting ongoing challenges in the patching lifecycle within organizations, even when leveraging advanced AI tools for discovery.
The new three-tiered structure includes Defense Access, Red Team Access, and Specialized Access. Defense Access is intended for general security teams focused on system defense, where Anthropic's Claude Opus 5.5 model exhibited significant refusal rates on security-related tasks. Red Team Access is geared towards penetration testing and offensive evaluations, with some restrictions still in place to prevent the generation of harmful content.
Specialized Access, described as a more exclusive tier, is reserved for a select group of verified organizations authorized to test safety-critical systems, such as those governing flight operations, power grids, and financial infrastructure. Participants in this tier are expected to encounter the fewest model refusals, excluding those using heavily modified open-weight models.
Initially, participants will be required to allow data retention by Anthropic as part of AI safety protocols. However, the company plans to introduce its Enterprise Frontier Safeguards program, which will offer zero data retention for eligible organizations, including those already using specific Claude models under similar terms.
The move comes shortly after Anthropic issued warnings about competitor AI models, highlighting the evolving landscape of AI capabilities and their potential impact on cybersecurity. The reconfiguration of these programs reflects Anthropic's ongoing efforts to balance the powerful capabilities of its AI models with robust safety and security considerations.