Anthropic AI models are being opened to more cybersecurity teams under a new program that gives vetted professionals access to powerful Claude models with fewer safeguards. The move follows a major finding: Anthropic’s Project Glasswing helped uncover more than 100,000 software vulnerabilities in critical systems.
Between April and July, organizations participating in Glasswing identified at least 129,000 verified vulnerabilities, while Anthropic’s own open-source scanning found another 5,500 between April and October. More than 33,000 of the reported vulnerabilities were rated critical or high severity. Anthropic says the actual impact could be at least five times larger because the figures cover only a limited group of partners.
Why Give AI Fewer Safeguards?
Anthropic’s new Cyber Verification Program (CVP) combines its Glasswing initiative with an earlier cybersecurity program that allowed vetted teams to use Claude with reduced safeguards.
The idea is straightforward: cybersecurity researchers sometimes need AI to investigate vulnerabilities, analyze malware and conduct authorized penetration testing. Restrictions designed for ordinary users can limit legitimate security research.
The revamped program provides three levels of access. The Defense tier supports incident response, malware analysis and vulnerability research. The Red Team tier adds authorized penetration testing. The most restricted Specialized tier is reserved for organizations testing safety-critical systems such as power grids, flight systems and interbank financial infrastructure.
The Bigger AI Security Question
The program includes access to Claude Opus 5.5, Sonnet 5.5, Mythos 5.1 and future models. Anthropic is also working with the U.S. government to vet participants.
But the strategy highlights a growing AI dilemma: the same capabilities that can help defenders find vulnerabilities faster could also become dangerous if misused.
Anthropic’s April release of Claude Mythos Preview had already raised concerns about increasingly capable AI systems being able to discover security weaknesses before organizations can fix them.





