Anthropic opens its most powerful AI models to security teams after 129,000 vulnerabilities found. Anthropic is changing how advanced AI can be used for cybersecurity
Anthropic is significantly expanding its Cyber Verification Program (CVP), giving verified security organizations access to more advanced Claude capabilities and reduced cyber safeguards for authorized security work.
The new program has three access tiers and includes Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1. The goal is to give defenders stronger AI capabilities without making those same capabilities unrestricted for malicious use.
The move follows results from Project Glasswing, where Anthropic says its partners identified at least 129,000 verified software vulnerabilities between April and July 2026.
More than 33,000 have so far been rated critical or high severity.
The bigger question is not simply how many vulnerabilities AI can find.
It is whether companies can give defenders increasingly powerful AI tools without giving attackers the same advantage.
Three access tiers
Defense Access
The first tier focuses on defensive security work.
It covers activities such as:
- incident response;
- malware analysis;
- vulnerability discovery and validation;
- code analysis;
- security operations;
- defending systems owned or maintained by the organization.
Anthropic says companies, universities, nonprofits, government organizations, critical-infrastructure operators and qualified individual researchers can potentially apply.
Red Team Access
The second tier adds authorized penetration testing and red-team work.
Organizations must be verified and must have the appropriate security controls.
The access is still not unlimited. Anthropic says actions that could cause physical harm or mass disruption remain blocked.
Specialized Access

The most restricted tier is designed for verified organizations testing systems where failures could have significant real-world consequences.
Examples include:
- power grids;
- telecommunications;
- aviation systems;
- financial infrastructure;
- government administrative networks.
Anthropic says organizations in this category undergo deeper review in collaboration with the U.S. government.
Why not simply give everyone the unrestricted model?
The core problem is dual-use AI.
The same capability that helps a security engineer discover a vulnerability can potentially help an attacker understand how to exploit it.
That is why generally available models retain stronger restrictions around cyber activity.
Anthropic’s approach is instead based on:
identity + authorization + security controls + access level.
The company is effectively treating advanced cyber AI as a capability that should be distributed according to verified need.
Anthropic’s benchmark shows how much safeguards can matter
Anthropic tested Claude Opus 5.5 using CyScenarioBench, an evaluation designed to measure whether models can plan and execute multi-stage cyber operations.
According to Anthropic’s published results:
- without CVP access, all tasks were blocked at the first prompt;
- in Defense Access, 46 of 50 trials were blocked at some point;
- in Red Team Access, the model completed 34 of 50 tasks without blocks.
These are Anthropic’s own evaluation results, not an independent benchmark.
That distinction matters when interpreting the numbers.
What does 129,000 vulnerabilities actually mean?
The number is striking, but it needs context.
Anthropic says the 129,000 vulnerabilities were verified software vulnerabilities identified by Project Glasswing partners between April and July 2026.
More than 33,000 have so far been classified as critical or high severity.
Anthropic also says the number is likely an underestimate because the data comes from only a subset of partners and does not represent every vulnerability discovered worldwide.
So the figure should not be interpreted as:
“Claude found 129,000 attacks happening on the internet.”
It refers to verified software vulnerabilities identified through the participating security program.
AI could compress the vulnerability-discovery timeline
This may be the most important industry implication.
Security auditing traditionally requires specialized teams and significant amounts of time.
Anthropic says several Glasswing partners reported that its models substantially increased their vulnerability-discovery rate, with some describing time savings measured in months or years.
If independently replicated, that could change a fundamental cybersecurity equation:
the speed of finding vulnerabilities could begin to approach the speed at which defenders need to fix them.
That would be a major shift.
But the same capability creates new risks
A model that becomes better at finding vulnerabilities may also become more useful to attackers.
Anthropic explicitly recognizes cybersecurity as a dual-use domain.
That is why the company is not opening the most advanced cyber capabilities to everyone.
Instead, access depends on:
who the organization is + what it is authorized to test + which security controls it has + what level of capability it needs.
This could become a broader model for deploying advanced AI in other high-risk domains.
What does it mean for businesses?
For enterprises, the potential impact is significant.
A relatively small security team could gain access to capabilities that previously required much larger teams and much longer analysis cycles.
But this does not mean AI replaces security professionals.
The structure of CVP points in the opposite direction: AI is being deployed as a tool under the control of verified professionals.
Humans remain responsible for:
- authorizing tests;
- interpreting results;
- deciding how vulnerabilities should be fixed;
- assessing risk;
- evaluating real-world impact.
What does it mean for ordinary users?
Most users will not immediately notice the change in Claude.
The impact could nevertheless be indirect.
If AI helps companies identify vulnerabilities faster, it could lead to:
- faster patches;
- shorter exposure windows;
- more frequent security audits;
- faster incident response;
- stronger protection for open-source software.
But the same progress could also reduce the time and cost required for attackers to analyze vulnerable systems.
The emerging contest is therefore not simply:
AI versus hackers.
It is increasingly:
AI versus AI — with humans deciding who gets access.
Why critical infrastructure is different
Specialized Access is particularly significant because the consequences of failure are no longer limited to an IT system.
A vulnerability in a power grid, aviation platform or financial network can have physical or economic consequences.
That is why Anthropic says this tier receives substantially deeper verification.
The emerging principle is straightforward:
the greater the potential physical impact, the tighter the controls around AI access should be.
What happens next?
Anthropic says the program will continue to expand and that future models will be incorporated into the CVP structure.
The program is available through the Claude Platform, Google Cloud Vertex AI and Microsoft Foundry, while Amazon Bedrock has specific eligibility conditions.
Anthropic is also developing Enterprise Frontier Safeguards, intended to combine zero-data-retention privacy with advanced safety controls.
For enterprise security teams, that could become increasingly important as AI moves deeper into sensitive infrastructure.
KEY TAKEAWAYS
- Anthropic has expanded its Cyber Verification Program into three access tiers.
- The program gives verified security teams more advanced access to Claude.
- The three levels are Defense Access, Red Team Access and Specialized Access.
- Project Glasswing identified at least 129,000 verified software vulnerabilities between April and July 2026, according to Anthropic.
- More than 33,000 have so far been classified as critical or high severity.
- The 129,000 figure is not a universal count of vulnerabilities across the internet.
- Claude Opus 5.5 was tested with different levels of cyber safeguards in CyScenarioBench.
- Those benchmark results are Anthropic’s own results, not an independent evaluation.
- Advanced cyber AI is inherently dual-use: it can help defenders and attackers.
- Anthropic is therefore tying access to verification, authorization and security controls.
- Critical infrastructure receives the most restrictive access model.
Anthropic is testing a new approach to cybersecurity AI: rather than making powerful AI less capable, it is trying to control who can use its most powerful capabilities.
Project Glasswing suggests that AI could significantly accelerate vulnerability discovery, while CVP represents an attempt to turn that capability into a defensive advantage.
The real test, however, will not simply be how many vulnerabilities AI can find. It will be whether defenders can maintain a larger AI advantage than attacker.