October 7, 2026

Anthropic Gives Vetted Defenders Fewer Claude Guardrails

Anthropic has merged Project Glasswing into a tiered access program for its advanced cyber LLMs, including Opus, Sonnet, and Mythos.

Anthropic Gives Vetted Defenders Fewer Claude Guardrails

Anthropic has merged Project Glasswing into a tiered access program for its advanced cyber LLMs, including Opus, Sonnet, and Mythos.

Anthropic will merge Project Glasswing into its existing Cyber Verification Program (CVP) to create an expanded, tiered program that gives vetted security professionals access to advanced AI cyber capabilities with varying levels of safeguards that experts say may or may not prevent misuse.

The Project Glasswing initiative consists of a tightly vetted group of companies that includes more than 40 organizations, such as Amazon, Apple, Microsoft, Google, Linux Foundation, JP Morgan Chase, NVIDA, and several others. It gives access to Claude Mythos, Anthropic’s most advanced cyber large language model (LLM). The company decided to limit broader access because of the frontier technology’s dual-use potential for abuse by threat actors; Mythos, Anthropic said, significantly accelerates vulnerability discovery.

The CVP previously covered two other models, Claude Opus and Sonnet, with a single level of access. After adding Project Glasswing, it will now grant certain organizations three different levels of cyber capabilities.

“Each tier includes access to our most capable models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models moving forward,” Anthropic’s Oct. 6 announcement read. The expanded CVP turns the two programs into a single, ongoing access system, and security professionals can now apply for access based on the type and risk level of their work.

The blog post notes that between April and July of this year, partners using the models uncovered at least 129,000 verified software vulnerabilities. Open source scanning revealed an additional 5,500 verified vulnerabilities between April and October. “Of these verified vulnerabilities, more than 33,000 have so far been rated as critical- or high-severity,” the company said in its blog post.

Ensar Seker, chief information security officer (CISO) at SOCRadar, tells Dark Reading that although the 129,000 figure signals AI can accelerate the vulnerability discovery window, the more important metric will be how much AI shortens the period during which exploitable weaknesses remain exposed.

“If discovery accelerates while remediation falls behind, organizations may accumulate a larger backlog rather than become safer,” he says. “AI gives defenders a chance to move ahead; converting that chance into an advantage requires faster, reliable remediation.”

Three Tiers of Claude Access

The broadest tier is “Defense Access,” built for defensive work including, the announcement noted, “security operations center and incident-response tasks, reverse-engineering malware, and analyzing and validating vulnerabilities.”

Anthropic expects a wide range of legitimate security organizations to qualify: this means corporate security teams, nonprofits, universities, government bodies defending systems they own or maintain, critical infrastructure operators, smaller security firms, open source maintainers, and “individual researchers with a track record of reported vulnerabilities.”

The next tier is “Red Team Access,” built for authorized public and private penetration testers running red teams offensive testing.

“Organizations in this tier can only perform adversarial testing against systems they are authorized to test, including IT systems in critical industries,” according to Anthropic. “Users will still experience real-time blocks on actions that could cause physical harm or mass disruption, such as deploying ransomware, damaging physical systems, or pen testing high-risk safety systems.”

The most exclusive tier is “Specialized Access,” which carries the fewest cyber limitations on how participants can use it. Like Project Glasswing before it, it’s reserved for verified organizations authorized to test systems that could impact people’s lives or impact markets, like power grids, flight operating systems, telecom networks, interbank transfer infrastructure, and government administrative networks. Existing Project Glasswing members will transition to this top tier, and future applications will be reviewed in depth with the US government.

Publicly available models will continue to be usable for software development and less critical security tasks.

What Does This Mean for Claude Misuse?

AI model misuse has been top of mind for months, as the wider world wonders what to do about AI agent escapes and threat actors abusing large language models (LLMs).

Seker warns that Anthropic’s tiered model is a sensible way to reduce misuse, but not proof in itself that misuse has been prevented.

“Separating defensive analysis, authorized red teaming and testing of safety-critical systems recognizes that those activities carry different risks. The difficult part is verifying authorization continuously,” he says. “A verified organization can still have a compromised account, a malicious insider or a legitimate user operating outside an approved engagement.”

Anthropic did not respond to Dark Reading’s request for comment by press time.

Originally published on Dark Reading