ThinkFacility Sign in
  1. Home
  2. News
  3. Anthropic

Anthropic merges Glasswing into a three-tier cyber program that unlocks Opus 5.5 and Mythos 5.1

In Anthropic's own test, the Red Team tier blocked nothing and Opus 5.5 finished 34 of 50 attack scenarios.

On October 6, 2026, Anthropic folded its two programs for security teams into one. The new Cyber Verification Program has three tiers, and each one gets Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1 with fewer cyber blocks than everyone else gets.

Until now, Project Glasswing gave Claude Mythos to a group of organizations securing critical software, and the old CVP lowered safeguards on Opus and Sonnet for vetted teams. Both had run for about six months.

Who runs it
Anthropic
Tiers
Defense Access, Red Team Access, Specialized Access
Models
Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1
Review time
a few days for Defense, a few weeks for Red Team
Required
data retention, so Anthropic can monitor for misuse

Who gets what

Defense Access covers incident response, malware reverse-engineering and checking whether a vulnerability is real. It's open to company and government security teams, critical infrastructure operators of any size (a regional hospital counts), open-source maintainers and individual researchers with a record of reported bugs. Anthropic says it expects many defenders to qualify.

Red Team Access adds authorized penetration testing. It's for organizations only, so individual researchers can't apply, and some actions stay blocked in real time even here.

Users will still experience real-time blocks on actions that could cause physical harm or mass disruption, such as deploying ransomware, damaging physical systems, or pen testing high-risk safety systems.

From Expanding the Cyber Verification Program \ Anthropic

Specialized Access has the fewest blocks. It's for a small set of organizations allowed to test systems like power grids, flight software and interbank transfers, and Anthropic reviews each one together with the US government. Glasswing members move straight into this tier.

The test Anthropic ran on its own tiers

Anthropic ran Claude Opus 5.5 through CyScenarioBench, which asks a model to plan and carry out multi-stage cyber operations, five times on each of 10 challenges per tier. Without the program, every task was blocked on the first prompt. In Defense Access, 46 of 50 runs hit a block at some point.

Red Team Access blocked nothing, and Opus 5.5 finished 34 of the 50 tasks. Anthropic says that's in line with the model's 67.6% success rate with no safeguards at all. So the middle tier gives you roughly the whole model, for offensive testing on systems you're allowed to attack.

The general models stay locked down. Anthropic says Opus 5.5, Fable 5.1 and Sonnet 5.5 "have conservative cyber safeguards that block most cyber work," though code review, patching known issues and triaging alerts still work without the program. (If you've hit that wall, our page on the safeguards-flagged error covers it.)

The same day, Mistral pitched its Mistral Large 4 to security teams on the grounds that closed models refuse this kind of work. Anthropic's answer is to verify the people asking.

What Glasswing found

Through the program, our partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026.

Expanding the Cyber Verification Program \ Anthropic

Anthropic's own open-source scanning found another 5,500 between April and October. More than 33,000 of the combined total were rated critical or high severity. The figures rest on partial data, mostly from 33 partner reports, and Anthropic says it expects the true impact to be at least five times higher.

Enterprise Frontier Safeguards, which Anthropic says will let eligible organizations keep their data in cloud infrastructure they control, is due later this fall.

More on Anthropic

All Anthropic stories