AI Briefing
KOSign in

Anthropic Restructures Cyber Verification Program into Three Tiers and Opens Access to Mythos 5.1

·2026.10.08 21:30

Key point

Anthropic introduces a three-tier system for Defense, Red Team, and Specialized Access, granting verified security teams access to the Mythos 5.1 model.

1 / 4

Details

On October 6, 2026, Anthropic expanded its Cyber Verification Program (CVP), integrating the existing program with Project Glasswing to introduce a three-tier classification system: Defense Access, Red Team Access, and Specialized Access. All tiers provide access to Claude Opus 5.5, Sonnet 5.5, Mythos 5.1, and subsequent models, with higher tiers offering relaxed cybersecurity blocks alongside stricter identity verification and security controls.

Access Rights and Requirements by Tier

  • Defense Access: Targeted at individual researchers and organizations performing defensive tasks such as Security Operations Center (SOC) monitoring, incident response, and malware analysis. A paid subscription is mandatory, and users must transition to phishing-resistant MFA (such as FIDO2/WebAuthn) and discontinue the use of static API keys by December 15, 2026.
  • Red Team Access: Available only to organizations conducting authorized penetration testing and red team activities. Actions causing physical damage or large-scale disruption, such as ransomware deployment, are blocked in real time.
  • Specialized Access: Requires in-depth vetting in collaboration with the US government for testing critical safety systems such as aircraft, power grids, and telecommunications networks. Existing Project Glasswing participants are automatically migrated to this tier.

Security Controls and Data Retention

All CVP-registered organizations are subject to data retention obligations for cyber misuse monitoring, and must designate security personnel and report incidents (within 72 hours for unauthorized access and within 24 hours for security incidents). Red Team and Specialized Access tiers must use phishing-resistant MFA and short-lived credentials expiring in 12 hours from the time of approval, with static API keys and service account keys prohibited. Enterprise Frontier Safeguards (EFS) are scheduled for phased rollout starting in late autumn.

Performance Evaluation and Real-World Cases

In CyScenarioBench evaluations, general public models showed a 0% completion rate across 10 tasks, whereas the Red Team Access tier achieved a 68% completion rate, demonstrating performance similar to an unguarded state. During the Project Glasswing operational period (April–July 2026), partners and open-source scans identified at least 135,610 vulnerabilities, of which 5,680 were critical. Cases involving Comcast and Booz Allen confirmed that Mythos models significantly improve analysis speed for large codebases.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.