AI NewsModels & agentsAnnouncement
Anthropic splits Claude cyber access into three tiers after testing
A defensive-leaning security team using Claude Opus 5.5 saw 46 of 50 offensive benchmark trials blocked under the new Defense Access tier, the most restricted of three new access levels for the Cyber Verification Program.
Why it mattersAny security team already using Claude for incident response, red-teaming or vulnerability work has to pick a tier, accept data retention, and in two of three cases get verified before the model will perform the higher-risk tasks.
An incident-response team asking Claude to help with a tricky offensive technique can now be told "no", "yes under review", or "yes after a government check", and which answer comes back depends on a tier the company just picked.
Anthropic expanded its Cyber Verification Program (CVP) and split access to higher-risk cyber capabilities into three use-case tiers, folding Project Glasswing into the broadest tier. Anthropic says the change will "extend the impact of our Project Glasswing to a much larger number of cyber defenders". The announcement sat on Anthropic's news page, and The New Stack reported it with the test numbers below.
Defense Access blocks most offensive work
Defense Access is the broadest and most restricted tier, aimed at smaller security firms, open-source maintainers and individual researchers with a track record of reported vulnerabilities. Anthropic tested its own tier against CyScenarioBench, its evaluation for planning and executing multi-stage cyber operations, and reports that Claude Opus 5.5 with Defense Access safeguards blocked 46 of 50 trials. Only four tasks got through.
Anthropic says this does not mean Defense Access blocks 92 percent of the defensive work the tier is designed for, because CyScenarioBench is an offensive benchmark. The New Stack points out that no comparable defensive benchmark exists, so a defender cannot yet say how often these safeguards will refuse a legitimate request.
For comparison, Anthropic says Claude Opus 5.5 with no CVP access blocks every task on the first prompt.
Red Team Access is close to unrestricted
The middle tier, Red Team Access, is aimed at red teams and penetration-testing firms. It covers Defense Access use cases plus authorised penetration testing. Individual researchers are, by default, barred from applying for this tier.
The gap between the two tiers is sharp. Anthropic says no trials were blocked for Opus 5.5 under Red Team Access safeguards, and the model completed 34 of 50 tasks. Anthropic's stated benchmark number for Opus 5.5 with no safeguards applied at all is a 67.6 percent success rate, so Red Team Access leaves Claude's offensive capability almost intact while the verification does the gatekeeping.
Specialized Access needs US government sign-off
Specialized Access is the least restricted tier and is reserved for organisations authorised to test safety-critical systems such as power grids or telecom networks. Project Glasswing members keep their current access without re-applying. Any new security team has to pass a review jointly conducted by Anthropic and the US government before it is admitted.
Anthropic says every tier gets access to the same frontier models: Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1, plus new models coming later. The practical difference is the safeguard profile sitting in front of them.
The data trade-off
Every tier accepts data retention. Enterprise Frontier Safeguards, due later in the fall, will allow eligible organisations to store CVP data in self-controlled cloud infrastructure. Organisations with access to Claude Fable 5.1 or Claude Mythos 5.1 under zero data retention are exempt until then.
Anthropic has not published a defensive benchmark, a timeline for Enterprise Frontier Safeguards beyond "fall", or the approval rate for Specialized Access review. A security team weighing a tier picks between a model that will often refuse a legitimate task and a verification process that opens the pattern of its work to a vendor and in one case to a government.
Source
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually using them to release software. Short, and only when there is something worth reading.
