Skip to main content
Anthropic's Claude AI interface on a screen, with "Defense Access" highlighted, signifying security team collaboration.

Editorial illustration for Anthropic Opens 'Defense Access' to Security Teams for Claude

Anthropic Launches Claude Access for Security Teams

• 4 min read

Anthropic has spent months running a quiet pilot called Project Glasswing, letting select security researchers use Claude without most of the guardrails that normally stop the model from helping with hacking tasks. Now the company is widening that pool. The new Cyber Verification Program opens Claude's less restricted capabilities to a broader set of vetted organizations and individual researchers, covering work like vulnerability research, malware analysis, incident response, and penetration testing.

Anthropic's public Claude models already block most of that work by default, since the same skills that help a defender patch a flaw can help an attacker exploit one. The CVP tries to split the difference by sorting applicants into three access tiers, with the strictest reserved for systems like power grids and banking networks, vetted jointly with the US government. Corporate security teams, universities, government agencies, and solo researchers fall under a lighter tier aimed at defensive work, while a separate tier covers authorized attack simulations for organizations only.

The results from the earlier pilot give some sense of what's at stake once that access widens.

Partners in the predecessor program, Project Glasswing, found at least 129,000 confirmed vulnerabilities between April and July 2026, according to Anthropic. More than 33,000 were classified as high-severity or critical. Those numbers come from surveys of a subset of partners, and Anthropic says the real-world impact is at least five times higher.

Why this matters

Anthropic is betting that vetting can substitute for the blunt filters that make Claude mostly useless for real offensive security work. That's a reasonable trade for the security teams this opens up to, corporate SOCs, university labs, critical infrastructure operators, who've long had to route around model guardrails or just skip AI assistance for malware analysis and pen testing. But the program's value depends entirely on how Anthropic defines "vetted" and how fast that review process moves, details the company hasn't fully spelled out.

A two-tier system, Defense Access for broad vulnerability work and Red Team Access for something more aggressive, also means Anthropic is now in the business of deciding who gets which level of a dangerous capability, which is a lot of discretionary power for one company to hold. For researchers and founders building security tools on top of Claude, the practical question is turnaround time on vetting and whether access actually scales past Anthropic's existing enterprise relationships. Watch whether other model makers follow with their own tiered access schemes, or whether this stays an Anthropic-only experiment.

Common Questions Answered

What is Project Glasswing and how does it relate to Anthropic's new Cyber Verification Program?

Project Glasswing was Anthropic's initial pilot program that allowed select security researchers to use Claude with reduced guardrails for security research tasks. The new Cyber Verification Program expands upon this foundation by opening Claude's less restricted capabilities to a broader set of vetted organizations and individual researchers for vulnerability research, malware analysis, incident response, and penetration testing.

How many vulnerabilities were discovered through Project Glasswing between April and July 2026?

Partners in Project Glasswing found at least 129,000 confirmed vulnerabilities between April and July 2026, with more than 33,000 classified as high-severity or critical. Anthropic estimates the real-world impact is at least five times higher than these surveyed numbers, indicating the program's significant security value.

What types of security work does the Cyber Verification Program support?

The Cyber Verification Program covers a range of defensive security activities including vulnerability research, malware analysis, incident response, and penetration testing. These capabilities are made available to vetted organizations and individual researchers who previously had to work around Claude's standard guardrails for these tasks.

Why does Anthropic believe vetting can replace traditional guardrails for security teams?

Anthropic is betting that thorough vetting of security teams can substitute for the blunt content filters that normally restrict Claude's capabilities for offensive security work. This approach aims to balance security concerns with providing legitimate defensive security professionals the AI assistance they need for malware analysis and penetration testing, rather than making Claude universally restricted.

LIVE16:11Google’s SynthID website now IDs AI-generated media