Anthropic has merged its two trusted-access schemes for security teams into a single, larger Cyber Verification Program, the company said on its own site on 6 October 2026. Qualifying applicants get Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and later models with fewer automatic refusals. How far the refusals relax depends on which of three tiers an applicant is approved for. The weak point is the vetting that decides who gets in.

Start with what is being relaxed. Anthropic’s generally available models sit behind blocking classifiers, meaning automatic filters that read a request and refuse it when they judge it harmful. The company describes its cyber settings as conservative enough to stop most cyber work. Defenders feel that hardest. Examining a suspicious file or testing your own network looks to a filter much like the first move of an intruder, and Anthropic itself calls the field dual use. A verified account simply meets that refusal less often.

Who qualifies is the easy part. The entry tier, Defense Access, is meant to be crowded: Anthropic expects many organizations doing defensive work to pass and aims to reply within days. The list leans toward in-house teams at companies, charities, universities, and public bodies protecting what they run, and it also admits solo researchers who have a record of reported flaws, plus the volunteers who maintain open-source projects and boutique consultancies. Hospitals and utilities count too, however small. The middle tier, Red Team Access, is for organizations only, so individuals are out. It covers authorized adversarial testing, takes a few weeks to review, and parks applicants in the entry tier while they wait.

What the gate actually checks is where the piece thins out. Anthropic says it verifies every applicant and asks for evidence that the controls required for the chosen tier are in place. Four things go unstated: what counts as acceptable evidence, who inside Anthropic makes the call, how an applicant’s claims are tested, and what follows if a member misuses access. The post offers only a way for users to report being blocked on work their tier should allow. Participants must accept data retention so Anthropic can watch for misuse. Zero data retention is available to some customers, and a product called Enterprise Frontier Safeguards, due later this fall, is meant to let eligible organizations keep data in their own cloud.

Now the ceiling, which the post describes unevenly. At Red Team Access, users still hit real-time blocks on “actions that could cause physical harm or mass disruption,” according to Anthropic. That is the only limit the company spells out anywhere on the ladder. The top rung, Specialized Access, is called the one with the fewest cyber blocks, and the post names no restriction that survives there. It is meant for a small group of vetted organizations authorized to test systems that touch lives or markets, such as aviation, energy, telecom, interbank payments, and government networks. Anthropic says it reviews each one in depth alongside the US government, and existing Project Glasswing members move up without reapproval.

The test results make the asymmetry plainer. To gauge its tiers, Anthropic ran Opus 5.5 through CyScenarioBench, an evaluation of multi-stage operations, using ten challenges and five attempts apiece in each tier. With no program access, the first prompt was refused every time. In the entry tier, 46 of 50 runs hit a block at some stage and four finished. In Red Team Access, nothing was blocked and 34 runs completed. For the top rung Anthropic did not run a separate configuration. It used the same model with no safeguards at all as the stand-in, and said that matched the Red Team result.

All of this is Anthropic’s description of its own programme and its own measurement. The post names no outside auditor, and it gives no external check on how well the tiers hold up once real users arrive.

Security teams that are refused today on ordinary defensive work have an easy first step, since the entry-tier answer is promised within days. The harder question is the top rung: a company that cannot name what stays blocked there is asking buyers to trust a screening process it has only partly explained.

Anthropic, “Expanding the Cyber Verification Program,” published 6 October 2026.