Skip to content
TECH CEO Daily

Anthropic opens cyber models to vetted defenders with three-tier verification program

Security teams can now apply for Claude models with fewer cyber restrictions, while open-source maintainers get a free scanner and critical infrastructure gets a partner program.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Anthropic replaced Project Glasswing with a three-tier Cyber Verification Program: Defense, Red Team and Specialized Access.
  • 2On October 8, Anthropic launched a Critical Infrastructure Defense Program with 11 founding partners, including CrowdStrike and Palo Alto Networks.
  • 3A free OSS Scanner will send AI-found vulnerability reports, some unreviewed, to open-source maintainers.

The news

Anthropic has reorganized how security professionals get access to its most capable models for cyber work. As reported by SiliconANGLE on October 6, 2026, the company folded Project Glasswing, its invitation-based vulnerability-hunting effort launched in April 2026, into a broader Cyber Verification Program with three tiers of access.

The entry tier, Defense Access, covers defensive work such as incident response and malware reverse engineering. According to SiliconANGLE, it is open to companies, universities, government bodies, critical infrastructure operators such as regional hospitals, and individual researchers with a record of vulnerability disclosure, and Anthropic aims to respond within days. Red Team Access permits penetration testing on systems an organization is authorized to test; review takes weeks, individual researchers are excluded for now, and real-time classifiers still block requests that drift toward activities such as ransomware deployment.

The top tier, Specialized Access, has the fewest cyber restrictions and is limited to organizations cleared to test critical safety systems such as power grids and telecom networks, with in-depth vetting involving the U.S. government, SiliconANGLE reported. Existing Glasswing members move into it automatically. The models covered are Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, available through Anthropic's own platform, Google Vertex AI, Microsoft Foundry and AWS Bedrock, the last for Enterprise Frontier Safeguards customers only.

On October 8, Anthropic followed with what SiliconANGLE described as a Critical Infrastructure Defense Program and a free OSS Scanner for open-source projects. The program has 11 founding partners: Accenture, Booz Allen Hamilton, Deloitte & Touche, PricewaterhouseCoopers, Dragos, Insane Cyber, Nozomi Networks, CrowdStrike (CRWD), Palo Alto Networks (PANW), Hitachi and Rockwell Automation (ROK).

CrowdStrike said in a blog post the same day that it will contribute its Falcon platform, IT and operational technology security data and threat intelligence, and in return gets access to Anthropic's technical guidance and frontier cybersecurity research, plus integration of Claude within its Charlotte AI assistant.

The OSS Scanner offers free periodic scans of eligible open-source projects using Anthropic's strongest models, with reports that include reproducers and candidate patches where possible. SiliconANGLE reported that some reports go to maintainers without human review and may contain errors such as wrong severity ratings. Eligibility follows the OSS-Fuzz standard of critical impact on infrastructure and user security, decided case by case.

The numbers

Verified vulnerabilities found by Glasswing partners, April to July 2026
129,000+
Rated critical or high severity
33,000+
Founding partners, Critical Infrastructure Defense Program
11
Candidate vulnerabilities found for open source in six months
29,000+
wolfSSL test: valid reports
72 of 74

Why CEOs should care

For CISOs, the practical change is that access is now something a security team can apply for, rather than wait to be invited into. Teams doing incident response or malware analysis should look at the Defense Access tier first, since Anthropic targets a response within days. Teams that run internal red teams should expect a review of weeks and should prepare documentation showing what systems they are authorized to test.

For operators of power, water, telecom and healthcare systems, the Critical Infrastructure Defense Program and the Specialized Access tier signal that AI-assisted testing of safety systems is moving from pilots to formal programs. Boards should ask whether the organization's existing security vendors, several of which are founding partners, plan to bring these models into their services, and on what data-handling terms.

Engineering leaders who depend on open-source components should prepare for more vulnerability reports, faster. SiliconANGLE reported that about 5,000 unreviewed AI-generated reports have already gone to maintainers. That means more patches upstream, but also more triage work and potential false alarms. Ask whether your software composition and patching process can absorb a higher volume of fixes.

The bigger picture

The moves reflect a bet that the same models that can find software flaws should be put in defenders' hands first, under identity checks, rather than kept fully locked down. According to SiliconANGLE, Glasswing partners identified more than 129,000 verified vulnerabilities between April and July 2026, over 33,000 of them rated critical or high. Those are company-reported figures, but they suggest the volume of AI-found flaws is outpacing the human capacity to fix them, which is why the scanner pushes candidate patches along with findings.

What’s next

Watch how quickly Anthropic processes applications for each tier, whether rivals offer comparable verified-access programs for defenders, and how open-source maintainers respond to the volume and accuracy of unreviewed scanner reports.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

AnthropicCrowdStrikeProject GlasswingPalo Alto NetworksOpen source security

Earlier coverage of Anthropic

All Anthropic coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.