How we read the signal

Analysis frame

Evidence level

Primary-source evidence

Analytical lens

Compare eligibility, allowed tasks and safeguards across three company-run access tiers while keeping simulated benchmark performance separate from real misuse rates.

Affected groups
  • Hospital, municipal and open-source defenders applying for stronger tools
  • Operators and users of high-risk systems that may be penetration tested
What remains unknown
  • No public independent audit establishes how often the authorization checks reject misuse
  • CyScenarioBench trials do not measure actual attacks, victim harm or long-term defender benefit
Second-order effects to watch
  • Qualified small defenders may gain capacity previously reserved for major vendors
  • Differential access and data-retention rules may concentrate power or deter privacy-sensitive teams

Three access levels, different powers

Defense Access includes defensive analysis; Red Team Access adds authorized penetration testing; Specialized Access covers a smaller group permitted to test systems whose failure could hurt people or markets. Anthropic says verification and controls grow with the tier.

The program is a policy enforced by one provider. It does not replace legal authorization from the system owner or independent oversight of consequential tests.

A benchmark is not an incident rate

Anthropic's 50-trial benchmark shows that the Red Team configuration enables much more simulated offensive work than Defense Access. That is its intended design for authorized testers, not a report of 34 actual breaches.

What matters next is how the company verifies permissions, audits misuse, handles false rejections and reports incidents. Its privacy and data-retention terms will also affect who can participate.

Primary trail

Go to the source

Read the evidence behind this analysis. External links open in a new tab.

Anthropic — Cyber Verification Program expansion Anthropic — Project Glasswing background