
Anthropic opens three tiers of powerful cyber AI to defenders, with different limits
A security team at a regional hospital does not need the same permissions as a government red team testing a power grid. Anthropic's expanded Cyber Verification Program is built around that distinction. Its Defense Access tier is meant for incident response, malware analysis and vulnerability validation on owned or maintained systems. Red Team Access adds authorized penetration testing for organizations, with real-time blocks retained for actions Anthropic says could cause mass disruption or physical harm. Specialized Access, including existing Project Glasswing participants, is limited to verified organizations authorized to test high-risk systems such as power grids, flight operations and interbank transfers; Anthropic says it reviews that tier with the U.S. government. This is a company-run access framework, not a public license establishing that every authorized use is safe. Anthropic tested its safeguards on 10 interactive cyber challenges with five attempts each. It says every generally available trial was stopped at the first prompt; in Defense Access 46 of 50 trials were blocked at some point and four succeeded; in Red Team Access none were blocked and the model completed 34 of 50. These are benchmark results, not evidence of real attacks, and the broad tier intentionally allows authorized offensive simulation. The central governance question is whether verification and monitoring can keep that permission tied to systems the user is allowed to test. Smaller defenders may gain access to better tools, but they also face application checks and data-retention requirements. If the tiers work, defenders gain speed without a general release of potent capabilities. If authorization checks or misuse detection fail, the same flexibility that helps red teams could lower the barrier for abuse.









































