Anthropic expanded its Cyber Verification Program to three access tiers on October 6. Organizations can apply to use powerful Claude models for defense, authorized offensive testing or specialized security work. Project Glasswing is being folded into the program.

Red Team Access permits more offensive tasks but requires verified authorization and tighter infrastructure controls. Published requirements include a named security contact, user attribution and deadlines for reporting security incidents. Requests involving ransomware, physical harm or mass disruption are still supposed to be blocked.

Anthropic’s own test illustrates the change in behavior. Across 50 simulated attempts, the standard configuration blocked every initial prompt. Red Team Access produced no such blocks and completed 34 tasks. These are provider-reported results in a controlled environment, not measurements of unauthorized attacks in the wild.

Anthropic generally requires data retention for monitoring. Existing approved zero-data-retention exceptions for certain models remain, however. A further safeguard service for sensitive enterprise deployments is planned for later in the fall.