The program, announced on the Anthropic website, makes advanced cyber capabilities and reduced blocking classifiers available to qualifying security professionals [1]. The company stated the revamped CVP combines two initiatives it has run for the past six months: Project Glasswing, which gave organizations securing critical software access to Claude Mythos, and the original CVP, which gave vetted security teams reduced safeguards on Claude Opus and Sonnet models [2].
Defense Access covers reverse-engineering malware, incident response and vulnerability analysis for company, nonprofit, university and government security teams, as well as critical infrastructure operators and individual researchers, according to Anthropic. Red Team Access permits authorized penetration testing for in-house red teams, government red teams and security firms, but individuals are not eligible and applications take weeks, the company said.
Meanwhile, Specialized Access imposes the fewest cyber restrictions and is limited to vetted organizations cleared to test safety-critical systems such as power grids, flight operating systems, telecom networks and interbank transfer infrastructure, Anthropic said. The tiered structure reflects an effort to balance security concerns with the operational needs of different types of organizations.
The company described the figures as an undercount and said it expects the true impact to be at least five times higher, noting the data comes from a survey of a limited number of partners [2]. Between April and July 2026, participants identified over 129,000 validated software vulnerabilities under the program, according to the company [3]. The benchmark results and vulnerability statistics together illustrate how the tiered structure shapes both the capabilities available to different users and the corresponding safeguards applied to each access level.
The U.S. Department of War is no longer using Anthropic's AI tools, an official told the BBC, months after the agency designated the company a supply chain risk on national security grounds [4]. The warning came on the same day Anthropic announced the expanded program.
Anthropic has previously restricted access to Mythos due to concerns about its cyber capabilities, and the company has faced scrutiny over prior incidents in which AI models engaged in unintended behaviors during testing [5][6]. The expansion comes amid continuing questions about AI access, centralized control and the role of government-corporate vetting in cybersecurity.
To release Mythos-level capabilities more broadly, the company has added additional safeguards, with Claude Fable 5.1 being the same underlying model as Claude Mythos 5.1 with safeguards for cybersecurity and biology [10]. As the program opens to more organizations, questions remain about who ultimately controls access to the most powerful dual-use AI systems.