Anthropic introduces three tiers for cybersecurity teams using its AI models
Anthropic has merged Project Glasswing and its Cyber Verification Program into a three-tier scheme giving different security professionals access to its AI models. The change is intended to match model capabilities and safeguards to users’ tasks, as the company seeks to help organisations find vulnerabilities while limiting potentially harmful use.
Anthropic says partners identified at least 129,000 verified software vulnerabilities from April to July 2026, with more than 33,000 rated critical or high severity, though it expects the true total to be higher. Its own figures show 516 of 5,674 confirmed vulnerabilities had been patched. The new tiers are Defense Access for defensive security teams, Red Team Access for penetration testing and cyber evaluation, and Specialized Access for a limited set of organisations testing systems such as power grids and banking infrastructure.
- Anthropic has combined two cyber security programmes into three access tiers.
- Partners reported at least 129,000 verified vulnerabilities.
- The company says just 516 of 5,674 confirmed issues had been patched.
New here? Start with this
Anthropic creates artificial intelligence tools, and security professionals use such AI to find software vulnerabilities—flaws that criminals could exploit. Anthropic wants to make its AI more useful for legitimate security work while ensuring the technology isn't misused for harmful purposes.
Anthropic has reorganised how it provides security teams with access to its models through a new three-tier system, combining two earlier programmes. Each tier matches a particular level of AI capability and safety protections to different types of security work.
The tiers are aimed at defensive security teams working to protect systems, penetration testers who search for software weaknesses, and a limited number of organisations testing critical infrastructure like power grids and banks. This allows Anthropic to tailor access based on what each group actually needs.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Anthropic's tiered system represents a thoughtful, risk-aware approach to enabling essential cybersecurity work. The identification of 129,000+ vulnerabilities—including over 33,000 critical or high-severity ones—demonstrates substantial defensive value for organisations seeking to address threats before malicious actors do. By verifying users, calibrating access to specific professional needs, and maintaining differentiated safeguards, the company balances the genuine security imperative for sophisticated tools with appropriate risk management.
The case against
Even well-designed tiered verification systems can be circumvented or compromised, and granting access to powerful AI-enhanced red team and penetration testing tools multiplies the risk of misuse beyond their intended defensive scope. The troubling gap between vulnerabilities identified (129,000+) and those actually patched (516 of 5,674 confirmed) suggests the programme may outpace organisations' remediation capacity, potentially expanding the attack surface rather than reducing it. Providing such potent capabilities to multiple verified users—each a potential vector for tool theft, leakage, or repurposing—introduces risks that may ultimately exceed the security benefits.
AI Business Companies Cricket Cybersecurity Sport Technology
Read the full article at the source →
Originally published by The Register as “Anthropic reconfigures its cool kids security program”.