Anthropic on Tuesday, Oct. 6, widened a program that lets qualifying security professionals use its Claude models with fewer of the automatic blocks that normally stop hacking-related work. Every level of the new program includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and future models. Mythos is the company's most cyber-capable family of models. For the past six months, a small group of organizations protecting the most critical software has used it through a separate program called Project Glasswing, which the new program folds in together with Anthropic's earlier security program.
The blocks exist because security skills cut both ways. Anthropic says the same abilities that help a security team find and fix a weakness can help an attacker break in, so its publicly available models have cautious safeguards that block most cyber work. They can still review code, patch known problems, search a company's own code for flaws and sort through security alerts.
The program now has three levels. Defense Access covers work such as responding to break-ins, taking apart malicious software and checking whether a suspected vulnerability, a weakness in software that an attacker could use, is real. Security teams at companies, nonprofits, universities and government bodies that defend their own systems can apply, along with operators of critical services such as regional hospitals or town utilities, people who maintain free public code, and individual researchers with a record of reporting flaws. Anthropic says it aims to answer them within a few days. Red Team Access adds red-teaming, deliberately attacking a system to find its flaws, against systems the organization is authorized to test. It is for organizations only, and Anthropic expects reviews to take a few weeks, with applicants getting the Defense level in the meantime. It still blocks actions such as deploying ransomware, damaging physical systems or testing high-risk safety systems.
Specialized Access has the fewest blocks. It is reserved for a limited set of organizations authorized to test systems that could put lives at risk or disrupt markets, such as flight systems, power grids, telephone networks and the systems banks use to move money between them. Anthropic says it reviews each of these organizations in depth with the US government, and current Project Glasswing members move into this level. In most cases, organizations in any level must let Anthropic keep their data so it can watch for misuse. Anthropic says some customers will be able to keep that data on their own cloud servers from later this fall. The program runs on Anthropic's own platform, Google Cloud and Microsoft's Foundry, and on Amazon's cloud only for some customers.
Anthropic says its own tests show the levels work as designed. It gave Opus 5.5 ten challenges that ask a model to plan and carry out a multi-step cyberattack, five tries each at each level. Without the program, every attempt was blocked at the first request. At the Defense level, 46 of 50 tries were blocked at some point, and the other four got through. At the Red Team level nothing was blocked, and the model finished 34 of 50, about what it manages with no safeguards at all.
Anthropic also says Glasswing partners found at least 129,000 verified software flaws between April and July, and that its own scanning of free public code found 5,500 more between April and October, with over 33,000 rated critical or high severity. Those figures come from reports by 33 partners, fewer than half of whom said how many flaws had been fixed. Because only some partners answered its survey, Anthropic believes the real number is at least five times higher. The company has not said how many organizations it expects to admit, what it charges, or what happens to a vetted member caught misusing the access.