
Share
A tiered access system now lets vetted security teams, including regional hospitals and critical infrastructure operators, tap into Claude's full offensive and defensive security capabilities, as the industry races to keep AI-powered attacks from outpacing defenses.
Anthropic just restructured how security teams get access to its most capable cyber tooling, and the changes matter if you're running infrastructure that attackers might actually want to break into.
The company's Cyber Verification Program (CVP) has been redesigned into three distinct tiers, each with its own verification bar and set of guardrails. All three grant access to Claude models, including Opus 5.5, Sonnet 5.5, and Mythos 5.1. The idea is simple: match the level of access to the sensitivity of the work, instead of a one-size-fits-all approval process.
That's a meaningful shift because Anthropic's publicly available models ship with what the company calls "conservative cyber safeguards" that block most security-adjacent tasks by default. Good for stopping bad actors from weaponizing an LLM. Bad for the blue team trying to find a vulnerability before someone else does. Anthropic's own framing cuts right to the tension: "the same capabilities that enable a security team to find and fix a vulnerability can also help a malicious actor exploit it." It's the classic dual-use problem, just now baked into model access controls instead of export restrictions.
Here's what each tier actually unlocks:
Outside of CVP entirely, Anthropic's generally available models still handle lighter-weight security tasks: code review, patching known issues, vulnerability discovery in code you own, and triage of security alerts. One catch worth flagging for compliance teams: data retention is mandatory for any organization enrolled in CVP, specifically so Anthropic can monitor for misuse. If your org is sensitive about what gets logged, that's a conversation to have before you apply.
Anthropic is inviting interested organizations to apply through its portal now.

This expansion doesn't exist in a vacuum. Just last month, Anthropic joined dozens of other AI and security firms, including chief rival OpenAI, which led the effort, in signing a public "call for collective action" urging critical infrastructure organizations, from hospitals to water treatment plants, to shore up their defenses while there's still a "limited window" to do so. The letter's language was blunt: AI-enabled cyberattacks are going to get "far more widespread and sophisticated" as models keep improving, and the infrastructure communities depend on is at risk.
The irony landed fast. Not long after that letter went out, OpenAI's own models were implicated in a breach of Medicare data in Australia, even as the company was rolling out new models boasting a "significant jump in cyber capabilities." It's a useful reminder that the companies warning loudest about AI-driven attack surfaces are also the ones expanding what their models can do.
Anthropic's Project Glasswing, launched back in April, is the other half of this story. That initiative brought together national governments and roughly 150 hand-picked organizations across critical sectors, healthcare included, to hunt for vulnerabilities tied to Anthropic's Mythos frontier models and the kinds of exploit tooling that could spin out of them. Epic was one of the participants, and the collaboration wasn't just theoretical: Epic found vulnerabilities serious enough that it paused new product development for several weeks to patch them.
Stirling Martin, Epic's chief of security, summed up the new reality for health systems in a recent interview with The New York Times: "Ultimately they need to get ready to patch, patch, patch. As soon as they think they are patching fast enough, they need to patch faster." That's not a comforting message for IT teams already stretched thin, but it tracks with where the threat landscape is heading.
Anthropic frames the CVP overhaul as a consolidation rather than a brand-new initiative. "For the past six months, we've enabled trusted access through two programs: Project Glasswing and the CVP," the company said. Project Glasswing gave select organizations access to Claude Mythos for securing critical software; the original CVP gave vetted security teams reduced safeguards on Opus and Sonnet. "Now, we're integrating these programs into one expanded offering, designed to give more security organizations access to the capabilities they need to protect their systems."
For practitioners, the practical upshot is this: if your organization sits anywhere near critical infrastructure, including regional hospitals, you now have a clearer, tiered path to get real access to frontier model capabilities for security work, rather than fighting against default safeguards built to stop misuse. The tradeoff is mandatory data retention and a verification process that scales with how dangerous your access level is. Given that Epic's own red-teaming under Glasswing surfaced bugs severe enough to halt a product roadmap, this isn't a hypothetical exercise. The attack surface is real, the tooling is getting sharper on both sides, and the organizations that get ahead of patching cycles now are the ones least likely to be the next cautionary headline.
Tags
Original Sources
Anthropic expands cybersecurity verification tools, invites hospitals to apply
↗ https://www.healthcareitnews.com/news/anthropic-expands-cybersecurity-verification-tools-invites-hospitals-apply
About the author
Kai built ML infrastructure at a Bay Area startup before developing an obsession with transformer architectures and inference optimisation that eventually pulled him out of product work entirely. A stint at a compute research lab sharpened his instinct for what actually matters in a model release versus what is marketing. He writes from the inside — from the perspective of someone who has debugged the systems he is describing at three in the morning. He is allergic to hype and instinctively drawn to the unglamorous plumbing questions that everyone else skips over.
More from The Engineer →This Week's Edition
9 October 2026
34 articles
Related Articles

Cisco's Edge Intelligence Tackles the Unsexy Problem of Getting IoT Data Out of the Field
Tools & Engineering · 5 min

The 2026 Nobel Prizes, and the Persistent Gap Science Still Hasn't Closed
Policy & Regulation · 5 min

Trump Declares Anyone Who Says "AI" Instead Of "Super Intelligence" An Enemy
Policy & Regulation · 5 min
Related Articles

Cisco's Edge Intelligence Tackles the Unsexy Problem of Getting IoT Data Out of the Field
Tools & Engineering · 5 min

The 2026 Nobel Prizes, and the Persistent Gap Science Still Hasn't Closed
Policy & Regulation · 5 min

Trump Declares Anyone Who Says "AI" Instead Of "Super Intelligence" An Enemy
Policy & Regulation · 5 min
More Stories
© 2026 Cedar & Bloom. All rights reserved.