Anthropic introduces three access levels for security work with Claude
Defense, Red Team and Specialized Access cover different security tasks. Verification and data-handling requirements remain part of the program.
In brief: Anthropic has expanded its Cyber Verification Program into three access levels for security work with Claude. Access depends on verification and the type of work involved.
Anthropic makes Claude, a family of AI models. Its 6 October update to Project Glasswing brings that initiative into the expanded program, giving existing Glasswing members Specialized Access.
What the three levels cover
According to Anthropic’s announcement, the levels distinguish different uses of the models:
- Defense Access: defensive work such as incident response, malware analysis and vulnerability validation.
- Red Team Access: also permits authorised penetration testing, where a security team attempts to find and demonstrate weaknesses.
- Specialized Access: reserved for a limited set of verified organisations testing sensitive systems whose failure could affect lives or markets.
The purpose is to reduce model refusals for qualifying security work. Red Team Access still blocks activities that could cause physical harm or mass disruption.
Why security work needs this distinction
The same technical knowledge can help someone understand a weakness or exploit it. A defender investigating suspicious software may therefore ask questions that resemble an attacker’s.
A program like this separates permission to use particular model capabilities from the permission to test a particular system. An approved account does not establish that the owner of a network has authorised a test against it.
Verification and data handling remain part of access
Anthropic’s current help page says applicants must document their work and applicable security controls. Individuals can apply only for Defense Access. The usage policy continues to apply after approval.
Data retention is required for misuse monitoring, with an interim exception for organisations that already have qualifying zero-retention access to Fable or Mythos. Enterprise Frontier Safeguards is described as a forthcoming option for eligible organisations to store data in infrastructure they control.
For Norwegian businesses, this is a change in how security professionals obtain AI capabilities. It is not automatic approval for a local team, or evidence that a system tested with those capabilities is secure.
Our AI hacking explanation covers the relationship between models, tools and actions.