Anthropic published a significant update to its Cyber Verification Program today, restructuring it from a single-tier model into three distinct access tiers — Defense Access, Red Team Access, and Specialized Access — and simultaneously folding Project Glasswing into the expanded framework. For healthcare security teams, the timing matters: the program now explicitly names regional hospitals and operators of critical infrastructure as qualifying candidates, while a pending data-custody solution addresses one of the most persistent regulatory blockers for adoption in regulated environments.
The expansion went live today, October 6, 2026. Existing CVP members retain their current settings and will be automatically evaluated for access to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1 under the new structure.
What Changed
The original CVP gave vetted security teams access to reduced safeguards on Opus and Sonnet models. Project Glasswing, which ran in parallel, gave a smaller group of critical infrastructure defenders access to Claude Mythos — the highest-capability tier. Today's announcement merges both programs and adds structure.The three new tiers are:
- Defense Access — Covers defensive work: SOC and incident response, malware reverse engineering, vulnerability analysis on owned systems. Explicitly includes security teams at companies, nonprofits, universities, government bodies, critical infrastructure operators of any size (including regional hospitals and municipal utilities), smaller security firms, open-source maintainers, and individual researchers with a track record of reported vulnerabilities. Anthropic says it aims to respond to applications within a few days.
- Red Team Access — Adds authorized penetration testing against systems the applicant is authorized to test, including IT systems in critical industries. In-house red teams, government red teams, and pen testing firms are the target. Hard blocks remain in place for actions that could cause mass disruption, including ransomware deployment and testing of high-risk safety systems. Applications are expected to take a few weeks; organizations are enrolled in Defense Access while Red Team Access is reviewed. Individual researchers are not currently eligible.
- Specialized Access — The fewest cyber blocks. Reserved for a limited set of organizations authorized to test safety systems that could impact lives or markets: flight operating systems, power grids, telecom networks, interbank transfer infrastructure, government administrative networks. Every organization is reviewed in depth in collaboration with the US government. Existing Project Glasswing members transition here without reapproval for current models.
All three tiers include access to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, with new models added as they're released.
What the Glasswing Data Shows
Anthropic disclosed Project Glasswing outcomes for the first time alongside the expansion announcement. Between April and July 2026, Glasswing partners found at least 129,000 verified software vulnerabilities. Anthropic's own open-source scanning efforts added another 5,500 verified vulnerabilities between April and October 2026. Of the combined total, more than 33,000 have been rated critical- or high-severity.Anthropic explicitly calls these numbers a lower bound — based on survey data from a subset of partners, with fewer than half disclosing patch counts, often because fixes were still in progress. The stated expectation is that the true impact is at least five times higher.
Two Glasswing partners published detailed accounts of how they applied the models.
Comcast used Claude Mythos Preview across 258 business-critical systems covering approximately 170 million lines of code. The notable finding was an authentication bypass vulnerability in a public-facing platform that was remediated before any exploitation was observed. The vulnerability was not caused by a single defective component — it emerged from the interaction of multiple systems that each appeared correct when reviewed in isolation.
"Discovery is becoming faster. Discovery is becoming easier. The volume of findings is enormous. Validation of these volumes of findings is the new bottleneck." — Noopur Davis, EVP and Chief Information Security and Product Privacy Officer, ComcastBooz Allen used Claude Mythos Preview for security reviews against a fixed engagement window — a constraint that limits how much code a human team can read before time runs out. In one documented case, a Mythos-class model identified a boot-time firmware vulnerability: code that runs before the operating system loads had left a security key unprotected, allowing an attacker to supply a substitute key and bypass the device's lock-or-erase mechanism indefinitely. The model traced that single unprotected setting across two separate programs written in two different languages, then confirmed no other control had compensated.
"One analyst reviewed eight production systems across 138 repositories in twelve days. Without Mythos, a portfolio review at that scale would have taken us several months with a larger team." — Brad Medairy, President of National Cybersecurity, Booz AllenThe Data Retention Problem — and the Pending Fix
CVP enrollment requires data retention so Anthropic can monitor for misuse. This is the sharpest point of friction for healthcare organizations: a mandatory data retention requirement from a third-party AI vendor has significant HIPAA implications and BAA complications that make it non-trivial for most healthcare security teams to use the program today, even if they qualify.Anthropic has a partial answer in place and a more complete one coming.
Currently, organizations with access to Claude Fable 5.1 or Claude Mythos 5.1 under zero data retention can still enroll in CVP with zero data retention. That's a narrow exception — it applies to organizations that already have a ZDR arrangement on those specific models, not to the general case.
The more complete answer is Enterprise Frontier Safeguards (EFS), announced in September 2026 and currently in phased rollout with broad availability expected later this fall. EFS separates the data custody problem from the monitoring requirement: activity data is stored in cloud infrastructure the customer controls (Amazon S3, Azure Blob Storage, or Google Cloud Storage), under the customer's own encryption keys, access policies, and audit logging. Automated monitoring still runs — looking for misuse patterns including offensive cyber and biological capability development, and credential theft — but flags go directly to the customer's team. No Anthropic human review is required.
For CVP on Amazon Bedrock specifically, EFS is required. Other platforms (Claude Platform, Google Cloud Vertex AI, Microsoft Foundry) can use CVP without waiting for EFS.
EFS is not yet generally available — organizations can register interest at the Anthropic form linked in Key Links. Once it is available, it should meaningfully change the calculus for regulated industries that would otherwise qualify for CVP but can't accept a third-party data retention requirement without a customer-controlled custody arrangement.
The Evaluation Methodology
Anthropic published benchmark data alongside the announcement, using CyScenarioBench — described as an evaluation that measures whether models can plan and execute multi-stage cyber operations under realistic constraints. Claude Opus 5.5 was tested across the CVP tiers with safeguards tuned accordingly, running five attempts on each of ten challenges per tier.The results:
| Tier | Blocks Encountered | Tasks Completed (of 50) |
|---|---|---|
| No CVP (general availability) | Every task blocked on first prompt | 0 |
| Defense Access | 46 of 50 trials blocked at some point | 4 |
| Red Team Access | No blocks | 34 (67.6% — equivalent to no safeguards) |
The Defense Access numbers are notable: 46 of 50 trials were blocked at some point during the challenge, with only 4 completing. That matches the intended design — defensive work doesn't require full offensive execution capability — but it also means security teams doing work that feels defensive to them may hit blocks that prevent task completion. The false-positive reporting channel is still the mechanism for those cases.
What This Means for Healthcare
Healthcare Security Teams Can Now Apply
The explicit inclusion of regional hospitals and critical infrastructure operators of any size as qualifying candidates for Defense Access is new. The original CVP was largely oriented toward security firms and enterprise organizations. Healthcare security teams conducting defensive operations — SOC work, incident response, vulnerability analysis on owned systems — now have a direct path to apply without needing to argue that they qualify.The Booz Allen data point is directly relevant to healthcare: one analyst covering 138 repositories across eight production systems in twelve days is the kind of throughput ratio that maps onto what healthcare security teams are being asked to do with resource constraints that haven't scaled proportionally to their attack surface. The model doesn't remove the analyst — it extends what one analyst can cover.
The Exploit Chain Problem in Healthcare Is Underappreciated
Both the Comcast and Booz Allen findings illustrate a pattern that healthcare environments reproduce at scale: vulnerabilities that don't exist in any single component but emerge from the interaction of systems that each appear correct individually. Healthcare IT environments are characterized by deep integration between systems with very different provenance — EHRs, medical devices, ancillary clinical applications, legacy infrastructure — most of which were never designed to be audited as a coherent security surface.Conventional scanning tools evaluate components in isolation. The Glasswing findings, particularly the Comcast authentication bypass, are cases where that approach produces a clean result and the real vulnerability goes undetected. Cross-system reasoning at the scale that Mythos-class models provide is architecturally suited to the healthcare problem in ways that static analysis tools are not.
The Data Retention Question Is Unresolved, But Not Indefinitely
EFS is the answer, but it isn't available yet. Healthcare security teams evaluating CVP today face a decision point: proceed under current retention terms, wait for EFS, or explore whether their organization already has a ZDR arrangement on Fable 5.1 or Mythos 5.1 that qualifies for the current ZDR exception.For organizations that have PHI flowing through their security tooling — which is less common in security operations than in clinical workflows, but possible depending on how security monitoring is instrumented — the BAA question also needs evaluation before enrollment. CVP use cases are generally bounded to code, configuration, and application behavior rather than clinical data, which may simplify that analysis, but security teams should not assume it's a non-issue without reviewing their specific deployment scope.
The Compliance Documentation Question
CVP requires security controls verification as part of the application process, and data retention is now a documented program requirement. Healthcare organizations considering the program should treat the enrollment process as a vendor risk management event: review what data flows to Anthropic, under what retention terms, for what monitoring purpose, and ensure that documentation is available before a compliance inquiry arrives.The Bigger Picture
The framing Anthropic uses for the CVP expansion — "giving defenders a permanent advantage" — is aspirational, but the Glasswing data gives it some empirical grounding. 129,000 verified vulnerabilities in four months, from a program that covered a limited set of organizations, is a meaningful number. The critical-severity subset — 33,000 — is more meaningful still. If even a fraction of those were in healthcare organizations or their software supply chains, the program has already produced security value at a scale that conventional scanning approaches would not have reached in the same timeframe.The harder question — one the data doesn't yet answer — is whether the vulnerability-finding capability translates into actual remediation at equivalent scale. The Booz Allen finding that validation and triage remain human-intensive is consistent with what Comcast's CISO described as the new bottleneck. Finding more vulnerabilities faster is only useful if the downstream workflow can process and fix them. That's a people and process question that CVP doesn't address, and it's where healthcare security teams should be thinking about what they need to build alongside the tool access.
The three-tier structure, the Glasswing results disclosure, and the EFS roadmap together represent Anthropic making a more concrete argument than before for why AI-assisted security tooling is a net positive for defenders rather than a symmetric uplift to attackers. That argument is worth evaluating on its merits, and healthcare security teams are now explicitly invited into the program to do that evaluation themselves.
This is an entry in the AI Security series. For related coverage, see Anthropic's Cyber Verification Program: What Defensive Security Teams Need to Know and Visa, Project Glasswing, and the Case for a Vulnerability Harness in Healthcare.
Key Links
- Anthropic: Expanding the Cyber Verification Program (Primary Announcement)
- Anthropic: How Comcast and Booz Allen Use Claude Mythos to Secure Their Codebases
- Anthropic: Developing Enterprise Frontier Safeguards with Our Customers
- Anthropic: Project Glasswing
- Apply for CVP Access
- Register Interest in Enterprise Frontier Safeguards
- Anthropic Help Center: CVP Tier Details