AI Security

Anthropic just wrote a license for offensive AI. The price is your prompts.

The new three-tier Cyber Verification Program gives vetted red teams Mythos 5.1 with no blocks on Anthropic’s own benchmark. Vetting becomes the moat, and data retention is the bill.

Oct 7, 2026 · 4 min read

Anthropic didn’t ship a new model on Tuesday. It shipped something more consequential for security buyers: a licensing system for offensive capability.

What changed. Project Glasswing and the old Cyber Verification Program are now one program with three tiers. Every tier gets Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1 (per Anthropic). Defense Access covers SOC and incident response, malware reverse engineering and vuln validation, with reviews in a few days. Red Team Access adds authorized pentesting and red teaming. It’s organizations only, reviews take a few weeks, and ransomware deployment, damage to physical systems and testing of high-risk safety systems stay blocked in real time. Specialized Access, with the fewest blocks, is for grids, flight systems, telecom networks and interbank rails. Anthropic vets those organizations with the US government, and Glasswing members move straight in.

The number that matters. Anthropic ran Opus 5.5 through CyScenarioBench, its multi-stage cyber operations test, five attempts at each of 10 challenges per tier. Without the program, every task was blocked on the first prompt. Defense Access blocked 46 of 50. Red Team Access blocked none and completed 34 of 50, the same as the model with no safeguards at all (per Anthropic).

Read that plainly. Inside its scope, the Red Team tier is the unrestricted model. The gate isn’t the classifier. The gate is the application.

Our POV. The lab is now the licensing authority for AI-assisted offense. Vetting works like KYC for exploit capability: prove who you are, what you’re authorized to test and what controls you run, and you get the same model as everyone else who cleared. That changes who has a moat. If any vetted pentest firm can run Mythos 5.1 with no blocks, “we have access to frontier models” stops being a differentiator. What’s left is scoping, evidence, retest discipline and the telemetry nobody else has.

The bill. Enrolled organizations must accept data retention so Anthropic can monitor for misuse. Enterprise Frontier Safeguards, which pairs zero-retention privacy with safeguards and lets eligible orgs store data in cloud infrastructure they control, arrives “later this fall.” Until then, only organizations that already have zero data retention on Claude Fable 5.1 or Mythos 5.1 can use the program without retention (per Anthropic).

For a red team, prompts aren’t harmless. They hold client hostnames, credentials pulled mid-engagement, unpatched findings. Many client contracts restrict where engagement data goes. Your legal team will flag this before your operators finish the application. They should.

The output claim, discounted. Anthropic says Glasswing partners found at least 129,000 verified vulnerabilities between April and July 2026, its own open-source scanning found 5,500 more, and more than 33,000 have been rated critical or high. It calls that an undercount built from 33 partner reports. That’s vendor-reported survey data, so treat it as directional. The direction is still loud: discovery volume is no longer the bottleneck. Triage and patching are.

Distribution detail. The program runs on the Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry. On Amazon Bedrock it’s only for customers eligible for Enterprise Frontier Safeguards. Mythos access on third-party clouds trails approval by about five business days (per Anthropic’s help center).

What we’d do this week. Apply for Defense Access. A few days of review for your SOC and IR team is cheap. If you run a red team, read your client MSAs on third-party data processing before any engagement data touches a retained workspace. Ask every AI pentest or vuln research vendor you pay which tier it runs on, where prompts are retained and for how long. And patch capacity: if your vendors find vulns this fast, your remediation queue is the next incident.

For analysts. Value moves toward whoever controls the gate and whoever owns the fix. Services firms whose edge was model access get squeezed. Vendors with proprietary data, workflow and remediation hold up.

Sources