Anthropic’s generally available Claude models block most offensive-looking cyber work by design, which also gets in the way of defenders who reverse-engineer malware or validate a vulnerability. The expanded Cyber Verification Program is Anthropic’s answer: verify who you are and what you defend, and get a model with fewer blocks. For Alberta’s utilities, municipalities, and oil and gas operators with operational-technology (OT) networks, the Defense tier is the one to read closely.
What Anthropic changed
Anthropic says that for six months it ran two trusted-access programs side by side. Project Glasswing gave a group of organizations securing critical software access to Claude Mythos. The original CVP gave vetted security teams reduced safeguards on Claude Opus and Sonnet models. The October 6 post folds both into one program.
“Now, we’re integrating these programs into one expanded offering, designed to give more security organizations access to the capabilities they need to protect their systems.”Anthropic, Expanding the Cyber Verification Program, October 6, 2026
Anthropic’s published figures come from its own testing and partner reports. On its CyScenarioBench evaluation, Anthropic says Defense Access safeguards blocked 46 of 50 trials, while Red Team Access had no blocks and Claude Opus 5.5 completed 34 of 50. It also says Glasswing partners found at least 129,000 verified software vulnerabilities between April and July 2026, and calls that figure a lower bound.
The three tiers, as Anthropic describes them
| Tier | For | Review |
|---|---|---|
| Defense Access | SOC and incident response, malware reverse-engineering, vulnerability analysis and validation. Examples include government bodies, municipal utilities, regional hospitals, smaller security firms, open-source maintainers | Post: “within a few days.” Help Center: within seven business days |
| Red Team Access | Adds authorized penetration testing and red-teaming. Organizations only | “A few weeks”; applicants are enrolled in Defense while under review |
| Specialized Access | Limited verified organizations authorized to test safety systems such as power grids and telecom networks | Reviewed in depth with the US government |
Even in Red Team Access, Anthropic says users will still see real-time blocks on actions that could cause physical harm or mass disruption, including damaging physical systems or pen testing high-risk safety systems. The two pages give different review times for applications. The post says Anthropic aims to respond “within a few days,” while the Help Center says it aims to send a decision or a request for more information within seven business days. Plan for the longer figure.
What data retention means for privacy
Anthropic’s post is direct: “Data retention is required for organizations enrolled in the program so that we can monitor for cyber misuse.” For a utility or municipality, that means prompts and files sent through CVP access, which could include logs, malware samples or network details, are retained by Anthropic rather than discarded. Anthropic says Enterprise Frontier Safeguards (EFS), which it describes as combining zero-data-retention privacy with safeguards, should arrive “later this fall” and will let eligible organizations store data in cloud infrastructure they control. Until then, organizations that already have Claude Fable 5.1 or Claude Mythos 5.1 with zero data retention can use CVP with zero data retention.
The Help Center adds operational requirements. Defense Access members have until December 15, 2026 to adopt phishing-resistant multi-factor authentication and stop using API keys. Until then, some form of MFA is required and API keys expire every seven days. On availability, the post lists the Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry, and says Amazon Bedrock access is only for customers eligible for EFS.
How it compares with Gemini 4 Argon’s restricted access
Google took a similar route with Gemini 4 Argon. As our Gemini 4 Argon briefing reported, Argon’s first users came through Google’s Fairwind Program for selected security partners. That program required controls including phishing-resistant MFA and limited access to internal security teams, and applications were reviewed with no guarantee of access. Both vendors are gating their strongest cyber capability behind verification. The difference in Anthropic’s case is breadth: its post says it expects “many organizations conducting defensive cybersecurity work” to qualify for Defense Access, and names operators “of any size.”
Should Alberta utilities, municipalities and security firms apply? (our advice)
What follows is our advice, not Anthropic’s. If your team does defensive work on systems you own or maintain, such as a municipal water or electric utility, a pipeline or gas-processing operator’s OT security group, or a smaller Alberta security firm, consider applying for Defense Access. First, write down the use cases you’d run, such as triaging alerts, analyzing a suspicious binary or validating a vendor advisory against your own assets. Next, check that you can meet the security controls, especially phishing-resistant MFA and removing API keys. Then decide what data may go in while retention applies. Keep OT network maps, customer data and anything covered by a regulator or contract out until your privacy review clears it, or until EFS gives you storage you control.
Run a privacy check under PIPEDA or the Alberta privacy law that covers your organization, whether you’re a public body or a private business, and record the decision. Our private AI security work covers that data boundary, and industrial AI Alberta covers the plant and field side.
