On 6 October 2026, Anthropic announced an expanded Cyber Verification Program: advanced cyber capabilities and reduced blocking for qualifying security professionals, across three access tiers.

Defense Access covers defensive work — security operations, incident response, reverse-engineering malware, and analysing and validating vulnerabilities. Red Team Access sits above it. Specialized Access has the fewest cyber blocks of the three. The programme covers the company's current models and, it says, future ones, and it folds the earlier verification scheme and Project Glasswing into a single offering.

Root Notes should say plainly that it has an interest here: this publication is written with the help of one of these models.

The number attached to it

The case Anthropic makes is a volume case. It reports that Glasswing partners identified at least 129,000 verified vulnerabilities between April and July 2026, that open-source scanning found a further 5,500 between April and October, and that more than 33,000 of them were rated critical or high.

Those figures describe the same shift visible from two other directions this week. Chrome shipped 247 security fixes in a single release, with a countable share of the reports credited to AI-assisted research. Microsoft counted nearly 40,000 CVEs in the first half of the year. Finding flaws has become dramatically cheaper, and this programme is one of the mechanisms making it so.

It also raises the question nobody in this chain has answered: 129,000 findings in four months is not a triage problem any existing process was designed for. Discovery scaled. Remediation did not.

What is actually being granted

The honest way to describe the product is that a verified user gets a model that refuses less on exactly the tasks the refusals exist for.

That is not a criticism. The refusals are coarse by necessity — a model cannot reliably tell a penetration tester from an intruder from the request alone, so it declines a category of work, and the people most inconvenienced are the defenders doing that work legitimately. Tiering by verified identity is a reasonable answer to a real problem, and it is the same answer the industry already uses for exploit frameworks and offensive tooling.

The cost is also the obvious one. The capability being unlocked is the capability an attacker wants, and the only thing standing between the two is the verification step.

Who checks the badge

Which makes the verification the whole control, and the public material is thin on it.

Three questions follow, and none of them is rhetorical. What evidence qualifies someone for Specialized Access, and who reviews it? What happens when a verified account is phished — does the attacker inherit the tier, and how quickly is that noticed? And does verification attach to an organisation or a person, because a red team's credentials sitting in a compromised password manager is a different risk from an individual's.

These are the ordinary questions one asks of any privileged-access scheme, and they are the ones worth asking here precisely because the programme is otherwise sensible. A tiering system is only as good as the enrolment process behind it, and enrolment is the part that has not been described.

The argument for doing it anyway

It is worth stating the other side properly rather than gesturing at it.

Attackers were never constrained by a vendor's refusal policy. They run models without guardrails, they use open-weight models, and this fortnight has produced three separate campaigns — a backdoor using Microsoft Graph, payloads in smart contracts, a botnet rendezvous in STUN — that needed no vendor's permission for anything.

Refusals that stop defenders and not attackers are a tax on one side of an asymmetric fight. Removing that tax for people who can prove who they are is a defensible trade. Whether it is the right trade depends entirely on how hard the proof is to fake, which is the part to watch.

What to do

  • If you run a security team, read the tier definitions against your actual workflows before applying. The tiers are described by task type, and that is the thing to match.
  • Treat a verified account as privileged infrastructure. Phishing-resistant authentication on it, and the same monitoring you would put on an administrative credential.
  • Plan for the output rather than the access. If AI-assisted research multiplies your finding rate, the bottleneck moves to triage and remediation, and that is where the capacity has to go.

What is not established

  • How verification is assessed, by whom, and what evidence is required for each tier.
  • What happens to tier access when an account is compromised, or how revocation works.
  • How the 129,000 figure was counted, what verified means in it, and how much of it was independently reported elsewhere.
  • Whether other model providers will follow with comparable schemes.