News

Anthropic Is Giving Vetted Security Firms a Claude That Performs Like It Has No Safeguards, by Its Own Test

Anthropic's new cyber tiers hand approved red teams a version of Claude Opus 5.5 that its own benchmark shows working about as well as the unguarded model, on the same day Jamie Dimon warned its Mythos model had made the world ten times riskier.

Anthropic Is Giving Vetted Security Firms a Claude That Performs Like It Has No Safeguards, by Its Own Test

Anthropic just decided that the safest way to handle its most dangerous hacking capabilities is to hand more of them out. On Tuesday the company restructured its Cyber Verification Program into three tiers that let vetted security organizations use Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1 with reduced safeguards.

The reason is a problem Anthropic built for itself. It treats cybersecurity as dual-use, so its public models ship with conservative classifiers that block most cyber work. When Claude Opus 5.5 launched on September 22, most security tasks sent to it were quietly routed to the older Opus 4.8 instead.

Three doors, three levels of trust

The broadest tier, Defense Access, covers incident response, malware reverse engineering and vulnerability analysis. It is open to security teams at companies, nonprofits, universities and government bodies, to smaller security firms, to individual researchers with a record of disclosed vulnerabilities, and to critical infrastructure operators "as small as a regional hospital." Anthropic says it aims to answer applications within a few days.

Red Team Access is for authorized penetration testing on systems an organization is cleared to test. In-house and government red teams and pentest firms qualify, individuals do not, and reviews take a few weeks. Classifiers still block, in real time, anything that could cause physical harm or mass disruption, such as deploying ransomware.

Specialized Access carries the fewest cyber restrictions and is reserved for organizations cleared to test safety-critical systems: power grids, flight operating systems, telecom networks, interbank transfer infrastructure. Applicants are vetted in depth jointly with the US government. Members of Project Glasswing, which has given Mythos to critical software defenders since April, move in without reapproval.

The number that matters

Anthropic tested the tiers on CyScenarioBench, a benchmark of multistage cyber operations, running Claude Opus 5.5 five times on each of its 10 challenges. With no program access, every attempt died on the first prompt. In Defense Access, 46 of 50 runs were stopped at some point.

At Red Team Access, nothing was blocked. The model finished 34 of 50 runs, which Anthropic itself says is effectively the same as its 67.6% success rate with no safeguards applied at all.

Anthropic's argument is that defenders need this. Glasswing partners found at least 129,000 verified vulnerabilities between April and July, and Anthropic's own open-source scanning turned up 5,500 more through October, with more than 33,000 of the total rated critical or high severity. Those figures come from just 33 partner reports, and the company believes the true impact is at least five times higher.

The timing was awkward. The same Tuesday, JPMorgan Chase CEO Jamie Dimon warned that Mythos had raised global cybersecurity risks tenfold. Earlier this year, during Anthropic's own safety evaluations, Mythos connected to the internet on its own and took actions nobody had asked for. And the gap between disclosure and abuse is already short: attackers started probing a Rejetto file server bug a day after researchers showed how Mythos had cracked it.

Enrolled organizations must let Anthropic retain their data so it can watch for misuse. Enterprise Frontier Safeguards, due later this year, will let eligible customers keep that data in cloud infrastructure they control, part of Anthropic's broader softening of Claude data retention rules after enterprise pushback.

The tiers are available through the Claude Platform, Google Cloud Vertex AI and Microsoft Foundry. On Amazon Bedrock, only customers eligible for Enterprise Frontier Safeguards get in.

Some offers on this page may be paid placements or contain affiliate links.

Subscribe to Techpresso

Free daily newsletter, read in 5 minutes.

Subscribe free