Full Report
Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional
Analysis Summary
# Industry News: Anthropic Launches "Cyber Verification Program" to Weaponize AI for Defense
## Summary
Anthropic has announced the expansion of its specialized cybersecurity testing initiative into a formal "Cyber Verification Program" (CVP), providing vetted security professionals with access to advanced AI models like Claude 5.5 with reduced safety guardrails. The move follows the success of Project Glasswing, which identified over 129,000 software vulnerabilities in just four months, signaling a major shift in how AI is utilized for large-scale vulnerability management.
## Key Details
- **Date:** October 2026
- **Companies Involved:** Anthropic (Primary), VulnCheck, Veracode (Secondary/Contextual)
- **Category:** Product Update / Specialized Service Launch
## The Story
Building on the momentum of "Project Glasswing," Anthropic is formalizing how cybersecurity teams interact with its most capable models. The new Cyber Verification Program (CVP) offers three distinct tiers—**Defense Access**, **Red Team Access**, and **Specialized Access**—each progressively removing the "refusals" and safety filters that usually prevent AI from engaging in sensitive security tasks.
The data justifying this expansion is significant: between April and July 2026, the program identified 129,000 verified vulnerabilities, with over 33,000 rated as high or critical severity. Anthropic believes the actual impact could be five times higher due to underreporting from partners. To ensure these tools aid defenders more than attackers, Anthropic is using a tiered vetting process, allowing tasks like malware reverse engineering and automated penetration testing that are typically blocked for standard commercial users.
## Business Impact
### For the Companies Involved
- **Anthropic:** Positions itself as the leading "safety-conscious" AI provider for the federal and enterprise security sectors. By creating a controlled environment for high-risk use cases, they capture market share that competitors may avoid due to liability concerns.
### For Competitors
- **OpenAI & Google:** Will face pressure to offer similar "unfiltered" access to specialized researchers. Anthropic’s success in finding 129,000 flaws sets a high benchmark for the efficacy of AI in automated security auditing.
### For Customers
- **Enterprise Security Teams:** Gain access to a powerful force multiplier for vulnerability discovery and patch analysis. However, they must balance this with reports that 44% of AI-generated code still introduces new security risks.
### For the Market
- **Vulnerability Research:** The sheer volume of AI-discovered flaws (129k in one quarter) threatens to overwhelm existing manual triage processes. The market may see a shift from "discovery" tools to "triage and remediation" tools to handle the surge.
## Technical Implications
The CVP proves that removing safeguards significantly increases utility for specialized tasks. Evaluations showed that while standard models blocked nearly all security tasks, the **Red Team Access** tier completed 34 of 50 complex tasks—matching the performance of a model with no safeguards at all. This demonstrates that "Safety Overlays" are currently a primary bottleneck for technical AI performance.
## Strategic Analysis
- **Market Positioning:** Anthropic is moving from a general-purpose LLM provider to a critical infrastructure security partner.
- **Competitive Advantage:** "Early Mover" advantage in providing sanctioned, "jailbroken-by-design" models for government and high-security enterprise use.
- **Challenges:** The "False Positive" and "Insecure Code" problem. As noted by Veracode, AI-generated patches often fail, meaning Anthropic’s tool could potentially create as many problems as it solves if not paired with human oversight.
## Industry Reactions
- **VulnCheck:** Noted that while discovery is high, actual exploitation remains low (only 0.67% of discovered flaws have been exploited), suggesting AI might be finding "theoretical" rather than "practical" risks.
- **Veracode/1Password:** Cautioned that AI-generated code still has a "security pass rate" of only ~56%, emphasizing the need for expert human review.
## Future Outlook
- **Predictions:** Expect a surge in "AI-Native" bug bounty programs where researchers use these CVP tiers to automate the discovery of low-hanging fruit at an unprecedented scale.
- **What to watch for:** Whether the influx of thousands of new CVEs leads to "vulnerability fatigue" among IT departments, potentially causing them to miss the critical 0.67% that actually get exploited.
## For Security Professionals
Practitioners should view this as a double-edged sword. While these tools will radically accelerate malware analysis and defensive posture auditing, the "noise" created by 129,000+ discovered vulnerabilities will require new automated triage workflows. Security leaders should begin vetting their own AI-generated code with the same rigor (or more) as human-written code.