Artificial intelligence is rapidly becoming a powerful tool for cybersecurity.
Security teams are using AI to analyze vulnerabilities, investigate incidents, reverse engineer malware, identify attack paths, review code, and accelerate security testing.
At the same time, these capabilities are inherently dual use.
The same AI system that can help a defender identify a vulnerability can potentially help an attacker understand how to exploit it.
Anthropic has responded to this challenge by expanding its Cyber Verification Program, bringing together its previous Cyber Verification Program and Project Glasswing into a single framework with three levels of access for qualified cybersecurity professionals. The program provides controlled access to advanced models including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and future models, with different verification requirements and security controls depending on the intended use.
The development represents an important shift in how organizations may need to think about AI security.
The question is no longer simply whether an organization should use AI for cybersecurity.
The more important question is:
Who should be allowed to use advanced cyber AI, what should they be allowed to do, and what controls should exist around that access?
Why Controlled AI Access Matters
Cybersecurity AI presents a unique security challenge.
A conventional business application might expose sensitive information if compromised.
A highly capable cybersecurity AI system can potentially provide assistance with vulnerability discovery, malware analysis, penetration testing, reverse engineering, and complex security research.
This creates a difficult balance.
Security professionals need sufficiently capable tools to defend modern environments, but organizations also need safeguards that prevent those capabilities from being misused.
Anthropic’s expanded program attempts to address this through tiered access.
Instead of applying exactly the same restrictions to every cybersecurity use case, access is aligned with the organization’s role and the sensitivity of the work.
Three Levels of Cybersecurity AI Access
The new framework divides access into three primary levels:
1. Defense Access
Defense Access is intended for defensive cybersecurity activities.
Examples include:
• Security operations center activities
• Incident response
• Malware reverse engineering
• Vulnerability analysis
• Vulnerability validation
• Security research
• Defensive security operations
Eligible organizations can include companies defending their own environments, government bodies, universities, critical infrastructure operators, smaller security firms, open source maintainers, and qualifying security researchers.
This tier demonstrates that AI can become a valuable extension of security operations.
Security analysts could potentially use advanced AI capabilities to investigate threats faster, understand malware behavior, analyze vulnerabilities, and prioritize remediation.
2. Red Team Access
Red Team Access provides additional capabilities for authorized offensive security testing.
This is intended for organizations conducting legitimate penetration testing and red team activities against systems they are authorized to assess.
The distinction between authorized testing and unauthorized activity is critical.
Organizations conducting red team exercises must have clearly defined:
• Scope
• Authorization
• Testing windows
• Target systems
• Rules of engagement
• Data handling procedures
• Incident escalation processes
Anthropic states that certain actions capable of causing physical harm or mass disruption remain blocked even within the more permissive tiers.
This highlights an important principle for AI enabled offensive security:
Greater capability must be accompanied by greater accountability.
3. Specialized Access
Specialized Access is reserved for a limited group of verified organizations that need to test safety critical systems.
Examples include:
• Power grids
• Flight systems
• Telecommunications infrastructure
• Interbank transfer infrastructure
• Government administrative networks
Because these environments can affect public safety, essential services, or financial stability, the access requirements are substantially more demanding. Anthropic says organizations in this tier undergo deeper review, including collaboration with the US government.
This is particularly relevant for critical infrastructure operators.
AI security testing in a banking application is different from testing a power grid or aviation system.
The potential consequences of an error are significantly higher.
AI Is Already Demonstrating Significant Security Value
The expansion of the program follows earlier work under Project Glasswing.
According to Anthropic, participating organizations identified at least 129,000 verified software vulnerabilities between April and July 2026 using Claude Mythos models.
Anthropic also reported identifying another 5,500 verified vulnerabilities through its own open source scanning efforts between April and October 2026.
More than 33,000 of the reported vulnerabilities were classified as critical or high severity. Anthropic also cautions that these figures represent only a subset of the overall activity and may underestimate the broader impact.
These figures illustrate the potential impact of AI assisted vulnerability research.
AI can significantly increase the speed at which security teams analyze large codebases and identify potential weaknesses.
However, automated discovery should not automatically mean automated remediation.
Human validation remains essential.
AI Does Not Replace Security Expertise
One of the biggest misconceptions surrounding AI security is that advanced models can eliminate the need for experienced cybersecurity professionals.
That is not the case.
AI can accelerate repetitive and analytical tasks, but security decisions often require business context, technical judgment, regulatory understanding, and knowledge of the environment being protected.
For example, an AI system may identify a vulnerability.
A security professional still needs to determine:
• Whether the vulnerability is actually exploitable
• What systems are affected
• What data could be exposed
• What business processes depend on the affected system
• Whether exploitation could affect safety
• How remediation should be prioritized
• Whether regulatory reporting obligations apply
AI should therefore be viewed as a force multiplier for security teams rather than a replacement for them.
Identity Security Becomes Critical
One of the most interesting aspects of Anthropic’s program is the emphasis on strong identity controls.
The program’s security requirements include named security contacts, user attribution, incident reporting, ongoing review, and restrictions on shared access.
For Defense Access, Anthropic requires stronger authentication measures over time, including phishing resistant MFA such as FIDO2 or WebAuthn security keys, passkeys, or smartcards. Long lived static credentials are also being restricted in favor of short lived credentials and platform managed identity mechanisms.
These controls reflect a broader cybersecurity principle:
The more powerful the system, the stronger the identity controls should be.
This principle should apply beyond AI platforms.
Organizations should use strong identity security for:
• AI systems
• Cloud infrastructure
• Security tools
• CI/CD platforms
• Privileged accounts
• API access
• Administrative interfaces
• Critical applications
Short Lived Credentials Reduce AI Risk
Long lived API keys create significant security risks.
If a static credential is exposed, an attacker may be able to continue using it until the organization discovers and revokes it.
Short lived credentials reduce that exposure window.
Anthropic’s requirements increasingly favor credentials issued through native identity systems rather than permanent API keys. The program also requires additional credential management controls for higher access tiers.
Organizations adopting AI security tools should consider similar principles:
• Short lived credentials
• Workload identity
• Secrets management
• Automatic credential rotation
• Strong access logging
• Rapid revocation
• Least privilege permissions
AI Security Requires Network Controls Too
Identity is only one layer.
AI systems capable of performing security operations may interact with external infrastructure, APIs, cloud systems, repositories, and testing environments.
This creates another potential attack surface.
Higher CVP access tiers include requirements around controlled network egress, logging, managed devices, credential systems, and incident procedures.
Organizations deploying their own security agents should consider:
• Network allowlists
• Controlled outbound connections
• Isolated testing environments
• Sandboxing
• Network monitoring
• API gateways
• Activity logging
• Secure development environments
An AI agent should not automatically have unrestricted access to the internet or enterprise infrastructure.
AI Red Teaming Needs Strong Governance
AI assisted penetration testing can significantly increase testing speed and coverage.
However, organizations must establish governance before deploying autonomous or semi autonomous security agents.
A mature AI red team program should define:
Authorization
Every target should be explicitly authorized.
Scope
Testing boundaries should be documented before an engagement begins.
Human Oversight
High impact actions should require appropriate human review.
Logging
AI prompts, tool calls, actions, findings, and remediation activities should be auditable.
Data Protection
Sensitive customer and enterprise information should be handled according to security and regulatory requirements.
Incident Response
Organizations should have procedures for unintended activity or AI agent misuse.
These principles become particularly important when AI systems can interact directly with live infrastructure.
Critical Infrastructure Needs Additional Protection
The Specialized Access tier highlights a broader challenge.
AI enabled cybersecurity tools will increasingly be used to assess critical infrastructure.
This creates enormous defensive potential.
Security teams can use AI to analyze:
• Industrial networks
• Power infrastructure
• Telecom systems
• Transportation environments
• Government systems
• Financial infrastructure
But AI security testing must account for operational consequences.
Testing a production system that supports essential services requires considerably more planning than testing a conventional development environment.
Critical infrastructure organizations should therefore combine AI security capabilities with:
• OT security assessments
• Network segmentation
• Asset discovery
• Vulnerability management
• Incident response
• Business continuity planning
• Disaster recovery
• Human approval controls
• Safety procedures
Compliance and AI Security Are Becoming Connected
AI security programs also need to address compliance.
Organizations operating in regulated industries must understand how AI systems process, retain, access, and transmit information.
Key questions include:
• What data does the AI system process?
• Where is that information stored?
• Who can access AI outputs?
• Are prompts retained?
• Are security logs maintained?
• Are sensitive datasets exposed to third parties?
• How are incidents investigated?
• How are AI activities audited?
• Are regulatory requirements being met?
Anthropic’s program itself includes requirements around incident reporting, security contacts, user attribution, monitoring, credential management, and ongoing review.
This demonstrates that AI access governance is becoming an important component of cybersecurity governance.
Industries That Can Benefit From Secure Cyber AI
Financial Services and Banking
Banks and financial institutions can use AI to accelerate vulnerability discovery, security monitoring, incident response, application testing, and threat analysis.
However, because financial systems are highly sensitive, AI access should be carefully controlled.
COE Security can help financial organizations assess AI security architecture, application security, identity controls, APIs, cloud environments, penetration testing programs, and compliance requirements.
Healthcare and Life Sciences
Healthcare organizations can benefit from AI assisted security operations while protecting sensitive patient and clinical information.
COE Security can help evaluate AI applications, cloud environments, identity controls, data governance, vulnerability management, and compliance aligned security programs.
Manufacturing and Industrial Organizations
Manufacturers increasingly depend on connected IT and OT environments.
COE Security can support OT and IT security assessments, penetration testing, vulnerability management, network security, application security, AI security reviews, and incident response readiness.
Government and Public Sector
Government organizations can use AI to support vulnerability research, threat detection, incident response, and security operations.
COE Security can help strengthen AI governance, identity security, cloud security, application security, data protection, vulnerability management, and compliance programs.
Energy and Utilities
Power and utility organizations represent particularly sensitive environments because cyber incidents can potentially affect essential services.
COE Security can help evaluate OT environments, network architecture, AI security controls, vulnerability management, penetration testing, and cyber resilience.
Telecommunications
Telecommunications networks require continuous security monitoring and strong access controls.
COE Security can support network security assessments, penetration testing, identity management, cloud security, vulnerability management, and AI security assessments.
Technology and SaaS Companies
Technology companies can use AI to accelerate application security, vulnerability discovery, secure development, and threat detection.
COE Security can help SaaS organizations secure AI enabled applications, APIs, cloud environments, CI/CD pipelines, software dependencies, and enterprise data.
What Organizations Should Do Now
Organizations adopting advanced AI security capabilities should consider several priorities.
1. Establish AI access governance
Define who can access AI security tools and what activities each user or team is permitted to perform.
2. Implement phishing resistant authentication
Use strong authentication mechanisms such as passkeys, FIDO2, or WebAuthn for privileged AI environments.
3. Apply least privilege
AI systems should receive only the permissions required for their specific security tasks.
4. Use short lived credentials
Avoid unnecessary long lived API keys and use managed identity and credential rotation wherever possible.
5. Control network access
Restrict AI agent outbound communication and isolate sensitive testing environments.
6. Monitor AI activity
Log prompts, tool calls, data access, authentication events, network activity, and security actions.
7. Maintain human oversight
High impact security decisions and actions should have appropriate human validation.
class=”isSelectedEnd”>8. Test the AI system itself
Organizations should conduct AI security assessments covering prompt injection, excessive agency, data exposure, insecure integrations, model behavior, and unauthorized tool use.
9. Align AI security with compliance
AI governance should be integrated with privacy, security, regulatory, and risk management programs.
The Bigger Lesson
Anthropic’s expanded Cyber Verification Program represents an important step toward a more structured approach to AI powered cybersecurity.
The three tier model recognizes that not every organization has the same mission, technical environment, or risk profile.
A security operations team investigating malware does not require exactly the same AI access as a red team conducting an authorized penetration test.
A company testing a web application does not face the same consequences as an organization assessing a power grid or flight system.
Access should therefore reflect risk.
This principle can be applied to enterprise AI more broadly.
Organizations should classify AI systems based on:
• Capability
• Data access
• User privileges
• Tool access
• Autonomy
• Business impact
• Regulatory requirements
• Potential physical consequences
The higher the potential impact, the stronger the controls should be.
Conclusion
Anthropic’s three tier Cyber Verification Program demonstrates how the cybersecurity industry is beginning to address one of the most difficult challenges created by advanced AI.
Powerful AI can help defenders discover vulnerabilities faster, analyze threats, investigate incidents, and improve security testing.
But those same capabilities can create significant risks if access is not properly controlled.
The answer is not to prevent security professionals from using advanced AI.
The answer is to build controlled, accountable, and risk based access to cyber AI.
Strong identity security, phishing resistant authentication, short lived credentials, network controls, activity monitoring, human oversight, secure testing environments, and clear authorization processes will become increasingly important as AI systems gain more autonomy.
For organizations, AI security should therefore be treated as part of the broader cybersecurity architecture rather than as a separate technology initiative.
The organizations that establish strong AI governance today will be better prepared to take advantage of advanced security capabilities while reducing the risks associated with increasingly powerful and autonomous AI systems.
About COE Security
COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.
Our offerings include:
• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services
• Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption.
In addition, COE Security helps organizations securely adopt and assess advanced AI security capabilities through AI security assessments, AI red teaming, AI application security testing, prompt injection testing, model validation, secure AI architecture reviews, identity and access management assessments, cloud security assessments, vulnerability management, penetration testing, threat monitoring, and compliance readiness programs.
For financial services and banking organizations, COE Security helps assess AI enabled applications, digital banking platforms, APIs, cloud environments, identity systems, vulnerability management programs, and security controls protecting sensitive financial information.
For healthcare and life sciences organizations, we help protect sensitive information and AI enabled systems through data governance, AI security assessments, application security testing, cloud security reviews, vulnerability management, penetration testing, and compliance aligned cybersecurity programs.
For manufacturing and industrial organizations, COE Security helps strengthen IT and OT security through AI security assessments, network security reviews, penetration testing, vulnerability assessments, secure architecture reviews, incident response readiness, and cyber resilience programs.
For government and public sector organizations, we help strengthen AI governance, identity controls, cloud security, application security, data protection, vulnerability management, threat detection, and compliance programs.
For energy and utility organizations, COE Security supports OT and industrial cybersecurity assessments, network security, vulnerability management, penetration testing, AI security reviews, incident response planning, and critical infrastructure protection.
For telecommunications organizations, we help assess network infrastructure, cloud environments, APIs, identity systems, application security, vulnerability management, and AI enabled security platforms.
For technology and SaaS companies, COE Security helps secure AI applications, APIs, cloud environments, CI/CD pipelines, software dependencies, identity systems, data flows, and enterprise AI integrations.
COE Security also helps organizations establish stronger governance around AI agents and advanced cybersecurity tools by evaluating access controls, authorization models, human oversight, secure integrations, data protection, logging, monitoring, and incident response procedures.
Our goal is to help organizations adopt powerful AI capabilities responsibly, identify security gaps, reduce cyber risk, protect sensitive information, strengthen cyber resilience, and maintain compliance as AI becomes increasingly integrated into enterprise and critical infrastructure environments.
Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption and to stay updated and cyber safe.
Click to read our LinkedIn feature article