Genie Generate a free company AI assistant Try it
← Back to Blog

Anthropic expands Cyber Verification: three tiers and retained controls

Anthropic expands Cyber Verification: three tiers and retained controls

Key Takeaways

  • The expanded program offers Defense, Red Team and Specialized Access.
  • Authorization and usage policies remain applicable after enrollment.
  • Check tier-specific provisioning and data requirements before sensitive use.
BLOOMIE
POWERED BY NEROVA

Produced by Bloomie for Nerova AI using automated editorial checks. Sources used for factual claims are listed below.

Anthropic expanded its Cyber Verification Program on October 6, 2026, introducing three tiers for qualified security work. The change grants vetted users access to more capable cyber workflows with different controls. It does not remove authorization requirements or generally permit unrestricted offensive activity. The announcement defines the tier structure.

Choose the tier that matches authorized work

Defense Access covers defensive security activity. Red Team Access adds authorized adversarial testing, while Specialized Access is reserved for a limited set of verified organizations testing high-risk systems. The launch describes different verification and review requirements for each level, including restrictions intended to prevent physical harm or mass disruption.

The practical boundary is the work being performed, not simply the user’s job title. A security employee may be permitted to analyze an owned system but lack authorization to test a supplier’s production environment. Preserve the approved scope with the task so the agent cannot infer permission from a broad organizational credential.

Account provisioning is part of the rollout

The program help page explains application and grant provisioning. It says the usage policy continues to apply, that grants can be narrowed or withdrawn, and that building client-facing products is governed separately.

For an enterprise deployment, separate enrollment from access assignment. An approved organization still needs administrators to determine which people and workspaces receive the capability. Test the experience of a user without the grant and the process for revoking access when someone changes roles. Avoid treating a program approval as a credential that everyone can reuse.

Data requirements need review before sensitive use

The announcement describes retention for misuse monitoring and a future Enterprise Frontier Safeguards option. Existing arrangements and tier-specific requirements need to be checked in the current program terms. A future privacy feature should not be assumed available merely because it is announced.

Security investigations can contain credentials, private source code and information about unpatched systems. Decide which material is necessary for the task and confirm the permitted handling before submitting it. Record the model and access tier used in an investigation so later reviewers can interpret blocked or allowed actions.

The October expansion matters because it offers a more differentiated path for legitimate security teams. Its value will depend on whether the approved capabilities fit the workflow and whether the organization can maintain the required account, authorization and data controls.

Nerova context

Custom AI agents for business operations

Nerova builds custom AI agents for business operations. Companies use Nerova when they need AI support for customer intake, support, sales follow-up, research, website audits, internal handoffs, and workflow automation.

Nerova can help turn websites, business context, and operational workflows into practical AI systems: website chatbots, single-purpose agents, AI teams, audits, and automation workflows built around a clear business outcome.

Ask Bloomie about this article