Reduced cyber safeguards need an authorization record, not just applicant vetting
Anthropic is expanding verified access to models with fewer safeguards for defensive security work. The important control is the full authorization lifecycle: admission, scope, logging, escalation and revalidation.

What happened
Anthropic introduced three Cyber Verification Program tiers—Defense, Red Team and Specialized—with different eligibility, verification and safeguard conditions. Reuters reported that the expansion follows large-scale defensive vulnerability work with partners.
Why it matters
Identity checks can establish who asks for access, but not whether each action remains inside an approved purpose. Organisations need evidence that access, tools, data and escalation rights remain aligned throughout the work.
Anthropic announced an expanded Cyber Verification Program on 6 October. It describes three routes. Defense is for organisations and professionals conducting legitimate defensive work. Red Team is for authorised testing of systems an applicant owns or has permission to assess. Specialized is intended for a narrower set of highly capable actors whose work may require substantially reduced safeguards. Eligibility, identity and organisational checks vary by tier.
Reuters reported that the change opens more capable configurations to additional security teams. The report says Anthropic and partners identified about 129,000 verified vulnerabilities from April through July, while the company found about 5,500 vulnerabilities in its own scans from April through October, including roughly 33,000 rated critical or high across the partner work. Anthropic cautioned that partner reporting was incomplete and estimated the true count might be at least five times higher. Those are operational counts, not a controlled estimate of model effectiveness or prevented harm.
Treat a tier as a work authorization
Admission is only the first control. For every approved project, preserve the sponsor, legal authority, target systems, allowed techniques, model configuration, connected tools, data classes, time window and named escalation owner. A verified person can still act outside scope; a legitimate project can also change after approval.
Use short-lived credentials and bind them to the approved environment. Log prompts, tool calls, target identifiers, model and policy versions, human approvals, outputs and external side effects. Separate research that produces hypotheses from actions that touch live systems. Require a second person for exploit execution, credential use, persistence or changes to production.
The program also describes data-retention requirements and future enforcement tooling. Those mechanisms matter, but retention alone is not oversight. Logs must support reconstruction: what authority existed at the time, which safeguard was relaxed, why it was necessary, what the model attempted and how a human resolved ambiguous outcomes.
Procurement should test this evidence path before granting live access. Give a candidate team a bounded scenario with an authorised target, a tempting out-of-scope asset and a change in ownership midway through the exercise. Check whether the system blocks the wrong target, whether the operator notices the boundary, whether the log preserves the attempted step and whether revocation reaches every connected tool. Repeat the exercise with incomplete target metadata and with an urgent defensive request. A pass means the organisation can reconstruct and govern the decision, not merely that the model refused once.
Track both defensive value and control cost. Useful measures include verified findings per reviewer hour, false-positive investigation time, time to suspend access, unresolved scope exceptions and the share of high-impact actions with two-person approval. Raw vulnerability counts can reward volume and differ with target mix; they should not become a performance quota.
Revalidate when the work changes
Set automatic expiry by project and tier. Re-run eligibility when personnel, ownership, targets, jurisdiction, model capability or tool access changes. Suspension should be possible without deleting evidence, and reinstatement should require a documented reason rather than a silent toggle.
The strongest counterargument is that these controls slow defenders while attackers ignore them. Speed is a real constraint, especially during an incident. Pre-approved emergency playbooks can preserve pace: define target classes, allowed actions, maximum duration and post-action review in advance. The answer to urgency is a bounded fast lane, not an unrecorded exception.
Anthropic's program creates a useful access taxonomy, but buyers and security leaders should evaluate the evidence around each authorization. The decision is not simply whether an applicant belongs in Defense, Red Team or Specialized. It is whether the organisation can prove that reduced safeguards remained necessary, proportionate and inside mandate for the entire engagement.