Citation and evidence

Anthropic Cyber Verification Program

21 min full readUpdated 37 references

This article's verification

Report a problem with this article

More

Use this article

Raw MarkdownExplore connections

Improve this page

Suggest editRevision historyDiscussion

Browse categories

AI SafetyAI in CybersecurityAnthropic

Cite this article

The Cyber Verification Program (CVP) is an application-based access program run by Anthropic that lets vetted cybersecurity practitioners and organizations use Claude models with some of their real-time cyber safeguards relaxed. Anthropic launched it on April 16, 2026, alongside Claude Opus 4.7, the first model on which Anthropic tested new safeguards that "automatically detect and block requests that indicate prohibited or high-risk cybersecurity uses."[2] The company describes the CVP as "a free application-based program for Opus and Sonnet that is designed to enable professionals to continue working on legitimate dual use tasks safely while minimizing interruption."[1] Approval lifts blocks on what Anthropic calls high-risk dual-use activity, such as exploit development or offensive security tooling. Prohibited uses such as ransomware development stay blocked regardless of CVP status.[1]

The program grew out of Project Glasswing, under which Anthropic gave Claude Mythos Preview to a limited set of partners and said it would test new cyber safeguards on less capable models first.[3][2] As Anthropic's models became more capable at offensive security, the CVP became the route by which defenders could get past the safeguards on each new Opus and Sonnet release. As of September 29, 2026, Anthropic's help center said the program covered Opus- and Sonnet-class models but not Claude Opus 5.5 or Claude Sonnet 5.5, and that Anthropic would "soon be expanding the Cyber Verification Program to include Opus 5.5, Sonnet 5.5, and Mythos class models."[1] With the Opus 5.5 launch on September 22, 2026, the company said the expanded program would have "three tiers for increasingly permissive trusted access, including access to Claude Mythos models."[13]

Overview

PropertyDetails (as of September 29, 2026)
OperatorAnthropic
First announcedApril 7, 2026, as "an upcoming Cyber Verification Program" in the Project Glasswing announcement[3]
LaunchedApril 16, 2026, with Claude Opus 4.7[2]
CostFree[1]
Who appliesOrganizations, through an authorized admin; approval is tied to a specific organization ID[1]
What it relaxesBlocks on "high risk dual use" cyber activity; prohibited uses are never unblocked[1]
Review timeAnthropic aims to email a decision within two business days[1]
Identity checkApplicants must verify their identity; Anthropic uses Persona Identities for identity and business verification[1][20]
Not eligibleOrganizations on Zero Data Retention (ZDR)[1]
Models coveredOpus- and Sonnet-class models, excluding Opus 5.5 and Sonnet 5.5, per Anthropic's help center[1]
Announced expansionOpus 5.5, Sonnet 5.5 and Mythos-class models, in three tiers[1][13][15]
SurfacesAnthropic first-party (Claude.ai, Claude Code, the Anthropic API), Claude Platform on AWS, Claude on Google Cloud, Microsoft Foundry, some third-party platforms; not Amazon Bedrock[1]

Expanded article table

Background

On April 7, 2026, Anthropic announced Project Glasswing, an initiative with launch partners including Amazon Web Services, Apple, Cisco, CrowdStrike, Google, Microsoft and Palo Alto Networks to use Claude Mythos Preview for defensive security work on critical software. Anthropic said it did not plan to make Mythos Preview generally available, and that it would "launch new safeguards with an upcoming Claude Opus model, allowing us to improve and refine them with a model that does not pose the same level of risk as Mythos Preview." A footnote to that sentence said: "Security professionals whose legitimate work is affected by these safeguards will be able to apply to an upcoming Cyber Verification Program."[3]

Claude Opus 4.7 was that model. Its launch post, on April 16, 2026, said Opus 4.7's cyber capabilities "are not as advanced as those of Mythos Preview," that during training Anthropic "experimented with efforts to differentially reduce these capabilities," and that the model shipped with safeguards that detect and block prohibited or high-risk cybersecurity requests. It added: "Security professionals who wish to use Opus 4.7 for legitimate cybersecurity purposes (such as vulnerability research, penetration testing, and red-teaming) are invited to join our new Cyber Verification Program."[2] Help Net Security's launch report repeated the invitation for vulnerability research, penetration testing and red-teaming.[28] Two weeks later, Anthropic's announcement of the Claude Security code-scanning beta noted that organizations whose work might trigger the Opus 4.7 safeguards could join the CVP, "which is part of our effort to make frontier capabilities available to defenders while keeping them out of the wrong hands."[24]

How the cyber safeguards work

Categories of blocked activity

Anthropic's help center sorts blocked cyber activity into two categories:[1]

CategoryAnthropic's definitionExamples givenEffect of CVP approval
Prohibited use"Cybersecurity activities that are almost always used maliciously and have little to no legitimate defensive application"Mass data exfiltration, ransomware code developmentNone; these stay blocked "regardless of CVP status"
High risk dual use"Cybersecurity activities that have legitimate defensive applications"Vulnerability exploitation, offensive security tooling developmentBlocked by default; can be adjusted for approved defensive users

Expanded article table

The Claude Opus 4.8 system card (May 28, 2026) described the same scheme with a third category. It said Anthropic's cyber mitigations "rely on probe-based classifiers" that cover prohibited use (for instance, developing computer worms), high-risk dual use (for instance, developing software exploits) and plain dual use (for instance, software vulnerability detection). The first two are blocked by default; the third is not. Practitioners with appropriate dual-use cases who hit blocks "can apply for exemptions from these safeguards through our Cyber Verification Program."[4] Google Cloud's documentation for the program lists ransomware development, command-and-control infrastructure generation, malware authoring and automated mass data exfiltration as prohibited, and vulnerability discovery, exploitability analysis, proof-of-concept exploit verification, red teaming and adversary attack path simulation as high-risk dual use.[21]

Classifier design by model generation

The safeguards have become stricter as Anthropic's models have gained cyber capability. Opus 4.7, Opus 4.8 and Claude Sonnet 5 share one set of probe-based safeguards; Anthropic said on June 30, 2026 that Sonnet 5's safeguards were "the same as those present in Claude Opus 4.7 and 4.8."[7] Claude Fable 5, released June 9, 2026, introduced much broader classifiers meant to block access to Mythos-level cyber capabilities, and routed flagged cyber requests to Opus 4.8.[6][7][19] Claude Opus 5 (July 24, 2026) used the Fable cyber classifier in two stages, a probe on the model's internal activations and a trained LLM classifier, with "one notable exception": vulnerability finding in source code was unblocked.[9] Anthropic said it expected the Opus 5 classifiers "to intervene around 85% less often than they do for Fable 5."[8]

Claude Opus 5.5 (September 22, 2026) moved to three stages: a probe that screens all traffic, a lightweight classifier running on Opus 5.5 itself, and a separate LLM classifier that decides, together with the probe's verdict, whether to block. The Opus 5.5 system card says the safeguards "enforce the same policy as on Claude Opus 5" but are more robust, and that Anthropic "opted for a temporarily wider safety margin against jailbreaks." Source-code vulnerability discovery is allowed at all access levels; vulnerability discovery in compiled binaries is blocked because "it is more commonly an offensive technique."[14] Claude Sonnet 5.5 (September 28, 2026) uses the same three-stage design and the same policy as Opus 5 and Opus 5.5.[16] The checks review everything the model reads, including memory, connector content, web search results and files, so content a user did not type can trigger them.[17][18]

Fallback models

Since Fable 5, a blocked request on Anthropic's most capable models is usually re-run on an older model rather than refused outright. Fallbacks happen automatically in Anthropic's own apps, with a notice that the model switched; on the API, developers must opt in, and until they do the model returns an HTTP 200 response with a refusal stop reason.[17][18][36]

Model (release date)Cyber safeguardsWhere blocked cyber requests goCVP status, September 29, 2026
Claude Opus 4.7 (Apr 16, 2026)Real-time classifiers blocking prohibited and high-risk requests[2]BlockedCovered since launch[2][1]
Claude Opus 4.8 (May 28, 2026)Probe-based classifiers; prohibited and high-risk dual use blocked by default[4]BlockedCovered[4][1]
Claude Sonnet 5 (Jun 30, 2026)Same safeguards as Opus 4.7 and 4.8[7]BlockedCovered; enrolled organizations got access "with no need to reapply"[7]
Claude Fable 5 (Jun 9, 2026) and Claude Fable 5.1 (Sep 1, 2026)Broad classifiers designed to block Mythos-level offensive capability; Fable 5.1 allows vulnerability discovery but not exploit development[6][10][19]Claude Opus 4.8[6][19]Not among the models the program lists; Anthropic refers blocked users to the CVP "for Opus"[19][1]
Claude Opus 5 (Jul 24, 2026)Two-stage probe and LLM classifier; source-code vulnerability finding allowed[9]Claude Opus 4.8[8][18]Covered; existing members got "immediate access to a version of Opus 5 with fewer security restrictions"[8]
Claude Opus 5.5 (Sep 22, 2026)Three-stage system, same policy as Opus 5[14]Claude Opus 4.8[13][14][18]Not yet available, per Anthropic's help center[1][18]
Claude Sonnet 5.5 (Sep 28, 2026)Three-stage system, same policy as Opus 5 and Opus 5.5[16]Claude Sonnet 5[15][16][17]Not available at launch[17]
Claude Mythos 5 and Claude Mythos 5.1Same weights as Fable 5 and 5.1 with cyber safeguards lifted (Mythos 5) or relaxed (Mythos 5.1) for vetted users[6][10]Not applicableCVP access promised "in the near future"[10][12]

Expanded article table

The Fable 5.1 system card recommended "Claude Opus 5 with access through the Cyber Verification Program today, and Claude Mythos 5.1 in the near future (when the program includes it)" for users whose cybersecurity work could not run on Fable.[11] The Sonnet 5 launch post, in June, had recommended Claude Opus 4.8 "for cybersecurity work that requires reduced guardrails."[7]

What approval changes

CVP approval "only lifts blocks on dual use activities," according to the help center.[1] The Opus 5 system card spelled out two levels of relief: for cyber defenders blocked on Opus 5, CVP exemptions "will remove blocks to enable activities such as bug bounty hunting and vulnerability research and verification," while "Enterprise customers can also apply to join the Cyber Verification Program to have mitigations removed to enable penetration testing."[9] The Opus 5.5 and Sonnet 5.5 system cards report cyber capability results with safeguards off, saying these reflect the capability level that will be available "to certain users via our Cyber Verification Program."[14][16]

Approval does not carry across organizations. Anthropic tells users who still hit blocks to compare the organization ID where they are blocked against the one on their approval email, since approval for a team's organization does not extend to a personal workspace.[1]

Eligibility and application

Anthropic says practitioners whose use case "has a legitimate defensive purpose" and is affected by the safeguards should apply.[1] The application path depends on how the organization reaches Claude:[1]

Access routeHow to apply
Anthropic first-party (Claude.ai, Claude Code, the Anthropic API)Apply through the Verification Portal; only authorized admins see the option
Microsoft FoundrySubmit the Cyber Use Case form with the Azure tenant ID and subscription ID, choosing "Azure" as the surface
Amazon BedrockNot available "at this time"
Claude Platform on AWSApply through the Verification Portal after linking an AWS account to an Anthropic account; admins only
Claude on Google CloudApply through the Verification Portal, link a Google account and configure data retention; admins only
Third-party platforms (coding tools and other apps)Ask the platform whether it participates; "Not all platforms participate in the CVP at this time"
Bring your own key (BYOK) customersSame as Anthropic first-party

Expanded article table

The Verification Portal describes itself as the place to "Apply for and manage trust programs for your Claude usage."[37] The Cyber Use Case form tells applicants who experience "cyber blocks on what you believe to be a legitimate use case under our Usage Policy" to apply for "safeguards adjustment under our Cyber Verification Program," and repeats that ZDR organizations are not currently eligible.[22] Companies that build products on Claude can ask whether their platform can participate through a separate Platform CVP Interest Form.[1]

Applicants must verify their identity.[1] Anthropic's identity-verification article says it uses Persona Identities as its verification partner; individuals need a physical government-issued photo ID and may be asked for a live selfie, and organizations also supply their legal name, address and business registration number.[20]

Anthropic says it aims to send a decision by email within two business days. It also acknowledges that it expects "to occasionally decline eligible applications incorrectly, and approved users may still experience blocks on legitimate work." A combined form handles both false-positive block reports and appeals of rejected applications.[1]

Data retention and monitoring

Organizations on Zero Data Retention agreements cannot currently join; Anthropic directs Sales-managed ZDR customers to their sales representative.[1] On Google Cloud, joining requires an administrator to accept Google's Advanced AI Safety Addendum for each project and to set per-model data settings. Google's documentation says prompts and responses sent to CVP-enabled models "are retained for abuse monitoring for up to 30 days," and that for Opus 5 and Opus 5.5 Anthropic also requires data sharing to be enabled for abuse monitoring.[21] Anthropic's help center gives a similar split: an "Advanced AI" setting for Sonnet 5, Opus 4.7 and Opus 4.8, and data sharing with Anthropic for Opus 5, without mentioning Opus 5.5.[1]

Mythos-class access has had stricter terms. When Anthropic launched Fable 5 and Mythos 5 in June 2026, it said it would "require 30-day retention for all traffic on Mythos-class models, on both first- and third-party surfaces," with the data used only for safety purposes.[6] Anthropic's Mythos page says that using Claude Mythos 5.1 "requires accepting a 30-day data retention policy for safety monitoring by default."[12]

Road to Mythos-class access and tiers

Anthropic has tied the CVP to its plan for broader release of Mythos-class models since the program began. The timeline below lists the company's statements.

DateEvent
April 7, 2026Project Glasswing announcement says professionals affected by forthcoming safeguards "will be able to apply to an upcoming Cyber Verification Program"[3]
April 16, 2026CVP launches with Claude Opus 4.7[2]
May 28, 2026Opus 4.8 system card describes CVP exemptions from its probe-based classifiers[4]
June 2, 2026"Expanding Project Glasswing" says Anthropic intends "to scale up our Cyber Verification Program, which would grant Mythos-class capabilities to many more organizations for specific cyberdefense tasks"[5]
June 9, 2026Fable 5 and Mythos 5 launch; Anthropic says it is "pursuing a trusted access program that allows cybersecurity organizations to apply in a more systematic manner" for Mythos 5[6]
June 12 to 30, 2026A US government export-control directive forces Anthropic to suspend Fable 5 and Mythos 5 for all users; after the controls are lifted, Mythos 5 access is restored "for a set of US organizations"[25][26]
June 30, 2026Sonnet 5 joins the CVP on the native Claude Platform, Claude Platform on AWS and Claude in Microsoft Foundry, with Google Vertex "coming soon"[7]
July 24, 2026Opus 5 launches; existing CVP members get immediate access to a less restricted version[8]
September 1, 2026Fable 5.1 and Mythos 5.1 launch; the CVP "will also include access to Claude Mythos-class models" "in the near future"[10]
September 17, 2026Anthropic opens its separate Life Sciences Verification Program to applications[27]
September 22, 2026Opus 5.5 launches; Anthropic says the expanded CVP will have three tiers, including Mythos access[13]
September 28, 2026Sonnet 5.5 launches; cyberdefenders will "soon" be able to apply for "tiered access to more advanced capabilities on Sonnet 5.5, Opus 5.5, and Claude Mythos models"[15]

Expanded article table

The Opus 5.5 launch post phrased the timing two ways: "In the coming weeks we will also be expanding access to our Cyber Verification Program, and verified cybersecurity practitioners will be able to use Opus 5.5 for their work," and later, "we'll soon be expanding our Cyber Verification Program to include Opus 5.5."[13] The Sonnet 5.5 system card called it "our forthcoming updated Cyber Verification Program" and said Sonnet 5.5 would join "in the near future."[16] As of September 29, 2026, Anthropic's launch posts, system cards and help-center articles did not say what each of the three tiers would unlock or who would qualify for each.

The public documentation did not line up exactly at the end of September. As of September 29, Anthropic's help center said that its cyber safeguards article "doesn't apply to Claude Opus 5.5 or Sonnet 5.5" and that "Opus 5.5 isn't currently available in the Cyber Verification Program."[1][18] Google Cloud's CVP page, last updated September 28, 2026, listed Claude Opus 5.5 among the models the program supports on its Agent Platform, alongside Opus 4.7, Opus 4.8, Sonnet 5 and Opus 5, with the program marked as a preview feature.[21]

Mythos 5.1 itself was, at launch, "only available to a set of US organizations," with Anthropic saying it was coordinating with the US government to widen access. Its launch page asked cyberdefenders to register interest in Mythos 5.1 access "through the CVP."[10]

  • Project Glasswing gave Mythos Preview, and later Mythos 5, to selected partners for defensive work; Anthropic's Transparency Hub presents it as support for the CVP, saying "Cybersecurity professionals can apply through our Cyber Verification Program to seek access for legitimate use cases on select models."[23][6]
  • Life Sciences Verification Program (LSVP) is the biology counterpart, opened to applications on September 17, 2026. Its grants relax biology safeguards only; "All other safeguards, such as cyber classifiers, will remain in place under LSVP grants."[27]
  • Claude Security, Anthropic's codebase-scanning product, entered public beta for Claude Enterprise customers on April 30, 2026 and was powered by Mythos 5.1 from September 2026. The Opus 5.5 post noted that "Claude Security is already available with access to Claude Mythos 5.1," before Mythos access through the CVP.[24][10][13]

Participants

Anthropic has not published a list of CVP members. Several security vendors announced that they had joined. Cycode said on June 18, 2026 that it had gained "verified access to the full dual-use capabilities of Claude" for work such as confirming whether a vulnerability is exploitable; its co-founder and CTO Ronen Slavin said the program "gives us verified access to those capabilities for defensive work."[30] Mitiga's John Vecchi wrote on July 9, 2026 that the company had joined, calling the program "a background check for defenders," and named the data-security company MIND as another participant.[31]

Reception and criticism

Early complaints came from independent security researchers. On April 17, 2026, the day after Opus 4.7's release, a bug bounty hunter filed a GitHub issue against Claude Code saying the new filter blocked drafting, analysis and proof-of-concept work on in-scope targets even with the program's authorization language in the model's context. The error message he quoted ended: "To request an adjustment pursuant to our Cyber Verification Program based on how you use Claude, fill out [form link]." He wrote that "The de facto requirements appear to favor researchers with a public CVE, conference talk, or established public track record," shutting out earlier-career researchers, and asked Anthropic to accept payout history on platforms such as HackerOne, Immunefi and Bugcrowd as evidence. He closed the issue on April 29, writing: "I got added to the cyber program after submitting my application twice."[34]

Trade coverage focused on what enrollment meant for automated tools. A May 2026 TechTimes article on Keygraph's open-source Shannon Lite penetration tester, which had moved to Opus 4.7, said users running legitimate scans "must now enroll in Anthropic's Cyber Verification Program to avoid automated refusals mid-scan," and pointed out that approval is tied to one organization ID and that ZDR organizations are excluded.[29]

Enrollment did not help with every model. The New Stack reported on September 28, 2026 that the day after Fable 5 launched, a Claude Code user doing defensive threat-intelligence work said on GitHub that 2,746 of 3,427 main-session messages that day had been generated by Opus 4.8 after fallbacks, and that this user's organization was already enrolled in the CVP.[33] Other users have filed reports of false positives that are unrelated to their request text. One August 2026 report said that in an authorized defensive security project, a Korean greeting triggered the cyber safeguard and downgraded Opus 5 to Opus 4.8; the user believed the classifier was reacting to the project's context files rather than the message.[35] Anthropic has warned that Sonnet 5.5 users "should expect increased refusals with Sonnet 5.5, even on benign cybersecurity-related tasks."[16]

Coverage of Opus 5.5 also questioned how much outsiders could check. Mixed noted that Anthropic said most cybersecurity tasks would be re-routed to Opus 4.8, and that "nobody outside it has tested which requests get handed over."[32]

References

  1. ^1 ^2 ^3 ^4 ^5 ^6 ^7 ^8 ^9 ^10 ^11 ^12 ^13 ^14 ^15 ^16 ^17 ^18 ^19 ^20 ^21 ^22 ^23 ^24 ^25 ^26 ^27Anthropic. "Real-time cyber safeguards on Claude Opus and Sonnet." Claude Help Center. Accessed September 29, 2026. support.claude.com/...ds-on-claude-opus-and-sonnet
  2. ^1 ^2 ^3 ^4 ^5 ^6 ^7Anthropic. "Introducing Claude Opus 4.7." April 16, 2026. anthropic.com/...claude-opus-4-7
  3. ^1 ^2 ^3 ^4Anthropic. "Project Glasswing: Securing critical software for the AI era." April 7, 2026. anthropic.com/glasswing
  4. ^1 ^2 ^3 ^4Anthropic. "System Card: Claude Opus 4.8." May 28, 2026. www-cdn.anthropic.com/...b5ee635c80fef830a37ea.pdf
  5. ^Anthropic. "Expanding Project Glasswing." June 2, 2026. anthropic.com/...expanding-project-glasswing
  6. ^1 ^2 ^3 ^4 ^5 ^6 ^7Anthropic. "Claude Fable 5 and Claude Mythos 5." June 9, 2026. anthropic.com/...claude-fable-5-mythos-5
  7. ^1 ^2 ^3 ^4 ^5 ^6Anthropic. "Introducing Claude Sonnet 5." June 30, 2026. anthropic.com/...claude-sonnet-5
  8. ^1 ^2 ^3 ^4Anthropic. "Introducing Claude Opus 5." July 24, 2026. anthropic.com/...claude-opus-5
  9. ^1 ^2 ^3Anthropic. "System Card: Claude Opus 5." July 24, 2026. www-cdn.anthropic.com/...s%205%20System%20Card.pdf
  10. ^1 ^2 ^3 ^4 ^5 ^6Anthropic. "Introducing Claude Fable 5.1 and Claude Mythos 5.1." September 2026. anthropic.com/claude-fable-and-mythos-5-1
  11. ^Anthropic. "System Card: Claude Fable 5.1 and Claude Mythos 5.1." September 1, 2026. www-cdn.anthropic.com/...205.1%20System%20Card.pdf
  12. ^1 ^2Anthropic. "Claude Mythos." Accessed September 29, 2026. anthropic.com/...mythos
  13. ^1 ^2 ^3 ^4 ^5 ^6Anthropic. "Introducing Claude Opus 5.5." September 22, 2026. anthropic.com/claude-opus-5-5
  14. ^1 ^2 ^3 ^4Anthropic. "System Card: Claude Opus 5.5." September 22, 2026. anthropic.com/claude-opus-5-5-system-card
  15. ^1 ^2 ^3Anthropic. "Introducing Claude Sonnet 5.5." September 28, 2026. anthropic.com/claude-sonnet-5-5
  16. ^1 ^2 ^3 ^4 ^5 ^6Anthropic. "System Card: Claude Sonnet 5.5." September 28, 2026. anthropic.com/claude-sonnet-5-5-system-card
  17. ^1 ^2 ^3 ^4Anthropic. "Why Claude switched models in your conversation with Sonnet 5.5." Claude Help Center. Accessed September 29, 2026. support.claude.com/...conversation-with-sonnet-5-5
  18. ^1 ^2 ^3 ^4 ^5 ^6Anthropic. "Why Claude switched models in your conversation with Opus 5 or Opus 5.5." Claude Help Center. Accessed September 29, 2026. support.claude.com/...tion-with-opus-5-or-opus-5-5
  19. ^1 ^2 ^3 ^4Anthropic. "Why Claude switched models in your conversation with Fable 5 or Fable 5.1." Claude Help Center. Accessed September 29, 2026. support.claude.com/...on-with-fable-5-or-fable-5-1
  20. ^1 ^2Anthropic. "Identity verification on Claude." Claude Help Center. Accessed September 29, 2026. support.claude.com/...ntity-verification-on-claude
  21. ^1 ^2 ^3Google Cloud. "Cyber Verification Program for Claude." Gemini Enterprise Agent Platform documentation. Last updated September 28, 2026. docs.cloud.google.com/...cyber-verification-program
  22. ^Anthropic. "Cyber Use Case." Claude by Anthropic. Accessed September 29, 2026. claude.com/...cyber-use-case
  23. ^Anthropic. "Anthropic's Transparency Hub: Voluntary commitments." Accessed September 29, 2026. anthropic.com/...voluntary-commitments
  24. ^1 ^2Anthropic. "Claude Security is now in public beta." Claude blog, April 30, 2026. claude.com/...claude-security-public-beta
  25. ^Anthropic. "Statement on the US government directive to suspend access to Fable 5 and Mythos 5." June 12, 2026. anthropic.com/...fable-mythos-access
  26. ^Anthropic. "Redeploying Fable 5." June 30, 2026. anthropic.com/...redeploying-fable-5
  27. ^1 ^2Anthropic. "Introducing the Life Sciences Verification Program." September 17, 2026. anthropic.com/...life-sciences-verification-program
  28. ^Markovic, Sinisa. "Anthropic releases Claude Opus 4.7 with automated cybersecurity safeguards." Help Net Security, April 16, 2026. helpnetsecurity.com/...claude-opus-4-7-released
  29. ^Belmonte, Kyle. "Shannon Lite v1.2.0 on Claude Opus 4.7: Anthropic's New Cyber Safeguards Require Pentesters to Enroll Before Scans." TechTimes, May 18, 2026. techtimes.com/...eguards-require-pentesters-enroll
  30. ^Cycode. "Cycode Joins Anthropic's Cyber Verification Program." Cycode blog, June 18, 2026. cycode.com/...nthropics-cyber-verification-program
  31. ^Vecchi, John. "We Joined Anthropic's Cyber Verification Program. Here's Why It Matters in the Post-Mythos Era." Mitiga blog, July 9, 2026. mitiga.io/...-anthropic-cyber-verification-program
  32. ^Zelich, Michael. "Claude Opus 5.5 sends most cybersecurity work to Opus 4.8 instead of doing it." Mixed, September 22, 2026. mixed-news.com/...rity-reroute-opus-4-8-safeguards
  33. ^Caswell, Amanda. "You picked Claude Sonnet 5.5, but Anthropic may send your request to Sonnet 5 in 'higher-risk' situations." The New Stack, September 28, 2026. thenewstack.io/claude-sonnet-cyber-safeguards
  34. ^John-Lussier. "Opus 4.6/4.7 refuses to do any cybersecurity research." GitHub issue #50162, anthropics/claude-code, April 17, 2026. github.com/...50162
  35. ^0blueteam0. "[Bug] Anthropic API [cyber] safeguard false positives on non-malicious messages in security project context." GitHub issue #88108, anthropics/claude-code, August 20, 2026. github.com/...88108
  36. ^Anthropic. "Refusals and fallback." Claude Platform documentation. Accessed September 29, 2026. platform.claude.com/...refusals-and-fallback
  37. ^Anthropic. "Verification Portal." Accessed September 29, 2026. portal.anthropic.com/...cvp

Improve this article

Add missing citations, update stale details, or suggest a clearer explanation. Every suggestion is reviewed for sourcing before it goes live.

1 revision · v2 · 4,113 words · full history

Fact-checks are independent of edits: a reviewer re-verifies the article against its sources and stamps the date. How we verify

Research and drafting on this wiki are AI-assisted, under named human editorial standards. How AI is used here

Reviewer note: xg12 V5 independent verification 29 Sep 2026: ~195 claims across 62 sources, ~70 quotes verbatim; 0 material, 3 minor fixed.

Cite this page: AI Wiki. "Anthropic Cyber Verification Program." aiwiki.ai, updated 29 Sept 2026, fact-checked 29 Sept 2026. CC BY 4.0. https://aiwiki.ai/wiki/anthropic_cyber_verification_program

Suggest edit