FTFuture Technology
SECURITY

Anthropic Expands Cyber Verification Programme

· 3 min read · By Nath Connell

Key takeaways

  • Anthropic is expanding its Cyber Verification Programme, giving more security researchers access to Claude for testing
  • The programme allows structured external security testing instead of keeping vulnerability research internal
  • This approach is relatively rare among AI labs and reflects Anthropic's philosophy of collaborative security research

Anthropic announced an expansion of its Cyber Verification Programme, which is designed to give security researchers, cybersecurity professionals, and approved organisations structured access to Claude and other Anthropic models for security testing and verification purposes. This is a genuine attempt to make AI model security less of a black box and more of a collaborative problem.

The core idea is straightforward but represents a different approach than most AI labs take. Instead of keeping models locked down and only releasing them through careful public releases, Anthropic is saying to the security community: come test these, find the flaws, help us understand the risks, and we'll work together to fix them. That's the responsible disclosure model, but for AI systems instead of software vulnerabilities.

Cybersecurity in the AI era is a genuine unsolved problem. These models can be used to help generate phishing campaigns, craft malware, automate attacks, or otherwise amplify malicious capability. They can also be used to detect those things and build better defences. Anthropic's position is that understanding both sides of that equation is important, and that cybersecurity professionals should have access to the models to do that work.

The verification programme initially worked on an application basis: security teams could apply for access, Anthropic would evaluate them, and if approved, they'd get to work with Claude in a structured environment. The expansion probably means more automatic approval processes, more streamlined onboarding, maybe access to more researchers, or broader availability for specific use cases.

What's interesting about this is how it reflects genuine technical differences between Anthropic and other AI labs. OpenAI, Google, Meta, they all have security testing happening, but mostly internally or through limited bug bounty programmes. Anthropic is saying: we want external experts involved because your security understanding is probably better than ours in specific domains, and we want to learn from you.

There are obvious risks to opening up model access for security testing. Someone could abuse it. Someone could use approved access to do unapproved things. The models could be used in ways Anthropic doesn't want them to be used. But Anthropic's position is that those risks are worth taking because the alternative, security through obscurity, doesn't actually work and leaves vulnerabilities undiscovered.

The future, in 3 minutes a day. The biggest tech story explained every morning, free. Get the briefing →

From a governance perspective, this matters. If Anthropic is doing this voluntarily and proactively, it means there's less pressure for regulators to mandate it. If other labs see that Anthropic is getting credit for security transparency and collaborative testing, they might follow. That could set a norm where AI companies actually work with the security community instead of against it.

The practical impact is probably biggest for security teams at large enterprises and government agencies. Those organisations have people whose job is to understand threats and build defences. Giving them access to Claude means they can test whether Claude could help an attacker, whether Claude has specific vulnerabilities, whether Claude's safety measures can be bypassed. That knowledge is actually valuable for defence building.

There's also a research angle. Academic cybersecurity researchers can study how large language models behave in adversarial conditions, what kinds of jailbreaks work, how to make models more robust. That research feeds back into better model training, better safety measures, better understanding of risks.

One thing to note: this is Anthropic, not all AI labs. OpenAI hasn't announced anything similar. Google's approach to security testing is murkier. Meta probably isn't doing this. So this is a specific choice by a specific company to approach security differently. It's notable, but it doesn't mean the entire industry is moving this direction.

The expansion of the programme probably also signals that Anthropic thinks it's working. If it was generating security reports, good insights, and genuine improvements, then expanding it makes sense. If it was mostly noise and time consumption, they probably wouldn't expand it.

Longer term, what's interesting is whether this becomes the default way AI companies handle security testing, or whether it remains a differentiator for Anthropic. Right now it's a rare enough approach that it's actually distinctive. As more companies do more AI security testing, the differentiation probably fades. But for now, it's a meaningful difference in how Anthropic operates compared to other labs.

Get the briefing, free

The biggest tech story, explained in 3 minutes every weekday. Choose your briefings →

Free. No spam. Unsubscribe in one click.