Anthropic PBC is expanding access to its most advanced artificial intelligence (AI) models, allowing a select group of organisations to test the startup’s cutting-edge cyber capabilities in collaboration with the US government.
The San Francisco-based company will grant verified organisations access to its most capable models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models moving forward, according to a statement on Oct 6.
Those with access can carry out "high risk offensive testing” of the safety systems designed to protect critical infrastructure like power grids, banks and flight operating systems, it said.
Anthropic granted US government agencies, financial institutions, and major software providers limited access to its Mythos model in April under Project Glasswing. The Mythos release was a watershed moment for cybersecurity because of the model’s ability to partially automate the work of sophisticated hackers.
Since then, a spate of incidents in which Anthropic and OpenAI’s models inadvertently hacked governments, companies and non-profit organisations has raised concerns about the safety of the technology.
Anthropic said on Oct 6 the latest limited release will include every member of Project Glasswing and require a review of all new organisations in partnership with the US government. In August, Washington said it would partner with private-sector firms to launch cyber attacks abroad, expanding the scope of national security operations that until now have been largely conducted by government agencies.
On Oct 6, JPMorgan Chase & Co chief executive officer Jamie Dimon told Bloomberg Television that Mythos had boosted global cybersecurity risks "10-fold.”
Different types of cybersecurity teams will be allowed to apply for lower levels of access. Red teams, which conduct authorised hacking of targets in order to find and fix weaknesses, will have more permissions to security test AI models, including for offensive testing, but Anthropic said it will still block behaviour that can cause physical harm and mass disruption.
Verified defence cybersecurity teams will have a slightly lower level of access, but it will allow tasks such as reverse engineering malware and incident response. – Bloomberg
