Frontier models now refuse or interrupt a lot of legitimate offensive-technique work by default — that's the correct default for the public internet. The Cyber Verification Program is Anthropic's pathway for the teams whose day job legitimately looks like an attack: it's a free, application-based program where Anthropic reviews the organization, and approved defenders get access to Claude's dual-use cyber capabilities with adjusted safeguards, scoped to defensive work — exploitability analysis, adversarial simulation, threat modeling, detection testing, security-control validation. Categories with no defensive reading (mass-exfiltration tooling, ransomware development) stay blocked for everyone, verified or not.
The context that makes this matter: in November 2025 Anthropic disclosed the first largely AI-orchestrated cyber-espionage campaign — an agent executing 80–90% of operations at machine speed. Agents are now on both sides of the line. The CVP exists so the defensive side isn't studying that reality with one hand tied.