Robots Atlas>ROBOTS ATLAS
Safety

Cyber Verification Program (CVP)

2026ActivePublished: 24 September 2026Updated: 24 September 2026Published
Key innovation
Moves the decision about whether a dual-use task is permissible from the level of an individual prompt to the level of a vetted organization — it does not change the model, only who is allowed to ask.
Category
Safety
Abstraction level
System
Operation level
DeploymentServing
Use cases
Exploitation analysis by defensive teamsAdversarial simulationOrganizational threat modellingPenetration testing with frontier modelsVulnerability discovery within legitimate security work

How it works

An organization seeking access submits an application and goes through a vetting process run by Anthropic. Once approved, it receives structured access to advanced Claude models in which the default restrictions on high-risk dual-use activity are lifted: vulnerability discovery, penetration testing and threat modelling. The lifting is not total — prohibited-use categories remain unavailable, so the program widens the scope of legitimate work rather than suspending the usage policy. CVP access is also documented on the cloud partner side; Claude models served through Google Cloud have separate documentation covering the program.

Problem solved

A model's safeguards cannot tell the difference between a security analyst studying a vulnerability and someone preparing an attack — the prompt looks the same. Blocking such tasks by default guards against misuse but cuts defenders off from the tool. CVP resolves this by moving the assessment of intent to the level of the organization and its vetting, instead of guessing it from the content of the query.

Components

Application and organizational vettingAccess gate

Access is not automatic — an organization applies and is vetted by Anthropic.

Reduced restrictions for dual-useThe substance of the entitlement

Approved organizations do not hit the default blocks on vulnerability discovery, penetration testing and threat modelling.

Retained prohibited categoriesThe program's limit

Outright prohibited uses remain blocked regardless of participation in the program.

Implementation

Implementation pitfalls
The program does not suspend the usage policyHigh

Participation widens the scope of legitimate work but does not grant free rein — prohibited categories still apply.

Fix:Before deployment, establish with the team which tasks fall within the program's scope and which remain outside it.
The entitlement is organizational, not personalLow

It is the organization that is vetted; the expanded access does not follow an individual specialist who changes employer.

Fix:Plan access as a company resource and account for it in security team onboarding.

Evolution

2026
The program is live and admitting organizations
Inflection point

From mid-2026 successive security companies publicly announce acceptance into the CVP; the announcements appear between June and August 2026.