Alex - stock.adobe.com
Anthropic opens cyber program applications, releases cheaper Haiku
Under the program, the vendor provides enterprises with models that can defend against bad actors.
Anthropic’s move to expand its cyber verification program and release Claude Haiku 5.5 as a cost-efficient, speedy model shows how the vendor aims not only to be known as a frontier model provider that prioritizes security but also to be accessible to enterprises seeking lower-cost options.
The Claude creator’s decision comes amid an AI market in which frontier model providers face challenges competing against Chinese open source vendors that offer capable models that include cyber capabilities at a lower cost.
“China is open sourcing … some of the most powerful models in the world that are roughly just as capable at cybersecurity and threat detection and analysis as the OpenAI and Anthropic models are,” said Carter Huffman, CEO and co-founder at Modulate, a voice AI vendor.
The Chinese open-weight models leave the U.S. open-weight market weaker than China’s because there isn’t, currently, a comparable U.S. open model. At the same time, the Chinese vendors are pressuring providers of proprietary AI models, such as Anthropic, to make their models more accessible to enterprises.
Cyber verification program
This tension is evident in Anthropic’s decision to expand its cyber verification program on Oct. 6. Anthropic originally introduced the CVP in April alongside Project Glasswing and Claude Mythos.
The expanded CVP provides qualifying security professionals with access to cyber capabilities, reduces the number of blocking classifiers, and offers three access tiers. Each tier provides access to powerful Anthropic models, such as Claude Mythos 5.1 (Anthropic’s previously restricted cyber model under Project Glasswing), the powerful but pricey Claude Opus 5.5 and the fast and more cost-efficient Claude Sonnet 5.5.
While Anthropic limited the release of Mythos to keep it out of the hands of cyber attackers, cybersecurity experts say bad actors’ attack capabilities are continually improving.
“We know that the cyber attackers are especially getting more sophisticated, so [enterprises] could use more sophisticated tools themselves,” said Chirag Shah, a professor at the University of Washington Information School.
Moreover, Chinese vendor Z.ai’s open-weight models, GLM-5.2 and GLM-5.3, are viewed as direct competitors to Mythos. Therefore, with more bad actors having access to open-weight models, such as those from Z.ai, they are more likely to be dangerous than the small number of people with access to Mythos, Huffman said.
“Having 10,000 people using the second-best model is way more effective than having 100 people using the best model,” he said. “The only way for people to make their systems robust and defended and secure is for them to have access to technology that can discover these vulnerabilities and help them fix them.”
Being safe, and challenges
Anthropic is trying to be more accessible and also practicing safety by releasing its models to select enterprises, Shah said.
“It’s a way to reduce the potential misuse of this,” he said. He added that Anthropic and its enterprise customers will have to trust each other for the expanded CVP to work.
Anthropic specified that applicants must demonstrate they have the required security controls. The vendor has to trust that participating enterprises have sufficient security controls to prevent the models from being leaked to hackers. Enterprises also need to trust that Anthropic’s cyber program is strong enough to protect them from attacks.
Anthropic is not the only generative AI vendor creating trusted security programs. OpenAI’s Daybreak and Google’s Fairwind programs also provide powerful frontier models to reliable cyber defenders.
While making the models more accessible means more enterprises can defend themselves with the most advanced AI cyber tools, the cost of these programs remains a factor, said Dennis Xu, an analyst at Gartner.
“From a cyber capability, these are obviously not cheap. They are expensive. You pay extra for better defense, better offensive testing,” he said, adding that while open-weight models offer effective cyber capabilities, they still fall behind those of Anthropic’s and OpenAI’s models.
He added that an option for enterprises is to explore other cyber defense programs. For example, CrowdStrike and Nvidia partnered to create SafeMind, an agentic cybersecurity model suite built on top of Nvidia Nemotron models.
Anthropic’s CVP is free, but accepted users must pay standard token consumption-based pricing.
Claude Haiku 5.5
One model whose pricing at Anthropic has reduced significantly is Claude Haiku 5.5. Released on Wednesday, the model is best for speed-sensitive tasks such as browser use and customer support, Anthropic said. Haiku costs $0.10 per input token up to 100,000 tokens and $0.50 per input token over 100,000 tokens; $0.50 per output token up to 100,000 tokens and $2.50 per output token over 100,000 tokens. Comparatively, GPT-6 Luna from OpenAI costs $0.10 per million input tokens and $0.50 per million output tokens.
Esther Shittu is a TechTarget news writer and podcast producer and host covering AI systems.