On October 6, 2026, two announcements took opposite positions on the same question.
Anthropic: capability by verified tier
Anthropic says its generally available models "have conservative cyber safeguards that block most cyber work." Its expanded Cyber Verification Program now has three tiers, each with access to Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1:
- Defense Access for SOC and incident-response work, "reverse-engineering malware," and validating vulnerabilities -- open to company, university and government security teams, critical-infrastructure operators "such as regional hospitals or municipal utilities," open-source maintainers, and individual researchers with a disclosure record. Anthropic aims to answer within days.
- Red Team Access adds authorised penetration testing, organisations only, with a review of a few weeks; real-time blocks remain on things like deploying ransomware.
- Specialized Access, with the fewest blocks, for organisations authorised to test systems like power grids and interbank transfers, vetted "in collaboration with the US government." Project Glasswing members move here.
Enrolment requires data retention so Anthropic can monitor misuse. Its own test on CyScenarioBench: without the program, every task was blocked on the first prompt; in Defense Access, 46 of 50 runs were blocked at some point; in Red Team Access none were, and Opus 5.5 completed 34 of 50. Anthropic also reports Glasswing partners found at least 129,000 verified vulnerabilities between April and July; SiliconANGLE notes that figure comes from only 33 partner reports.
Mistral: capability by self-deployment
Mistral's launch post for Mistral Large 4 says that on an Artificial Analysis Cyber Index test asking a model to reproduce and then patch a real open-source vulnerability, ML4 scores 82%, while "Several leading closed models, including Claude Opus 5.5 and GPT-6 Astra, score near zero on the same test because they refuse to perform the task." Its argument is that "provider-level refusals can block legitimate vulnerability research and incident response," and that open weights let organisations "run advanced security work under their own policies." Weights are due by the end of October.
Why this is a trend, not a spat. Both companies accept that cyber capability is now strong enough to be dangerous. They disagree on where the control sits: with the provider, through identity verification, monitoring and per-tier classifiers; or with the deployer, through owning the weights. Anthropic's own description of its default models confirms the mechanism Mistral is selling against.
Opinion (analysis): for most enterprise security teams, the practical question is less philosophical. The tiered route brings frontier capability, but also data retention and an application process. The open-weight route brings control, but also the job of keeping a capable offensive tool away from the wrong insiders and attackers -- with no classifier behind it. Expect regulators to ask which of the two a critical-infrastructure operator chose, and why.
On October 6 Anthropic widened access to its cyber capabilities through three verified, monitored tiers while Mistral marketed Large 4's coming open weights on closed models' cyber refusals -- two opposite answers to whether the provider or the deployer should control dual-use security capability.