AI companies face a strange problem in cybersecurity:
A tool that can find a security vulnerability to help you fix it could also help someone else exploit that same vulnerability.
That’s why advanced AI capabilities in security can’t be treated in the same way as ordinary desktop software.
This idea is called dual use.
The same technical capability can have both a legitimate and a harmful use. The outcome depends not only on the tool, but also on who uses it and for what purpose.
This is clearly illustrated by Anthropic’s decision to expand its cyber verification program, which gives qualified security teams access to its most capable models with fewer restrictions on some cybersecurity tasks.
Why are there restrictions in the first place?
Advanced models can now read and analyze huge volumes of code and find bugs that would be difficult for a person to spot quickly.
That’s extremely useful for a team looking to protect its systems.
But the problem is that some tasks used to test systems are similar in nature to tasks an attacker might carry out.
That’s why companies put safeguards in place to prevent models from carrying out certain dangerous requests.
The problem is that these safeguards can’t always accurately determine a user’s intent.
A security researcher might ask to analyze a real vulnerability in a system they’re authorized to test, but the system may block the request because it looks similar to an attack.
Here’s the challenge:
How do you stop attackers from using the same capability without stopping defenders?
The solution: not all users are equal
Instead of easing restrictions for everyone, Anthropic is moving toward a different model:
The more sensitive the capability, the stricter the requirements for accessing it.
The new program offers different levels of access depending on the type of security work and the level of verification.
Teams working on incident response and malware analysis can receive one level of access, while testing more sensitive systems is subject to stricter controls and verification.
The specialized tier, which can be used on systems such as power grids, aviation, telecommunications, and financial infrastructure, is reserved for a limited number of vetted organizations. Anthropic says it thoroughly reviews these organizations in coordination with the U.S. government.
The idea is similar to how permissions are granted within companies.
Not every employee needs access to every file.
An accountant gets the permissions they need to do their job, a systems administrator gets broader access, and the most sensitive systems remain restricted to a small number of people.
Do more powerful capabilities make a real difference?
According to Anthropic, the Glasswing project showed why giving defenders broader capabilities can be useful.
Between April and July 2026, the company said program partners discovered at least 129,000 confirmed software vulnerabilities, in addition to 5,500 vulnerabilities found through the company’s open-source scanning efforts by October.
Of the combined total, more than 33,000 have so far been classified as high or critical severity. Anthropic says these figures may be far lower than the true impact because the data came from only some of the partners.
These figures highlight an important aspect of the cybersecurity economy:
Automation can reduce the cost of finding a problem.
Instead of waiting for an expert to read millions of lines of code by hand, AI can scan far more code, allowing people to focus on verification and remediation.
But why not make these capabilities available to everyone?
Because lowering the cost of finding vulnerabilities cuts both ways.
If it becomes faster and cheaper for defenders to find a security issue, it could become faster and cheaper for attackers, too.
That creates an unusual race:
Who will find the vulnerability first?
The company that can fix it, or the party looking to exploit it?
That’s why the challenge with AI isn’t just building a more powerful model, but deciding who gets access to that power and under what conditions.
From product safety to access management
This could be one of the major shifts in how AI is governed in the future.
Instead of a simple model where capabilities are either available or blocked, we may see systems that take into account a user’s identity, the type of organization, the intended use, and the level of oversight.
In other words, the safety question won’t just be:
What can the model do?
It will also be:
Who do we allow to do it?
That’s where AI safety moves beyond simply building restrictions into the model and becomes a broader matter of managing trust, permissions, and risk.
Comments (5)
No comments yet. Be the first to comment!