Anthropic on October 8 launched the Anthropic Cyber Mission, a long-term effort to help defend power grids, water systems, transportation networks, government systems and open-source software. The announcement matters because highly capable AI models can help defenders find vulnerabilities, but similar capabilities are also available to attackers.
The initiative begins with two programs. The Critical Infrastructure Defense Program will provide frontier Claude models, on-site engineering support and threat research to companies that protect operational technology, including industrial control systems and networks. Anthropic identified Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation as founding partners.
Operational technology often runs critical facilities for decades and can be difficult to take offline for security updates. Anthropic said several partners are already working with Claude to fix vulnerabilities and help customers do the same. The company is beginning with a small cohort of providers and plans to expand the program to more partners and sectors.
Free scanning for open-source projects
Anthropic also introduced OSS Scanner, an opt-in service that gives enrolled open-source projects periodic security scans from its most capable models at no charge. Each report can include a proof of concept, an explanation of the vulnerability and a suggested fix when one is available. Anthropic cautions that the reports are model-generated without human review and can contain inaccuracies, including incorrect severity ratings.
The scanner builds on Anthropic’s earlier cyber-security work. In its October 6 update to the Cyber Verification Program, the company said its own open-source scanning efforts found an additional 5,500 verified software vulnerabilities between April and October 2026.
Why the announcement matters
Anthropic’s move places an AI developer more directly inside the security operations of infrastructure providers and software maintainers. The company says defenders still face shortages of staff, time and safe maintenance windows, while verifying, prioritizing and fixing vulnerabilities remains slower than finding them.
The approach also carries limits. AI can help identify and explain weaknesses, but operators remain responsible for validating fixes in environments where an incorrect change could interrupt electricity, water, transportation or manufacturing. Anthropic said the initial program will help determine which uses are practical and reliable before broader deployment.
How organizations can participate
- Critical-infrastructure security providers can register interest in the Critical Infrastructure Defense Program through Anthropic’s announcement.
- Maintainers of important open-source projects can apply to enroll in OSS Scanner.
- Security teams can apply to the expanded Cyber Verification Program for access to Anthropic’s cyber-focused models and capabilities.
Anthropic’s announcement reflects a broader shift in which frontier AI developers are using their models for cyber defense as well as capability testing. Its success will depend on whether infrastructure operators and software maintainers can verify, prioritize and safely fix the weaknesses that AI discovers.
References
- Anthropic. (2026, October 8). Introducing the Anthropic Cyber Mission. https://www.anthropic.com/news/anthropic-cyber-mission
- Anthropic. (2026, October 6). Expanding the Cyber Verification Program. https://www.anthropic.com/news/cyber-verification-program
- Axios. (2026, October 8). Exclusive: Anthropic’s new plan to protect critical infrastructure. https://www.axios.com/2026/10/08/anthropic-critical-infrastructure-cybersecurity
