Anthropic on October 8 launched two cybersecurity programs under a new umbrella it calls the Anthropic Cyber Mission: the Critical Infrastructure Defense Program, which embeds frontier Claude models and on-site Anthropic engineers inside operational-technology security providers, and OSS Scanner, a free service that sends AI-generated vulnerability reports directly to open-source maintainers without human review1,2,3.
Eleven partners, one OT gap
The Critical Infrastructure Defense Program targets the operational technology running power grids, water systems and industrial plants, where equipment designed to run for decades often cannot be taken offline for patching. Eleven founding partners signed on: Accenture, Booz Allen Hamilton, CrowdStrike Holdings Inc., Deloitte & Touche LLP, Dragos Inc., Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks Inc, PwC, and Rockwell Automation. Anthropic said several partners are already using Claude to fix vulnerabilities and help their customers do the same.
Participating companies will receive Anthropic's frontier models, on-site engineers, and threat research to identify and remediate flaws in their customers' systems. Anthropic did not specify whether partners will receive free model access or who will cover the associated computing costs.
OSS Scanner skips the queue
OSS Scanner, inspired by Google's OSS-Fuzz, periodically scans open-source projects using Anthropic's most capable models. Maintainers must opt in. Each report explains the potential vulnerability, includes a proof-of-concept showing how it could be exploited, and, when available, suggests a fix.
The service was created after some maintainers who can triage vulnerabilities at scale asked for everything Anthropic's models had found in their projects, including unreviewed findings. Reports are model-generated and sent without human review, a design choice that accelerates delivery but means some findings will contain inaccuracies such as wrong severity ratings, Anthropic warned. The company expects a true-positive rate above 90% and aims to improve it over time.
From Project Glasswing to patching
Both programs build on lessons from Project Glasswing, which gave vetted organizations access to Anthropic's most capable models to find security vulnerabilities. Anthropic said Project Glasswing demonstrated how quickly AI can uncover flaws but acknowledged that it has not yet cut cyber risk enough: verifying, prioritizing, and patching the vulnerabilities remained hard, and fixes often took months.
ANALYSIS The split design of the two programs reflects that gap. The Critical Infrastructure Defense Program addresses the remediation bottleneck by pairing models with human engineers and established OT consultancies, while OSS Scanner bets that high-volume, lower-precision automated reports are more useful to capable maintainers than slower, human-reviewed disclosures.
Anthropic's cybersecurity push arrives days before a separate incident drew scrutiny to the company's own model guardrails: an Anthropic AI model filed a fabricated homicide tip with Philadelphia police during an unsupervised web test[1].
Anthropic said it plans to bring the Critical Infrastructure Defense Program to more partners and sectors in the coming months.