Anthropic unveiled the Anthropic Cyber Mission on 8 October 2026, a long-term commitment to backing defenders, with two initiatives starting now: the Critical Infrastructure Defense Program (CIDP), which brings frontier models, engineers deployed on site and threat research to the providers trusted by operators of power grids, water utilities and transport networks; and OSS Scanner, an opt-in, free service that periodically scans open-source projects with the company's most capable models. Anthropic expects that scanner to be right more than 90 % of the time, and its reports go out with no prior human review.
What was announced
The critical infrastructure programme starts with eleven founding partners. They include consultancies and large integrators — Accenture, Booz Allen, Deloitte, PwC — industrial equipment makers such as Rockwell Automation and Hitachi, and firms specialising in industrial and corporate network security: CrowdStrike, Dragos, Insane Cyber, Nozomi Networks and Palo Alto Networks. Anthropic explains that it is not approaching operators directly, but rather that ring of providers who already tell them what is exposed and what can safely be touched on a running plant.
The reasoning rests on a trait of so-called operational technology: controllers, control software and industrial networks designed to last decades, which often cannot be taken down for patching. Hence a known flaw can sit unresolved for years. The company says several partners are already working with Claude on fixing vulnerabilities, and that it is starting with a small group to find out which approaches genuinely work. Anyone building security products or services for critical infrastructure can register interest on the programme page.
The second front is open source. OSS Scanner — inspired, Anthropic says, by Google's OSS-Fuzz — offers periodic analysis to projects that sign up. Each alert arrives with an explanation of the problem, a demonstration of how it could be abused and, where one exists, a proposed fix. The important caveat: the reports are generated by the model and go out directly, with nobody checking them first. They arrive sooner, yes, but there will be mistakes — a misassigned severity, for instance. That is why the service is aimed at projects able to digest that volume; for everyone else, Anthropic says it will keep sending human-verified disclosures under its coordinated disclosure policy.
Funding is a separate matter. Anthropic says it has financially supported the Python Software Foundation, the Apache Software Foundation and both Alpha-Omega and OpenSSF through the Linux Foundation, as well as Akrites and Gold Eagle, two efforts that aggregate and coordinate vulnerability reports so maintainers are not swamped. The Defender Advantage Fund, announced in August, underwrites the pilots and keeps the scanner free. Maintainers can also apply for free Claude Max subscriptions and for expanded access through the Cyber Verification Program.
Where it comes from
The Cyber Mission is the direct heir of Project Glasswing, the programme under which Anthropic scanned hundreds of widely used open-source projects and reported findings privately to their maintainers. The company states the outcome plainly: plenty of vulnerabilities were found, but actual risk did not fall far enough. Finding is cheap; verifying, prioritising and fixing remain slow. Under Glasswing, it says, months commonly passed between a finding and a patch.
Glasswing has been folded this week into the expanded Cyber Verification Program, which this blog covered when it was announced and which gives more security teams access to the models with fewer blocking classifiers. And back in June Anthropic had started a cyber defence programme for state, local, tribal and territorial government in the United States: it claims to have since reached most of the country's states and some of its largest public infrastructure operators, speeding up work such as code scanning, incident response and red teaming.
It also acknowledges the underlying reason: frontier models can be turned to exploiting vulnerabilities, and attackers already have that capability to hand. Defensive tooling, by contrast, has not reached enough people.
What it means
For anyone maintaining software, the concrete point is this: if you run a widely used open-source project, there is now a channel through which automated vulnerability reports written by a model, proof of concept included, may start arriving. Signing up is voluntary, and it is best treated as a capacity decision rather than a curiosity: a steady stream of unfiltered findings needs someone to triage it. Anthropic says as much when it recommends the service only to those who can keep pace.
The second consequence concerns timing. The company forecasts that in two years AI will favour the defence — catching bugs before shipping, writing secure code from the outset, defending systems with models — but warns this may not hold in the near term, because the cost of exploiting a flaw has fallen while verifying, disclosing and fixing still depends on people. In operational technology that gap is extreme: a patch may have to wait for a safe window on running machinery, and Anthropic goes as far as mentioning rare cases where the wait is measured in decades.
And a third, less visible: the CIDP is not sold to operators but to their providers. Anyone working in integration, industrial auditing or equipment manufacturing has a direct route in; anyone running a plant will see it arrive via their usual supplier.
What the announcement does not say
There are no financial figures for the CIDP: not how much Anthropic is putting in, nor how many engineers it is deploying, nor for how long. Nor is it spelled out what "engineers on site" means exactly, or who pays for them. How many projects OSS Scanner will take, the entry criteria and the scan frequency are left equally open.
The 90 % accuracy is the company's own forecast, not a measured and published result: Anthropic speaks of an expectation and of improving it over time. The eleven partner statements accompanying the announcement are, by definition, claims from companies taking part in the programme. And the coverage figure for US administrations since June comes with no verifiable list either.
Missing, too, is the piece Glasswing showed to be the bottleneck: who does the fixing. The announcement describes an intention to automate triage and patching "for projects that want it", but with no timeline or scope. Meanwhile, finding speeds up and fixing stays where it was.
Anthropic published the initiative in its official announcement and says it will extend the programme to more partners and sectors over the coming months, sharing what fails along with what works.
