Most AI security coverage focuses on what attackers can do with frontier models. Anthropic’s new effort, announced October 8, 2026, works the other side of the board. The Anthropic Cyber Mission is a long-term program to put models, engineers, and research in the hands of defenders, starting with two areas where the gap between attacker speed and defender capacity is widest: operational technology (OT) and open-source software.
Why these two targets
Anthropic’s argument is about resource asymmetry, not novelty. Power grids, water systems, and transport networks run on controllers and industrial software built to last decades. That equipment often can’t be taken offline to patch, so known vulnerabilities can sit unresolved for years. On the open-source side, almost all software depends on code maintained by small volunteer teams with no security budget.
There’s also a hard-won lesson baked in. Under the earlier Project Glasswing effort, partners uncovered many vulnerabilities, but Anthropic states they haven’t achieved a sufficient reduction in cyber risk — finding bugs got easy; verifying, prioritizing, and fixing them stayed hard. That diagnosis shapes both new programs.
The Critical Infrastructure Defense Program
The Critical Infrastructure Defense Program doesn’t sell directly to utilities. It routes frontier Claude models, on-site engineers, and threat research through the trusted providers operators already rely on — consulting firms, security vendors, and equipment manufacturers. Founding partners include Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation.
The distribution choice matters for anyone building in this space. Anthropic explicitly says it wants to work through companies, coalitions, governments, and nonprofits that operators trust, rather than becoming another vendor in the stack. Several partners are already working with Claude to fix vulnerabilities, and the first phase is a small cohort meant to learn which strategies actually work in environments where a mistake can take down a plant.
This builds on a government-facing program launched in June, which has offered frontier models and technical support to more than half of US states and several large public infrastructure operators. If you’ve been tracking how Anthropic structures tiered access for security work, this connects directly to the expanded Cyber Verification Program and its three access tiers, which Project Glasswing was merged into just before this announcement.
OSS Scanner: fast reports, honest tradeoffs
The open-source side is more immediately actionable for most developers. During Project Glasswing, Anthropic scanned hundreds of widely used projects and privately reported human-reviewed findings. Some maintainers with triage capacity asked for everything, reviewed or not. That request became OSS Scanner, an opt-in service inspired by Google’s OSS-Fuzz. Enrolled projects get periodic scans from Anthropic’s most capable models, free, with each report including a proof of concept, an explanation, and a suggested fix where available.
The caveat is stated plainly: reports are model-generated and sent without human review, so some will contain inaccuracies like wrong severity ratings. Anthropic expects a true-positive rate above 90%. The service targets projects with capacity to keep up; everyone else still gets human-verified disclosures under the coordinated vulnerability disclosure policy.
What this means for your roadmap
Two takeaways for builders. First, if you’re shipping security tooling, free model-driven scanning at this quality level raises the baseline for what maintainers expect — a plain vulnerability list looks thin next to a report with a PoC and a suggested patch. Second, the verification bottleneck Anthropic named applies everywhere, not just OT: finding issues is cheap; triaging them is the cost center. Any agent workflow you design should budget for that stage, not just detection.
The honest limitation: this is a first step, and Anthropic itself says critical infrastructure has problems AI cannot fix. Practical next move — if you maintain an open-source project with triage capacity, enrollment is open, and maintainers can also apply to Claude for Open Source for free Claude Max subscriptions.
