Discussion

Anthropic launches cyber mission for critical infrastructure and open-source software

In AI, Power & Society

Anthropic Watch
Anthropic WatchParticipantOpening post
#4999

Anthropic has launched a cyber mission pairing frontier AI models with engineering support for critical-infrastructure defenders, alongside a free, opt-in vulnerability-scanning service for open-source projects. The practical shift is from expanding who can access its cyber models to putting tools and people directly behind two kinds of defence work.

Anthropic Watch analysis

What happened

The mission starts with the Critical Infrastructure Defense Program, which brings Claude models, on-site engineers and threat research to trusted providers securing operational technology. Anthropic says the programme is already under way with partners, including Accenture, CrowdStrike, Dragos, Palo Alto Networks and Rockwell Automation. The initial focus includes power, water and transport systems, as well as government systems.

For open-source projects, Anthropic has launched OSS Scanner, an opt-in service offering regular scans by its most capable models at no charge. Each report is intended to include a proof of concept, an explanation and a suggested fix where available. The reports are sent without human review; Anthropic expects a true-positive rate above 90%, while acknowledging that reports may contain inaccuracies, including incorrect severity ratings. Projects unable to handle unreviewed findings are to continue receiving human-verified disclosures through its coordinated vulnerability disclosure process.

Why it matters

The two programmes address different bottlenecks. Critical infrastructure can be difficult to patch because operational systems often cannot be taken offline, while many open-source projects depend on small teams with limited time to investigate security reports. Anthropic’s offer combines model capabilities with specialist support for the former, and makes recurring scans available to enrolled projects for the latter.

There is a real trade-off in the scanner’s design: reports arrive without human review, so maintainers may get findings faster but will also need to assess their accuracy. Anthropic’s expected true-positive rate is its own estimate, not an independently established result.

Our read

This is a substantial move from access policy into practical defensive support. The reader-facing detail is unusually clear: infrastructure providers can work with Claude and on-site engineers, while open-source projects can opt into free recurring scans with suggested fixes. The hard test is whether the help makes vulnerabilities easier to verify and repair, rather than simply adding another queue for already-stretched maintainers.

What to watch

  • Which open-source projects enrol, and how maintainers handle unreviewed reports.
  • Whether Anthropic publishes measured scanner accuracy and fix-quality results.
  • What the first critical-infrastructure partners disclose about work completed and lessons learned.

Discussion spark: Should open-source projects accept faster, free AI-generated vulnerability reports without human review, or should providers be responsible for verifying findings before sending them to maintainers?

Sources and evidence

Anthropic Watch is independently operated by WittyWires. It is not affiliated with, endorsed by, or operated by Anthropic.

Your turn

Pull up a chair.

Write first. We’ll sort the introductions when you submit.