Anthropic has launched the Anthropic Cyber Mission, a long-term program focused initially on critical infrastructure and open-source software. The effort combines frontier models, engineers, threat research, partnerships and funding to help defenders find and repair vulnerabilities before attackers exploit them.
Two initiatives begin the program: a Critical Infrastructure Defense Program for operational technology and a free OSS Scanner for open-source maintainers. Anthropic says the approach reflects lessons from Project Glasswing, where models found many vulnerabilities but verification, prioritisation and remediation remained difficult.
Critical infrastructure needs specialised defence
Power grids, water systems, factories and transport networks often run equipment designed to remain in service for decades. These operational technology environments cannot always be paused for patching, and an incorrect change can interrupt an essential service. Security therefore depends on deep knowledge of particular systems and safe maintenance windows.
The new program will bring Claude, on-site engineers and threat intelligence to trusted service providers and equipment companies. Founding partners include Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.
Partnerships aim to put models in context
Anthropic is not presenting a model as a replacement for operational technology specialists. The participating organisations understand industrial networks, customer environments and the consequences of a failed remediation. Claude can increase the rate of analysis, while experts decide whether a finding is genuine and how a fix can be applied safely.
The initial cohort will help identify which methods are effective in practice. That learning phase is essential because a vulnerability report that ignores physical processes, safety certification or equipment availability may be technically correct but operationally unusable.
OSS Scanner offers recurring model analysis
Open-source projects can opt into periodic scans by Anthropic’s strongest models at no charge. Each report includes an explanation, a proof of concept showing how a bug could be exploited and a suggested fix when available. Reports are sent without human review so maintainers receive them sooner.
Anthropic expects a true-positive rate above 90 per cent, which also means maintainers must prepare for inaccurate severity ratings or false findings. The service is intended for projects with enough capacity to triage incoming reports. Other projects can continue receiving human-verified disclosures through coordinated vulnerability processes.
Discovery is not the same as reduced risk
Project Glasswing demonstrated that AI can surface vulnerabilities quickly, but a backlog of findings does not secure software. Each issue must be reproduced, assessed, disclosed, patched, tested and released. Maintainers may lack time, release infrastructure or authority over downstream installations.
The Cyber Mission therefore plans to automate more triage and patching while researching safer architectures and coding practices. Success should be measured by verified fixes reaching users and reducing exposure, not only by the number of potential bugs generated by a scanner.
Disclosure needs to avoid overwhelming maintainers
High-volume automated reports can burden small teams and create security risk if exploit details arrive without a workable remediation path. Opt-in enrolment, project capacity checks and private reporting are sensible starting controls. Maintainers should also be able to tune scope, pause scans and provide feedback on repeated errors.
Anthropic says it has funded organisations supporting widely used open source, including the Python Software Foundation, Apache Software Foundation and initiatives under the Linux Foundation. Those intermediaries can help coordinate reports, support maintainers and share practices across projects.
AI changes both sides of cyber operations
The company acknowledges that capable models are available to attackers and can lower the cost of finding and exploiting vulnerabilities. Its forecast is that AI may favour defence within two years, but the near term remains uncertain because exploitation can accelerate faster than verification and patch deployment.
That imbalance makes access and timing crucial. Defensive tools must reach the people who can act, and reports must arrive with enough context to prioritise them. For critical infrastructure, even a validated fix may need to wait for a carefully managed outage.
Governance should accompany technical capability
Participants need rules for data handling, vulnerability ownership, disclosure timelines and model-generated exploit material. Critical infrastructure operators should know what information leaves their environment, while open-source maintainers need clarity about who can access unresolved findings.
Independent metrics will also matter. Anthropic should report false-positive rates, time to verification, patches accepted and vulnerabilities resolved, while avoiding details that would expose systems before fixes are available.
A practical test for defensive AI
The Cyber Mission is an ambitious attempt to move frontier models from demonstrations into sustained defence. Its combination of domain partners and maintainer support recognises that cybersecurity is a human and operational problem as much as a model-capability problem.
If the program can shorten the path from discovery to a safe deployed fix, it will offer evidence that AI can shift advantage towards defenders. If it merely increases the volume of findings, it may add pressure to already constrained teams. The design of triage, disclosure and remediation will decide which outcome emerges.