Critical-infrastructure defenders will receive frontier models, on-site engineers and threat research through Anthropic’s new cybersecurity program. Eligible open-source projects can also apply for a free vulnerability scanner, though maintainers will need to validate its findings themselves.
The Anthropic Cyber Mission, announced on October 8, 2026, is a long-term effort beginning with operational technology behind power grids, water systems and transportation networks, alongside protection for government systems. Its open-source component, OSS Scanner, offers recurring security scans using the company’s strongest models.
The expansion takes Anthropic’s work beyond earlier research demonstrations by establishing ways to deliver capabilities to security providers and software maintainers. Access differs between the two programs: OSS Scanner has a stated application process, while the infrastructure program begins with selected providers. Important operational and safe-deployment details remain unspecified.
Infrastructure Support Starts With Trusted Providers
The Critical Infrastructure Defense Program, or CIDP, combines frontier Claude models with Anthropic engineering support and threat research. Initially, it will work through organizations that already build, secure or support essential systems. It is not an unrestricted service that any infrastructure operator can immediately activate.
Anthropic names 11 founding partners: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. The group spans consultancies, security companies and equipment manufacturers, reflecting the different organizations involved in protecting industrial environments.
Several partners are already using Claude to fix vulnerabilities and help customers do the same, according to the company. This is a vendor-reported description of work underway; Anthropic has not published an assessment of how much risk the program has reduced.
Operational technology presents different constraints from ordinary application development. Controllers, industrial networks and control software can remain in service for decades. Anthropic’s announcement notes that systems often cannot be taken offline for patching, equipment is proprietary, and a mistaken change can disrupt a plant.
A proposed repair must fit the equipment, operating conditions and acceptable downtime. Involving established providers acknowledges that model capability alone does not supply the operational knowledge needed to move from finding a weakness to fixing it.





