Critical-infrastructure defenders will receive frontier models, on-site engineers and threat research through Anthropic’s new cybersecurity program. Eligible open-source projects can also apply for a free vulnerability scanner, though maintainers will need to validate its findings themselves.
The Anthropic Cyber Mission, announced on October 8, 2026, is a long-term effort beginning with operational technology behind power grids, water systems and transportation networks, alongside protection for government systems. Its open-source component, OSS Scanner, offers recurring security scans using the company’s strongest models.
The expansion takes Anthropic’s work beyond earlier research demonstrations by establishing ways to deliver capabilities to security providers and software maintainers. Access differs between the two programs: OSS Scanner has a stated application process, while the infrastructure program begins with selected providers. Important operational and safe-deployment details remain unspecified.
Infrastructure Support Starts With Trusted Providers
The Critical Infrastructure Defense Program, or CIDP, combines frontier Claude models with Anthropic engineering support and threat research. Initially, it will work through organizations that already build, secure or support essential systems. It is not an unrestricted service that any infrastructure operator can immediately activate.
Anthropic names 11 founding partners: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. The group spans consultancies, security companies and equipment manufacturers, reflecting the different organizations involved in protecting industrial environments.
Several partners are already using Claude to fix vulnerabilities and help customers do the same, according to the company. This is a vendor-reported description of work underway; Anthropic has not published an assessment of how much risk the program has reduced.
Operational technology presents different constraints from ordinary application development. Controllers, industrial networks and control software can remain in service for decades. Anthropic’s announcement notes that systems often cannot be taken offline for patching, equipment is proprietary, and a mistaken change can disrupt a plant.
A proposed repair must fit the equipment, operating conditions and acceptable downtime. Involving established providers acknowledges that model capability alone does not supply the operational knowledge needed to move from finding a weakness to fixing it.
Anthropic describes the first phase as a small cohort intended to establish which approaches are effective and practical. Companies building security products or services for critical infrastructure can register interest, though the invitation does not promise immediate enrollment for every utility, transport operator or government agency.
OSS Scanner Offers Free Scans, Not Reviewed Findings
OSS Scanner is an opt-in service offering eligible open-source projects periodic vulnerability scans at no cost. Anthropic says the scans use its strongest models, including Claude Mythos.
Reports are fully model-generated, without human review or triage before delivery. Anthropic explicitly warns that they may be incorrect or invalid.
The workflow follows a bottleneck in the company’s earlier scanning work. Over the preceding six months, Anthropic says it discovered more than 29,000 candidate vulnerabilities but manually reviewed and triaged approximately 6,000. These are candidate findings and review counts, not evidence of 29,000 confirmed vulnerabilities.
OSS Scanner gives maintainers who can handle their own validation a faster route to the model’s output. Each report includes a self-contained reproducer and an explanation of the vulnerability, according to Anthropic. Where possible, the scanner attempts to identify when the bug was introduced; a candidate patch is included when available.
A reproducible example gives a maintainer something concrete to check, and a proposed patch can shorten the path toward remediation. Neither establishes that the finding is valid in the project’s actual threat model or that the patch is ready to merge.
Anthropic will continue manually disclosing human-verified reports through its coordinated vulnerability disclosure process, particularly for projects without the resources to triage findings themselves. OSS Scanner remains a separate, optional faster channel.
Enrollment is more defined here than for CIDP. Core maintainers can apply by submitting a pull request to the repository linked from the scanner announcement, using its standard project template. Eligibility is assessed case by case, with emphasis on projects that have a critical impact on infrastructure and user security.
The no-cost offer covers the scanning service. It does not guarantee acceptance or provide a general account for unrestricted use of Anthropic’s strongest models. The announcement also distinguishes OSS Scanner from Claude Security, its code-scanning and patching product aimed at enterprise defense.
Early Validation Helps, but Does Not Set a Reliability Rate
In an early evaluation of OSS Scanner’s output, Anthropic says expert penetration testers reviewed 97 critical- and high-severity findings across 48 projects. Of those, 85, or 88%, met the bar for its coordinated vulnerability disclosure process.
Of the remaining findings, 11 were real issues that duplicated known problems or other findings from the scan. One was invalid.
The 88% figure is an acceptance rate under Anthropic’s disclosure criteria for that evaluated group. It does not measure the scanner’s overall precision, and the single invalid report does not establish a general false-positive rate. The evaluation covered an early version, a specific severity range and a limited collection of findings. Anthropic reported the results; they are not an independent assessment of the service across all eligible projects.
The company also acknowledges feedback that severity ratings can be inflated or that the scanner can misunderstand a project’s threat model. Even when the underlying code defect is real, maintainers still need to determine whether an issue is reachable, what an attacker would require, and how urgently it should be fixed.
Detailed unreviewed reports may be useful to a well-resourced project while adding work for a small volunteer team. The relevant measure is how much verified remediation the service enables after accounting for the time spent checking its findings.
The Earlier Water-Plant Study Was a Simulation
Anthropic’s critical-infrastructure defense research, published on January 8, 2026, was separate from the new infrastructure program.
That work involved Pacific Northwest National Laboratory, or PNNL, using Claude to emulate attacks against a high-fidelity simulation of a water treatment plant. The experiment took place in summer 2025 and used Claude Sonnet 4.
PNNL researchers built a software scaffold that supplied tools and translated natural-language requests into attack sequences. The configured research system operated in a controlled environment. It did not demonstrate an unmodified chatbot safely managing a live utility.
According to Anthropic’s account, PNNL estimated that attack reconstruction took three hours rather than multiple weeks. That result concerns the specific adversary-emulation task and setup. It does not establish that infrastructure vulnerabilities can generally be found, validated and repaired on the same timescale.
The research supplied a proof of concept for accelerating defensive testing. CIDP supplies a delivery arrangement involving security providers, model access, engineers and threat research. That is a consequential difference, but the earlier simulation cannot establish that the newly announced program is already safe or effective across production infrastructure.
Access Is Becoming Clearer Than Deployment Assurance
The announcements establish what Anthropic intends to deliver, though neither provides a complete operational specification.
For CIDP, the published material leaves questions about admission criteria, supported regions, service limits, precise model access and how engineering support will be allocated. It also does not establish that participation or all associated services are free. The explicit no-cost offer applies to OSS Scanner.
The infrastructure announcement also does not explain a common process for authorizing tests, isolating risky model actions, validating proposed fixes or reversing a change that affects operations. These are unanswered implementation questions, not evidence that participating providers lack their own controls.
OSS Scanner has clearer enrollment guidance and a more explicit output format. Maintainers still need to understand the scope and frequency of scans, how reports are handled, and what support exists when a finding or proposed repair is disputed. Without human triage, a project’s capacity to investigate is especially important.
Anthropic identifies the broader problem in its announcement: finding vulnerabilities has become easier, while verification, prioritization and repair remain difficult. The Cyber Mission’s strongest feature is its attention to delivery as well as discovery, pairing infrastructure support with an opt-in reporting service for open source.
Success should be judged by the resulting repairs. Infrastructure defenders need validated remediation that preserves safe operation; maintainers need actionable security improvements without an unmanageable review burden. More findings would demonstrate scanning activity. Fewer unresolved, exploitable weaknesses would demonstrate defensive value.
Sources
- Anthropic Cyber Missionanthropic.com
- OSS Scanneranthropic.com
- critical-infrastructure defense researchanthropic.com





