WHAT HAPPENED
● 8 October 2026. Anthropic launched the Cyber Mission, covering critical infrastructure and open-source software.
● 11 founding partners in the Critical Infrastructure Defense Program: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.
● OSS Scanner is free for enrolled open-source projects. Periodic scans from Anthropic's most capable models, each report carrying a proof of concept and a suggested fix.
● Enrol at red.anthropic.com/oss-scanner if you maintain a critical open-source project.
What the infrastructure programme actually gives partners
The Critical Infrastructure Defense Program is aimed at the companies that protect operational technology — power grids, water systems, transport networks. Not the operators themselves, but the vendors, integrators and equipment manufacturers who build the security products those operators buy.
Enrolled partners get three things: frontier Claude models, on-site Anthropic engineers, and threat research. Anthropic says several partners already use Claude to fix vulnerabilities, and that it is deliberately starting with a small cohort rather than opening the doors.
The founding eleven are worth reading as a list, because it is unusually operational. Dragos, Nozomi Networks and Rockwell Automation are OT security specialists rather than general consultancies — Rockwell builds the industrial control systems themselves. That is a different bet from signing up the big four and calling it a programme.
Companies that fit the profile can register interest at claude.com/form/critical-infrastructure-defense-program-interest.
OSS Scanner: free scans, model-generated reports
The open-source half is the part most readers can actually use today. OSS Scanner is opt-in and free. Enrolled projects receive periodic scans from Anthropic's most capable models, and each report includes a proof of concept, an explanation, and a suggested fix where one exists.
Anthropic is explicit about two limits, and both matter more than the launch framing suggests:
- Reports are sent without human review. They are model-generated. Anthropic says some will contain inaccuracies, including wrong severity ratings.
- The expected true-positive rate is above 90%. That is a good number and it is also an admission: roughly one report in ten is wrong.
Which is why enrolment is gated on capacity rather than need. Anthropic says the scanner is for projects that can keep up with the findings; everyone else gets human-verified disclosures under its coordinated disclosure policy instead. A single maintainer on a weekend project does not want a stream of unreviewed AI security reports, and Anthropic appears to know it.
The design is borrowed openly from Google's OSS-Fuzz, which has run continuous fuzzing for open-source projects since 2016. The difference is that OSS-Fuzz finds crashes; a model reads intent.
The funding, which is the part that makes it durable
Free scanning is only free while someone pays for it. Anthropic has funded the Python Software Foundation, Alpha-Omega and OpenSSF through the Linux Foundation, and the Apache Software Foundation. It also supports Akrites and Gold Eagle, which coordinate vulnerability reports.
The Defender Advantage Fund, launched in August, is what keeps OSS Scanner free. That is a more credible commitment than a launch post, because it is a standing budget line rather than a pilot.
This also did not come from nowhere. Anthropic merged Project Glasswing into an expanded Cyber Verification Program earlier the same week, and Glasswing had already scanned hundreds of widely used open-source projects. In June, Anthropic launched a cyber defence programme for state, local, tribal and territorial governments, and says it has since offered Claude models and technical support to more than half of US states.
The claim underneath all of it
Anthropic's stated forecast is that AI will favour defence within two years. That is a real position, and it is contested.
The argument for it: defenders have to find every vulnerability, attackers only one, and a model that reads a whole codebase repeatedly for free changes that asymmetry more for the side doing the reading. The argument against: the same capability reads code for an attacker just as well, and attackers do not need a 90% true-positive rate or a disclosure policy.
Worth watching rather than accepting. The programme is a bet on the first argument, and the next two years will settle it in public.
What to do today
- Maintain a widely used open-source project? Enrol at red.anthropic.com/oss-scanner. Free scans with a 90% true-positive rate are worth the triage cost if you have the capacity.
- Maintain a smaller project? Do not enrol. Take the human-verified disclosure route instead — the unreviewed report stream will cost you more time than it saves.
- Build security products for OT? The CIDP interest form is open, and the cohort is small by design.
- Run a security team of any size? The Cyber Verification Program takes applications at portal.anthropic.com/login.
- Open-source maintainer generally? Separately, Anthropic offers free Claude Max subscriptions via claude.com/contact-sales/claude-for-oss.
Sources