TL;DR

Anthropic announced the Anthropic Cyber Mission on Thursday 8 October, a long-running effort to help defenders secure the systems society relies on. It starts in two places: a Critical Infrastructure Defense Program for the operational technology behind power, water and transport, and OSS Scanner, a free service that runs Anthropic’s strongest models over open-source code.

Defending operational technology

Industrial controllers and control software are built to run for decades and often cannot be switched off for patching, so known flaws can linger for years. Operators of all sizes lean on a handful of trusted security providers to tell them what is exposed and which fixes are safe to apply to live equipment.

The new programme works through those providers. It gives them frontier Claude models, Anthropic engineers on site and the company’s threat research. There are 11 founding partners: PwC, Deloitte, Accenture and Booz Allen, alongside CrowdStrike, Palo Alto Networks, Dragos, Nozomi Networks, Insane Cyber, Hitachi and Rockwell Automation. Several are already using Claude to fix vulnerabilities, and Anthropic says it will begin with a small group to learn what works before widening it.

Free scans for open source

OSS Scanner is opt-in and modelled on Google’s OSS-Fuzz. Enrolled projects get regular scans, and each report carries a proof-of-concept exploit, an explanation and, where possible, a proposed fix. Reports go out without human review, which makes them faster but means some will be wrong, for instance on severity. Anthropic expects more than 90% of findings to be genuine. The service suits maintainers who can keep pace with the volume; others will still receive human-checked disclosures.

Anthropic has also funded groups behind widely used open-source code, among them the Python and Apache software foundations, and says its Defender Advantage Fund, launched in August, keeps the scanner free.

Why now

The launch follows Anthropic folding Project Glasswing into an expanded Cyber Verification Program earlier this week. The company admits Glasswing found many bugs without cutting cyber risk enough: finding flaws is now easy, but checking, ranking and fixing them is slow. It forecasts that within two years AI will tilt the balance towards defenders, while warning that this may not hold in the near term.

Looking forward

The programme reaches operators only through their security providers, and the government defence programme Anthropic launched in June has so far served US states and public bodies. In our view, the more immediately useful piece for UK organisations is OSS Scanner, since open-source code sits underneath almost all software, as Anthropic notes. For water and energy operators, the honest point in Anthropic’s own post is the patching lag: a fix that must wait for a safe moment on live machinery can, it says, take decades in rare cases.