Anthropic has launched what it calls the Anthropic Cyber Mission, “a long-term commitment to securing the systems everyone depends on”. It has two parts: a programme for the security firms that protect power grids, water and transport, and a free service that sends open-source projects bug reports written by its AI models without human review. Everything below is Anthropic’s own description unless stated.
What was announced (confirmed, company announcement)
In its post of 8 October, Anthropic says the Cyber Mission is “a new effort to support defenders with tools, research, and resources”, starting with critical infrastructure and open-source software [1]. It says it will “expand the Cyber Mission” into other areas later. It also confirms that “earlier this week, we merged Project Glasswing into our expanded Cyber Verification Program”, which TSN covered here [1].
Critical Infrastructure Defense Program
The Critical Infrastructure Defense Program (CIDP) is aimed at the “trusted providers” that operators rely on, not at the operators directly. Anthropic says it brings “frontier Claude models, on-site engineers, and our threat research” to them [1]. The 11 founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation [1].
Anthropic says power grids, water utilities and factories run on “operational technology” that “often cannot be taken offline to patch”, and that on some equipment a fix may take “decades” in “some rare cases” [1]. It calls its first step “a small cohort of providers” and says several partners are already working with Claude to fix vulnerabilities [1]. It publishes partner statements but no results.
OSS Scanner
OSS Scanner is a free, opt-in service for open-source projects, inspired by Google’s OSS-Fuzz. Enrolled projects get periodic scans from Anthropic’s strongest models, with a report, an explanation and a suggested fix where one exists [1][2]. The reports are “model-generated and sent without human review”, so Anthropic warns some “will contain inaccuracies, such as a wrong severity rating” [1].
An expectation, not a measured rate. Anthropic says: “We expect a true-positive rate above 90%” [1]. Its own validation, described in a separate post, had Anthropic’s reviewers check 97 critical and high-severity findings across 48 projects; 85 (88%) met the bar for its disclosure process, 11 were real but duplicates, and one was invalid (company claim, checked by Anthropic’s own reviewers) [3].
Because the findings are unreviewed, Anthropic says it will not apply a 90-day disclosure deadline to them. Projects short of capacity will keep getting human-verified reports [2]. Enrolment is limited to core maintainers of established projects, using criteria similar to OSS-Fuzz’s [2].
Anthropic also says it has found “over 29,000 candidate vulnerabilities” in six months, but could manually review only “approximately 6,000” (company claim) [3].
Anthropic’s forecast
“Our forecast is that in two years, AI will favor defense”, Anthropic writes, adding that “in the near term, that may not be true” because exploiting flaws has become cheaper while verifying and fixing them “is slow and still depends on people” [1]. It is a forecast, not a finding.
What this does not prove
- That OSS Scanner’s reports are accurate. The “above 90%” figure is an expectation; the 88% figure is Anthropic’s own check of a sample. No independent test has been published [1][3].
- That the programme has made grids or water systems safer. Anthropic has published partner statements but no results [1].
- That AI will favour defenders. That is Anthropic’s forecast, and Anthropic itself says the near term may differ [1].
- That maintainers will welcome unreviewed reports. Anthropic says the service is for projects that can keep up with the volume [2].
The Bottom Line
The Anthropic Cyber Mission puts Claude and Anthropic engineers alongside 11 critical-infrastructure security providers, and offers open-source maintainers free, unreviewed, model-written bug reports (confirmed, company announcement). The numbers on accuracy are Anthropic’s expectations and its own checks. The useful test will be whether operators and maintainers find the work accurate, and fix flaws faster.
Sources
- Anthropic, “Introducing the Anthropic Cyber Mission”, 8 October 2026 (company announcement). https://www.anthropic.com/news/anthropic-cyber-mission
- Anthropic, “OSS Scanner” (service page: eligibility, enrolment and disclosure policy), read 9 October 2026 (company page). https://red.anthropic.com/oss-scanner
- Anthropic, “Launching an opt-in vulnerability-finding service for open-source software”, 8 October 2026 (company research post; source of the validation figures and vulnerability counts, which are company claims). https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source

