Anthropic Launches Cyber Mission to Defend Power Grids and Code
Anthropic's Cyber Mission pairs Claude with 11 security partners on critical infrastructure and launches a free scanner for open-source vulnerabilities.

Anthropic launched the Anthropic Cyber Mission on October 8, 2026, a long-term program that puts Claude to work defending power grids, water systems and open-source code instead of just finding bugs in them. The mission opens with two concrete pieces: the Critical Infrastructure Defense Program (CIDP), which gives eleven security and engineering partners — including Accenture, CrowdStrike, Palo Alto Networks, Dragos and Rockwell Automation — direct access to frontier Claude models and on-site Anthropic engineers, and OSS Scanner, a free, opt-in service that runs Anthropic's strongest models against open-source repositories and emails maintainers proof-of-concept vulnerability reports.
What Anthropic announced
In a post on its official news page, Anthropic framed the Cyber Mission as "a long-term commitment to securing the systems everyone depends on," built around tools, research and funding rather than a single product launch. The company said it is starting with two areas it considers most exposed and least served by existing AI security tools: the operational technology (OT) that runs power grids, water utilities and transportation networks, and the open-source code that "most software depends on."
Both pieces ship immediately. The CIDP is live today with eleven founding partners already working with Claude on real vulnerabilities, according to Anthropic, while OSS Scanner is open for maintainers to enroll their repositories now. Anthropic says it plans to expand the mission into further areas over time, and frames both programs as a direct response to lessons learned from Project Glasswing, the red-teaming effort it ran earlier in the year.
Why operational technology is such a hard target
The case Anthropic makes for starting with critical infrastructure is specific: power grids, water utilities, factories and transportation networks run on controllers and industrial networks that were built to last for decades, not to be patched regularly. Operators often cannot take these systems offline to fix a known flaw, so vulnerabilities can sit unresolved for years — in some cases, Anthropic says, a safe fix might not be applicable "for decades." Equipment is proprietary, changes are risky, and a mistake can shut down a plant.
That combination — valuable targets, slow patch cycles, a small pool of specialized vendors — is why Anthropic is routing the CIDP through existing trusted providers rather than selling directly to plant operators. The company says state-sponsored adversaries "have spent years gaining footholds in these systems," and that AI is now making it cheaper for attackers to find exploitable flaws faster than defenders can verify and fix them.
| Program | Focus | Launched | Access model |
|---|---|---|---|
| Project Glasswing | Frontier-model red-teaming of critical software | April 7, 2026 | 12 launch partners (AWS, Apple, Microsoft, Google, Cisco, JPMorganChase, NVIDIA and others) |
| State/local government cyber defense | Code scanning, patching, incident response for public agencies | June 2026 | Offered to over 50% of US states and large public infrastructure operators |
| Defender Advantage Fund (0xDAF) | Funds pilot programs and keeps defensive tools free | August 2026 | Grant-funded, not a product |
| Cyber Verification Program (expanded) | Reduced blocking classifiers, broader model access for vetted security teams | October 6, 2026 | Application-based, three access tiers |
| Critical Infrastructure Defense Program | Frontier Claude models, on-site engineers, threat research for OT | October 8, 2026 | 11 founding partners, interest form for others |
| OSS Scanner | Free automated vulnerability scanning for open-source projects | October 8, 2026 | Opt-in via GitHub pull request |
Inside the Critical Infrastructure Defense Program
The CIDP's eleven founding partners span three roles Anthropic says operators rely on: consulting and technology firms that run security programs (Accenture, Booz Allen, Deloitte, PwC, Hitachi), security vendors that monitor industrial and business networks (CrowdStrike, Dragos, Nozomi Networks, Palo Alto Networks) and an equipment specialist (Rockwell Automation), plus boutique OT firm Insane Cyber. Anthropic says several partners are "currently working with Claude to fix vulnerabilities" rather than merely piloting the idea, and that its first step is to work with this small cohort "to learn which strategies are most effective and practical" before widening access.
Partner statements published alongside the announcement give a sense of what each company expects to get out of it. Palo Alto Networks' Unit 42 said combining its threat intelligence with Anthropic's models is meant to help operators "close attack paths before exposure becomes impact." Insane Cyber's CEO Dan Gunter was more specific about the operational problem the deal targets: remote substations, offshore platforms and air-gapped plants generate "more data than any team can work through, at more sites than any team can staff," and Claude is pitched as the way to close that staffing gap rather than replace the analysts themselves. Rockwell Automation's Tony Baker and Dragos CTO Jon Lavender both framed the program as a way to pool lessons across vendors instead of keeping OT security knowledge siloed inside each company.
Anthropic is explicit that this is a narrow, early-stage rollout, not a general-purpose product: it says critical infrastructure is "hard to defend in many ways that AI cannot fix," and that companies building security products or services for critical infrastructure can register interest in joining as the program expands, with no pricing or broad self-service signup published yet.
OSS Scanner: free vulnerability scanning for open source
The second piece, OSS Scanner, is aimed at a different and much larger problem: the volunteer-maintained open-source code that "almost all software relies on." Anthropic says the service is directly inspired by Google's OSS-Fuzz project, and grew out of Project Glasswing, where Anthropic scanned hundreds of widely used open-source projects and privately reported vulnerabilities to maintainers through its coordinated vulnerability disclosure (CVD) process. Some maintainers, Anthropic says, asked for everything its models had found, reviewed or not — which is effectively what OSS Scanner now offers as an option.
Enrolled projects get periodic scans from Anthropic's strongest models, run inside hardened sandboxes with internet access fully disabled so the scanning agents can only audit code the project's own Dockerfile makes available offline. Each report includes a proof-of-concept exploit, an explanation and a suggested fix where one exists. Maintainers can choose a "fast track" that sends model-generated reports straight to them before any human review — faster, but Anthropic warns the reports "will contain inaccuracies, such as a wrong severity rating" — or stick with human-verified disclosures through the standard CVD pipeline, which Anthropic says has reviewed more than 6,000 reports as of October 2026.
- Cost to enrolled maintainers: free
- Expected true-positive rate on unreviewed fast-track reports: above 90%, per Anthropic
- Enrollment: open a pull request to the
anthropics/oss-scannerGitHub repository with aproject.yamland a Dockerfile - Standard coordinated-disclosure reports: 6,000+ reviewed as of October 2026
- Funded in part by the Defender Advantage Fund (0xDAF), launched August 2026
To keep the free tier sustainable, Anthropic says it has funded the Python Software Foundation, Alpha-Omega and OpenSSF (through the Linux Foundation), the Apache Software Foundation, and vulnerability-coordination groups Akrites and Gold Eagle. Maintainers can separately apply to Claude for Open Source for free Claude Max subscriptions, and to the Cyber Verification Program for broader access to Claude's defensive security capabilities. Readers who want the technical detail — the GitHub submission format, sandbox rules and report lifecycle — can check Anthropic's own write-up on its security research site. Unreviewed findings fall outside Anthropic's standard responsible disclosure policy timeline; validated reports still get the usual 90-day coordinated-disclosure window.
How this builds on Glasswing and the Cyber Verification Program
None of this starts from zero. Anthropic's defensive cybersecurity push traces back to Project Glasswing, launched April 7, 2026 after the company said its then-unreleased Claude Mythos Preview model showed vulnerability-hunting skills that could "surpass all but the most skilled humans." Glasswing recruited twelve launch partners — AWS, Apple, Microsoft, Google, Cisco, Broadcom, JPMorganChase, NVIDIA, CrowdStrike, Palo Alto Networks, Anthropic and the Linux Foundation — plus more than 40 additional organizations, and reported finding thousands of high-severity zero-days, including a 27-year-old OpenBSD flaw and a 16-year-old FFmpeg bug that automated fuzzing had reportedly missed across five million prior test runs.
Earlier this week, on October 6, Anthropic folded Project Glasswing into an expanded Cyber Verification Program, which gives vetted security teams broader access to Claude's models with reduced safety-blocking classifiers for defensive work. Anthropic describes this week's Cyber Mission launch as the next layer on top of that: where the Cyber Verification Program is about giving defenders model access, the CIDP and OSS Scanner are about pairing that access with engineers, funding and purpose-built tooling for two specific, high-stakes categories of software.
In June 2026, Anthropic had already extended a related cyber defense program to state, local, tribal and territorial governments, and says it has since worked with more than half of all US states and some of the country's largest public critical infrastructure operators on code scanning, patching, incident response and red-teaming.
The underlying bet: will AI favor attackers or defenders?
Anthropic is unusually candid about the uncertainty here. The company's own post argues that "highly cyber-capable AI models are widely available to attackers now," while defensive tools — including its own — haven't yet reached enough of the people who need them. Its stated forecast is that within two years AI will tip the balance toward defense, making it easier to catch bugs before shipping and to write secure code from scratch. In the near term, though, Anthropic says that may not hold: the cost of finding and exploiting a vulnerability has fallen sharply, while verifying, prioritizing and fixing one still depends heavily on human judgment and, in OT environments, on maintenance windows that may not come around for years.
That gap is the explicit justification for routing Anthropic's own engineers and models directly into the CIDP's partner organizations rather than shipping a self-serve product. It's a similar logic to the one behind Anthropic's broader AI agent push — persistent, task-focused systems doing specialized work over long stretches — applied here to security triage instead of office productivity.
Why this matters beyond security teams
The Cyber Mission lands as Anthropic is also preparing for a public listing, reportedly as soon as late November 2026, which makes government and enterprise partnerships like this one as much a business signal as a safety one — more on the IPO timeline here. Programs with named Fortune-500-scale partners and government reach give Anthropic visible proof that Claude is being deployed in sensitive, regulated environments, not just chat windows — a useful story to tell prospective investors regardless of how the security outcomes play out.
For the industries involved, the more immediate stakes are operational. Water utilities, power grids and transportation networks are exactly the kind of systems where a successful attack has physical consequences, and where AI-assisted attackers have already begun outpacing manual defense work, according to several of the partner statements published by Anthropic. Whether a handful of Claude-equipped engineers embedded with eleven vendors can meaningfully shift that balance is, by Anthropic's own admission, still an open question the company says it expects to take years to answer.
What's next
Anthropic says it will expand the CIDP "to more partners and more sectors" over the coming months and will publish what works — and what doesn't — along the way. On the open-source side, the company's stated roadmap includes getting findings to maintainers faster, automating more of the triage and patching work that is currently manual, and researching new "secure by construction" coding and architecture practices with projects willing to go further than simple patching. Companies that build security products or services for critical infrastructure can register interest in the CIDP as it expands; open-source maintainers can enroll directly in OSS Scanner; and security teams of any size can apply to the Cyber Verification Program for model access. None of the three has published public pricing for the infrastructure-facing pieces, so near-term scrutiny is likely to focus on how many of the eleven founding partners — and how many additional ones — actually ship fixes attributable to the program, rather than on the announcement itself.
Frequently asked questions
What is the Anthropic Cyber Mission?
It's a long-term Anthropic program, launched October 8, 2026, that provides tools, engineers and funding to defenders securing critical infrastructure and open-source software, rather than a single product.
What is the Critical Infrastructure Defense Program (CIDP)?
A new Anthropic program giving frontier Claude models, on-site engineers and threat research to trusted providers that secure operational technology like power grids, water systems and transportation networks.
Who are the Critical Infrastructure Defense Program's founding partners?
Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.
What is OSS Scanner and is it free?
OSS Scanner is a free, opt-in service that scans enrolled open-source repositories with Anthropic's strongest models and emails maintainers proof-of-concept vulnerability reports with suggested fixes. Enrollment is free, via a pull request to the anthropics/oss-scanner GitHub repository.
How accurate are OSS Scanner's reports?
Anthropic expects a true-positive rate above 90% for the unreviewed 'fast track' reports, which are sent before human review and may contain errors such as an incorrect severity rating. Fully human-verified reports still go through Anthropic's standard coordinated vulnerability disclosure process.
How does the Cyber Mission relate to Project Glasswing and the Cyber Verification Program?
Project Glasswing (launched April 2026) was Anthropic's original red-teaming effort that surfaced thousands of vulnerabilities. On October 6, 2026, Anthropic folded Glasswing into an expanded Cyber Verification Program giving defenders broader model access. The Cyber Mission, announced two days later, adds dedicated engineers, funding and tooling on top of that model access for critical infrastructure and open source specifically.
Sources
- Anthropic: Introducing the Anthropic Cyber Missionanthropic.com
- Anthropic: OSS Scanner technical overviewred.anthropic.com
- Anthropic: Expanding the Cyber Verification Programanthropic.com
- Anthropic: Project Glasswinganthropic.com
- Google: OSS-Fuzz on GitHubgithub.com
- Anthropic: Responsible Disclosure Policyanthropic.com
Theo Park runs the AI desk at Pandromeda. He follows model launches from the frontier labs and the open-weight community, tracks the assistants and developer tools built on them, and explains what each release changes on pricing, capability and safety. His reporting leans on primary sources: model cards, technical reports, API documentation and the companies' own announcements.

