Money and business in the Middle East.

Economy

Anthropic launches cyber defense push for power grids, open-source code

Anthropic launched Anthropic Cyber Mission on October 8, 2026, starting with two defense programs.

· Last verified: 10 Oct 2026 (Anthropic)

Summary

  • Anthropic launched Anthropic Cyber Mission on October 8, 2026, starting with two defense programs.
  • Eleven founding partners, including CrowdStrike and Palo Alto Networks, will get frontier Claude models and on-site engineers.
  • Registered open-source projects receive free recurring scans with exploit proofs and suggested fixes.

The latest

Frontier Claude models, on-site engineers and threat research will be channeled to security vendors protecting power grids, water systems and transport networks under a program Anthropic announced on October 8, 2026. The company said the effort, called Anthropic Cyber Mission, begins in two areas with plans to add more, and described it as a long-term effort to help defenders secure their systems.

Details

  • The first track: The Critical Infrastructure Defense Program targets operational technology, the systems behind electricity grids, water utilities, transport networks and government systems. Anthropic said it will supply frontier Claude models, on-site engineers and threat research to trusted security providers that critical infrastructure operators already rely on.
  • The partners: Eleven founding partners were named: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. Anthropic said several already use Claude to patch vulnerabilities, and that the program starts small before expanding to other partners and sectors in coming months.
  • How to join: Security firms serving critical infrastructure can register interest through a form on claude.com. Anthropic did not publish a timetable for admitting the next group of providers, or name which sectors it intends to add first.
  • The second track: The OSS Scanner is an opt-in service modeled on Google's OSS-Fuzz. Registered open-source projects get recurring reviews by Anthropic's most capable models at no cost, with each report carrying a proof of concept showing how a flaw could be exploited, an explanation, and a suggested fix where one is available.
  • The caveat: Anthropic said the reports are model-generated and sent without human review, so some may carry errors such as incorrect severity ratings. It said it expects a true-positive rate above 90% and plans to improve it, aiming the service at projects able to keep pace with the findings.
  • Everyone else: Projects outside the scanner continue to receive human-verified disclosures under Anthropic's coordinated vulnerability disclosure policy, the company said, drawing a line between automated output and reviewed reporting.
  • The funding: Anthropic said it has funded bodies including the Python Software Foundation, Alpha-Omega, OpenSSF through the Linux Foundation, the Apache Software Foundation, Akrites and Gold Eagle. The Defender Advantage Fund, launched in August, backs the experiments and keeps the OSS Scanner free of charge.
  • For maintainers: Open-source maintainers can apply to Claude for Open Source for free Claude Max subscriptions, and to the Cyber Verification Program for expanded access to cyber capabilities intended for defensive work. Project Glasswing was folded into the expanded Cyber Verification Program earlier the same week.
  • The precedent: Anthropic launched a cyber defense program in June for US state, local, tribal and territorial governments. It said it has since provided Claude models and technical support to more than half of US states and to several large public critical infrastructure operators.

Background

Operational technology runs physical processes in utilities and industrial plants, and is typically older and harder to patch than ordinary corporate IT. That gap is why Anthropic is routing its models through established security vendors rather than directly to operators.

Between the lines

The two tracks run on opposite risk settings. For critical infrastructure, Anthropic inserts human engineers and works only through vetted providers. For open-source code, it ships unreviewed model output and accepts an error rate it puts below 10%, limiting the service to projects that can absorb bad findings. The same models, two different tolerances for being wrong.

What's next

Watch for the next wave of Critical Infrastructure Defense Program partners and sectors Anthropic said will be added in coming months, and whether the OSS Scanner's stated true-positive rate holds above 90% in practice.

Source: Anthropic

Anthropic launches cyber defense push for power grids, open-source code · INXEN