Anthropic launches Cyber Mission and free OSS Scanner
Anthropic is pairing frontier models with critical-infrastructure support and free vulnerability scans, turning AI cyber defense into a public deployment program.
Anthropic has launched the Cyber Mission, a long-term program that combines frontier-model research, security tooling and direct support for defenders of critical systems. Its first initiatives target two areas: operational technology used by power, water and transport networks, and the open-source software supply chain.
What is launching
The company’s Critical Infrastructure Defense Program will provide frontier Claude models, on-site engineering support and threat research to organizations defending operational technology and government systems. Anthropic also launched OSS Scanner, an opt-in service that periodically scans enrolled open-source projects for vulnerabilities at no cost.
Scanner reports include a proof of concept, an explanation of the flaw and a suggested fix when available. Unlike Anthropic’s coordinated-disclosure work, the reports are model-generated and sent without human review. Anthropic expects a true-positive rate above 90%, while acknowledging that severity ratings and proposed fixes can still be wrong.
The program grew out of Project Glasswing, in which Anthropic scanned widely used open-source projects and had humans triage many findings before disclosure. The company says its broader work has uncovered thousands of verified vulnerabilities, but the new service is designed to shorten the gap between discovery and maintainer action.
Why it matters
The strategic shift is from demonstrating that models can find vulnerabilities to placing them inside the maintenance loop of software that other systems depend on. That could make AI-assisted security useful to small projects that cannot afford professional auditing, while also creating a new burden: maintainers must process a potentially continuous stream of machine-generated findings.
Anthropic’s own warning is important. Critical infrastructure may take years or decades to patch safely, so a model that finds bugs faster does not automatically make physical systems safer. The Cyber Mission will be judged by verified fixes and reduced exposure, not by the number of vulnerabilities reported.