Two programmes, one argument

Anthropic announced the Anthropic Cyber Mission on Thursday, a long-term effort aimed at defenders that begins with two pieces: a Critical Infrastructure Defense Program and a free vulnerability scanner for open-source projects.

The argument behind both is stated plainly in the post. The cost of finding and exploiting a vulnerability has fallen, while verifying and fixing one has not. “Our forecast is that in two years, AI will favor defense,” the company writes — which is also an admission about the two years in between.

The scanner, and the part that is new

OSS Scanner is opt-in and free. Enrolled projects get periodic scans from Anthropic’s most capable models, and each report carries a proof of concept, an explanation and, where one exists, a suggested fix. Anthropic says it was inspired by Google’s OSS-Fuzz.

The notable detail is that the reports are model-generated and sent without human review. Anthropic says it expects a true-positive rate above 90% and will work to improve it, and warns that some reports may contain errors.

That lands in a week when the other direction was also on display. Google stopped accepting bug reports for its open-source projects because too many of them were machine-written. Anthropic is proposing the opposite bet: that a high enough hit rate makes an unreviewed machine report worth a maintainer’s time. Nine in ten is Anthropic’s own expectation, not a measured result published alongside it.

An aerial view of a water treatment plant with circular tanks
Water systems are among the named targets of the programme. Illustrative photograph. Corentin Jacquemaire · pexels · Pexels License

Money to the foundations

Anthropic says it has funded the Python Software Foundation, Alpha-Omega and OpenSSF through the Linux Foundation, and the Apache Software Foundation. It also supports Akrites and Gold Eagle, which coordinate vulnerability reports. The Defender Advantage Fund, launched in August, pays for pilots and keeps OSS Scanner free. Core maintainers can apply for free Claude Max subscriptions through Claude for Open Source.

That sequencing matters. A free scanner that generates work for volunteer maintainers is a cost shifted onto them unless the funding arrives first.

The infrastructure programme

The Critical Infrastructure Defense Program gives selected security providers frontier Claude models, on-site Anthropic engineers and threat research, aimed at operational technology: power grids, water systems, transport networks and government systems.

Eleven founding partners are named: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. Several are already working with Claude, and Anthropic says it will start with a small cohort and expand. A programme it opened in June for state, local, tribal and territorial governments has reached more than half of US states.

An industrial control panel with dials and switches
Some operational technology fixes wait for a safe maintenance window. Illustrative photograph. Florent Bertiaux · pexels · Pexels License

The honest caveat

Anthropic is explicit that the near term is uncertain, and that some operational technology fixes take years — in rare cases decades — because they can only be applied when the machinery can safely be stopped. A model that finds a flaw in a turbine controller does not shorten the maintenance window in which it can be patched.

What to watch

The first maintainers to publish what OSS Scanner actually sent them. A stated expectation of 90% true positives is checkable by anyone who receives ten reports, and the open-source community has shown this month that it keeps count.