Announced 8 Oct 2026 · Sources checked
What is the Anthropic Cyber Mission?
The 8 October announcement says the Cyber Mission is “a long-term commitment to securing the systems everyone depends on,” starting with two areas: critical infrastructure and open-source software. For infrastructure it introduces CIDP. For open source it launches OSS Scanner. The post frames both as a response to Project Glasswing: partners found many vulnerabilities, but “verifying, prioritizing, and fixing these findings remains challenging.”
Earlier in the week, the same post says, Anthropic merged Glasswing into an expanded Cyber Verification Program, which lowers blocking classifiers for qualifying defenders. The Cyber Mission is the deployment and funding layer on top of that access change. Claude Security remains the general-access enterprise scanner in Anthropic’s own wording.
Anthropic writes that state-sponsored adversaries have spent years gaining footholds so they can disrupt systems, and that defenders “have faced severe resource shortages.” Those are Anthropic’s threat claims. The company says it will expand the Mission with more tools and research later.
What does the Critical Infrastructure Defense Program offer?
CIDP is aimed at the “trusted providers” that operators already use, not at every utility directly. Anthropic says operational technology — controllers, control software and industrial networks “built to last for decades” — often cannot be taken offline to patch, so known bugs can sit for years. The program “brings frontier Claude models, on-site engineers, and our threat research to those trusted providers.”
The founding-partner list in the post is Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. Anthropic groups them as consultancies that run security programs, vendors that guard business and industrial networks, and manufacturers that build and patch the equipment. “Several partners are currently working with Claude to fix vulnerabilities and help customers do the same.” We have not seen those work tickets.
The post includes named quotes from Tony Baker of Rockwell Automation, Harshul Joshi of PwC, Sam Rubin of Palo Alto Networks Unit 42, Moreno Carullo of Nozomi Networks, Dan Gunter of Insane Cyber, Hiroaki Koiwa of Hitachi, Adnan Amjad of Deloitte, Andrew Turner of Booz Allen, and Harpreet Sidhu of Accenture. Those are supplied partner statements. Anthropic says it is starting with a small cohort “to learn which strategies are most effective and practical,” and that companies that build security products or services for critical infrastructure can register interest from the post. We did not submit a registration.
What is already running for U.S. public operators?
In June, Anthropic says, it launched a cyber defense program for state, local, tribal and territorial governments. “Since then, we’ve offered frontier Claude models and technical support to more than half of all US states and some of the country’s largest public critical infrastructure operators,” for code scanning and patching, incident response, red teaming and other workflows. That “more than half” figure is Anthropic’s. The post does not list the states.
The stated method is to work through companies, coalitions, governments and nonprofits that operators already trust, rather than to replace those relationships.
How does OSS Scanner fit, and what is not being re-reported?
Under the same umbrella Anthropic launches OSS Scanner as an opt-in, free, model-generated scan service inspired by OSS-Fuzz. Reports go out without human review. That product has its own research post, Apache-2.0 repository and terms. We reported it separately; see Anthropic’s OSS Scanner launch. This article does not repeat enrollment fields, the 88% early-review figure, or the $1,000 liability cap.
The Mission post adds only the framing: Glasswing already sent human-triaged mail; some maintainers asked for the unverified remainder; the scanner is that fast track; human coordinated disclosure continues. Anthropic says it has funded the Python Software Foundation, Alpha-Omega and OpenSSF through the Linux Foundation, the Apache Software Foundation, and Akrites and Gold Eagle. The Defender Advantage Fund launched in August is said to keep OSS Scanner free. Those funding lines are Anthropic’s. They sit beside, and are not the same as, the October disclosure-dashboard totals.
What forecast does Anthropic attach, and what is still open?
“Our forecast is that in two years, AI will favor defense: it will be easier to catch bugs before they ship, write fundamentally secure software from scratch, and actively defend systems with models. But in the near term, that may not be true.” Anthropic says the cost of exploiting bugs has dropped while verification and fixes still depend on people, and that Glasswing often saw months between a find and a fix. For operational technology, it says a safe fix “might take decades” in rare cases.
Success, in Anthropic’s words, means water, power, transport and communications keep running with fewer exploitable paths. The company says the Mission will change as it learns what works, and that it wants other AI developers, security companies and governments to run parallel efforts. We have not measured a defender-advantage shift, joined CIDP, or confirmed a partner’s production use of Claude on a live industrial control system.
Common questions
Is CIDP the same product as OSS Scanner?
No. CIDP is a partner program for operational-technology vendors and operators. OSS Scanner is an opt-in mail service for open-source maintainers. They were announced in the same Cyber Mission post.
Can a utility enroll in CIDP directly?
The post is written for “trusted providers” and invites companies that build security products or services for critical infrastructure to register interest. It does not publish a public application form for every operator.
Did Anthropic prove that AI already favors defenders?
No. The two-year “favor defense” sentence is labeled a forecast. The same paragraph says the near term may go the other way.
What to remember
Read CIDP as a named-partner OT program and OSS Scanner as the already-covered maintainer track. Keep Anthropic’s state-coverage count and two-year forecast in the vendor column until a public roster or an independent result appears.
Sources & further reading
How this story was made
Written by Kristian Kostov with AI assistance and checked against the linked sources. Company performance claims are attributed to the company. Analysis reflects AiLookout’s interpretation; we have not independently tested the products discussed. Cover photography is illustrative and does not depict the specific announcement or product.
Our editorial standards





