Anthropic Cyber Mission puts frontier Claude models in front of power grid and water defenders
On October 8, 2026 Anthropic launched a Critical Infrastructure Defense Program with 11 founding partners and a free open-source scanner. The claims are Anthropic's own, and the 90 percent accuracy figure is an expectation, not a result.
By Yash Malviya
Published

Anthropic announced on October 8, 2026 what it calls the Anthropic Cyber Mission, which it describes as "a long-term commitment to securing the systems everyone depends on." The first two pieces are a Critical Infrastructure Defense Program for the operators of power grids, water systems and transport networks, and a free scanner for open-source code. This is the clearest sign yet that Anthropic is turning its strongest cyber-capable models into a program, not just a product tier.
What the Cyber Mission actually is
The Critical Infrastructure Defense Program, or CIDP, is aimed at operational technology: the control systems behind electricity, water, transportation and government networks. Anthropic says it will give trusted providers frontier Claude models, on-site engineers and threat research. Eleven companies are founding partners: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.
Note who is on that list. These are integrators, security vendors and industrial suppliers, not utilities. The program reaches grids and water plants through the firms that already sell to them. Anthropic says the first phase works with a small cohort of providers, and other companies can register interest through a form on claude.com. Several partners, it says, are already using Claude to fix vulnerabilities, but the post does not name a single operator or give a count of systems covered.
OSS Scanner: free, automated and unreviewed
The second piece is OSS Scanner, which Anthropic says is inspired by Google's OSS-Fuzz. Open-source projects opt in and get periodic scans from Anthropic's most capable models at no charge. Each report includes a proof of concept, an explanation and, where possible, a suggested fix.
The catch is stated in Anthropic's own post. The reports are model-generated and sent without human review, so some may contain errors, such as wrong severity ratings. Anthropic says it expects a true-positive rate above 90 percent and aims to improve it. That is a forecast, not a measurement. Maintainers of small projects already drown in low-quality automated reports, and a free scanner that sends unreviewed findings could add to the pile if the real rate falls short. For projects without capacity to triage, Anthropic says human-verified disclosures continue.
The company also says it funds the Python Software Foundation, Alpha-Omega and OpenSSF through the Linux Foundation, and the Apache Software Foundation, and that a Defender Advantage Fund launched in August keeps OSS Scanner free. The post gives no dollar amounts for these grants, so the scale of the support cannot be judged.
“Operational technology is the next frontier for autonomous AI-enabled attacks.”

How it fits the Mythos story
Anthropic says Project Glasswing, its earlier effort that scanned hundreds of widely used open-source projects and reported findings privately to maintainers, has been merged into an expanded Cyber Verification Program that gives more defenders access to top models. We covered the tiers of that program on October 7. The Cyber Mission is the next layer: the same models, aimed at physical infrastructure and at the open-source software underneath it.
The backdrop is government use. SecurityWeek reported on July 7, 2026, relaying Reuters, that the Cybersecurity and Infrastructure Security Agency was reportedly using Anthropic's Mythos model to scan federal code repositories, according to three unnamed sources. Neither Anthropic nor CISA commented on the record, and the severity of flaws and the volume of software reviewed were not disclosed. That report is unconfirmed.
The risk side is just as concrete. Our earlier report on CVE-2026-61500 in Rejetto HFS showed a bug being exploited within a day. Anthropic does not hide the tension. It says it expects AI to favor defense within two years, but that the near term may be harder because exploiting vulnerabilities has become cheaper than fixing them.
What the partner quotes tell you
The launch post carries quotes from partners. Andrew Turner of Booz Allen says: "Operational technology is the next frontier for autonomous AI-enabled attacks." Dan Gunter of Insane Cyber says Claude closes a gap so that analysts and operators spend their time on judgment calls. Tony Baker of Rockwell Automation also contributed a quote. These are statements from companies that stand to sell services around the program, so they are best read as demand signals, not evidence of results.
What is missing
Several things a skeptical reader would want are absent. There is no measured false-positive rate. There is no list of operators actually protected. There is no price for the defense program, only the line that OSS Scanner is free and that open-source maintainers can apply to Claude for Open Source for free Claude Max subscriptions. And there is no independent evaluation of how well the models find vulnerabilities in industrial control software, which is a different problem from scanning web libraries.
The June precedent is also worth noting. Anthropic says its cyber defense program for state, local, tribal and territorial governments has reached more than half of US states and some large public critical infrastructure operators. That is the closest thing to a track record, and again the figure comes from Anthropic.
Who this is really for
The audience for the defense program is the integrator and the security vendor, which is a deliberate choice. Few water utilities or regional grid operators have teams that can safely run a frontier model against operational technology, where a mistaken change can interrupt service. By working through firms such as Dragos, Nozomi Networks and Rockwell Automation, which already sit inside industrial networks, Anthropic reaches those systems with people who understand them. The cost is that the end operators, the ones whose names would make the program credible, are not yet public.
Our take
This is a sensible program with a credible partner list and an honest caveat about unreviewed reports. It is also a lab marketing its most dangerous capability as a public good, with the evidence still to come. We would judge it on two numbers Anthropic has not yet published: the scanner's measured true-positive rate on real maintainers' projects, and the number of operators, not vendors, running Claude on live control systems. Until then, the 90 percent is a goal.
We have no on-the-record Anthropic executive quote beyond the post itself, and we have not tested the scanner.
Frequently asked questions
What is the Anthropic Cyber Mission?
It is a program Anthropic announced on October 8, 2026, described as a long-term commitment to securing critical systems. It starts with a Critical Infrastructure Defense Program for operational technology and a free, opt-in OSS Scanner for open-source projects.
Who are the founding partners of the Critical Infrastructure Defense Program?
Anthropic lists 11: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. They are integrators, security vendors and industrial suppliers rather than utilities.
Is Anthropic's OSS Scanner free?
Yes. Enrolled open-source projects get periodic scans from Anthropic's most capable models at no charge, and a Defender Advantage Fund launched in August keeps it free. Reports are model-generated and sent without human review.
How accurate is the OSS Scanner?
Anthropic says it expects a true-positive rate above 90 percent and aims to improve it. That is an expectation, not a published measurement, and the post warns that some reports may have errors such as wrong severity ratings.
What happened to Project Glasswing?
Anthropic says it has been merged into the expanded Cyber Verification Program, which gives more defenders access to top models. Glasswing had scanned hundreds of widely used open-source projects and reported findings privately to maintainers.
Is CISA using Anthropic's Mythos model?
Reuters reported on July 6, 2026, citing three unnamed sources, that CISA was using Mythos to scan federal code. Neither Anthropic nor CISA commented on the record, so the report remains unconfirmed.
Sources
What each one is, and whose it is.
- 1
Anthropic Cyber Mission, Anthropic (October 8, 2026)
Vendor announcement - 2
CISA reportedly using Anthropic's Mythos to scan government software for flaws, SecurityWeek (July 7, 2026)
Press reportIndependent of the vendor - 3
AI news today, October 8 to 9, 2026, AI Weekly (October 9, 2026)
Press reportIndependent of the vendor