Anthropic on Thursday, Oct. 8, launched what it calls the Anthropic Cyber Mission, which it describes as a long-term effort to help the people who defend the computer systems everyone depends on. It starts in two places: free security scans for open-source software, the code that is free for anyone to use, study, change and share and that almost all software relies on, and a program that brings its most advanced Claude models and its own engineers to companies that protect power grids, water systems and transport networks.
The scanning service, called OSS Scanner, is opt-in. Core maintainers of open-source projects can sign up, and Anthropic decides case by case which to accept, saying projects should be ones whose security matters to critical systems and many users. It is meant for projects with enough people to keep up with the reports; Anthropic says it will keep sending reports checked by its own staff to the rest. Enrolled projects get regular scans from Anthropic's strongest models at no cost. Each report shows how a flaw it finds could be used in an attack, explains it and, where it can, suggests a fix.
Anthropic says it built the service because its AI now finds problems faster than its staff can check them, and some maintainers asked to get every finding, checked or not. Anthropic says its models flagged more than 29,000 possible vulnerabilities, weaknesses in software that an attacker could use, in important projects over the last six months, but its staff could review only about 6,000. OSS Scanner sends its reports straight from the model, with no person reviewing them first. Anthropic says that gets them to maintainers sooner but means some will contain mistakes, such as an overstated severity. It expects more than 90% of findings to be real. When its security testers checked 97 serious findings from an early version, 85 were solid enough for the warnings Anthropic normally sends after a person checks them, 11 were real but repeated known problems or other findings from the same scan, and only one was false.
The second program, the Critical Infrastructure Defense Program, aims at the equipment that runs power grids, water utilities, factories and transport networks. Anthropic says those systems are built to last decades and often cannot be taken offline to install fixes, so known weaknesses can stay open for years. Its 11 founding partners are consulting, security and equipment companies that, Anthropic says, utilities and other operators already rely on: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. Anthropic says several are already using Claude to fix weaknesses, and that it is starting with a small group to learn what works.
Anthropic has not said whether partners get its models for free or who covers the computing costs, and it is not yet clear how fixes will be tested and installed without disrupting the utilities that run on this equipment. Anthropic predicts that within two years AI will help defenders more than attackers, but says that may not be true in the near term, because using weaknesses to attack has become cheap, while checking and fixing them is slow and still depends on people.