AI/News

Anthropic opens free security scans for open-source projects - model-written reports, no human review, "a true-positive rate above 90%" expected - and a critical-infrastructure programme with eleven partners

The Anthropic Cyber Mission, launched 8 October: OSS Scanner for maintainers who opt in, and a Critical Infrastructure Defense Program for the firms that secure grids, water and transport. Every figure is Anthropic's own.

By Daily Aletheia · Checked against the primary source · 9 October 2026 · 2 min read


Image: Anthropic - the header image of its Anthropic Cyber Mission announcement, anthropic.com, 8 October 2026

Anthropic launched the Anthropic Cyber Mission on 8 October, "a long-term commitment to securing the systems everyone depends on", with two first programmes: a Critical Infrastructure Defense Program for the companies that secure power grids, water systems and transport networks, and OSS Scanner, which "offers open-source projects regular security scans from our strongest models, for free".

OSS Scanner is opt-in, "inspired by Google's OSS-Fuzz". Enrolled projects "receive periodic scans from our most capable models, free of charge". "Each report includes a proof of concept of how the bug could be exploited, an explanation, and a suggested fix where one is available." The page is plain about the trade: "The reports are model-generated and sent without human review. That means maintainers receive them faster, but it also means that some will contain inaccuracies, such as a wrong severity rating. We expect a true-positive rate above 90%". The service "is meant for projects with the capacity to keep up with surfaced findings"; for the rest Anthropic says it will keep sending human-verified disclosures. The Defender Advantage Fund, launched in August, "keeps OSS Scanner free".

The infrastructure programme "brings frontier Claude models, on-site engineers, and our threat research" to eleven founding partners: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. Since a June programme for state and local governments, the page says, Anthropic has "offered frontier Claude models and technical support to more than half of all US states".

The reasoning is stated: "Highly cyber-capable AI models are widely available to attackers now. But defensive tools—including our own—have not yet reached enough of the defenders who need them." Its forecast is "that in two years, AI will favor defense", with the caveat that "in the near term, that may not be true" - under Project Glasswing, now merged into the Cyber Verification Program, "we often saw months pass between a vulnerability being found and being fixed".

Sources & further reading

  1. 01Anthropic - Introducing the Anthropic Cyber Mission (8 Oct 2026) ↗Primary