Science & Tech · AI · 2 days ago
Anthropic launches AI cybersecurity program for infrastructure and open-source software
Anthropic has launched a program to help find and fix software security weaknesses in critical infrastructure and open-source projects.
The work involves its Claude AI models and engineers, cybersecurity companies, infrastructure operators and open-source maintainers.
Critical infrastructure includes systems that provide essential services, while open-source software is code that people and organizations can use and develop.
Anthropic says many defenders lack the resources to keep pace with threats, and that AI tools could help identify weaknesses before attackers use them.
For eligible open-source projects, an opt-in service will offer free, periodic scans, but reports may contain errors and are not reviewed by a person.
Anthropic says it will begin by working with a small group of infrastructure providers, while its longer-term goal is to automate more security checks and repairs.
The company predicts attackers will have the advantage for the next two years, before defenders may be able to use AI to catch flaws earlier.
Anthropic launched programs to help defend critical infrastructure and open-source software from cybersecurity vulnerabilities.
Its critical infrastructure program combines Claude models, Anthropic engineers and threat research with outside cybersecurity companies.
An opt-in service will offer eligible open-source projects free, periodic security scans with findings and suggested fixes.
Anthropic said the scans may contain inaccuracies and that reports are sent without human review.
The company says AI can help defenders find and repair weaknesses, while warning that attackers currently have the advantage.
- Who
- Anthropic, working with cybersecurity companies and open-source project maintainers.
- What
- It launched programs to scan for and help fix cybersecurity vulnerabilities in critical infrastructure and open-source software.
- When
- Thursday, October 8, 2026.
- Where
- The programs cover critical infrastructure and open-source projects; Anthropic said it has offered support to more than half of U.S. states.
- Why
- Anthropic says defenders face severe resource shortages and that AI tools can help find and repair weaknesses before they are exploited.
This story does not have two clearly opposing sides.
Defenders of critical infrastructure and the [open-source software] community have decades of security experience but have faced severe resource shortages that are exacerbated by this moment,
We are recognizing their expertise in these domains and offering our support.
Critical infrastructure is hard to defend in many ways that AI cannot fix, but we believe that frontier models can help find and repair weaknesses before those weaknesses are used to cut off power or make water unsafe,
Anthropic said AI models found 20 percent of vulnerabilities.
Anthropic announced its critical infrastructure defense program and an opt-in scanning service for open-source software.
- Program
- Critical Infrastructure Defense Program
- Open-source service
- OSS Scanner
- Eligible projects
- Established projects with a critical impact on infrastructure and user security
- Partner companies
- Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation
- AI vulnerability detection
- More than 85 percent, according to Anthropic
- States offered support
- More than half of U.S. states










