Anthropic’s Cyber Mission: On-Site Engineers for OT, Unreviewed Model Output for Open Source
On 8 October 2026, Anthropic launched the Anthropic Cyber Mission, described as a long-term commitment to securing the systems everyone depends on. It starts in two places: critical infrastructure, via a new Critical Infrastructure Defense Program, and open-source software, via a free OSS Scanner. The announcement is unusually candid about the asymmetry it is responding to — highly cyber-capable models are widely available to attackers now, while verification, disclosure, and fixing remain slow, manual, and people-bound — and it contains one genuinely bold operational choice worth examining: the scanner's reports go to maintainers with no human review.
Engineers, not just API access, for OT
The Critical Infrastructure Defense Program brings frontier Claude models, on-site engineers, and Anthropic threat research to the trusted providers that already defend operational technology — power grids, water systems, transportation networks, and government systems. The eleven founding partners span the OT defense stack: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. Anthropic says the work is already underway, with partners using Claude to fix vulnerabilities and help customers do the same, and that the first step is deliberately a small cohort, to learn which strategies actually work before expanding.
The framing acknowledges what models cannot fix: OT equipment is proprietary, changes are risky, a mistake can take down a plant, and some fixes must wait for safe maintenance windows — in rare cases, the announcement says, decades. That sentence matters because it bounds the AI-hype reading of the program. The value proposition is narrower and more plausible: triaging exposure and preparing fixes for running systems faster, inside providers operators already trust, rather than asking operators to trust a new model directly. It also extends a track Anthropic started in June with a cyber defense program for state, local, tribal, and territorial governments, which it says has since reached more than half of all US states plus large public infrastructure operators.
OSS Scanner: free scans, PoC included, nobody checked
The open-source half is the more interesting security design decision. Under Project Glasswing, Anthropic scanned hundreds of widely used projects, human-triaged the findings, and reported them through coordinated disclosure — and repeatedly watched months pass between a vulnerability being found and fixed. Some maintainers with triage capacity asked for everything the models found, reviewed or not. The answer is OSS Scanner: enrolled projects get periodic scans from Anthropic's most capable models, free, with each report carrying a proof of concept, an explanation, and a suggested fix — sent without human review.
Anthropic states an expected true-positive rate above 90%, warns plainly that some reports will contain inaccuracies such as wrong severity ratings, and scopes the service to projects with the capacity to keep up — everyone else stays on human-verified disclosure under its coordinated-vulnerability-disclosure policy. That scoping is the load-bearing wall of the whole design: unreviewed model output is being routed only to maintainers who asked for the raw feed and can absorb a one-in-ten false-positive rate. The stated roadmap — faster delivery, automated triage and patching, research into hardening and rewriting code — plus funding for the Python Software Foundation, Alpha-Omega, OpenSSF, the Apache Software Foundation, and the Akrites and Gold Eagle triage coordinators, with the August-launched Defender Advantage Fund keeping the scanner free, reads as an attempt to fix the disclosure-to-patch latency Glasswing exposed rather than the find rate.
Two adjacent moves complete the picture. Earlier in the week, Anthropic merged Project Glasswing into its expanded Cyber Verification Program, widening defender access to its most capable models — and the Cyber Mission will deploy engineering talent, tools, and funding on top of that access. And the announcement's forecast is explicit about the bet: in two years, AI favors defense — catching bugs before they ship and writing secure software from scratch get easier — but in the near term, the cost of exploiting vulnerabilities has dropped while fixing them still depends on people.
What to do
- If you maintain a critical open-source project with triage capacity, evaluate OSS Scanner enrollment. The raw-feed model only works if someone reads every report; a PoC-attached unreviewed feed landing in an unmonitored inbox is just noise with exploit instructions. Projects without that capacity should stay on the human-verified disclosure path.
- Treat scanner output as untrusted input to your own triage. Above-90% true positive still means wrong severity ratings and false alarms by the vendor's own admission. Confirm the PoC in your own environment before prioritizing, and feed corrections back — the program's improvement loop depends on it.
- If you build security products for critical infrastructure, the partner cohort is open for registration. Early participation shapes what the program measures; late participation inherits someone else's metrics.
- Plan for the near-term asymmetry, not the two-year forecast. Exploit costs have fallen today; defense-at-scale arrives later. OT operators should assume adversaries are already scanning with equivalent models and prioritize exposure reduction on internet-facing control-system surfaces now.
Verification note: the launch date (8 October 2026), program structure (Cyber Mission; Critical Infrastructure Defense Program; OSS Scanner), the eleven founding partners, the June SLTT program and its stated reach, Glasswing findings-handling history, the unreviewed-report design with PoC/explanation/suggested fix and above-90% true-positive expectation, the funding recipients, the Defender Advantage Fund's August launch, and the two-year defense forecast were read by us directly from Anthropic's announcement. Corroboration of the launch and its two pillars via Axios, CyberScoop, and industry coverage published the same day was checked through search-result summaries. Partner quotes in the announcement were not independently verified and are not relied on above.
Sources: