"Defenders of critical infrastructure and the [open-source software] community have decades of security experience but have faced severe resource shortages that are exacerbated by this moment," Anthropic wrote in a blog post.
Anthropic's stated rationale
Anthropic announced a program it described as a "long-term commitment" to pair its Claude models, Anthropic engineers and threat research with outside cybersecurity firms to find and fix vulnerabilities in critical infrastructure and open-source software. The company framed the effort as support for defenders who possess experience but face resource shortages, and said frontier AI models can help surface and repair weaknesses before they are exploited.
How the program will operate
Anthropic said it will begin with a small cohort of providers to identify which strategies are "most effective and practical." The firm has already offered frontier models and technical support to more than half the states in the U.S., as well as to large operators of critical infrastructure for activities including scanning and patching code, incident response, and red teaming. Anthropic emphasized that "critical infrastructure is hard to defend in many ways that AI cannot fix," while arguing that frontier models can assist in finding and repairing weaknesses that might otherwise be used to cut off power or make water unsafe.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleNamed industry partners
The program will combine Anthropic’s tools with the expertise of a range of cybersecurity companies. Anthropic named the following partners: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. Those companies are billed as collaborators in applying AI-driven scans, engineering support, and threat research to operational systems and software.
The open-source opt-in scanning service
Anthropic said it has been working with maintainers of large open-source projects and that some organizations requested "everything the model had found in their software, even unreviewed findings." That demand prompted Anthropic to create an opt-in scanning service for open-source software: organizations can receive periodic scans at no cost that include a proof of concept, an explanation of findings, and suggested patching options. Anthropic cautioned that reports produced under the program will be delivered faster but "may contain inaccuracies."
What this means for critical-infrastructure operators, open-source maintainers, and cybersecurity vendors
- Critical-infrastructure operators: Anthropic positions its models as a tool to help scan, patch, and assist in incident response and red teaming; the company has already offered these capabilities to more than half the U.S. states and to large operators.
- Open-source maintainers: The new opt-in scanning service offers free, periodic scans with proofs of concept and patch suggestions, but Anthropic warns maintainers the automated findings can be inaccurate and previously requested unreviewed output from some projects motivated the decision to make scanning opt-in.
- Cybersecurity vendors and consulting partners: Named firms will be part of the initial cohort that combines human expertise with Anthropic’s Claude models and threat research to learn which approaches work best in real-world operational contexts.
Anthropic tied the initiative to a broader industry concern: as AI models gain capabilities to find and even exploit known vulnerabilities, frontier AI companies worry that malicious actors could acquire tools faster than legitimate organizations. In response, Anthropic — along with OpenAI, the company said — has launched programs that funnel their technology to businesses and governments free of charge for defensive cybersecurity.
Anthropic’s stated long-term goal is to automate most triage and patching and to develop new security architectures and coding standards. For now, the company’s next step is concrete and modest: learn from a small cohort of provider partners, refine practices, and attempt to balance speed of delivery with the risk of inaccuracies in model-produced reports.


