
Anthropic is turning its AI security work into a wider programme aimed at two places where a software flaw can travel far: critical infrastructure and open-source code. The company announced its Cyber Mission on Thursday, saying it will put Claude models, security researchers and engineers to work alongside organisations that defend essential services. It is also opening a free scanning tool to maintainers of important open-source projects.
The infrastructure effort is designed around the systems behind electricity, water, transport and other services that cannot simply be switched off while a security team investigates an alert. Anthropic says it is working with established cybersecurity and industrial-technology partners, including CrowdStrike, Dragos, Palo Alto Networks and Rockwell Automation. The idea is to help defenders identify weaknesses and assess threats faster, but the people running these systems will still have to decide which findings are real and what can safely be changed.
On the software side, the new OSS Scanner is an opt-in service for open-source maintainers. Anthropic says it can periodically examine eligible projects and send reports with an explanation of a suspected vulnerability, a proof of concept and a suggested fix. That could be useful for projects maintained by small teams despite being embedded in products used by millions of people. It is not, however, a promise that every report is correct or that a suggested patch is ready to deploy.
Anthropic is unusually explicit about that limitation. Its announcement says the scanner’s findings are generated by AI and are not reviewed by humans before they reach maintainers. The company expects a true-positive rate above 90%, but that is an expectation, not a demonstrated result for every project. Maintainers may still face a substantial verification burden, especially when the alleged flaw is difficult to reproduce or the proposed repair risks breaking software that others depend on.
The broader tension is familiar. The same models that can help locate a vulnerability may also help an attacker search for one. Anthropic has previously described efforts to disrupt misuse of Claude in cyberattacks and surveillance. Cyber Mission is an attempt to move defensive work earlier in that contest, before a weakness turns into an incident. Its success will depend less on the number of potential flaws a model finds than on whether trusted teams can validate and fix them in time.
There is a practical global angle here. Open-source components are used far beyond the countries where their maintainers live, so a well-supported fix can improve security for organisations in Africa as well as in the US and Europe. But Anthropic has not announced a Nigeria-specific rollout or promised that the scanner will cover every open-source project. Access, eligibility and the quality of the reports will matter as much as the technology itself.
For now, this is a significant commitment of tools and personnel rather than proof that AI has solved cybersecurity. Power grids and public software libraries need careful human oversight, and they need patches that survive contact with the real world. The measure of Anthropic’s mission will be whether it helps defenders close verified gaps without burying them in new alerts.







