Marcus Chen, YuSMP Group
Marcus Chen Staff Engineer (Backend & Cloud), YuSMP Group · Infrastructure security for US and EU enterprise teams
A dim industrial control room with operators at glowing consoles and a wall of network graphs, with a laptop showing code and a magnifying glass on circuit diagrams in the foreground, illustrating AI-assisted vulnerability review

The announcement in brief

AI-driven bug hunting is moving from pilots into the open-source supply chain that most commercial software is built on. On 8 October 2026 Anthropic announced the Anthropic Cyber Mission, a long-term effort that starts with two programs: OSS Scanner and the Critical Infrastructure Defense Program (CIDP).

OSS Scanner gives eligible open-source projects regular, free security scans by Anthropic’s Claude models. Each report comes with a proof of concept, an explanation and, where possible, a suggested fix. CIDP pairs frontier models, on-site engineers and threat research with 11 founding partners that protect operational technology, such as power grids, water systems and transport networks.

The company says the reports are sent without human review and expects a true-positive rate above 90%. Early numbers from maintainers support that claim, but the volume of findings is the real story for anyone who ships software.

How does OSS Scanner work?

OSS Scanner is opt-in. Only core maintainers can enroll a project, and they do it by adding the project to Anthropic’s oss-scanner repository on GitHub. Anthropic borrowed its eligibility rules from Google’s OSS-Fuzz: the service targets established projects with a critical impact on infrastructure and user security, not every library on a package registry.

Enrolled projects get periodic scans. Each finding arrives as a report with a working proof of concept, a plain explanation of the flaw and a proposed patch where the model can produce one. Maintainers decide what to fix and when to disclose.

The early feedback quoted by Anthropic is strong. wolfSSL, which makes an embedded TLS library, received 74 reports in trials; 72 were valid and five became CVEs. PostgreSQL’s Noah Misch said an unusually high share of findings were real defects and that several came with fixes the team could use almost as they were. SiliconANGLE reports that Anthropic’s models flagged more than 29,000 candidate vulnerabilities in widely used software over the past six months.

What is the Critical Infrastructure Defense Program?

CIDP is aimed at operators of operational technology (OT): industrial control systems in energy, water, manufacturing and transport. These environments run old protocols and devices that are hard to patch, which makes them slow to defend and attractive to attack.

Rather than selling directly to utilities, Anthropic is working through security vendors and consultancies that already serve them. The 11 founding partners include OT specialists Dragos, Nozomi Networks and Insane Cyber, automation vendors Rockwell Automation and Hitachi, and large integrators such as Accenture, Deloitte, PwC and Booz Allen. Booz Allen’s Andrew Turner called OT “the next frontier for autonomous AI-enabled attacks”, according to SiliconANGLE.

What are the caveats?

No human in the loop. Anthropic says plainly that reports go out without human review, so some will be wrong. That is a deliberate trade of accuracy for speed, and it puts the triage burden on maintainers.

Data terms. The Register notes that project inputs and outputs may be used for model training under Anthropic’s consumer terms. Maintainers of projects with sensitive code paths should read those terms before enrolling.

Attackers have the same tools. Anthropic itself says attackers currently hold the advantage and expects AI to favour defenders within about two years. Until then, the same capability that finds bugs for maintainers can find them for criminals.

What it means for US & EU software teams

Expect more CVEs in the libraries you already use. The first enrolled projects are exactly the ones inside most stacks: TLS libraries, databases, language runtimes. More findings mean more patch releases, often on short notice. A team that updates dependencies once a quarter will fall behind.

Your patch pipeline is now a security control. Automated dependency updates, a fast test suite and a release process that can ship a library bump within days are what turn upstream fixes into real protection. Without them, a faster upstream only widens the gap between “fixed” and “deployed”.

Regulators expect this discipline anyway. In the EU, NIS2 and DORA require documented vulnerability handling, and the Cyber Resilience Act will add duties for products with digital elements. In the US, SBOM and secure-development expectations already shape federal procurement. An up-to-date software bill of materials is what lets you answer “are we affected?” in minutes.

OT and manufacturing teams should talk to their vendors. If you run plants, grids or logistics hubs, ask your existing security provider whether it takes part in CIDP and what that changes in your assessments.

What to do now

  1. Generate an SBOM for every production service and keep it current in CI.
  2. Turn on automated dependency updates and make sure the test suite can validate a library bump without manual work.
  3. Subscribe to advisories for your most critical upstream projects, such as your TLS library, database and runtime.
  4. Set a patch SLA by severity, for example critical fixes in production within 7 days, and measure it.
  5. If you maintain a critical open-source project, review Anthropic’s data terms and decide whether to enroll in OSS Scanner.

Frequently asked questions

What is Anthropic OSS Scanner?

OSS Scanner is a free, opt-in service launched by Anthropic on 8 October 2026. It runs regular security scans of critical open-source projects with Anthropic’s strongest models and sends maintainers reports with a proof of concept, an explanation and, where possible, a suggested fix.

Who can enroll a project in OSS Scanner?

Only core maintainers can enroll a project, by opening a pull request to Anthropic’s public oss-scanner repository. Eligibility follows Google OSS-Fuzz criteria: established projects with a critical impact on infrastructure and user security.

How accurate are the OSS Scanner reports?

Reports are model-generated and sent without human review. Anthropic expects a true-positive rate above 90%. In early trials wolfSSL found 72 of 74 reports valid, and five became CVEs.

What is the Critical Infrastructure Defense Program?

It is the second part of the Anthropic Cyber Mission. It combines frontier Claude models, on-site engineers and threat research for defenders of operational technology, delivered through 11 founding partners including CrowdStrike, Palo Alto Networks, Dragos, Rockwell Automation and Accenture.

Does OSS Scanner affect companies that only use open source?

Indirectly, yes. More findings in widely used libraries mean more security releases and CVEs. Teams need an up-to-date SBOM, automated dependency updates and a patch SLA so upstream fixes reach production quickly.

Sources

Anthropic — Introducing the Anthropic Cyber Mission (8 October 2026)
The Register — AI company moves to defend critical infrastructure and open-source projects from AI (9 October 2026)
Axios — Anthropic’s new plan to protect critical infrastructure (8 October 2026)
SiliconANGLE — Anthropic launches critical infrastructure program and free OSS Scanner for open source (8 October 2026)