On October 8, 2026, Anthropic announced the launch of the “Anthropic Cyber Mission,” presented as a long-term commitment to “secure the systems everyone depends on.” The US company, which develops the Claude models, wants to provide defenders with tools, research and resources. It is starting with two areas: critical infrastructure and open-source software. Before judging the scope of the announcement, it is worth looking at how the setup works.

Two concrete programs at launch

The first component is the Critical Infrastructure Defense Program (CIDP). It targets operational technology (OT), meaning the controllers, control software and industrial networks that run power grids, water distribution or transport. Anthropic adds the protection of government systems. The CIDP brings three elements: access to the most advanced Claude models, Anthropic engineers on site and the company’s threat research.

Importantly, the program is not aimed directly at operators. It works through the providers they already rely on. The eleven founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. They include consulting firms, IT and industrial security companies, and equipment manufacturers. According to Anthropic, several of these partners already use Claude to fix vulnerabilities.

The second component is OSS Scanner, a free service available on registration, inspired by Google’s OSS-Fuzz. Registered open-source projects receive periodic scans carried out by Anthropic’s most capable models. Each report contains a proof of concept, an explanation and, where possible, a proposed fix. These reports are generated by the model and sent without human review. Anthropic acknowledges that some will contain errors, such as a misjudged severity, and says it is aiming for a true-positive rate above 90%. The service is reserved for projects able to absorb this flow. Others will continue to receive human-verified reports.

What is fact, what is claim and what is intention

Several levels need to be distinguished in the text.

  • Announced facts: the launch of the CIDP and OSS Scanner, the list of partners, and the merger, earlier in the week, of Project Glasswing into an expanded Cyber Verification Program that gives more defenders access to the most capable models. Anthropic also says it has funded the Python Software Foundation, Alpha-Omega and the OpenSSF via the Linux Foundation, as well as the Apache Software Foundation.
  • Claimed track record: since June, a program for US public authorities has reportedly provided models and technical support to more than half of US states. This is a claim by the company that the source does not allow to be verified.
  • Partner statements: the quotes from executives at Rockwell Automation, PwC, Palo Alto Networks, Dragos and CrowdStrike mostly describe ambitions, such as a defense able to act “at machine speed.”
  • Intentions and forecasts: extending the CIDP to other sectors “in the coming months” and publishing what did not work. Anthropic also forecasts that AI will favor defense within two years, while admitting that this may not be the case in the short term.

Clear-eyed about the limits

On one point, the announcement remains measured. Anthropic writes that Project Glasswing led to the discovery of numerous vulnerabilities without sufficiently reducing cyber risk. Finding flaws has become easier; verifying, prioritizing and fixing them remains difficult. The company mentions months between discovery and fix. In OT, where machines often cannot be shut down to be updated, the wait could even last decades in rare cases. Anthropic also acknowledges that frontier models can be misused to exploit vulnerabilities. This is at the heart of the debate on the offensive capabilities of AI models, even though the text does not mention Claude Mythos.

And for Swiss operators?

The source mentions neither Switzerland nor Europe. What follows is therefore analysis, not news. Since the CIDP works through providers, a Swiss operator (electricity distributor, water utility, transport company) cannot access it directly. It will only benefit if its own security or equipment suppliers are part of the small initial cohort, or join it when the program expands. The question to ask one’s providers is therefore simple: are they taking part, and with what validation guarantees before any intervention on a production system?

Two doors seem more directly open. According to Anthropic, the expanded Cyber Verification Program is open to security teams “of all sizes,” including critical infrastructure operators. The source specifies no geographical restriction, but does not confirm the absence of one either. OSS Scanner, for its part, concerns the core maintainers of critical open-source projects, which may include developers based in Switzerland. For the rest, this is for now a US program in a learning phase. It is worth following, without expecting miracles in the short term.

Sources

Julie Favre is an AI editorial persona of 2clics.com.