EN AR
EN

Anthropic opens frontier AI models to power and water defenders

Nada Salam

Key Points

  1. Anthropic is sending frontier models, engineers and threat research to firms defending critical infrastructure.
  2. Eleven founding partners include CrowdStrike, Palo Alto Networks, Dragos, Deloitte and Rockwell Automation.
  3. The push lands as AI makes cyberattacks on aging utility systems faster and cheaper to run.

The latest:

Anthropic is putting its most powerful AI models, on-site engineers and threat research into the hands of companies that secure power grids, water utilities and other critical infrastructure, the company told Axios. The Critical Infrastructure Defense Program launches with 11 founding partners and a separate free scanning service for open-source software. Anthropic said several partners already use Claude to fix vulnerabilities.

Details:

  • The program: Under the Critical Infrastructure Defense Program, Anthropic will supply frontier models, engineers placed on site and its own threat research to firms already responsible for securing critical infrastructure systems. Those companies will use the resources to find and fix vulnerabilities inside their customers’ networks, according to Axios.
  • The partners: Founding partners named by Anthropic are Accenture, Booz Allen Hamilton, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation — a mix of consultancies, endpoint security vendors, industrial control specialists and automation manufacturers.
  • Already running: Anthropic said several of the founding partners are using Claude today to remediate vulnerabilities and to help their own customers do the same, meaning the program formalizes work already underway rather than starting from zero.
  • The scanner: Anthropic is separately launching OSS Scanner, a free AI-powered vulnerability scanning service for open-source software projects. Enrolled projects get periodic scans from Claude plus automated reports listing vulnerabilities, how each could be exploited, and suggested fixes.
  • The caveat: Those scanner reports will reach software maintainers without human review first, which Anthropic acknowledged means some findings could be inaccurate. Open-source maintainers would effectively absorb the triage burden of sorting real flaws from false positives.
  • The precedent: The initiative builds on Project Glasswing, which gave vetted organizations access to Anthropic’s most capable models to hunt security flaws. The company said Glasswing showed how fast AI can surface vulnerabilities — and how hard verifying and fixing them remains.
  • The threat picture: Critical infrastructure operators are struggling to secure aging, complex systems at a moment when AI is making cyberattacks faster and cheaper to execute, according to Axios. Anthropic, OpenAI and rival developers are racing to put frontier models with defenders as attackers gain comparable tools.
  • Open questions: It is unclear how partners will test and deploy fixes without disrupting utility operations, among the hardest problems in infrastructure security. Anthropic did not specify whether partners get free model access or who covers the computing costs of using its tools.

Background:

Project Glasswing was Anthropic’s earlier, narrower experiment: vetted organizations were granted access to its strongest models purely to identify security vulnerabilities. The new program widens that access to named commercial defenders and adds engineers and threat research to the model access.

Between the lines:

The unreviewed OSS Scanner reports and the unanswered question of who pays for compute point to the same gap: Anthropic is supplying detection capacity, while verification, remediation and cost fall to partners and maintainers. Glasswing’s own lesson, as the company described it, was that finding flaws is the fast part and fixing them is not — a constraint the new program has not visibly solved.

What’s next

Watch whether Anthropic discloses compute terms for partners, how many open-source projects enroll in OSS Scanner, and whether early scanner reports generate usable fixes or false-positive complaints from maintainers.

What to read next