Anthropic Launches AI Tools for Open-Source Security and Operational Technology Defense
Anthropic introduces OSS Scanner for AI-driven vulnerability reporting in open-source projects and the Critical Infrastructure Defense Program to bolster OT security.

Anthropic has unveiled two significant cybersecurity initiatives aimed at enhancing the security posture of both open-source software and critical operational technology (OT) infrastructure. The first, OSS Scanner, leverages advanced AI models to automatically identify and report vulnerabilities within open-source projects, while the second, the Critical Infrastructure Defense Program (CIDP), focuses on securing the systems that power essential services.
OSS Scanner is a free service designed to assist open-source maintainers by proactively discovering potential security flaws. Inspired by Google's OSS-Fuzz, the tool utilizes Anthropic's most capable AI models to scan opted-in projects. Each report generated by OSS Scanner includes a detailed explanation of the vulnerability, a proof-of-concept demonstrating its exploitability, and, where available, suggested fixes. This initiative aims to accelerate the vulnerability disclosure and remediation process, addressing a bottleneck that has previously delayed the patching of critical flaws.
Anthropic acknowledged that while finding vulnerabilities has become easier with AI, the subsequent steps of verification, prioritization, and patching remain challenging. Lessons learned from previous efforts, such as Project Glasswing, indicated that even when vulnerabilities are uncovered, their resolution can take months. By providing AI-generated reports directly to maintainers without human review, OSS Scanner aims to expedite this process. However, Anthropic cautions that some reports may contain inaccuracies, such as incorrect severity ratings, but expects a true-positive rate exceeding 90% and plans continuous improvement.
The Critical Infrastructure Defense Program (CIDP) targets the security of operational technology (OT) systems, which are vital for sectors like power, water, manufacturing, and transportation. This program brings Anthropic's frontier Claude models, on-site engineers, and threat research capabilities to companies that provide OT security solutions. The initial cohort of founding partners includes prominent firms such as Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation, encompassing consulting firms, security vendors, and industrial equipment manufacturers.
Anthropic highlighted the unique challenges in securing OT environments, where systems often cannot be taken offline for patching, leading to vulnerabilities remaining unresolved for years, and in some rare cases, patches taking decades to implement safely. The CIDP aims to address these issues by providing enhanced AI capabilities and expert support to OT security providers. Several partners are reportedly already utilizing Claude to assist in fixing vulnerabilities and supporting their customers.
Anthropic is commencing CIDP with a select group of providers to refine the most effective and practical strategies for OT security. The company plans to expand the program to more partners and sectors in the coming months, indicating a long-term commitment to safeguarding critical infrastructure. This dual approach underscores Anthropic's strategy to apply its AI advancements across different facets of cybersecurity, from software development to the protection of essential physical systems.
The company's efforts reflect a broader trend in the cybersecurity industry where AI is increasingly being deployed not only for threat detection and response but also for proactive vulnerability management and the defense of critical infrastructure. By bridging the gap between AI-driven vulnerability discovery and the complex realities of OT security, Anthropic seeks to make a tangible impact on global cybersecurity resilience.