Anthropic is launching a critical infrastructure protection program under which companies responsible for securing energy grids, water utilities, and other vital facilities will gain access to advanced artificial intelligence models and support from engineers. The initiative is intended to help identify and eliminate vulnerabilities in systems that are often difficult to protect because of their age and technical complexity, Axios reports.
AI will help find vulnerabilities in critical infrastructure
The new Critical Infrastructure Defense Program will bring Anthropic together with companies already engaged in cybersecurity for critical systems. Partners include Accenture, Booz Allen Hamilton, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation.
Anthropic will provide participants with access to its advanced AI models, engineers for on-site work, and threat research. Using these resources, partners will be able to detect vulnerabilities in their clients’ systems and help remediate them. According to the company, some participants are already using Claude to find and fix security issues.
The need for such measures is tied to the fact that advances in AI could make cyberattacks faster and cheaper to carry out. At the same time, critical infrastructure operators continue to work with complex systems, including legacy ones, that are difficult to protect and update.
A free AI scanning service will be launched for open-source projects
At the same time, Anthropic will introduce OSS Scanner, a free AI-powered service for finding vulnerabilities in open-source projects.
Claude will periodically scan projects participating in the program and generate automated reports. These reports will describe discovered vulnerabilities, possible ways they could be exploited, and proposed fixes.
However, the results will not be reviewed by a human before being sent to developers. This means that some recommendations may contain inaccuracies or errors. Developers will have to assess the findings themselves before making changes to the code.
After Project Glasswing, Anthropic is betting on defenders
The new initiative continues Anthropic’s work on Project Glasswing, a project under which vetted organizations were given access to the company’s most powerful models to identify security issues.
According to Anthropic, this experience showed how quickly AI can detect vulnerabilities. At the same time, it revealed another problem: finding a potential security gap is not enough. It is necessary to verify that it actually exists, determine the level of risk, and remediate it safely.
Anthropic is not the only developer trying to use advanced models for cyber defense. Other AI companies are also interested in such capabilities as hackers likewise gain access to tools capable of automating vulnerability discovery and other stages of attacks.
The main question is how to fix vulnerabilities without putting infrastructure at risk
Even if AI detects a problem and suggests a way to fix it, implementing that fix in a critical system may be difficult. A mistake during a software update or while validating changes could disrupt the operation of a facility on which entire cities or industries depend.
Anthropic has not yet explained how program participants will be able to test and deploy fixes without putting municipal and energy systems at risk. It is also unclear whether partners will receive free access to the models or whether they will have to pay for computing resources themselves.
Thus, the program is intended to help specialists find weak points in digital defenses more quickly, but its practical effectiveness will depend not only on AI capabilities. Equally important are verification of results, safe deployment of fixes, and the resources required for this work.






