In this guide
Short answer
Anthropic is expanding defensive AI support, but finding more bugs is only useful when teams can verify and fix them. Its October 8 Cyber Mission combines specialist infrastructure support with an opt-in open-source scanning service. This article separates the launch from our proposed adoption checks.
What was announced
The Cyber Mission announcement introduces a Critical Infrastructure Defense Program with frontier Claude access, on-site engineers and threat research for an initial cohort of eleven partners. Its focus includes the operational technology behind power, water and transport systems.
The same announcement launches free periodic OSS Scanner scans for enrolled open-source projects. Reports include an exploitation proof of concept, an explanation and a proposed fix where available. They are model-generated and delivered without human review. Anthropic expects a true-positive rate above 90%; that is a vendor expectation, not a DiscoverAI benchmark. Projects unable to absorb that flow can continue receiving human-verified disclosures through its existing process.
Why opt-in matters
The scanner research post explains the service and enrollment. Maintainers should inspect that current documentation rather than assuming every public repository is automatically enrolled.
Our editorial assessment is that opt-in gives a project the chance to decide whether it can handle the queue. More findings can create work before they reduce exposure. A small volunteer team needs a way to establish severity, reproduce an issue and judge a patch without diverting all its maintenance time.
A maintainer’s adoption checklist
Assign an owner to triage incoming reports. Decide what evidence is required before marking an issue confirmed, how sensitive reproduction details are stored and when a proposed change can enter review. Keep proof-of-concept execution in an appropriate isolated test environment.
Track the full path: received report, reproducible issue, accepted patch, regression tests, release and adoption. Count incorrect findings and rejected patches too. A good scanning dashboard can coexist with a backlog of unshipped fixes; neither a finding count nor a generated patch count measures reduced risk on its own.
For a pilot, choose a bounded component and document the review effort. Compare the new queue with existing checks and incoming reports. Retain decisions about false positives so repeated findings do not consume the same attention indefinitely.
Infrastructure requires a different deployment standard
For an ordinary application, a reviewed release may be straightforward. For a controller operating a physical process, update timing, compatibility and rollback require the operator’s specialist judgment. The initial partnership model recognizes that domain expertise matters; it is not an invitation to apply model-written patches autonomously to live equipment.
Buyers should ask how a proposed change is validated, who approves deployment and how its effect is observed. Keep that approval separate from the model’s assessment that an issue is serious.
What to watch next
Look for reproducible findings, maintainer workload, accepted fixes and deployed remediation. Independent evaluation would be more useful than repeating a forecast. Anthropic’s broader launch is a commitment and service introduction, not demonstrated elimination of the patch backlog.
See our [earlier Cyber Verification coverage](/articles/anthropic-cyber-verification-three-access-tiers-2026) for the access-program context and our [agent-evaluation report analysis](/articles/anthropic-agent-evaluation-internet-restrictions-2026) for why task boundaries deserve their own tests.
Transparency
How this guide was checked
Editorial accountability
Who checked this guide
- Evaluation type
- Research-based verification
- Last materially checked
- Evidence
- 2 listed sources
Hands-on testing is identified explicitly. Research-based coverage uses cited product documentation and other named sources; it does not imply every paid plan was used. Read the full methodology.
Editorial basis
What this guidance is based on
- Editorial basis
- Source-led analysis
- Primary references
- 2
- Products covered
- 1
- Last checked
- 2026-10-11
Important limits
- • Reported findings and forecasts are attributed to Anthropic; DiscoverAI has not independently reproduced them.
Sources and verification
Product details and claims were checked against the following primary sources.
Frequently asked questions
Are OSS Scanner reports reviewed by people before delivery?
The announcement says enrolled projects receive model-generated reports without human review.
Is the expected true-positive rate independently verified here?
No. It is attributed to Anthropic and is not a DiscoverAI test result.
Tools mentioned in this article
Claude
Anthropic's thoughtful, safety-focused AI with exceptional long-form reasoning
Claude excels at deep analysis, long-form writing, and nuanced reasoning. Built by Anthropic with a focus on safety and helpfulness.
Read next
Recommended for you

Audit AI Citations Before the Answer Leaves Your Team
A clickable citation is a route to evidence—not proof that the evidence is current, authorized, complete, or correctly interpreted.
Use a repeatable source audit for AI research, financial analysis, legal work, and client materials. Check identity, time, rights, support, and transformation.
Read guide
ChatGPT Dots vs. Claude Dispatch: Cloud Agent or Desktop Delegate?
How to Analyze Customer Interviews With AI Without Losing the Evidence
Run a Two-Week AI Desktop Assistant Pilot
