Anthropic Critical Infrastructure Security Expands, but Deployment Is the Hard Part
Anthropic expanded its critical infrastructure security effort on October 8, bringing Claude models, threat research, and on-site engineers to 11 founding partners. The program targets power grids, water systems, transportation networks, factories, communications, and government systems. Yet its success will depend on something less dramatic than finding vulnerabilities. Partners must safely verify and deploy fixes without interrupting essential services.
That distinction matters because operational technology, or OT, controls physical equipment and industrial processes. A flawed update in ordinary business software can disrupt a workflow. A flawed change inside a treatment plant, electrical substation, or factory can affect public safety.
Anthropic is therefore placing security vendors, consultants, system integrators, and equipment manufacturers between Claude and infrastructure operators. This partner-led model acknowledges that advanced AI cannot replace the specialized knowledge needed to modify running industrial systems.
The initiative also puts Anthropic into a broader contest over whether frontier AI will favor defenders or attackers. OpenAI has launched its own major cyber defense program, while government agencies continue promoting cautious, risk-based OT security practices. The central question is no longer whether AI can find weaknesses. It is whether institutions can validate and repair them faster than attackers can exploit them.
Anthropic Critical Infrastructure Security Starts With Trusted Providers
Anthropic is not giving an autonomous Claude agent direct control over power plants or water utilities.
The company’s new Critical Infrastructure Defense Program provides frontier Claude models, Anthropic engineers, and threat research to organizations already trusted by infrastructure operators. The 11 founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation.
That membership reveals the program’s operating model. Consulting companies manage security programs. Cybersecurity vendors monitor enterprise and industrial networks. Equipment manufacturers understand the controllers, firmware, and maintenance requirements inside physical facilities.
Anthropic says several partners are already using Claude to find and repair vulnerabilities. Its initial rollout remains deliberately limited, however. The company describes the first stage as a small cohort designed to identify which strategies are practical in operational environments.
The distinction between enterprise IT and OT shapes every part of the effort. Many industrial systems were designed to operate for decades, not to receive weekly software updates. Their components can be proprietary, geographically dispersed, and difficult to replace. Operators may also lack realistic test environments for validating a proposed change.
A utility cannot casually restart a controller that manages water pressure. A factory cannot apply every recommended patch if downtime stops production or creates a safety hazard. Even a technically correct fix can be operationally unacceptable.
Anthropic’s Cyber Mission places domain specialists in the approval path for that reason. Claude can analyze code, reconstruct attack paths, propose patches, and support incident response. Human operators and established vendors still decide whether a recommendation is accurate, safe, and suitable for deployment.
The company says the program will initially cover power, water, transportation, communications, manufacturing, and government systems. Over the coming months, it plans to add partners and sectors while publishing lessons from the work, including failed approaches.
That promise is significant because industrial cybersecurity rarely produces universal fixes. A mitigation that works in one facility can create unexpected consequences in another. Useful reporting will therefore need to describe deployment conditions, validation procedures, false positives, and avoided disruptions.
Anthropic has not disclosed how many infrastructure operators are participating through the founding partners. It also has not published a deployment schedule, program budget, or common performance benchmark. Those missing details prevent an independent assessment of the program’s current scale.
What changed is still clear. Anthropic has moved from experimental access programs toward a structured delivery channel for critical infrastructure defense. The program connects frontier AI capabilities with organizations that can translate model output into controlled operational changes.
Why Vulnerability Discovery Is No Longer Enough
The difficult bottleneck has shifted from finding possible flaws to proving which findings matter and repairing them safely.
Anthropic’s earlier Project Glasswing program showed how quickly AI-assisted security research can generate findings. The company says its partners identified at least 129,000 verified software vulnerabilities between April and July 2026. Anthropic’s open-source scanning reportedly found another 5,500 verified vulnerabilities through October.
More than 33,000 of those findings received critical or high-severity ratings, according to Anthropic. The company calls the total a lower bound because its data came from only 33 partner reports. Fewer than half of participating partners disclosed patch counts.
Those figures are company-reported and use different partner triage methods. They should not be treated as a standardized comparison with conventional security tools. They do demonstrate the scale of the workflow problem created when AI finds weaknesses faster than organizations can assess them.
Anthropic openly identifies that problem in its expanded Cyber Verification Program. The company says verifying, disclosing, prioritizing, and patching findings has become the primary constraint. The new infrastructure initiative attempts to move beyond discovery by involving organizations that already manage these steps for customers.
This is especially important in OT systems. Security teams must consider exploitability, equipment age, process dependencies, available maintenance windows, and the physical consequences of a change. A high-severity software score does not automatically establish the correct operational priority.
The new program can help at several points in that process. Claude can summarize unfamiliar code, compare a vulnerability against system configurations, reconstruct an attack sequence, and draft a proposed repair. It can also support repeated analysis after engineers modify a system.
However, each step needs controls. Models can misinterpret proprietary code, generate an incomplete fix, or overlook a dependency. Automated reports can also overwhelm small security teams if findings lack reliable prioritization.
Anthropic’s separate OSS Scanner illustrates that tension. The opt-in service gives eligible open-source projects periodic scans, exploit explanations, and suggested fixes. Those reports reach maintainers without prior human review, which allows wider coverage but also leaves room for inaccurate findings.
The critical infrastructure program uses a more controlled structure. Established providers supply operational context and human judgment before changes reach live environments. That does not guarantee safe deployment, but it places accountability with organizations familiar with the relevant equipment and customers.
This approach also answers a persistent access problem. Anthropic’s generally available models use conservative cybersecurity safeguards because offensive and defensive work can involve similar commands. A request to exploit a vulnerability might represent authorized testing or a real attack.
The Cyber Verification Program uses tiered access to handle that ambiguity. Defensive teams can obtain capabilities for incident response, malware analysis, and vulnerability validation. Authorized red teams receive broader testing access. A specialized tier covers high-risk systems, including grids, telecommunications networks, financial infrastructure, and aviation systems.
Anthropic says the specialized tier requires extensive organizational review with the United States government. It also retains real-time restrictions on activities that could cause physical harm or widespread disruption. These controls matter because wider cyber capability creates risks alongside defensive value.
The expanded infrastructure initiative therefore represents more than a new model distribution program. It is an attempt to build an institutional verification layer around highly capable, dual-use AI.
The Real Contest Is Defense Speed Versus Operational Safety
Anthropic must help defenders move faster without importing software-industry deployment habits into safety-critical systems.
The strongest evidence for AI-assisted infrastructure security comes from a controlled simulation, not a live utility. Anthropic and Pacific Northwest National Laboratory tested Claude against a high-fidelity water treatment model operated for federal security research.
Researchers used Claude Sonnet 4 with a software scaffold, which connected natural-language instructions to predefined network tools. The system reconstructed an attack against the simulated facility in three hours. PNNL estimated that a human expert would have needed several weeks.
During one test, a predefined method for bypassing Windows User Account Control failed. Claude selected another known technique and continued the attack simulation. That behavior showed why advanced models can help red teams, but it also demonstrated their dual-use potential.
The water system research did not prove that Claude can safely repair a live treatment plant. It showed that AI can accelerate adversary emulation, which recreates attacker behavior to expose defensive gaps. The researchers tested a cyber-physical model rather than production equipment.
This boundary is central to Anthropic critical infrastructure security. Speed benefits defenders when it shortens investigation, testing, and remediation. It creates new danger when recommendations bypass engineering review or reach systems without representative testing.
Government guidance reflects that caution. CISA recommends risk-based decisions for operational technology because unexpected downtime can carry serious consequences. Updates should be tested in an environment that reflects production conditions whenever possible.
CISA’s OT security principles also frame security as a business continuity issue. Decisions must account for system safety, operational requirements, recovery planning, and residual risk. Finding more defects addresses only one part of that framework.
Anthropic’s founding partners can provide missing context. Rockwell Automation understands industrial equipment and product-security processes. Dragos and Nozomi Networks specialize in OT monitoring and threat detection. CrowdStrike and Palo Alto Networks contribute broader incident and threat intelligence.
Consulting firms can connect technical findings to governance, change management, and customer operations. System integrators can identify dependencies that are invisible in a source-code scan. These capabilities explain why Anthropic chose an indirect partner network instead of selling a fully autonomous infrastructure agent.
The tension remains unresolved. Claude can generate more candidate findings than human teams previously handled. Yet every additional finding competes for limited engineering time, test facilities, maintenance windows, and disclosure coordination.
A useful program must improve the ratio of repaired weaknesses to submitted findings. It should also reduce investigation time without increasing unsafe changes. Public vulnerability totals alone cannot demonstrate either outcome.
False positives present one measurable risk. If engineers repeatedly investigate inaccurate reports, the tool consumes the capacity it was meant to restore. False negatives matter too, although they are harder to observe. A model that misses an exploitable path can create misplaced confidence.
Model behavior can also vary across prompts, tools, and system contexts. Industrial operators need reproducible evidence showing why a recommendation applies to their equipment. They need rollback procedures when a change produces unexpected behavior.
These requirements do not negate the value of AI security plans. They define the conditions under which those plans become useful. The winning system will not simply detect the most vulnerabilities. It will consistently turn well-supported findings into safe, documented, and recoverable changes.
OpenAI Raises the Pressure on Anthropic’s Partner Model
Anthropic is building a specialist delivery network while OpenAI is competing through broader funding, access, and training commitments.
OpenAI announced Daybreak for Frontline Defenders in September 2026. The company committed $1 billion in subsidized access, technical support, training, and partnerships for organizations protecting essential services.
Daybreak targets water systems, electricity providers, local governments, health systems, community banks, and other frontline organizations. OpenAI also describes a Defense Factory approach that uses agents to find vulnerabilities, validate them, and prepare tested fixes for human review.
The Daybreak initiative gives Anthropic a direct strategic comparison. Both companies argue that frontier models should help defenders before similar capabilities become widely available to attackers. Both emphasize human review and the need to validate fixes.
Their initial delivery choices differ. OpenAI has attached a stated global commitment and a broad access mission to its program. Anthropic has emphasized a founding cohort of 11 providers with established infrastructure relationships and on-site technical support.
Neither approach has yet produced enough public evidence to establish superiority. A large funding commitment does not guarantee adoption in under-resourced utilities. A selective partner program does not guarantee that benefits will reach small operators beyond major customer accounts.
Anthropic’s route has practical advantages. Infrastructure operators already depend on equipment makers, integrators, consultants, and security vendors. Adding Claude to those existing relationships can reduce the need for operators to evaluate a frontier model provider directly.
The model also lets Anthropic learn from multiple security layers. Equipment manufacturers see product defects. network-security vendors observe attack behavior. Consultants manage governance and implementation. Combining those perspectives can improve prioritization.
However, the partner route introduces coordination costs. Each company has its own products, customer contracts, data policies, testing methods, and commercial incentives. Anthropic has not explained how participants will share findings or measure results across the cohort.
OpenAI’s wider initiative creates another kind of pressure. A utility comparing AI security plans may ask whether it should access models directly, work through an existing provider, or join a government-supported program. Fragmented access channels can complicate an already crowded security market.
Competition can still benefit defenders. Anthropic expects other AI developers, governments, and security companies to launch related efforts. Shared evaluation methods, vulnerability disclosures, and tested remediation guidance would matter more than exclusive claims about model performance.
There is also a systemic reason to avoid dependence on one laboratory. Frontier models can experience outages, policy changes, and newly discovered safety problems. Critical infrastructure organizations need resilient workflows that remain usable if a model becomes unavailable.
The healthiest competitive outcome would separate model choice from operational control. Operators should be able to compare findings, preserve audit records, require human authorization, and switch providers without rebuilding their security processes.
Anthropic’s partner model will face that test as it expands. If Claude becomes deeply embedded inside vendor platforms, customers will need clarity about data handling, model access, incident reporting, and responsibility for flawed recommendations.
The competition is therefore not just Anthropic versus OpenAI. It is a contest between different ways of delivering advanced cyber capability into institutions with limited tolerance for error.
What Anthropic’s AI Security Plans Still Do Not Prove
The announcement establishes a serious delivery structure, but it does not yet establish measurable risk reduction.
Anthropic says success means fewer exploitable attack paths, faster recovery, and continued operation during attacks. Those are sensible outcomes. The company has not yet provided a baseline, target, reporting schedule, or independent evaluation process for measuring them.
The published numbers from Project Glasswing mainly describe discovered vulnerabilities. Discovery volume can rise even when an organization’s overall exposure remains unchanged. Risk declines only after teams validate, prioritize, remediate, deploy, and monitor the relevant fixes.
Patch completion is therefore more useful than finding volume, but even that metric needs context. A hundred minor software corrections may matter less than one verified repair to a remotely reachable controller. Counts should be paired with severity, exploitability, deployment status, and affected-system criticality.
Time measurements also matter. The program should report how long teams take to move from detection to validation and from validation to safe remediation. Faster triage would support Anthropic’s central argument even when a facility cannot immediately deploy a patch.
Safety outcomes need equal weight. Operators should track failed tests, rejected recommendations, rollbacks, unplanned downtime, and model-generated changes that required major correction. Publishing these results would help distinguish operational progress from promotional activity.
The current disclosure leaves commercial questions unanswered. Anthropic has not said whether founding partners receive model access without charge. It also has not explained who pays for inference, engineering support, testing facilities, or long-term maintenance.
These details affect adoption. Large infrastructure vendors can absorb experimental costs more easily than municipal utilities or regional health systems. A partner program could improve elite defenses while leaving smaller operators exposed unless benefits reach customers at sustainable terms.
Data handling creates another unresolved issue. Infrastructure security work can reveal network diagrams, device configurations, vulnerabilities, and response procedures. These records are highly sensitive even when they do not include ordinary customer information.
Anthropic’s verification program requires data retention for many participants so the company can monitor misuse. It has announced additional safeguards for organizations that need stronger control over stored information. The infrastructure program should explain which arrangements apply to each partner workflow.
Accountability also needs definition. Suppose Claude proposes a repair, a vendor approves it, and an operator deploys it. If the change disrupts service, responsibility could involve the model provider, security partner, equipment manufacturer, integrator, or operator.
Existing contracts may allocate that liability, but the public announcement does not address it. Clear approval records and traceable evidence will become essential as models contribute more directly to remediation.
The program must also defend against automation bias. Engineers can overvalue a confident recommendation when it comes from an advanced model. Requiring independent validation, documented assumptions, and explicit human authorization can reduce that risk.
Anthropic acknowledges that AI cannot fix many of the hardest infrastructure problems. That restraint strengthens the announcement. Aging equipment, staff shortages, incomplete asset inventories, constrained budgets, and limited maintenance windows will remain after Claude arrives.
The credible case for Anthropic critical infrastructure security is therefore narrower than universal automation. Claude can expand expert capacity, accelerate controlled analysis, and help trusted providers prepare fixes. It cannot eliminate the operational constraints that determine whether those fixes reach production.
Three Signals Will Show Whether the Program Works
The next evidence should focus on deployed repairs, repeatable safety controls, and access beyond the founding cohort.
The first signal is a verified remediation report from a participating provider. Anthropic or a partner should document how Claude found a weakness, how experts validated it, and how the operator tested the proposed correction. The report should explain whether the repair reached production and whether service continued normally.
That evidence would strengthen the program’s core claim. It would connect model capability to measurable risk reduction inside a real operational workflow. A report limited to vulnerability discovery would leave the central question unanswered.
The second signal is a common safety and evaluation framework across the 11 partners. Useful criteria would include false-positive rates, validation requirements, authorization controls, rollback plans, audit logging, and deployment outcomes. Shared methods would make results more comparable across sectors.
A fragmented framework would weaken confidence. Each partner needs flexibility for its customers, but entirely different measurements would prevent operators from understanding performance. Common minimum controls could coexist with sector-specific procedures.
The third signal is evidence that the program reaches smaller infrastructure operators. Anthropic says it will expand into more sectors and partners over the coming months. The important measure is not simply a longer partner list. It is whether municipal utilities, regional hospitals, and smaller transportation providers gain usable support.
That access might arrive through managed services, government partnerships, equipment vendors, or expanded verification programs. Whatever the route, it should include technical assistance rather than model access alone. Under-resourced organizations rarely lack security alerts. They lack people and time to investigate and act on them.
OpenAI’s competing initiative will make this distribution question harder to avoid. Both companies now argue that defenders have a limited window before AI-assisted attacks become more capable. Their progress should be judged by protected organizations, safely deployed fixes, and improved recovery, not commitments alone.
Readers who manage security, procurement, or infrastructure technology should ask direct questions before adopting these systems. What evidence supports each finding? Where is sensitive data stored? Who authorizes testing? How are physical consequences modeled? What happens when a recommendation fails?
Developers should watch whether the security partners publish reusable tooling and verified patches. Open-source maintainers should examine how automated findings affect triage workloads. Enterprise buyers should request auditability, reproducibility, and clear responsibility boundaries.
The next phase of Anthropic critical infrastructure security will not be defined by another impressive vulnerability total. It will be defined by whether trusted providers can convert model speed into safer systems without creating new operational hazards.
That is the action worth following over the next three months. Look for a verified deployment case, shared partner controls, and access for smaller operators. If all three appear, Anthropic’s program will begin to show that AI can improve infrastructure defense beyond a controlled demonstration.



