Anthropic Gives Infrastructure Defenders Claude, but Safe Repairs Can Take Decades
Eleven security firms can use Claude and Anthropic expertise, but some industrial systems cannot be taken offline easily to install a fix.
Anthropic launched a program on October 8 that gives a small group of critical-infrastructure security providers access to Claude models, Anthropic engineers and threat research. The goal is to help them find and fix vulnerabilities in systems serving power, water and transport networks.
Finding a flaw is only half the challenge. Some industrial equipment must keep running while it is repaired, and taking it offline to install a security patch may be risky or impossible.
Security help for systems that cannot easily stop
Anthropic’s Critical Infrastructure Defense Program has 11 founding partners:
- Accenture
- Booz Allen
- CrowdStrike
- Deloitte
- Dragos
- Hitachi
- Insane Cyber
- Nozomi Networks
- Palo Alto Networks
- PwC
- Rockwell Automation
Anthropic says several partners are already using Claude to help address vulnerabilities and support their customers. The company describes the group as an initial, small cohort meant to test practical ways to protect operational technology: the controllers, software and industrial networks behind essential services.
These systems can be proprietary and built to last for decades. A shutdown to install a patch may be dangerous or unworkable, leaving known weaknesses in place. Anthropic says repairs may have to wait until they can be made safely. In rare cases, that could take decades.
Axios reported that providers still face the challenge of testing and deploying fixes without disrupting utility operations. Anthropic also says finding vulnerabilities is only part of the work. Defenders must verify, prioritize and repair them.
A free scanner, with no human review
Anthropic has also launched OSS Scanner, a free, opt-in service that periodically checks enrolled open-source projects for security flaws. Reports generated with Claude can include an explanation, a proof of concept and a suggested fix when available.
The reports are sent to maintainers without human review. Anthropic warns that findings, including severity ratings, may be inaccurate. The company says the service is intended for projects equipped to assess the results. It plans to continue human-verified disclosures for projects that need them.
That creates different pressures for the two groups. Open-source maintainers get faster access to possible vulnerabilities, but must assess the reports themselves. Infrastructure operators face a harder operational question: how to apply a repair without interrupting services people rely on.
Anthropic is offering AI-assisted help to find vulnerabilities, but safe repairs still depend on human checks and whether critical systems can be taken offline.
What comes next
Anthropic says it plans to add more partners and sectors over the coming months. Axios reported that the company had not specified whether partners would receive free access to its models or who would cover the computing costs.