Security5 publishersAlso reported elsewhere2 min readPublished
Anthropic pairs Claude with CrowdStrike and Dragos in a critical infrastructure defense program
Anthropic announced a Critical Infrastructure Defense Program that pairs Claude with outside security firms, CrowdStrike among them. Alongside it, Anthropic is running a free, opt-in scanning service for open-source maintainers directly, CyberScoop reported.
The Watch · Security desk

What happened
- CyberScoop's account of Thursday's announcement lists 11 partners, among them Accenture, Booz Allen, Deloitte, Dragos, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.
- Anthropic says it has already given frontier models and technical support to more than half of US states and to large infrastructure operators for scanning, patching, incident response and red teaming.
- Enrolled open-source projects are scanned periodically, and each report carries a proof of concept, an explanation and suggested patch options.
- CrowdStrike says membership gives it Anthropic's technical guidance, frontier cybersecurity research and a community of infrastructure-focused leaders.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- cost Maintainers who opt in do the review Anthropic skipped, spending their own hours separating real bugs from model errors before they trust a suggested patch.
- decision Operators below the large-operator tier who expect AI-found bugs to arrive through CrowdStrike or Dragos have no product or date to plan around, because direct access has so far gone to states and large operators.
- constraint In OT, a finding does not convert directly into a fix, because CrowdStrike itself says patching in those environments is not always possible.
The open-source scan exists because maintainers asked for it. Some organizations wanted everything the model had found in their software, including findings nobody had reviewed [6]. Anthropic said reports under the new service arrive faster and may contain inaccuracies [8]. That puts the review on the maintainer, who has to separate real bugs from model errors before trusting a suggested patch [18].
Anthropic called the infrastructure side a trial. "Our first step is to work with a small cohort of providers to learn which strategies are most effective and practical," the company wrote [5]. It was also direct about limits. "Critical infrastructure is hard to defend in many ways that AI cannot fix," Anthropic wrote, adding that frontier models "can help find and repair weaknesses before those weaknesses are used to cut off power or make water unsafe" [9].
Only part of the vendor channel is visible so far. CrowdStrike already offers Claude inside its Charlotte AI product [12], so Falcon customers can reach Anthropic's models today. CrowdStrike's post calls the new program a forum to share defensive practices, inform research and put frontier AI expertise behind the organizations already defending these environments [10]. The post does not describe partners scanning customer code with program tooling or give a date for it [10]. The evidence shows the incumbents are part of the program. It does not yet show AI-found bugs reaching operators through their consoles.
Repair is the hard step in the sectors the program targets. Writing about energy, water, manufacturing and transportation, CrowdStrike wrote: "Downtime is not an option, and patching isn't always possible." [13]
Some readers can ignore this announcement for now. Anthropic's existing access has gone to states and large infrastructure operators. The infrastructure program is limited to a small cohort of providers, and the scan covers open-source projects. An operator outside those groups has nothing in the announcement to request today [19].
The program fits a pattern among frontier labs. Anthropic and OpenAI have both started programs that give their technology free to businesses and governments for defensive security [15]. Those programs followed worries at frontier AI companies that attackers could get the tools faster than legitimate organizations [14]. Anthropic's stated long-term goal is to automate most triage and patching and to develop new security architectures and coding standards [16].
What to watch
- Any of the 11 named partners shipping a customer feature built on the program, with a release date attached.
- Anthropic publishing what the small provider cohort learned, or opening the infrastructure program beyond it.
- Maintainers reporting how many opt-in scan findings held up on review.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Anthropic announced a new program Thursday that will combine its AI tools with outside cybersecurity companies to find and fix vulnerabilities in critical infrastructure and open-source software.
- [2]
The critical infrastructure defense program pairs Claude models, Anthropic engineers and threat research with cybersecurity companies including Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.
- [3]
CrowdStrike is joining Anthropic's Critical Infrastructure Defense Program.
- [4]
Anthropic said it has offered frontier models and technical support to more than half the states in the U.S., as well as large operators of critical infrastructure, to scan and patch code or assist in incident response and red teaming.
- [5]
"Our first step is to work with a small cohort of providers to learn which strategies are most effective and practical."
- [6]
Anthropic said some organizations whose open-source projects it worked with asked for everything the model had found in their software, even unreviewed findings.
- [7]
Anthropic created an opt-in scanning service for open-source software in which organizations get free, periodic scans of their projects with a proof of concept, explanation and suggested patching options.
- [8]
Anthropic noted that under the open-source scanning program, organizations will receive their reports faster but they may contain inaccuracies.
- [9]
"Critical infrastructure is hard to defend in many ways that AI cannot fix, but we believe that frontier models can help find and repair weaknesses before those weaknesses are used to cut off power or make water unsafe"
- [10]
CrowdStrike describes the program as creating a forum to share defensive practices, inform research, and put frontier AI expertise behind the organizations already protecting critical infrastructure environments.
- [11]
Through the program, CrowdStrike will have access to Anthropic's technical guidance, frontier cybersecurity research, and a community of leaders focused on critical infrastructure.
- [12]
Claude is available within CrowdStrike Charlotte AI.
- [13]
"Downtime is not an option, and patching isn't always possible." (CrowdStrike, on environments powering energy, water, manufacturing and transportation that combine decades-old OT with modern IT)
- [14]
As AI models developed more powerful cybersecurity capabilities, such as finding and exploiting known vulnerabilities, frontier AI companies worried that bad actors could gain access to the tools faster than legitimate organizations.
- [15]
Anthropic and OpenAI have both started programs funneling their technology to businesses and governments, free of charge, for defensive cybersecurity.
- [16]
The long-term goal is to automate most triage and patching and develop new security architectures and coding standards.
- [17]
CyberScoop's list names 11 partner companies.
Derived - [18]
Under the opt-in scan, verifying findings falls to the receiving maintainer, who must separate real bugs from model errors.
Derived - [19]
An operator that is not a US state, a large infrastructure operator, a partner firm in the cohort, or an open-source maintainer has nothing in the announcement it can request today.
Derived
Sources
5 independent publishers whose own reporting we read for this story.
- crowdstrike.comCrowdStrike and Anthropic Give Critical Infrastructure Defenders the AI Advantage
1 article
- cyberscoop.comAnthropic rolls out program for ‘long-term commitment’ to secure critical infrastructure, open source software
2 articles · October 8, 2026
- mezha.netAnthropic залучає партнерів до кіберзахисту критичної інфраструктури
1 article · October 8, 2026
- siliconangle.comAnthropic launches critical infrastructure program and free OSS Scanner for open source
1 article · October 8, 2026
- theverge.comAnthropic launches free AI security scans for open-source projects
1 article · October 8, 2026