← Back to the feed

Anthropic launches AI vulnerability scanning for infrastructure and open-source projects

The Register ·

Anthropic has launched the Anthropic Cyber Mission to help critical infrastructure operators and selected open-source projects find and fix software vulnerabilities using its AI models. The move aims to give defenders access to capabilities that could also help attackers, at a time when the company says security teams face serious resource shortages.

The effort has two parts: a Critical Infrastructure Defense Program, which pairs Anthropic’s most capable models with on-site engineers and industry partners, and OSS Scanner, which offers regular scans to established open-source projects with significant security impact. Reports are automated and not reviewed by people; participating maintainers must also accept terms allowing scan inputs and outputs to be used for model training. Anthropic says AI now finds more than 85 per cent of vulnerabilities, compared with 20 per cent at the start of 2025, and predicts defenders may gain the advantage within two years, while attackers have it for now.

  • Anthropic is offering AI security support to critical infrastructure and selected open-source projects.
  • Its OSS Scanner sends automated vulnerability reports without human review.
  • Anthropic says attackers have the advantage for now, but expects that to change within two years.

New here? Start with this

Software vulnerabilities are flaws in computer code that can be exploited by attackers to damage systems, steal data, or gain unauthorised access. Finding and fixing these flaws before attackers discover them is a critical priority for organisations that manage important infrastructure and popular software that millions of people rely on.

Security teams responsible for hunting down vulnerabilities have long faced resource constraints—there is far more code to check than there are people available to check it. Artificial intelligence has emerged as a potential tool to speed up this process and help identify flaws that human reviewers might miss.

The use of AI for security scanning creates both opportunity and complexity. Such tools could help defenders strengthen systems and software against attacks, but the same powerful AI capabilities designed to find vulnerabilities could eventually be adapted for malicious purposes, which is why how these tools are developed and shared matters.

Both sides, in good faith

The strongest fair case each way — we don't pick a winner.

The case for

Anthropic's programme addresses a critical imbalance in cybersecurity. Defenders struggle with severe resource constraints whilst attackers already exploit undetected vulnerabilities, making AI vulnerability scanning with 85 per cent detection rates a transformative capability for under-resourced security teams. By providing these tools to critical infrastructure operators and important open-source projects, Anthropic helps level an unequal playing field and gives defenders the assistance they desperately need to protect systems that society depends upon.

The case against

Anthropic risks accelerating a dangerous arms race by distributing advanced vulnerability scanning capabilities. Whilst attackers currently lack such automated tools, they will inevitably gain access and exploit these models far more effectively than resource-constrained defenders, making the current advantage temporary and illusory. The requirement for training data consent also creates misaligned incentives for Anthropic, and automated reporting without human review compounds risks of false positives or unintended security consequences.

AI Business Companies Technology

Read the full article at the source →

Originally published by The Register as “AI company moves to defend critical infrastructure and open-source projects from AI”.