Advertisement

Anthropic rolls out program for ‘long-term commitment’ to secure critical infrastructure, open source software

The critical infrastructure defense program will seek to pair Claude models, Anthropic engineers and threat research with the expertise of cybersecurity companies.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
Aerial view of water treatment factory at city wastewater cleaning facility

Anthropic announced a new program Thursday that will combine its AI tools with outside cybersecurity companies to find and fix cybersecurity vulnerabilities in critical infrastructure and open-source software.

Advertised as part of a new, “long-term commitment” to cybersecurity, the critical infrastructure defense program will pair Claude models, Anthropic engineers and threat research with the expertise of cybersecurity companies, including Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation.

“Defenders of critical infrastructure and the [open-source software] community have decades of security experience but have faced severe resource shortages that are exacerbated by this moment,” Anthropic wrote in a blog post. “We are recognizing their expertise in these domains and offering our support.”

Anthropic said it has offered frontier models and technical support to more than half the states in the U.S., as well as large operators of critical infrastructure to scan and patch code or assist in incident response and red teaming activities.

Advertisement

“Critical infrastructure is hard to defend in many ways that AI cannot fix, but we believe that frontier models can help find and repair weaknesses before those weaknesses are used to cut off power or make water unsafe, the company wrote. “Our first step is to work with a small cohort of providers to learn which strategies are most effective and practical.”

The company said it has engaged in similar work with maintainers of large open-source software projects, and some organizations asked for everything the model had found in their software, even unreviewed findings.

That spurred Anthropic to create a new opt-in scanning service for open source software, where organizations can get free, periodic scans of their projects with a proof of concept, explanation and suggested patching options. Anthropic noted that under this program, organizations will receive their reports faster but they may contain inaccuracies.

The long-term goal is to automate most triage and patching and develop new security architectures and coding standards.

As AI models have developed increasingly powerful cybersecurity capabilities, such as finding and exploiting known vulnerabilities, frontier AI companies have worried that bad actors could gain access to the tools faster than legitimate organizations. Anthropic and OpenAI have since both started programs funneling their tech to businesses and governments, free of charge, for defensive cybersecurity.

Derek B. Johnson

Written by Derek B. Johnson

Derek B. Johnson is a reporter at CyberScoop, where his beat includes cybersecurity, elections and the federal government. Prior to that, he has provided award-winning coverage of cybersecurity news across the public and private sectors for various publications since 2017. Derek has a bachelor’s degree in print journalism from Hofstra University in New York and a master’s degree in public policy from George Mason University in Virginia.

Latest Podcasts