The cyber arms race just crossed into the physical world — and for the first time, defenders are being handed the same AI firepower attackers already have, pointed straight at the systems that keep our lights on and our water flowing.
The Arms Race Just Moved Down to the Grid
Picture this: an attacker armed with an autonomous AI agent scans the public internet for vulnerabilities at network speed, chains exploits across open-source projects, and within seconds — not hours, not minutes — finds a path into an operational technology (OT) network running a city's water treatment plant. That is no longer a thriller script. It is Tuesday.
The asymmetry that defined the last decade of cybersecurity has always been this: attackers need one working exploit, defenders need every one to hold. That imbalance is collapsing fast. Highly capable AI models are now widely available to attackers as a service — but, until this week, the defensive tools built around them had not reached enough defenders to matter. That changes today.
On October 8, 2026, Anthropic launched the Anthropic Cyber Mission — a Critical Infrastructure Defense Program that ships frontier Claude models, on-site engineers, and dedicated threat research directly into the networks that most of us never think about until the lights go out. It is the closest thing yet to a coordinated "AI defense equals AI offense" moment on the physical grid.
Inside the Cyber Mission: Claude Goes On-Site at the Grid
The program is deliberately small at launch: a founding cohort of eleven partners who already sit in the operating rooms of critical infrastructure. Accenture, Booz Allen, Deloitte, and PwC bring the consulting reach; CrowdStrike and Palo Alto Networks bring the endpoint and network detection; Dragos, Nozomi Networks, and Insane Cyber bring the OT-specialized know-how; and Hitachi and Rockwell Automation bring the industrial control hardware itself.
The value proposition is blunt: Claude finds the weaknesses, the partners decide which ones matter, and together they patch them — before an autonomous agent does it for someone with darker intentions. Anthropic has already offered frontier model access to more than half the U.S. states and to large infrastructure operators for code scanning, incident response, and red-team support, but the Cyber Mission formalizes that into a standing partnership rather than an ad-hoc favor.
The Bottleneck Problem Nobody Wants to Talk About
Here is the dirty secret of OT security: the systems running our power grids, water utilities, and factories were built to last for decades — not to be rebooted every Patch Tuesday. A breaker panel in a substation or a PLC on a factory floor can sit unpatched for years because taking it offline means taking the line down. Known flaws don't get fixed; they become permanent features of the architecture.
As one partner put it, OT is "the next frontier for autonomous AI-enabled attacks" — because the attacker only needs the one path that never got patched, while the defender carries the weight of every system that cannot be patched at all [SiliconANGLE]. Discovery has gotten cheaper and faster; remediation, tragically, has not.
The OSS Scanner: Shoot First, Validate Second
Tackling the open-source half of the problem, Anthropic also launched OSS Scanner — a free, opt-in service that runs its strongest models against eligible open-source projects and ships maintainers a report that includes a proof-of-concept exploit, a severity estimate, and where possible a candidate patch.
The catch is intentional: reports go out without human review, so they land faster but some will contain mistakes, from wrong severity ratings to duplicate findings. The trade is worth it, because the alternative is letting maintainers drown in a backlog while attackers automate the same scan-and-exploit loop themselves.
Anthropic tested the scanner before opening it up. Of 97 critical and high-severity findings reviewed across 48 projects by expert penetration testers, 85 cleared the bar for disclosure [Anthropic Research]. Independent security firms — including Trail of Bits, Ada Logics, Doyensec, Ophion Security, Anvil, and Calif.io — now also vet Claude-generated findings through the coordinated disclosure pipeline before anything is reported privately to maintainers.
The Numbers Behind the Fire Hose
As of October 2, Anthropic's coordinated disclosure program had produced an eye-catching stack of metrics [Data Studios]:
- 6,157 vulnerabilities disclosed across 591 open-source projects
- 5,103 findings acknowledged by maintainers; 516 patched upstream
- 584 formal identifiers issued — 219 CVEs plus 365 GitHub Security Advisories
- 5,674 of 6,123 externally reviewed findings confirmed valid — a 92.7% true-positive rate
- Roughly 29,000 candidate vulnerabilities generated, with about 6,000 manually reviewed and 5,000 reports sent directly to maintainers who asked for the full unreviewed batch
That 29,000-to-6,000 gap is the pipeline in action: Claude generates candidates at machine speed, and human reviewers filter the plausible noise from the real bugs. The 92.7% true-positive rate in the reviewed subset is the part that should make defenders sit up — AI-generated reports are no longer "mostly slop." They are, in practice, beating manual triage.
The CVE Gap: Finding Bugs Faster Than Bureaucracy Can Name Them
But here is where the story gets uncomfortable. For all that discovery velocity, only 584 of those 6,157 disclosed flaws earned formal identifiers (CVEs + GHSAs). That is a 9.5% identification rate — the gap between "we found a real bug" and "bureaucracy has a number for it" has become one of the most important security metrics nobody is tracking publicly.
Discovery jumped 168% between Anthropic's August 26 snapshot (2,300 disclosures across 392 projects) and October 2 (6,157 across 591 projects) [Data Studios]. Patching over that same stretch rose just 23% (421 to 516). The bottleneck is no longer finding vulnerabilities — it is validating, prioritizing, and fixing them. As Anthropic puts it: independent human triage is now the rate-limiting step in the entire security pipeline [Anthropic Research].
That divergence tells defenders exactly where to point their budget: not at the scanner that never sleeps, but at the human teams that still have to read, reproduce, and act on what it finds.
State Adversaries Are Already Living in the Grid
The urgency underneath all of this is that AI as an offensive tool is not theoretical. Recent incidents have shown frontier models breaking into dozens of organizations, and the public record shows state-sponsored adversaries already embedded deep in OT environments across multiple sectors. The defensive window is closing: once attackers have the same automated discovery, exploit generation, and lateral-movement capability as Anthropic's partners, the "small cohort" advantage of the Cyber Mission disappears.
Anthropic's forecast is that defenders should have the upper hand within two years, once AI catches bugs before they ship [The Register]. Until then — and this matters — attackers have the advantage. The question is whether the defenders who sign on today close that gap fast enough.
What This Means for Your Security Posture
For aratech's clients operating critical infrastructure and high-value open-source dependencies, the new equation is simple: the defender's advantage will come not from buying a bigger firewall, but from running the same AI models the attackers already have — and doing it with a human-in-the-loop triage and patching workflow that does not drown maintainers.
The Client Takeaway
If your organization runs OT environments, maintains widely used open-source packages, or operates infrastructure that cannot tolerate frequent downtime, the Cyber Mission is a direct line into Claude-level vulnerability discovery today — not in two years when the general market catches up. The practical plays are:
- Map your unpatchable surface — inventory OT assets that cannot reboot on a patch cadence, and treat them as permanently exposed to automated discovery
- Enroll high-impact OSS projects in OSS Scanner via the open opt-in pull request to Anthropic's GitHub repository — if your project is on the critical-path of infrastructure, the free scan now ships exploitable proof-of-concepts faster than a CVE number gets assigned
- Stand up an AI-triage layer that can scale with discovery — pair model findings with human validation, because the 92.7% true-positive rate still leaves noise that will consume a SOC team that is not prepared for machine-speed volume
- Demand model access on your terms — negotiate for Claude-grade discovery on your own networks rather than waiting for the attackers to bring the same capability to their next red-team engagement
The grid does not wait for consensus. Neither should your defense.
*Published by Aratech — AI-powered digital innovation. Stay ahead of the threat curve.