Driving the news: Under its new Critical Infrastructure Defense Program, Anthropic will provide its frontier AI models, onsite engineers and threat research to companies already responsible for securing critical infrastructure systems.
- Participating companies will use these resources to identify and fix vulnerabilities in their customers’ systems.
- The program’s founding partners include Accenture, Booz Allen Hamilton, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.
- Anthropic said several partners are already using Claude to fix vulnerabilities and help customers do the same.
Zoom in: Anthropic is also launching a free AI-powered vulnerability scanning service for open-source software projects, called OSS Scanner.
- Participating projects will receive periodic scans from Claude, along with automated reports detailing vulnerabilities, how they could be exploited and suggested fixes.
- The reports won’t undergo human review before being sent to software maintainers, meaning some findings could be inaccurate.
The big picture: Anthropic, OpenAI and other AI developers are looking for ways to put their most powerful models in the hands of cyber defenders as hackers gain access to similar capabilities.
- Anthropic’s new initiative builds on lessons from Project Glasswing, which gave vetted organizations access to its most capable AI models to identify security vulnerabilities.
- The company said the project demonstrated how quickly AI can uncover vulnerabilities, but also how difficult it remains to verify and fix them.
Yes, but: It’s unclear how participating companies will safely test and deploy fixes without disrupting utilities’ operations, one of the biggest challenges in securing critical infrastructure.
- Anthropic also didn’t specify whether partners will receive free model access or who will cover the computing costs associated with using its AI tools.