Anthropic Turns Claude Toward Critical Infrastructure

Anthropic Turns Claude Toward Critical Infrastructure

Artificial Intelligence & Machine Learning
,
Critical Infrastructure Security
,
Next-Generation Technologies & Secure Development

11 Industry Partners Will Pair Claude With Engineers to Tackle OT Vulnerabilities

Tiffany Wang •
October 9, 2026    

Anthropic Turns Claude Toward Critical Infrastructure
Image: Shutterstock

Anthropic is taking a crack at fixing vulnerable operational technology systems that cannot easily be taken offline to patch by pairing artificial intelligence with human expertise on the intricacies of OT.

See Also: Freeing Public Security and Networking Talent to do more with Automation

Through its Critical Infrastructure Defense Program announced Thursday, the AI developer is giving frontier Claude models, on-site engineers and threat research to 11 companies that advise operators of power grids, water utilities, factories, transportation networks and government systems.

The program makes a nod to the complexities of OT and internet of things systems, but its impact will depend on whether operators can implement prioritized fixes as quickly as AI identifies vulnerabilities, without disrupting operations.

“The real challenge in securing critical infrastructure environments is parsing through those risk signals to find the ones that need the most immediate attention where taking a system offline can have serious consequences,” Jen Sovada, public sector general manager at OT security firm Claroty, told ISMG.

The program follows the company’s expansion of its Cyber Verification Program to all critical infrastructure operators, offering access to AI models with reduced guardrails for defensive and offensive cybersecurity work (see: Anthropic Expands Access to Frontier Cyber AI Models).

“It acknowledges how unique OT/IoT systems are from a patching and maintenance perspective,” said John Gallagher, vice president of OT cyber hygiene provider Viakoo. “For example, many OT/IoT systems only patch during a quarterly maintenance window, yet with AI-driven threats shrinking the time to exploitation down to a day or two it requires new methods of patching at scale and at AI-speed.”

The OT defense program brings in “a small set of trusted providers” that tell OT maintainers what’s exposed and which fixes to make on a running system to complement the limitations of AI.

Anthropic said the program’s founding partners – Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation – have already started using Claude to fix vulnerabilities and propagate those results to their customers.

“Our first step is to work with a small cohort of providers to learn which strategies are most effective and practical,” the company said.

Although these large commercial providers serve only a fraction of the country’s critical infrastructure, the initiative marks an effort to close the widening gap between AI-powered attacks and defenses.

Cyberattacks disrupting critical infrastructure have made headlines in recent months. A small power plant in the United Kingdom was knocked offline for four days in August, while more than 30 community water systems in Minnesota were forced to switch to manual controls over two days in July following a coordinated attack (see: Hackers Disrupt Controls at Minnesota Water Utilities).

Programmable logic controllers, devices that automate industrial machinery and processes, have drawn scrutiny in both incidents amid warnings that Iranian-affiliated hackers are targeting internet-exposed controllers. But many legacy OT devices remain difficult to identify and secure, with some running outdated software, using default credentials or operating outside conventional security monitoring – and AI can solve some of those problems.

For example, “AI is ideal for rapidly unpacking binary firmware blobs across obscure edge sensors, IP security devices and PLCs to uncover deeply nested, unpatched open-source libraries (e.g., BusyBox, log4j, or outdated OpenSSL forks),” Gallagher said.

While there is no shortage of commercial solutions that help critical infrastructure accelerate threat detection, vulnerability triage and silent zero-day discoveries, they often fall short at the “last mile” of defense, Gallagher said.

“The flurry of programs risk worsening ‘vulnerability fatigue’ if it only accelerates the rate of discovery without solving how critical infrastructure operators physically remediate devices. Announcing a high-severity vulnerability faster does not protect a water utility or power substation if applying the fix still is difficult to implement,” he said.

Sovada said Anthropic is moving in the right direction by bringing in experts who understand physical operations in OT.

“AI cannot replace the human expertise needed to understand how these systems operate and what’s at stake if something goes wrong,” Sovada said. “Many OT systems cannot be taken offline without disrupting essential services, so identifying a vulnerability is only half the battle. AI can help defenders see the risk more clearly, but human expertise is critical to determining how to address it safely.”

OT security also calls for a distinct approach, as standard security practices elsewhere can disrupt industrial systems.

“The best practices for IT can be quite dangerous in fragile OT,” said Josh Corman, executive-in-residence for public safety and resilience at the Institute for Security and Technology. “The reason for the word fragile is in a lot of these environments, even doing normal asset discovery or port scanning, which is a basic IT practice, can cause reboots or breaking of OT equipment like old programmable logic controllers.”

As efforts to secure OT systems expand, Corman said there needs to be tailored solutions to many operators relying on aging equipment that cannot be patched frequently, if at all.

“Even if they do get patches, they can’t patch very often or can’t patch at all. So if they are using the newest, latest, greatest supported versions of these products, they still have to plan patch management windows – sometimes once a year, sometimes if they’re lucky, more often,” Corman said.

“What’s worse and more common is the products they’re using are older, unsupported versions of a Schneider, a Rockwell, a Honeywell, an Eaton, a Siemens and they’re going to have to keep using it because a lot of the time the lifespan for this equipment is 30 plus years,” he said.