Key Takeaways
- Frontier AI models now find software vulnerabilities faster than human teams can patch them, which makes the same capability both the biggest threat to critical infrastructure and its strongest defence.
- Anthropic’s Project Glasswing has surfaced more than 10,000 high- or critical-severity vulnerabilities since April 2026, and expanded in June to about 150 further organisations across 15 countries.
- OpenAI committed $1 billion on 3 September 2026 to its Daybreak for Frontline Defenders programme, subsidising AI cyber tools for water utilities, grid operators, local government and community banks.
- The Center for Internet Security and OpenAI launched an AI Cyber Defense Pilot on 11 September for state, local, tribal and territorial governments through the MS-ISAC community.
- California established an AI Cyber Defense Program in August 2026, placing an AI Cybersecurity Officer in every state agency.
- The constraint has moved from discovery to remediation — a high or critical bug found by AI takes two weeks to patch on average, and some maintainers have asked for disclosures to slow down.
- Attackers are already automating the full kill chain, with one documented operation using AI agents to rebuild malware automatically whenever security products detected it.
Cyber AI protects critical infrastructure by doing at machine speed what defenders have never had enough people to do by hand: reading every line of exposed code, testing every internet-facing surface, and proposing fixes before an attacker finds the same hole. The shift matters most for the operators least able to afford it — the water utilities, rural hospitals, local governments and small grid operators that run essential services on thin budgets and ageing software.
Three efforts now define how that capability reaches those defenders. Anthropic gates its most capable model behind Project Glasswing and gives access only to organisations that operate or protect critical systems. OpenAI has committed $1 billion to subsidise its cyber models for under-resourced defenders through Daybreak. Governments have started building their own programmes on top of both. Together they describe a narrow window — the period in which defenders hold capability that attackers do not yet have at the same scale.
Why Critical Infrastructure Became the Focus
The exposure is structural. Water systems, electricity grids, hospitals and municipal services run operational technology that was never designed for an internet-connected world, maintained by teams of a handful of people, often with no dedicated security staff at all. Meanwhile, hackers linked to China, Iran, Russia and North Korea are using frontier models across the attack lifecycle, and criminal groups are shipping AI-generated tooling including ransomware.
What changed in 2026 was the speed differential. Anthropic’s Frontier Red Team lead Logan Graham put it plainly: “We basically need to start preparing for a world where there is zero lag between discovery and exploitation.” A patch cycle measured in quarters made sense against human attackers. It does not survive contact with an automated one.
Anthropic’s September 2026 threat intelligence report shows what that looks like in the field. An operation it tracks as GTG-20006, attributed to Russian-speaking operators, ran for 130 days and engaged 24 of 27 targeted institutions, including Ukrainian ministries, defence bodies and drone supply-chain manufacturers. AI agents monitored the group’s own deployed malware, detected when a security product flagged it, and automatically recompiled the code until it evaded detection. The operation also hijacked DNS records through at least three hotel Wi-Fi providers to stage malware on guests’ devices. The report’s central finding is that AI has erased most of the gap in skill and staffing that separated a state-backed team from a single operator.
Project Glasswing: Finding Flaws Before Attackers Do
Anthropic launched Project Glasswing on 7 April 2026 around Claude Mythos Preview, a model it has declined to release publicly on misuse grounds. The initial cohort of roughly 50 partners included Amazon Web Services, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks. On 2 June the company added approximately 150 organisations across 15 countries, deliberately covering sectors underrepresented in the first wave — power, water, healthcare, communications and hardware — with many new partners being vendors whose code underpins infrastructure systems.
The results give a sense of the scale change.
| Organisation or scope | Finding |
|---|---|
| Programme total since April 2026 | More than 10,000 high- or critical-severity vulnerabilities |
| Cloudflare | 2,000 bugs across critical-path systems, 400 rated high or critical, with a false-positive rate the company described as better than human testers |
| Mozilla | 271 vulnerabilities found and fixed in Firefox 150, more than ten times the number found in a previous version using an earlier model |
| Open-source scan (1,000+ projects) | 23,019 potential vulnerabilities flagged, 6,202 estimated high or critical |
| Independent assessment of 1,752 findings | 90.6 percent confirmed valid; 62.4 percent confirmed high or critical severity |
One example shows why severity ratings matter more than counts. In wolfSSL, an open-source cryptography library used by billions of devices, the model constructed an exploit that would let an attacker forge certificates — enough to host a convincing fake website for a bank or email provider. Several partners reported bug discovery rates rising more than tenfold after deployment. The background on the model itself, its restrictions and the scepticism it has attracted is covered in our guide to Claude Mythos and Project Glasswing.
The Bottleneck Moved
Anthropic’s own assessment is the most important line in the programme’s update: progress in software security used to be limited by how quickly vulnerabilities could be found, and is now limited by how quickly they can be verified, disclosed and patched. A high or critical bug found by Mythos Preview takes two weeks to patch on average. Several open-source maintainers have told the company they are severely capacity-constrained, and some have asked it to slow the rate of disclosure because they need more time to design fixes.
That is the defining problem for infrastructure operators specifically, because uptime constraints make patching harder than in ordinary enterprise IT. A joint report from the Cloud Security Alliance, SANS Institute and OWASP concluded that organisations are likely to be overwhelmed in the near term by threat actors using AI to find and exploit vulnerabilities faster than defenders can close them. Anthropic has also released Claude Security, built on its publicly available Opus 4.8 model, which the company says patched more than 2,100 vulnerabilities in three weeks.
OpenAI’s $1 Billion Daybreak Commitment
OpenAI announced Daybreak for Frontline Defenders on 3 September 2026, committing $1 billion in subsidised access to frontier cyber capabilities, training and technical support, with the commitment targeted to be consumed over roughly six months. The programme grew out of Daybreak, launched in May 2026, which the company says roughly 2,000 organisations already use across two tiers — Blue, running standard models for routine defensive work, and Red, providing approved organisations with specialised models for more sensitive security tasks.
The US-focused arm, Daybreak for America, prioritises four groups: water and wastewater systems, electric grid operators, state and local governments, and community and regional banks, with nonprofits and open-source maintainers also named. The company presented the programme at a summit attended by around 300 security leaders, with utilities represented from 40 states, and says it plans to extend the model to partner countries. The Daybreak Defense Network brings the cyber models into more than 35 enterprise products and partner-operated services.
Sasha Baker, OpenAI’s Head of National Security Policy, framed the timing: “We have a defender’s window: a narrowing opportunity to use frontier AI to close security gaps before attackers seize them.” The programme follows a wave of documented attacks on US utilities in July 2026, some linked to entities in Iran.
Independent commentary has been supportive but sceptical of the headline figure. OpenAI has not specified exactly what is subsidised or by how much, and at least one security practitioner argued the MS-ISAC training pilot matters more than the billion-dollar number — because the binding constraint for a small water utility is staff capable of acting on findings, not access to a model.
Public-Sector Programmes Now Building on Top
On 11 September 2026, the Center for Internet Security announced an AI Cyber Defense Pilot with OpenAI for state, local, tribal and territorial governments and critical infrastructure organisations, drawing on the MS-ISAC community. The pilot deliberately mixes organisations of different sizes, regions and security maturity, and evaluates whether AI helps them detect risks faster, prioritise actions better, strengthen cyber hygiene and improve readiness. Participants use the technology to identify, validate and prioritise findings and support remediation, aligned to the CIS Critical Security Controls.
Brian Calkin, CIS Chief Technology and Innovation Officer, described the aim: “This pilot will help us understand how AI can help organizations make smarter decisions, respond faster, and focus on the risks that matter most.” The pilot is also designed to produce implementation guidance and recommendations for wider public-sector adoption — arguably its most durable output.
States have moved in parallel. On 10 August 2026, California directed agencies to establish an AI Cyber Defense Program within the California Cybersecurity Integration Center, covering vulnerability detection, network hardening and incident response; to expand access to AI-enabled defences for local governments and infrastructure partners; and to designate an AI Cybersecurity Officer in every state agency. At federal level, a June 2026 executive order directed Treasury, working with the National Cyber Director, NSA and CISA, to form an AI cybersecurity clearinghouse that coordinates vulnerability scanning, validates findings and prioritises remediation and distribution.
| Programme | Launched | Who it serves | Core mechanism |
|---|---|---|---|
| Project Glasswing (Anthropic) | April 2026, expanded June | ~200 organisations in 15 countries | Gated access to Mythos Preview for vulnerability discovery |
| Daybreak for Frontline Defenders (OpenAI) | September 2026 | Water, grid, SLTT government, community banks, nonprofits, OSS | $1bn subsidised model access, training, technical support |
| CIS AI Cyber Defense Pilot | September 2026 | SLTT governments and infrastructure via MS-ISAC | Guided deployment plus published implementation guidance |
| California AI Cyber Defense Program | August 2026 | State agencies, local government, infrastructure partners | Cal-CSIC capability plus an AI Cybersecurity Officer per agency |
| Federal AI cybersecurity clearinghouse | June 2026 executive order | Agencies, states, infrastructure operators | Coordinated scanning, validation and remediation prioritisation |
What AI Defence Actually Does on the Ground
Strip away the programme names and the work falls into four repeatable functions. Continuous discovery replaces periodic scanning — models read code and probe internet-facing surfaces without the bandwidth limits that cap human teams. Triage and prioritisation cut the noise, validating which findings are real and which are reachable in the operator’s actual environment rather than in theory. Machine-speed remediation generates and applies patches, with autonomous agents handling detection, investigation and response across networks, identities and applications. And continuous monitoring watches behaviour rather than signatures, which is the only approach that survives an attacker whose malware rewrites itself.
Google has described its version as an always-on loop of four phases — Prepare, Scan and Prioritize, Remediate, Monitor — using simulation agents to map attack paths, identify reachable vulnerabilities and validate risk against operational context. The underlying techniques are not new; behavioural analysis and automated response have been part of AI-assisted cyber defence for years, and the practical patterns are set out in our review of real-time threat detection and automated response in practice. What is new is that the models are now good enough to find original flaws rather than recognise known ones, which is also why AI pentesting platforms built around validation and proof of closure have moved from novelty to procurement line item.
The Open Problems
Three gaps remain unresolved. The first is remediation capacity: finding 10,000 vulnerabilities helps nobody if the organisations holding them cannot patch at that rate, and infrastructure operators are the least able to take systems down to do it. The second is tooling that blocks its own defenders — during the Hugging Face breach, commercial models refused to analyse real attack logs because the same guardrails that block exploit code also block incident responders, forcing the security team onto an open-weight model. That episode produced the Open Secure AI Alliance, a 37-member group building open tooling for exactly this scenario.
The third is information sharing. AI developers hold threat intelligence nobody else has, and the asymmetry is growing. With CISA 2015 set to expire in September 2026, there has been sustained argument for extending the statute beyond cyber to cover AI-related threats and mitigations, so that developers can share what they know without legal exposure. That is a policy question, not a technical one, and it is currently unresolved.
The defender’s window is real but narrow. Right now, vetted organisations have capability that most attackers lack at scale. Whether that advantage converts into safer water systems and power grids depends less on model quality than on whether the people running those systems have the staff, the maintenance windows and the legal cover to act on what the models find.
If you are interested in this topic, we suggest you check our articles:
- Claude Mythos Guide: Anthropic’s Cybersecurity AI Model Explained
- Real Examples of AI Reinforcing Cybersecurity
- Reinforcing Cybersecurity with AI
- Best AI Pentesting Software for Enterprise Security Teams in 2026
- Nvidia Pledges to Lead New Open-Source AI Security Group
Sources: Anthropic, CyberScoop, Industrial Cyber, SecurityWeek, Office of Governor Newsom, The White House
Written by Alius Noreika

