Article

Anthropic Launches Critical Infrastructure Defense Program for OT Providers

Anthropic’s new OT defense program offers models and engineering support through providers. What operators and vendors can pursue, and what remains unknown.

Editorial illustration for Anthropic Launches Critical Infrastructure Defense Program for OT Providers: a geometric block represents a model release. Not documentary evidence.

On October 8, 2026, Anthropic announced the Critical Infrastructure Defense Program for providers securing industrial and other critical systems. The program offers frontier Claude models, on-site engineers and threat research to providers protecting operational technology (OT).

For operators, the practical next step is to ask existing OT suppliers whether a relevant engagement is available for their equipment. For vendors, the decision is whether to pursue program participation and clarify permission to deliver a customer-facing service.

Who can engage now

Anthropic names 11 founding partners: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.

Security vendors, systems integrators and equipment manufacturers can register interest as the program expands. This is an interest route, not immediate enrollment or a guarantee that a particular customer can buy a ready-made service.

Anthropic says several partners are already using Claude to fix vulnerabilities. That describes ongoing work; it does not establish independently verified remediation speed, production safety or customer savings.

Keep three decisions separate

Our analysis: program participation, permitted model use and authority to change plant systems require separate answers. A positive answer to one does not establish the other two.

Decision

What the evidence establishes

What to ask

Provider engagement

The CIDP interest page invites defenders to express interest.

Can the supplier support the specific equipment and software versions in scope? What work will it deliver?

Customer-facing model use

The separate CVP documentation says an internal grant does not cover client-facing products or services; those require separate application and approval.

Which permission covers work on customer systems? Confirm the applicable arrangement instead of assuming CIDP participation overrides that restriction.

Plant changes

NIST’s OT guidance recommends offline and regression testing, with knowledgeable OT personnel deciding when and how to deploy patches.

Who validates the proposed fix, approves deployment and selects compensating controls if patching must wait?

The separate Cyber Verification Program also excludes high-risk safety-system testing from Red Team access. For model-access tiers and retention questions, see RohitAI’s existing CVP guide; CIDP adds a provider-engagement question, not a replacement tier system.

What buyers still need in writing

The reviewed CIDP announcement and interest page do not specify prices, model versions, admission timing, service levels or data-handling terms. On-site engineering support does not establish on-premises inference or air-gapped operation.

Our recommendation: request a data-flow diagram showing which code, logs and device information leave the environment, where models run and who reviews output. Resolve those details before sharing operational material.

For an initial engagement, ask for an asset-specific mitigation plan with finding validation, engineering review, deployment approval and closure evidence. Evaluate accepted mitigations and review effort, not just the number of model findings. These are proposed evaluation criteria, not measured CIDP results.

Methodology: This AI-assisted brief draws on published Anthropic material and NIST guidance checked on October 8, 2026. No hands-on testing or independent outcome measurement was performed.