Anthropic's Free OSS Scans Come With No Human Triage
Anthropic's new OSS Scanner gives free model-run vulnerability scans with no human triage, alongside a three-tier cyber access program for security teams.

Anthropic will now scan open-source projects for vulnerabilities for free, using its strongest models and no human triage. The same month, it restructured paid cyber access into three verified tiers. Both moves point one way: the company has decided that letting defenders use a frontier model means identifying who is asking, not loosening the model for everyone.
What OSS Scanner actually gives you
The new service is called OSS Scanner. Anthropic says open-source projects that opt in get "thorough, periodic security scans by our strongest models at no cost." The Verge reported the launch on October 8, noting the reports include output from Claude Mythos.
The catch is stated plainly in Anthropic's own wording, quoted by The Verge: "The outputs of this opt-in vulnerability scanner will be fully model-generated, without human review or triage. This will enable faster and more frequent scanning, but means that it is possible reports will be incorrect or invalid."
Read that as a trade the maintainer makes, not a detail buried in a footnote. You get scans from models you could not otherwise afford to run at that cadence. You also get a queue of findings nobody has triaged, in a year when triage capacity is the scarce resource. The Verge points out that some open-source projects are already struggling to keep up with the volume of AI-generated bug reports, naming Linus Torvalds and Google among those who have pushed back.
The same report notes AI tools have found real flaws recently, citing the "Copy Fail" bug that it says affected nearly every Linux distribution in May. So the yield is not zero. The open question is the ratio, and OSS Scanner ships without a published one.
Paid cyber access splits into three tiers
Separately, Anthropic folded its Cyber Verification Program and Project Glasswing into a single offering with three tiers of access for security teams that can prove who they are. The change was made in October 2026 and is live for Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models going forward.
Before this, the two programs ran separately: Glasswing gave organizations securing critical software access to Claude Mythos, while the original Cyber Verification Program loosened safeguards on Opus and Sonnet for approved teams. Under the new structure every tier includes those frontier models, and what differs is the verification requirement and the security controls attached.
Defense Access covers security operations, incident response, malware reverse engineering, and vulnerability analysis. Eligible applicants include teams defending their own systems, critical-infrastructure operators, small security firms, open-source maintainers, and individual researchers with a history of reported bugs. Anthropic says it aims to answer those applications within a few days.
Red Team Access adds authorized penetration testing, limited to systems the organization is allowed to test. Actions that could cause physical harm or mass disruption, including ransomware deployment, stay blocked in real time.
First-party access runs through Claude.ai, Claude Code, and the Anthropic API. Amazon Bedrock availability is limited to customers with Enterprise Frontier Safeguards. A webinar on the program is scheduled for October 14 at 9 a.m. PT.
Why the two announcements belong together
The structural problem both moves address is the same one. Frontier labs have spent two years tightening classifiers that stop models from helping with intrusion, and those same classifiers block defenders who need the model to read malware, trace an exploit, or draft a detection rule. The answer here is not to drop the guardrails but to identify the user and then relax them.
That design has a visible seam. A SOC analyst reversing a malware sample and a contractor running an offensive engagement are different risks, and putting both behind one checkbox made the old program either too loose or too slow. Splitting them is how you keep defensive use available without handing an unrestricted frontier model to anyone holding an API key.
OSS Scanner is the unpaid edge of the same strategy. Open-source maintainers are named as eligible for Defense Access, and they are also the target of the free scanning service — a group that mostly cannot pay for frontier model access, maintaining code that everything else depends on.
What to check before you opt in
If you maintain an open-source project, the decision is about triage capacity, not model quality. Ask who on your team will read fully model-generated reports with no vendor triage behind them, and what your policy is when a report is wrong. A scanner that files more findings than you can close moves your backlog, not your risk.
If you run a security team, the question is which tier you land in and what remains blocked inside it. Defense Access and Red Team Access carry different verification burdens and different controls, so budget for the evidence you will have to produce, and note that Bedrock access depends on Enterprise Frontier Safeguards rather than on your tier alone.
Enterprises buying model access will start asking which tier they are on, what is still blocked, and whether logs stay in their own cloud. Anthropic's Enterprise Frontier Safeguards, which let regulated customers keep Claude logs in AWS, Azure, or GCP under their own keys, is the storage half of the same pitch.
What to watch next
The October 14 webinar is the first checkpoint: it should clarify evidence requirements and how fast Red Team Access is approved. The practical test is whether incident responders get through in days rather than weeks while a case is live — if the queue slips, teams keep using weaker, less restricted models for the work that matters most. The second thing to watch is whether the real-time blocks on mass-disruption tasks hold once red teams are inside the program. A verification badge is only worth something if the remaining limits are specific and enforced.
More from DangMua