Government of Alberta scans 466 million lines of code with Claude, finds and fixes vulnerabilities in hours
The Government of Alberta's Ministry of Technology and Innovation used Claude Code, running Opus and Sonnet models, to scan its entire software estate for cybersecurity vulnerabilities, completing in about 20 hours a review the province estimates would have taken roughly 6.5 years using traditional methods.
What's new
About 50 autonomous Claude Code agents worked in parallel to scan 466 million lines of code across 1,280 applications and 3,400 code repositories spanning 27 provincial ministries. The initiative, which Anthropic detailed in a case study published July 6, found and remediated vulnerabilities across the government's legacy IT footprint at a scale and speed the province says was not previously feasible with manual security review.
One concrete example cited: a legacy subsidy portal, originally built over five months roughly 25 years ago, was rebuilt in four to five days using Claude. Alberta says it now plans to consolidate 185 legacy applications into 16 reusable ones, using the same AI-assisted approach to modernize its software base.
Nate Glubish, Alberta's Minister of Technology and Innovation, put the result plainly: "By using AI to find and fix vulnerabilities across our systems, we accomplished in hours what would have taken a traditional approach years to complete."
Context
Government IT systems are a recurring target for state-level and criminal cyberattacks, and provincial and state governments have historically struggled to keep pace with vulnerability discovery and remediation across sprawling, decades-old codebases — many written in legacy languages and maintained by shrinking in-house teams. Alberta's initiative began in 2025 and represents one of the more extensive documented public-sector deployments of agentic coding tools for security work, rather than the more common use cases of code generation or developer productivity.
Anthropic has been pushing Claude Code into enterprise and government security workflows more broadly, positioning autonomous, parallelized code review as a way to compress work that would otherwise require large teams of security engineers. The Alberta case follows a string of Anthropic announcements this year expanding Claude's footprint in regulated and public-sector environments, including partnerships aimed at bringing Claude into government and industrial settings.
Why it matters
The scale of the Alberta deployment — tens of millions of lines of code reviewed in under a day, using dozens of parallel agents — is a concrete data point for how agentic AI changes the economics of software security work that has traditionally been bottlenecked by the number of qualified engineers available to do it. For governments in particular, where legacy systems often accumulate technical and security debt over decades due to budget and staffing constraints, this kind of tooling could meaningfully shift what's operationally possible.
It also signals a shift in how AI vendors court public-sector customers: rather than pitching chat assistants or drafting tools, Anthropic is positioning Claude Code as infrastructure for large-scale, autonomous security remediation — a higher-stakes, higher-trust use case that, if it scales to other jurisdictions, could become a meaningful new market for frontier AI labs beyond consumer and typical enterprise deployments.
Corroborating sources
- Anthropic
https://www.anthropic.com/news/alberta-government-claude-cybersecurity
“By using AI to find and fix vulnerabilities across our systems, we accomplished in hours what would have taken a traditional approach years to complete.”