Anthropic's Cyber Mission targets power, water and transit controls. Here's what controls and electrical subs should expect from owners
Anthropic is putting frontier models behind operational-technology security firms defending grids, water systems and transit. Contractors who install the controls on those systems should expect sharper cybersecurity questions at commissioning and closeout.
Anthropic has put its frontier models behind the security firms that defend power grids, water systems and transportation networks. For a controls, electrical or mechanical sub that installs and commissions the networked equipment on those systems, the likely effect is more pointed security questions from owners at commissioning and closeout, not a new rule.
What did Anthropic announce?
On October 8, Anthropic launched the Cyber Mission, which it describes as "a long-term commitment to securing the systems everyone depends on." It starts with two programs.
| Program | What it does | Who it touches |
|---|---|---|
| Critical Infrastructure Defense Program | Gives operational-technology (OT) security providers frontier Claude models, on-site engineers and threat research | Owners of power, water and transit systems, and the firms that defend them |
| OSS Scanner | Free, opt-in scans of open-source projects, with a proof of concept and suggested fix | Maintainers of software that device and controls vendors build on |
The eleven founding partners for the infrastructure program include Rockwell Automation, Hitachi, Nozomi Networks, Dragos, Palo Alto Networks, Deloitte and Accenture. Anthropic says it is starting with a small cohort.
What does this mean for a controls or electrical sub?
You are not a participant. But the people who will inspect your installed work now have stronger tooling. The practical shifts to plan for:
- Closeout gets harder to wave through. An owner whose security provider is finding weaknesses faster will ask what was installed, on which network, with which credentials.
- Default passwords and open ports become your problem at handover. These are basic, and they are the first things any scan flags.
- Patch support matters. Anthropic itself notes that some OT fixes "may take decades." Equipment you install now may sit unpatched for years, so know which vendor owns updates for each component.
What is still hype or unproven?
Quite a bit. Anthropic says plainly that "critical infrastructure is hard to defend in many ways that AI cannot fix." The OSS Scanner reports are model-generated and sent without human review, so some may be wrong, including severity ratings. The company's accuracy figure is a target, not a measured result. And none of this creates a contract obligation for you.
Should a mid-size sub act now?
Not with new spending. Do three inexpensive things on your next controls or power job:
- Read the owner's cybersecurity and turnover requirements before you price, and ask who is responsible for network configuration.
- Build a device list as you install, with models, firmware versions and the vendor patch contact.
- Change every default credential and record that you did, in the closeout package.
If an owner's security team hands you a findings list after turnover, a dated record of what you installed and how you left it is the document that separates your scope from theirs.
- What is the Anthropic Cyber Mission?
- It is a long-term cybersecurity effort Anthropic announced on October 8, 2026. It has two initial parts: a Critical Infrastructure Defense Program for operational-technology security providers, and a free, opt-in OSS Scanner for open-source projects.
- What is operational technology in construction terms?
- Operational technology is the hardware and software that runs physical systems, such as power distribution, water treatment and transportation controls. On a building project, the closest equivalents are the building automation, SCADA and controls systems that mechanical and electrical subs install and commission.
- Does the Anthropic Cyber Mission change what contractors must do?
- No. It is a vendor program, not a rule or a contract requirement. It matters because it signals that owners and their security providers will have better tools for finding weaknesses in installed controls, which can show up as questions during commissioning and turnover.
- How should a controls or electrical sub prepare for owner cybersecurity questions?
- Keep an inventory of every networked device you install, remove default passwords before handover, document which vendor supports patches for each component, and read the owner's security requirements in the contract before pricing.