Partnerships
Cardinal Program Brings Free AI-Driven Security Testing To US Utilities

Method Security and Palantir Technologies on September 10, 2026, announced the Cardinal Program, a joint initiative that will provide select U.S. municipalities, utilities, and critical infrastructure operators with opt-in, continuous autonomous security assessments at no cost.
In a joint release datelined New York and Miami, the companies described Cardinal as an initiative to strengthen national cyber resilience through safe, autonomous red teaming. The companies stated that these institutions protect the systems and services that underpin daily life and now face adversaries using increasingly capable AI to find and exploit vulnerabilities at unprecedented speed and scale. Cardinal, they said, is their effort to close that gap by bringing autonomous cyber systems, advanced AI, and expert operators together in support of the teams protecting essential American infrastructure.
The program’s official site states that its mission is to equip national critical infrastructure and municipal organizations with continuous, safe, adversarial-informed hardening guidance to outpace cyber adversaries. The site describes these institutions as often security under-resourced and presents Cardinal as a technical coalition of American technology and security companies delivering a joint offering across the market.
“Attackers are putting these capabilities to work now,” the companies wrote in the joint release. “Defenders should not have to wait to do the same.”
How the Assessments Will Run
Under the program, Method’s platform and security operators will map, probe, and safely test participating organizations’ internet-facing assets to identify attack paths. Frontier and open-weight models will power the assessments, which the companies said are intended to help defenders understand how attackers armed with the same capabilities might approach their systems.
Palantir Foundry, AIP, and the Ontology for Cybersecurity will provide secure infrastructure for Method to integrate and deliver findings and support collaboration. According to the release, AIP enables validation of repeatable, automated assessment workflows for these high-consequence missions, while the Ontology contextualizes findings in terms of real mission impact to focus response actions.
The assessments will emulate real-world adversary behavior within scope and rules of engagement defined by participants, with safeguards and human oversight enforced to prevent disruption, according to the companies. Security experts will review the findings and provide adversary-informed hardening guidance.
Eligibility, Controls, and Enrollment
The program site states that any American critical infrastructure organization in energy, transportation, communications, public health, or hospital operations, and any municipality responsible for water or safety, qualifies for free assessments.
According to the site, the free tier consists of semi-frequent autonomous red team assessments of an organization’s external attack surface with directly delivered strategic hardening guidance, plus the ability to engage monthly with a security expert to review that guidance. The output takes the form of adversarial-informed hardening guidance, such as adjusting a network control or removing permissive access, delivered with accompanying evidence.
Each participating organization sets its own target scope of allowed and disallowed assets and can define fine-grained rules of engagement covering what actions can be performed, at what times, and with what level of human approval. Scope and rules can be changed after sign-up through a portal that holds all of the participant’s settings and results. The site states that participant findings are access-controlled and that details are never made public beyond a support engineer.
Enrollment begins with a form submission, after which a Method engineer assesses qualification. Qualified participants then sign a red team agreement before being onboarded to the program.
Beyond the free tier, larger enterprises can engage the program’s operating partners directly for dedicated paid commercial programs built on the same model, the site states. Government agencies can use Cardinal as a technical platform for more expansive security initiatives, such as delivering a continuous assessment program for their own systems or authorized third parties, built on federal funding or another agreed economic model. The companies said their goal is to deliver capabilities to defenders now while demonstrating a model that can scale, and that they hope Cardinal could give government agencies a proven technical vehicle to direct these capabilities toward systems within their mandates. National cyber resilience, they added, will require urgent collaboration across industry and government.
The Companies Behind the Program
Method describes itself as a builder of autonomous cyber systems for the U.S. Government and the Fortune 500, and the company’s website states a mission of delivering cyber resilience to the U.S. Government and critical enterprises. The site states that Method builds full-spectrum security products to arm cyber operators with a decisive advantage, and lists two: Bastion, which maps, validates, and controls the totality of resources and possible attack paths in the context of a customer’s business, and Reaper, which plans and executes red team operations and adversary emulation exercises on autonomy and software-defined command-and-control infrastructure. Method lists OpenAI, Palantir, Andreessen Horowitz, General Catalyst, and Blackstone as partners.
The release invites organizations protecting critical systems or public services to request a security assessment through the Cardinal Program site. It lists Lisa Gordon as Palantir’s media contact and MR Snell as the contact for Method Security.












