Skip to main content
Cybersecurity

Congress Proposes AI-Powered Cyber Defense Program

US Capitol Building hallway with lawmakers, staff, and a laptop near a sunny window.

“If we don’t get ahead of it, it can mean a disaster for our families,” Rep. Josh Gottheimer said when he introduced a legislative package this week that includes the AI Cyber Defense Act, a plan to give critical infrastructure operators free, CISA-backed access to frontier artificial intelligence models to find and fix cybersecurity gaps.

What Rep. Josh Gottheimer proposed

Gottheimer, a House Democrat tapped to lead his party’s work on artificial intelligence, introduced the AI Cyber Defense Act on Monday. The bill would direct the Department of Homeland Security, through the Cybersecurity and Infrastructure Security Agency (CISA), to create a pilot program that allows “owners and operators of critical infrastructure that participate in the Program [to] securely utilize artificial intelligence procured through the Secretary and technical assistance provided by the Secretary to protect against, detect, test for, and remediate vulnerabilities in the cybersecurity of such critical infrastructure.”

The measure is explicitly inspired by a recent string of cyberattacks on water facilities and is sponsored on a bipartisan basis: co-sponsors include Reps. Don Bacon (R‑Neb.), Zach Nunn (R‑Iowa), Hillary Scholten (D‑Mich.), and Greg Landsman (D‑Ohio). Gottheimer holds two roles relevant to the bill — he is one of three co-chairs of the House Democratic Commission on Artificial Intelligence and the top Democrat on the House Intelligence Committee’s cyber subcommittee — positions he cited when announcing the legislation.

Program design: CISA procurement, technical assistance, and prioritized applicants

Under the bill’s language, CISA would both procure frontier AI capabilities and provide technical assistance. The pilot would let participating critical infrastructure entities use those models “securely” to protect, detect, test for, and remediate cybersecurity vulnerabilities — in short, to use AI as a defensive scanner and fixer rather than merely as an investigative tool.

The bill directs the program to prioritize nonprofit, publicly owned, rural and small-sized organizations when granting participation. Gottheimer framed that prioritization as a response to limited local resources, saying, “Right now federal funding for critical infrastructure has an uncertain future and many of our local communities just don’t have the resources they need to pay for AI tokens to do the patching they need.”

Funding, timing, and political context

The legislation would authorize $100 million for the pilot program from 2027 through 2031, at which point the authorization would end. The bill’s authorization is not an appropriation: Gottheimer acknowledged that “appropriators would have to follow through on providing the actual dollars.” The bill’s introduction also came with a political note about recent budget choices: “The Trump administration has significantly cut CISA funding in its second term,” the source reports, a fact the bill’s sponsors invoked to explain funding uncertainty for local communities.

How this differs from the Office of the National Cyber Director’s Texas pilot

The AI Cyber Defense Act arrives near — but not identical to — a test program the Office of the National Cyber Director (ONCD) recently announced in Texas. The report cited a criticism of that ONCD pilot: private sector companies provided cyber and AI services on a purely voluntary basis and the pilot lacked “significant budget” to expand beyond voluntary contributions. Gottheimer’s measure aims to square that gap by authorizing federal procurement through CISA and setting aside an explicit funding authorization.

How critical-infrastructure owners and operators, CISA, and appropriators will respond

  • Critical-infrastructure owners and operators: Small, rural, nonprofit and publicly owned utilities — the categories the bill prioritizes — would gain a pathway to use frontier AI tools for vulnerability discovery and remediation without directly purchasing model access, provided they are accepted into the pilot.
  • CISA: The agency would be asked to act as both procurer and technical supporter, an operational role that would require defining secure model access, managing technical assistance, and setting participation criteria for the prioritized applicants named in the bill.
  • Appropriators in Congress: Even with the $100 million authorization from 2027–2031, the pilot’s launch and scale depend on future appropriations — a point Gottheimer himself emphasized when warning communities lack resources to “pay for AI tokens to do the patching they need.”

Gottheimer framed the tension plainly: “The same technology that can help a small town’s IT guy find and patch a gap in cybersecurity can also help a hostile government find a hundred more it hasn’t even discovered yet,” and he added, “AI didn’t create this threat, but it’s accelerated it, and our defenses have to keep up.” The bill offers a concrete federal route to provide defensive AI to selected, resource-constrained operators — but it leaves open the critical question he flagged: will Congress provide the appropriations needed to make that route usable by 2027?

https://cyberscoop.com/gottheimer-ai-cyber-defense-act-cisa-pilot/