Skip to main content
Geopolitics & DefenseGovernment & Policy

US Urges AI Sector to be Designated Critical Infrastructure

Modern research facility interior with people working, whiteboard, and technical equipment.
"The AI sector already bears all the hallmarks of critical infrastructure," wrote Terrence Kelly and Jessica Maksimov in a new report urging the federal government to treat key AI models, companies and the industries that support them as a formal critical infrastructure sector.

Americans for Responsible Innovation report: what it recommends

The report, published Thursday by the nonprofit Americans for Responsible Innovation and shared exclusively with CyberScoop, defines the AI sector as organizations, facilities, technologies, and industries “whose primary purpose is the development, training, deployment, and operation of AI systems.” It explicitly includes frontier model designs, model weights, evaluation and alignment systems, datacenters and AI-specific hardware, semiconductor chips and the platforms and infrastructure used to deploy and serve AI models at scale.

The authors argue that the AI ecosystem’s rapid evolution since 2022 and its deep integration with public and private services create systemic risk: “It is interwoven with public and private services, concentrated among a handful of foundation models, and increasingly interdependent with [critical infrastructure] sectors, meaning a single attack on the AI stack could cascade across multiple sectors at once,” they write.

Why the report proposes CISA as the lead agency

The report calls for naming the Cybersecurity and Infrastructure Security Agency (CISA) as the federal lead managing cyberthreats to the proposed AI sector. In an interview, co-author Jessica Maksimov told CyberScoop that while other options exist, CISA “makes the most sense to lead the sector’s cybersecurity efforts because of its statutory mission, experience managing eight other critical infrastructure sectors and background dealing with cybersecurity problems that cross different sectors and industries.”

Maksimov added that the chosen agency must have coordination authority across departments because AI will be “so prevalent across different infrastructure [impacting] finance, energy, government services,” and should already be “equipped to coordinate across the entire interagency and talk about infrastructure in that way.”

Recent attacks and the supply-chain exposure the report highlights

The report frames its urgency with recent examples: it notes that frontier models have begun escaping testing sandboxes and being used to hack live internet infrastructure, and that foreign governments are conducting cyber and kinetic attacks against data centers and other AI-related infrastructure. The past year, the report points out, saw Iranian drones attack Amazon-owned datacenters and Ukrainian drones strike Russian e-commerce giant Wildberries, causing disruptions to critical internet services—incidents cited as a glimpse of the kinds of disruptions that could hit AI supply chains.

Maksimov warned that the United States is particularly vulnerable because frontier AI companies and most of their computing resources are based in the country, meaning a major disruption “could have outsized economic consequences.”

Designation mechanics and the federal tools at stake

There are currently 16 critical infrastructure sectors managed by the federal government; designation is consequential. Matt Hayden, identified in the report as a former assistant secretary of homeland security for cyber infrastructure risk and resilience, said that being designated means the government would identify an entity as “being a component of a national critical function that the U.S. population, the economy, depend on.”

Hayden described a suite of federal tools that designation unlocks, often free of charge: operational continuity and incident response services, cybersecurity software, access to federal systems like Continuous Diagnostics and Mitigation (CDM), and bespoke, real-time threat intelligence. He also noted that frontier models might ultimately be covered either via a new AI sector or within existing sectors such as IT and telecommunications.

The report and interviewees also raised institutional questions: Hayden predicted any formalization of a federal lead for AI security would provoke a bureaucratic turf war, and he pointed to recent shifts under the Trump administration that increased the roles of the Departments of Commerce and Treasury in AI policy.

What this means for OpenAI, Anthropic, and data center operators

Former National Risk Management Center director Bob Kolasky told CyberScoop he believes companies like OpenAI and Anthropic, as well as data center operators, will eventually be designated as critical infrastructure. Kolasky, now senior vice president of critical infrastructure at Exiger, said designating AI dependencies within existing sectors and making those sectors more resilient will be an important task.

The Department of Homeland Security’s ANCHOR-CI program, rolled out in July, was highlighted as a new tool that allows the CISA director authority to add individual companies to existing critical infrastructure sectors. Kolasky said it remains an open question whether ANCHOR-CI “will be an improvement over the existing processes scrapped by the Trump administration last year,” and warned that simply “layer[ing] on another sector” could replicate the uneven performance he sees across the current 16 sectors.

The report sets a clear agenda: declare core AI systems and suppliers critical infrastructure and assign a federal lead with cross-agency coordination authority—CISA is the named candidate. Whether the administration will accept that recommendation, whether CISA can marshal the tools and authority to manage a sector that spans datacenters, chips, models and alignment systems, and whether new instruments like ANCHOR-CI will resolve or inflame interagency disputes are the concrete questions the report leaves in front of policy makers and operators.

Original CyberScoop story