What happened
Rep. Josh Gottheimer (D-NJ) introduced the AI Cyber Defense Act in the House this week. The bill would direct the Department of Homeland Security, working through CISA, to set up a program letting owners and operators of critical infrastructure use artificial intelligence procured through the department, along with technical assistance, to protect against, detect, test for and remediate vulnerabilities in their systems.
The measure authorises 100 million dollars for the pilot between 2027 and 2031, though appropriators would still have to provide the money. The bill gives priority to nonprofit, publicly owned, rural and small organisations, which are the operators least able to buy security capability on their own.
Gottheimer said the series of cyberattacks on water facilities in recent months was the trigger. "The same technology that can help a small town's IT guy find and patch a gap in cybersecurity can also help a hostile government find a hundred more it hasn't even discovered yet," he said. He added that many local communities cannot afford the AI tokens needed to analyse their own systems and find those gaps.
The bill is separate from, but adjacent to, a test program the Office of the National Cyber Director announced in Texas. That pilot has drawn criticism for relying on voluntary contributions of cyber and AI services with no meaningful budget behind it. The wider context is awkward: the current administration has significantly cut CISA funding, so a new CISA program would depend on money that has to be argued for rather than assumed.
Why this is a GRC story
The state is moving from regulator to capability broker. Most of what a GRC team reads about AI is obligation: assess it, disclose it, govern it. This bill is the opposite direction, with government buying and handing out defensive tooling to organisations that cannot fund it. That changes how small operators will be told to close gaps.
Free access still creates third party risk. If models and technical assistance flow through a department, the operator needs answers on data handling, who holds the access, how it is authorised and what happens when the pilot ends. None of that becomes someone else's problem because the capability was free.
Critical infrastructure funding is patchy. A pilot aimed at the smallest and least resourced operators is a recognition that the "we cannot afford it" argument is now a policy problem. For GRC practitioners in small utilities, that argument has been the honest answer to many risk register items.
What to watch
Watch whether the bill moves and, more importantly, whether the money actually appears in an appropriation. Watch how the CISA pilot and the Texas program are kept distinct, and whether voluntary contributions are treated as adequate.
If your organisation could qualify, it is worth tracking the program design now. Eligibility, application and procurement terms will matter more than the headline number.
Attribution: Analysis based on CyberScoop and related public reporting. This article is original commentary, not a repost of the source material.
