Security1 publisher2 min readPublished
House bill would authorize $100 million for CISA to buy frontier AI access for critical infrastructure operators
Josh Gottheimer's AI Cyber Defense Act, co-sponsored by two Republicans and two Democrats, would have CISA procure frontier models for small water systems and utilities through 2031. Appropriators still have to fund it.
The Watch · Security desk

What happened
- Rep. Josh Gottheimer, D-N.J., introduced the AI Cyber Defense Act on Monday, directing DHS to run a CISA test program that gives critical infrastructure operators free access to frontier AI models.
- Gottheimer said the bill was prompted by the series of cyberattacks on water facilities in recent months.
- Co-sponsors are Don Bacon of Nebraska, Zach Nunn of Iowa, Hillary Scholten of Michigan and Greg Landsman of Ohio, giving the measure two Republican and two Democratic backers alongside the sponsor.
- The text would authorize $100 million for the pilot from 2027 to 2031, at which point the program ends.
- Owners and operators would apply to take part, and the bill tells CISA to give priority to nonprofit, publicly owned, rural and small-sized organizations.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint The pilot would have to be stood up inside an agency whose funding has been cut significantly in the Trump administration's second term, so it competes for dollars CISA does not currently hold.
- cost If appropriated, Washington picks up the token bill Gottheimer says small towns cannot pay, and the model selection moves with the money to DHS.
- precedent Funding the work through an authorized line would set a different template for these pilots than the donated, unbudgeted services offered through the Texas program.
Spread across the five fiscal years the bill covers, the authorization averages $20 million a year [17]. An authorization is a ceiling, not a transfer. Appropriators decide whether the money moves, and CISA has lost significant funding under the Trump administration's second term [5][6]. The first year the bill reaches is 2027, so this fiscal year holds no decision for any operator [18].
What an applicant would get is in the bill text. Participating owners and operators would "securely utilize artificial intelligence procured through the Secretary and technical assistance provided by the Secretary to protect against, detect, test for, and remediate vulnerabilities in the cybersecurity of such critical infrastructure" [4]. Procurement sits with DHS. That puts the operator-side question on data handling: what configuration, asset and vulnerability data a water district feeds into a model DHS picked for it.
Gottheimer's stated premise is unit cost. "Right now federal funding for critical infrastructure has an uncertain future and many of our local communities just don't have the resources they need to pay for AI tokens to do the patching they need," he said when he introduced the bill [8]. He also said, "It's expensive to bring the AI in to analyze your system and find those vulnerabilities" [9].
There is already a second AI-and-water pilot in the field. CyberScoop reports that the Office of the National Cyber Director recently announced a test program in Texas, adjacent to but distinct from Gottheimer's proposal [13], and that one criticism of it is that private companies offered their cyber and AI services on a purely voluntary basis with no significant budget behind the pilot [14]. The $100 million line is the answer to that criticism, and it is the part that depends on appropriators [5].
Gottheimer is one of three co-chairs of the House Democratic Commission on Artificial Intelligence and the top Democrat on the House Intelligence Committee's cyber subcommittee [15]. On the dual-use problem he said: "The same technology that can help a small town's IT guy find and patch a gap in cybersecurity can also help a hostile government find a hundred more it hasn't even discovered yet" [10]. He added, "AI didn't create this threat, but it's accelerated it, and our defenses have to keep up" [11]. Of the water attacks that prompted the bill he said, "If we don't get ahead of it, it can mean a disaster for our families" [16].
Before an application window exists, a utility security lead has to decide what an outside model may read from the OT side of the network and under whose retention terms.
What to watch
- Whether an FY2027 appropriations bill funds the pilot at anything near the authorized level.
- Whether DHS names the model providers it would procure through, and on what retention terms operator data is handled.
- Whether the Texas pilot run through the Office of the National Cyber Director gets a budget of its own.