Artificial intelligence has never been more important to the federal government.
Under the Trump administration, AI has been adopted rapidly across the private sector and federal agencies. Software developers now use large language models to generate much of their code. Frontier AI models are escaping testing sandboxes to hack live internet infrastructure. Foreign governments are conducting cyber and kinetic attacks targeting data centers and other AI-related infrastructure.
The AI industry’s lightning-fast evolution since 2022 and growing importance to U.S. economic and national security have prompted calls for stronger federal oversight in order to better manage emerging threats.
A new report published Thursday from the nonprofit Americans for Responsible Innovation, shared exclusively with CyberScoop, calls for the federal government to declare key AI models, companies and its supporting industries as critical infrastructure. It also calls for naming the Cybersecurity and Infrastructure Security Agency as the lead agency managing cyberthreats for the sector.
The report defines the AI sector as organizations, facilities, technologies, and industries “whose primary purpose is the development, training, deployment, and operation of AI systems.” It includes frontier model designs, model weights, evaluation and alignment systems, datacenters and AI-specific hardware, semiconductor chips and the platforms and infrastructure used to deploy and serve AI models at scale.
“The AI sector already bears all the hallmarks of critical infrastructure,” wrote authors Terrence Kelly and Jessica Maksimov. “It is interwoven with public and private services, concentrated among a handful of foundation models, and increasingly interdependent with [critical infrastructure] sectors, meaning a single attack on the AI stack could cascade across multiple sectors at once.”
In an interview, Maksimov told CyberScoop that while there are other options, CISA makes the most sense to lead the sector’s cybersecurity efforts because of its statutory mission, experience managing eight other critical infrastructure sectors and background dealing with cybersecurity problems that cross different sectors and industries.
“We want an agency that has coordination authority across all other departments, because we believe that AI will just be so prevalent across different infrastructure [impacting] finance, energy, government services, that’s already equipped to coordinate across the entire interagency and talk about infrastructure in that way,” she said.
The U.S. is particularly susceptible to AI supply chain disruptions because frontier AI companies and most of their computing resources are based in the country. As the Trump administration pushes broader adoption across government and the private sector, experts warn that a major disruption could have outsized economic consequences.
The past year has offered a potential vision of that future, with Iranian drones attacking Amazon-owned datacenters and Ukrainian drones striking Russian e-commerce giant Wildberries, causing disruptions to critical internet services.
“I would say that because of the value that attackers would put on U.S. AI capabilities and systems, that the infrastructure that supports all those capabilities is very vulnerable,” to both physical and cyber attacks, Maksimov said.
There are currently 16 critical infrastructure sectors managed by the federal government, and the designation carries real weight in terms of how departments and agencies prioritize their limited resources.
Matt Hayden, a former assistant secretary of homeland security for cyber infrastructure risk and resilience, said designating a sector or industry as critical infrastructure means the government puts you in a special category where you’re “identified as being a component of a national critical function that the U.S. population, the economy, depend on.”
The designation unlocks a wide range of federal tools and resources, often free of charge, including operational continuity and incident response services, cybersecurity software, access to federal systems like Continuous Diagnostics and Mitigation (CDM), and bespoke, real-time threat intelligence.
Hayden said that the AI ecosystem described in the report captures many critical industries, and he believes that at the very least, frontier models will one day be covered as critical infrastructure, whether through a new designated sector or existing ones, like the IT and telecommunications sector.
But he noted that other sectors, such as space or cloud computing, have similarly argued for a critical infrastructure designation. He also predicted that any effort to formalize a federal lead for AI security would result in a bureaucratic turf war. Under the Trump administration, the Departments of Commerce and Treasury have played more prominent roles in shaping policy and regulation around AI systems.
“We have fought those battles in the policy circus for trying to get space-based critical infrastructure carved out, and it’s as complicated as trying to find an owner,” said Hayden, now a vice president at General Dynamics Information Technology. “Everyone in the government has to agree that that [agency] is the primary, and as a result it’s very difficult to get those documents across the finish line.”
Hayden also said that new programs like ANCHOR-CI allow CISA to quickly convene ad-hoc stakeholder meetings to address emerging cyber threats. It also gives the CISA director authority to add individual companies to existing critical infrastructure sectors.
Bob Kolasky, former director of the National Risk Management Center at CISA, told CyberScoop that he believes companies like OpenAI and Anthropic, as well as data center operators, will eventually be designated as critical infrastructure. He said it’s still an open question whether ANCHOR-CI, which was rolled out by DHS in July, will be an improvement over the existing processes scrapped by the Trump administration last year.
“Every sector is going to rely on artificial intelligence and making more resilient the sectors themselves and understanding how they use AI and the dependencies” is still going to be an important task, said Kolasky, now senior vice president of critical infrastructure at Exiger.
And while CISA is well-positioned as a potential lead, Kokasky said the AI sector is likely to bring its own unique set of challenges and coordination issues.
“If you just sort of layer on another sector and say ‘function like the other 16 sectors,’ right now, those 16 sectors are all over the place in terms of how they’re functioning,” said Kolasky.
The post The push to designate AI as the next critical infrastructure sector appeared first on CyberScoop.
from CyberScoop https://ift.tt/GrQLy7W
https://ift.tt/rJyWAPS