Congress May Expand CISA to Include AI Security, Affecting Procurement Choices
Congress is considering an expansion of the Cybersecurity Information Sharing Act (CISA 2015) to address AI security risks before its September 2026 expiration. This could reshape procurement policies for AI vendors by enhancing information sharing and antitrust guidance.
Key Signals
- Congress evaluating CISA expansion to include AI security threats before September 2026 expiration
- FTC and DOJ to clarify legal protections for AI threat information sharing
- AI vendors may face new requirements for contract compliance related to cybersecurity
"The FTC and DOJ should clarify that sharing AI threat information beyond cyber-specific threat information is unlikely to raise antitrust concerns."
As Congress approaches the expiration of the Cybersecurity Information Sharing Act of 2015 (CISA 2015) in September 2026, lawmakers are evaluating potential extensions to the act that would include a focus on artificial intelligence (AI) security risks. Currently, CISA has aimed primarily at cyber threats, but the growing reliance on AI technologies introduces new vulnerabilities and risks that necessitate a re-evaluation. The proposed legislative changes would not only broaden the scope of information sharing but would also aim to provide enhanced legal protections and clearer antitrust guidance to incentivize AI developers to share critical threat insights. This legislative shift reflects the national security requirements in the context of swiftly evolving AI technologies.
Federal agencies such as the Federal Trade Commission (FTC), the Department of Justice (DOJ), and the Cybersecurity and Infrastructure Security Agency (CISA) are pivotal in shaping these policies. Their efforts indicate a growing recognition that the threat landscape in AI requires a collaborative approach among industry stakeholders. Enhanced cooperation in sharing security threat information could play a vital role in fortifying defenses against emerging AI risks, thereby aiding in risk mitigation. The changing nature of threats posed by AI systems elevates the urgency for this type of legislative reform.
For procurement professionals, this evolving landscape signifies potential changes in requirements for contractors involved in AI technology development. As new obligations may emerge from the expanded CISA, companies providing AI solutions might face new contract terms, stipulations regarding cybersecurity measures, and compliance mandates. Thus, entities must remain vigilant and adaptable to the changing regulatory environment and the implications it could have on their operations and contractual obligations.
Moreover, organizations engaged in the development or integration of AI technologies within federal systems will find it crucial to stay informed about these shifts. Understanding the evolving legal landscape regarding information sharing will empower contractors and agencies to engage more actively in cooperative cybersecurity efforts without fear of violating antitrust regulations. Pavlo Reddish, a respected figure in the field, emphasizes this point: "The FTC and DOJ should clarify that sharing AI threat information beyond cyber-specific threats is unlikely to raise antitrust concerns." This clarity will be essential for fostering an environment conducive to open information exchange, which is vital in pre-emptive security strategies.
Procurement planners within federal agencies and contractors will also need to prepare for possible updates to cybersecurity policies that may explicitly include AI-related vulnerabilities. This proactive approach will not only enhance procurement strategies but will also refine risk management tactics across the board. As both government and private sector organizations adapt to these forthcoming changes, alignment on best practices for threat intelligence sharing will become a cornerstone of robust cybersecurity posture against both traditional and AI-specific threats.
In summary, the ongoing discussions regarding the expansion of CISA reveal significant implications for federal procurement, particularly for vendors in the AI domain. As the dialogue progresses, stakeholders must proactively adjust their strategies to align with prospective policy changes and ensure compliance with new cybersecurity frameworks.
Agencies
- Congress
- Federal Trade Commission
- Department of Justice
- Cybersecurity and Infrastructure Security Agency
- White House
Vendors
- OpenAI
- Anthropic
- Google DeepMind
- Meta
- Microsoft
Sources
- The time is now: Incentivize AI companies to share critical security information | Federal News NetworkFederal News Network · Sep 11