A new report advocates for the designation of artificial intelligence (AI) and its supporting infrastructure as the 17th critical infrastructure sector in the United States. This move would unlock federal resources and services for an industry increasingly vital to national and economic security, according to the report.
The report, published by the nonprofit Americans for Responsible Innovation, specifically calls for the Cybersecurity and Infrastructure Security Agency (CISA) to lead cybersecurity efforts for this proposed sector. Authors Terrence Kelly and Jessica Maksimov argue that the AI sector, encompassing organizations, facilities, technologies, and industries involved in the development, training, deployment, and operation of AI systems, already exhibits characteristics of critical infrastructure. This includes frontier model designs, model weights, evaluation and alignment systems, data centers, AI-specific hardware, semiconductor chips, and platforms for deploying AI models at scale.
Maksimov emphasized that CISA is well-suited for this role due to its statutory mission, experience managing eight other critical infrastructure sectors, and its established ability to address cybersecurity issues across various industries. The report highlights the interconnectedness of AI with public and private services, its concentration among a few foundation models, and its growing interdependence with existing critical infrastructure sectors. This interdependence means a single attack on the AI "stack" could trigger cascading failures across multiple sectors.
Experts note that the U.S. is particularly vulnerable to AI supply chain disruptions because most frontier AI companies and their computing resources are based domestically. With the current administration pushing for broader AI adoption across government and the private sector, a major disruption could have significant economic consequences. Recent incidents, such as Iranian drones attacking Amazon-owned data centers and Ukrainian drones striking the Russian e-commerce giant Wildberries, illustrate the potential for critical internet service disruptions.
Matt Hayden, a former assistant secretary of homeland security for cyber infrastructure risk and resilience, explained that a critical infrastructure designation places an industry in a special category, identifying it as a component of a national critical function essential to the U.S. population and economy. Such a designation provides access to a wide array of federal tools and resources, often free of charge. These include operational continuity and incident response services, cybersecurity software, access to federal systems like Continuous Diagnostics and Mitigation (CDM), and bespoke, real-time threat intelligence.
Hayden believes that at a minimum, frontier AI models will eventually be covered as critical infrastructure, either through a new sector or by integrating them into existing ones like IT and telecommunications. However, he cautioned that efforts to formalize a federal lead for AI security would likely lead to bureaucratic disputes, citing similar challenges faced by sectors like space and cloud computing in their pursuit of critical infrastructure designations.
Bob Kolasky, former director of CISA's National Risk Management Center, anticipates that companies such as OpenAI and Anthropic, along with data center operators, will eventually be designated as critical infrastructure. He also noted that while CISA is well-positioned, the AI sector will present unique challenges and coordination issues. Kolasky pointed out that the effectiveness of simply adding AI as another sector, functioning like the existing 16, is an open question, given the varied operational approaches among current critical infrastructure sectors.
The Department of Homeland Security's new ANCHOR-CI program, rolled out in July, allows CISA to convene ad-hoc stakeholder meetings for emerging cyber threats and grants the CISA director authority to add individual companies to existing critical infrastructure sectors. It remains to be seen whether this program will improve upon previous processes.






