ai-cybersecuritytrade-pressNewsThe Broadside2 min read

Aspen Digital urges CISA to seed AI defense council under ANCHOR-CI

The proposal treats AI defensive tools as a distribution problem (not a procurement one) and wants CISA to solve it before the councils are even seated.


TL;DR

Aspen Digital is pushing CISA to establish a cross-sector council dedicated to distributing AI defensive tools to critical infrastructure operators, using the yet-unseated ANCHOR-CI partnership structure. The Aug. 4 proposal from senior director Matt Altomare argues CISA should move now (before councils are populated) to build a catalog of vetted AI models, reference workflows, and validation guidance. Standing up the council, Altomare contends, would operationalize the June 2 Trump AI executive order's directive for CISA to facilitate access to cybersecurity tools including frontier models.

The blog post lands in a gap that CISA hasn't filled yet. ANCHOR-CI was announced July 1 as the replacement for the Critical Infrastructure Partnership Advisory Council, which DHS Secretary Kristi Noem terminated in March 2025. The new structure envisions four council types (Sector, Cross-Sector, Industry, and Regional) but none have been seated. Altomare's pitch is to claim the first cross-sector slot for AI defense before anyone else stakes a claim, and to staff it with AI companies, state and local governments, ISACs, and civil defense outfits like the UC-Berkeley Cyber Resilience Corps.

What makes the proposal more than a think-piece is how cleanly it slots into existing machinery. The Trump administration's June 2 AI executive order already tasks CISA with issuing binding operational directives to push cybersecurity tools (including frontier AI models) to federal agencies, states, localities, and critical infrastructure operators. CISA published its first responsive BOD on June 10, focused on risk-based vulnerability management prioritization. Altomare is essentially saying: the EO gave you the mandate, the BOD gave you the method, and ANCHOR-CI gives you the table, now seat it.

The catalog, and what's missing

Altomare's core recommendation is a publicly accessible catalog of useful AI models, harnesses, and guidance, modeled on CISA's existing catalog of no-cost cybersecurity tools launched in 2022. But he's explicit that a catalog alone is noise without validation. "Many defenders lack vulnerability research experience and have no basis for judging what a model's output means," he writes, arguing CISA should pair any model listing with reference workflows, proven examples on real codebases, and operator training.

The urgency framing is deliberate. Altomare points to threat actors and models that can now discover and exploit vulnerabilities within hours of disclosure, and to Chinese open-weight models that he says are closing the capability gap. Whether CISA leadership agrees that a cross-sector AI council should jump the queue ahead of other ANCHOR-CI priorities is an open question, and the separate, still-unresolved effort to stand up an AI-ISAC under the 2025 AI action plan suggests the interagency landscape for AI coordination is already crowded.


Published ·Deep Fathom