cisatrade-pressNewsThe Broadside2 min read

CISA 2015 reauthorization hangs on lame-duck session

USTelecom is now tying the threat-sharing law's fate to AI-driven exploitation, the first time machine-speed vulnerability discovery has been used to frame the urgency calculus for Congress.


TL;DR

The Cybersecurity Information Sharing Act of 2015, which provides liability and antitrust protections for industry threat-sharing with DHS and among peers, runs through Dec. 11 on its third short-term extension. The House passed a reauthorization through 2035 as part of the fiscal 2027 NDAA; the Senate has a competing 2036 endpoint via Homeland Security ranking member Gary Peters (D-MI). USTelecom's Robert Mayer and Brandon Heiner are pressing for the long-term fix, explicitly linking reauthorization to AI-enabled attacks that probe critical infrastructure at speed, a framing shift from the nation-state and ransomware threats that dominated earlier renewal arguments.

USTelecom is making a new argument for an old law. In a Sept. 25 post ahead of the trade group's cybersecurity leadership summit, Robert Mayer and Brandon Heiner tied reauthorization of the Cybersecurity Information Sharing Act of 2015 directly to the threat of AI-driven exploitation, marking a shift in how industry frames what's at stake if the law lapses.

"We've all seen the headlines and read the threads, warnings that the next generation of AI systems may be able to find and exploit vulnerabilities autonomously, at machine speed and with little human direction," they wrote. The post argues that the Trump administration's openness to sharing AI threat information with other governments "will only be as strong as the information-sharing framework we maintain here at home."

CISA 2015 has been running on short-term extensions since its original Sept. 30, 2025 expiration date. The current patch, tucked into a continuing resolution, runs through Dec. 11. That pushes the fight into the lame-duck session, where lawmakers will have to reconcile competing bills.

The House has already acted. Legislation led by Homeland Security Chairman Andrew Garbarino (R-NY) and cyber subcommittee Chair Andy Ogles (R-TN) to extend the law through fiscal 2035 was included in the House-passed fiscal 2027 NDAA, which cleared the chamber 216-212 on July 22. The Garbarino bill makes modifications to the law that industry players have received favorably.

What the Senate holds

Senate Homeland Security ranking member Gary Peters has proposed a reauthorization through fiscal 2036. The Senate Armed Services Committee advanced its NDAA version in a closed-door markup on June 10, but Senate leadership hasn't brought the defense bill to the floor. It's possible the chambers reach a defense policy deal without a floor vote on the Senate version, a path that would leave the CISA 2015 endpoint to negotiators.

Mayer and Heiner argue the Dec. 11 extension "provides valuable continuity and reflects the broad recognition on both sides of the aisle that real-time cyber threat sharing is essential to confronting fast-moving threats, including those increasingly enabled by AI." Their post frames the machine-speed threat as the new urgency: "Nation-state actors, ransomware syndicates, and increasingly sophisticated AI-enabled attacks are probing critical infrastructure, including the communications networks that everything else depends on, on a near-constant basis."

Cairncross and the White House position

National Cyber Director Sean Cairncross has made reauthorization a priority since his 2025 confirmation. At an Oct. 27 industry event, Cairncross said he wants "a clean 10-year reauthorization" and called the law "foundational," emphasizing that the liability and antitrust protections are "vital to our threat assessment and response." He noted the White House backs the position and that ONCD is "working with the Hill" alongside interagency colleagues.

Previous attempts to pass the reauthorization through unanimous consent in the Senate were blocked by Homeland Security Committee Chairman Rand Paul (R-KY), contributing to the cycle of short-term extensions. The Dec. 11 deadline gives Congress one more chance to break that cycle before the CR expires.


Published ·Deep Fathom