GAO Official Pushes AI Amendment to CISA 2015
The cyber threat-sharing law he wants updated for AI is lurching between short-term extensions; the Senate just bought three more months.
TL;DR
GAO IT and cybersecurity managing director Nick Marinos told a GovCIO AI event Thursday that amending the Cybersecurity Information Sharing Act of 2015 to explicitly cover AI threat data would be smarter than pursuing standalone AI safety bills. CISA 2015's threat-sharing provisions expire this September; the Senate passed a short-term extension to December 11 on August 8. The law briefly lapsed during last year's 43-day government shutdown. Cyber Threat Alliance CEO Michael Daniel agreed, telling Nextgov that Congress "should update the definitions in the Act to clearly cover information about threats to AI systems."
Marinos's suggestion is operationally straightforward: amend the definitions in CISA 2015 so that threat indicators shared between government and industry explicitly include AI-specific attack data. The Cyber Threat Alliance's Michael Daniel told Nextgov the existing protections arguably cover AI threat information already, but a statutory update would remove the ambiguity.
The complication isn't legal design. It's that the vehicle Marinos is pointing to can't get a permanent reauthorization from the same Congress that's actively drafting new AI bills. CISA 2015's sharing provisions expire in September. The Senate's August 8 stopgap buys only until December 11. This is the second short-term patch in a year. The law briefly lapsed during the 43-day government shutdown in late 2025 before Congress retroactively extended it in February.
Marinos's broader argument is that government remains "behind the eight ball" on AI threats, and the gap isn't new. GAO designated information security a high-risk area roughly 30 years ago. Marinos noted that even then, "the pace of technological innovation was moving at an exponentially faster rate than government guidance and action." His practical framing (whether the government is monitoring activity to prevent the most catastrophic consequence of an AI vulnerability) is the kind of question an amended CISA 2015 could help answer. But first Congress has to keep the law alive, and on current form that means three months at a time.
Published ·Deep Fathom