Gottheimer bill would fund $100M CISA AI pilot for critical infrastructure
The proposal arrives as ONCD's Texas Watershed 250 pilot runs without dedicated federal funding, and as the Trump administration's AI executive order left critical-infrastructure testing largely voluntary.
TL;DR
Rep. Josh Gottheimer (D-N.J.) introduced the AI Cyber Defense Act, which would authorize $100 million over fiscal years 2027, 2031 for a CISA-run pilot giving critical infrastructure operators free access to frontier AI models for vulnerability detection and remediation. The bill would prioritize nonprofit, publicly owned, rural, and small organizations. Gottheimer cited the recent wave of cyberattacks on water facilities as the impetus. Unlike the ONCD-led Watershed 250 pilot in Texas, which relies on voluntary private-sector contributions, the legislation puts a dollar figure on the table, though appropriators haven't followed through yet, and CISA has faced funding cuts under the Trump administration.
Gottheimer's bill directs DHS, through CISA, to establish a program through which critical infrastructure owners and operators can "securely utilize artificial intelligence procured through the Secretary" along with technical assistance to protect against, detect, test for, and remediate vulnerabilities. Participation is application-based, with priority given to smaller and publicly owned entities.
The legislation lands in a crowded landscape. The Office of the National Cyber Director rolled out Project Watershed 250 in Texas in August 2026, a six-month pilot drawing on volunteer expertise and technology from cyber and AI companies to protect water systems. National Cyber Director Sean Cairncross framed it as a collaboration between states, industry, and the federal government. But that pilot carries no line-item budget. Gottheimer's bill, by contrast, puts $100 million in authorization behind the idea.
Whether the money materializes is a separate question. The Trump administration has cut CISA funding during its second term, and an authorization doesn't obligate appropriators. Gottheimer acknowledged the tension: "Right now federal funding for critical infrastructure has an uncertain future and many of our local communities just don't have the resources they need to pay for AI tokens to do the patching they need."
The bill has bipartisan co-sponsors, Reps. Don Bacon (R-Neb.), Zach Nunn (R-Iowa), Hillary Scholten (D-Mich.), and Greg Landsman (D-Ohio), which gives it a path broader than a messaging bill. Gottheimer also sits in two relevant seats: he co-chairs the House Democratic Commission on Artificial Intelligence and is the top Democrat on the House Intelligence Committee's cyber subcommittee.
The broader context matters. Trump's June 2026 AI executive order kept testing voluntary and shortened the pre-release review window from 90 to 30 days after industry pushback. The order also created an AI cybersecurity clearinghouse housed at Treasury, NSA, and CISA, but left critical-infrastructure AI testing as an opt-in arrangement. Gottheimer's bill pushes in a different direction, putting CISA in the procurement seat and funding access for the operators least able to pay.
"The same technology that can help a small town's IT guy find and patch a gap in cybersecurity can also help a hostile government find a hundred more it hasn't even discovered yet," Gottheimer said. "AI didn't create this threat, but it's accelerated it, and our defenses have to keep up."
Published ·Deep Fathom