HR 10519
To direct the Secretary of Homeland Security, acting through the Director of the Cybersecurity and Infrastructure Security Agency, to establish a Critical Infrastructure AI Cyber Defense Pilot Program, and for other purposes.
TL;DR
Rep. Josh Gottheimer (D-NJ) introduced a bill directing CISA to launch a pilot program that uses AI to defend critical infrastructure (think power grids, water systems, financial networks) against cyberattacks. It's a government-run pilot, not a mandate on private companies, though critical infrastructure operators would likely be invited to participate.
How This Might Impact Your Business
Critical infrastructure operators (energy, water, transportation, finance, healthcare, communications) would gain access to a CISA-run AI cyber defense pilot, potentially at reduced or no cost.
Participation appears voluntary based on the pilot structure, so no new mandatory compliance burden is created at this stage.
Cybersecurity vendors, especially those selling AI-driven threat detection, would see a new federal customer and validation channel through CISA partnerships.
Companies already designated as critical infrastructure under CISA's 16 sectors are the primary audience; small businesses outside those sectors are not directly affected.
No penalties, fines, or reporting obligations are established in the bill text as introduced.
Timeline is uncertain: the bill sits in the House Homeland Security Committee and has not advanced, so any pilot launch is likely 12 to 24 months out if enacted.
Data sharing arrangements with CISA could emerge as a practical consideration for participants, including how threat intelligence and telemetry from company networks would be handled.
What Should You Do
If you operate in one of CISA's 16 critical infrastructure sectors, flag this bill to your CISO and government affairs lead as a potential future funding or partnership opportunity.
Ask your cybersecurity team whether current AI-based threat detection tools could integrate with a CISA pilot, and what data sharing terms would be acceptable.
Cybersecurity vendors should track this bill and prepare capability briefings for CISA procurement staff in case the pilot advances.
Monitor the House Homeland Security Committee calendar for markup or hearings; the bill has not yet been scheduled.
No immediate compliance action required, but add this to your quarterly regulatory watch list.
Who It Affects
Sponsors
Status Timeline
committee
Referred to the House Committee on Homeland Security.
September 21, 2026