HR 10519 · Federal · introduced Sep 21, 2026In Committee

HR 10519

To direct the Secretary of Homeland Security, acting through the Director of the Cybersecurity and Infrastructure Security Agency, to establish a Critical Infrastructure AI Cyber Defense Pilot Program, and for other purposes.

Low RiskInformational. No immediate compliance impact.

TL;DR

Rep. Josh Gottheimer (D-NJ) introduced a bill directing CISA to launch a pilot program that uses AI to defend critical infrastructure (think power grids, water systems, financial networks) against cyberattacks. It's a government-run pilot, not a mandate on private companies, though critical infrastructure operators would likely be invited to participate.

How This Might Impact Your Business

Critical infrastructure operators (energy, water, transportation, finance, healthcare, communications) would gain access to a CISA-run AI cyber defense pilot, potentially at reduced or no cost.

Participation appears voluntary based on the pilot structure, so no new mandatory compliance burden is created at this stage.

Cybersecurity vendors, especially those selling AI-driven threat detection, would see a new federal customer and validation channel through CISA partnerships.

Companies already designated as critical infrastructure under CISA's 16 sectors are the primary audience; small businesses outside those sectors are not directly affected.

No penalties, fines, or reporting obligations are established in the bill text as introduced.

Timeline is uncertain: the bill sits in the House Homeland Security Committee and has not advanced, so any pilot launch is likely 12 to 24 months out if enacted.

Data sharing arrangements with CISA could emerge as a practical consideration for participants, including how threat intelligence and telemetry from company networks would be handled.

What Should You Do

1

If you operate in one of CISA's 16 critical infrastructure sectors, flag this bill to your CISO and government affairs lead as a potential future funding or partnership opportunity.

2

Ask your cybersecurity team whether current AI-based threat detection tools could integrate with a CISA pilot, and what data sharing terms would be acceptable.

3

Cybersecurity vendors should track this bill and prepare capability briefings for CISA procurement staff in case the pilot advances.

4

Monitor the House Homeland Security Committee calendar for markup or hearings; the bill has not yet been scheduled.

5

No immediate compliance action required, but add this to your quarterly regulatory watch list.

Who It Affects

Energy and UtilitiesCybersecurityFinancial ServicesHealthcareTransportation and LogisticsTelecommunications

Sponsors

Status Timeline

  1. committee

    Referred to the House Committee on Homeland Security.

    September 21, 2026

AI-generated analysis for informational purposes only. Not legal advice. Always consult a qualified attorney for legal guidance.Last action Sep 21, 2026

Need help preparing your team for AI compliance?

Talk to LaunchReady about AI Training

Get the Weekly AI Law Roundup

Plain-English summaries of the AI laws that matter for your business. Every Monday. Free.

No spam. Unsubscribe anytime.