Congress Urged to Extend CISA 2015 to Cover AI Threat Intelligence Sharing
With the Cybersecurity Information Sharing Act of 2015 expiring in September 2026, defense experts are urging Congress to modernize the statute. Expanding legal protections to AI vendors will incentivize voluntary sharing of critical model vulnerabilities across defense networks.
The upcoming sunset of the Cybersecurity Information Sharing Act of 2015 (CISA 2015) in September 2026 presents Congress with a pivotal window to recalibrate federal information-sharing frameworks. Originally designed to protect private entities sharing cyber threat indicators from antitrust scrutiny and civil liability, the expiring statutory framework must evolve to address artificial intelligence vulnerabilities, adversarial manipulation, and model-poisoning vectors. As the federal enterprise accelerates commercial AI integration into national security architectures, establishing clear legislative incentives for AI developers is becoming an urgent operational imperative.
For the Department of Defense and federal civilian agencies, current threat-sharing channels fall short of capturing non-traditional operational risks unique to machine learning, such as prompt injection exploits, training data corruption, and model inversion attacks. Without explicit statutory liability protections and safe harbor provisions similar to those provided under CISA 2015, commercial frontier AI developers face substantial legal exposure if they proactively disclose algorithm-level vulnerabilities to government authorities. Reauthorizing and broadening the law ensures national security leaders obtain early visibility into model threats before hostile actors weaponize algorithmic flaws against critical mission infrastructure.
From an industry and procurement standpoint, expanding the CISA framework will directly impact defense acquisition strategies and corporate risk management. Integrating rigorous AI reporting requirements into federal contracts without statutory liability shields risks chilling participation from non-traditional tech firms. Conversely, codifying standardized, legally protected channels for threat sharing will enable contractors to collaborate seamlessly with CISA and defense intelligence components without fearing regulatory penalties, public exposure, or loss of proprietary IP.
Defense contractors, AI vendors, and government program managers should closely monitor legislative activity surrounding CISA reauthorization ahead of the September 2026 target. Prime contractors must evaluate their current vulnerability disclosure pipelines and prepare internal risk management frameworks for broader reporting expectations as lawmakers align cyber defense policies with the reality of national security AI. (Source: Federal News Network)
Executive takeaway
Subscribe to receive signals like this — plus the executive analysis behind them.
Get the Signals