Americans for Responsible Innovation (ARI) released a report warning that the growing integration of artificial intelligence across health care, finance and manufacturing creates infrastructure vulnerabilities that could have sector-wide consequences if attacked. It identifies that voluntary corporate security measures are insufficient as reliance on AI expands across private and public sectors. Furthermore, the report recommends that U.S. President Donald Trump designate AI as critical infrastructure, subjecting the sector to incident reporting requirements. It also calls for the Cybersecurity and Infrastructure Security Agency (CISA) and the Center for AI Standards and Innovation (CAISI) to coordinate on security standards covering the AI infrastructure stack.
Titled ‘The Invisible Backbone: How to Secure AI Infrastructure Today for Tomorrow,’ the report noted that the AI sector lacks formal recognition as critical infrastructure, leaving it without public-private coordination mechanisms, information sharing, asset mapping, and protection standards commensurate with AI’s growing role in critical operations.
Simultaneously, the AI sector faces threats that existing federal frameworks were not designed to address. First, adversarial attacks, including data poisoning, distillation, and supply chain manipulation, can exploit the characteristics of AI systems that differ from those of conventional software. Second, because only a handful of providers build the foundation models that other sectors depend on, vulnerabilities in one model can propagate across the codebases built atop it. Third, AI is growing increasingly interdependent with existing critical infrastructure, expanding the attack surface of both the AI sector and the systems it is becoming intertwined with.
“To address these risks, the President must designate AI as a critical infrastructure sector,” Terrence Kelly and Jessica Maksimov wrote in an ARI report published last week. “The designation would allow the U.S. government to identify a lead AI infrastructure agency, define which entities constitute the sector, establish industry-wide coordination mechanisms, and develop AI-specific national security standards. To this end, Congress should also empower the executive to set security baselines for AI infrastructure, build federal capacity to coordinate and share threat information, and invest in AI safety and security research and development.”
The report disclosed that AI systems are increasingly integrated into CI functions, forming interdependencies as these sectors rely on AI and AI relies on them. “Between August 2022 and August 2023, AI-related federal contracts increased by almost 150 percent to $675 million. U.S. government services use AI systems for enterprise-wide functions and individual productivity.”
Federal agencies already deploy AI tools to carry out their mandates. The Food and Drug Administration (FDA) uses AI systems to review drug applications, the Centers for Disease Control and Prevention (CDC) uses them to analyze medical images for abnormalities, the Department of Transportation (DOT) uses machine learning AI to predict flight delays, and U.S. Customs and Border Protection (CBP) deploys AI systems to analyze border crossing patterns.
A 2024 Ernst & Young survey also found that 51% of state and local public sector employees, and 64% of federal employees, use AI applications several times a week or daily.
The U.S. military already relies on AI systems for predictive maintenance and military logistics, and is increasingly turning to AI technologies for military planning and operations. In a January 2026 memorandum, Secretary of War Pete Hegseth instructed the Department of War (DOW) to implement AI tools with speed, noting that ‘the risks of not moving fast enough outweigh the risks of imperfect alignment.’
U.S. military AI adoption is increasing. In 2026, Deputy Secretary of War Steve Feinberg designated Palantir’s Maven Smart System (MSS) as a program of record to allow for the AI system’s eventual ‘enterprise-wide integration’ into the U.S. military’s command and control systems. The U.S. military has already deployed AI tools on classified data to provide real-time targeting in U.S. military operations in Iran. In addition, open-source reporting indicates that AI tools were used in U.S. operations to capture the former Venezuelan president, although the exact use cases remain classified.
The Central Intelligence Agency (CIA) is also reportedly deploying AI systems to help analyze the plans, intentions, and capabilities of foreign nations, with CIA Deputy Director Michael Ellis revealing that the agency recently used AI to create the CIA’s first autonomous intelligence report.
AI is increasingly integrated across critical infrastructure sectors. The energy sector is using AI for grid maintenance prediction, anomaly detection, and efficiency optimization. While machine learning has long analyzed grid data, generative AI now extends these applications to grid planning, operations, and security. The DOE cautions that foundation models can produce unpredictable outputs without proper safeguards for energy systems.
“The Energy Paper in this series identifies transmission as the most vulnerable link for AI functionality in the energy sector,” ARI mentioned. “First, U.S. transmission is constrained by inadequate capacity and decade-long timelines for permitting and building new high-voltage lines. Second, the U.S. grid is disaggregated across the country. This structure limits power sharing, meaning localized generation failures cannot be easily offset by drawing power from other regions. Third, the specialized substations and large power transformers (LPTs) that serve AI data centers are chokepoints; these structures are typically lightly guarded and vulnerable to both physical sabotage and cyberattacks.”
Mentioning that a successful strike on one of these could take a facility offline for months, the ARI document identified that most AI data centers only maintain short-term backup power, which cannot support long-term disruptions during prolonged attacks. “Separately, grid modernization through smarter control and behind-the-meter generation introduces new cyber vulnerabilities, as these technologies depend on the integrity of grid sensor data, making them susceptible to attacks that can corrupt or interrupt the data flow. Disrupting power control systems, particularly those used by grid operators to balance supply and demand, would give an adversary significant leverage.”
Based on previous state-sponsored infiltration operations by China-linked Salt and Volt Typhoon groups, major adversaries may already possess the capability to cause such disruptions. Finally, the concentration of large AI data center loads in select regional clusters creates systemic risks. For example, if the facilities’ protective controls disconnect unexpectedly during a grid disturbance, the sudden loss of massive loads can destabilize entire regional power systems. This means that a single point of failure could cascade into widespread AI service disruption.
The ARI report pointed out that the space and bioeconomy sectors sought critical infrastructure designation but were denied. The Cyberspace Solarium Commission recommended space systems as critical infrastructure due to adversarial targeting, dependence on other sectors, unique technical characteristics, and overseas U.S. infrastructure. CISA similarly proposed evaluating both sectors. However, NSM-22 (2024) declined to designate either. Officials cited space’s deep integration across existing sectors as making standalone designation impractical, and deemed bioeconomy risks insufficiently distinct from hazards already regulated elsewhere.
Unlike space and bioeconomy, the AI sector presents a compelling case for critical infrastructure designation precisely because it lacks adequate regulatory oversight and faces unique vulnerabilities. While existing authorities govern space systems and bioeconomy risks parallel those in other sectors, AI confronts threats without parallel, such as training-data poisoning, model-weight theft, proprietary system distillation, and concentration of foundation models where a single compromise propagates across dependent systems. These distinct risks, combined with the absence of regulatory frameworks matching AI’s integration scale, position the sector as satisfying the very conditions space and bioeconomy could not meet.
The ARI report recommends that the President designate AI as critical infrastructure through a national security memorandum, subjecting it to incident reporting requirements under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). This designation would establish an AI-specific Sector Risk Management Agency (SRMA) tasked with coordinating across federal agencies and with industry to manage and mitigate AI-specific risks while building governmental capacity. The SRMA would work with relevant agencies to incorporate AI into the biennial National Risk Management Plan submitted to the President and would be empowered to create security and resilience standards across the entire AI infrastructure stack in collaboration with both public and private stakeholders.
Beyond oversight and standard-setting, the SRMA would facilitate public-private engagements among interdependent critical infrastructure sectors and would identify AI-specific Systemically Important Entities to prioritize government resources and security measures.
The report further recommends directing the intelligence community to conduct intelligence estimates on AI sector risks and share findings with industry as permitted by law. Finally, the SRMA should be authorized to coordinate existing executive authorities, including the Defense Production Act, along with financing and other capabilities that would enable government intervention to secure essential AI supply chains and expedite infrastructure development through mechanisms like streamlined permitting.
In addition, CISA and NIST should conduct a risk-based assessment to classify systems according to their frontier level, intended use cases, deployed sector, and potential impact on human health, safety, and security. This would create a dynamic federal framework for selecting the entities that constitute the AI sector and mitigating their vulnerabilities.


