A critical infrastructure designation would give AI companies 72 hours to report a cyberattack, put their data centers under federal security standards, and name the firms the government defends first.
Key Takeaways
- Americans for Responsible Innovation (ARI) asked the President to add AI to the critical infrastructure list, which already covers power, water, banking, and hospitals.
- A 2022 law requires critical infrastructure companies to report cyberattacks within 72 hours, and a designation would extend that duty to AI companies. The law is not in force for anyone yet because CISA has not yet written the regulation that puts it into effect.
- ARI says the need for critical infrastructure designation is urgent as adversaries are already attacking AI infrastructure.
- ARI cited recent Iranian drone strikes that destroyed two Amazon data centers in the United Arab Emirates as proof.
Americans for Responsible Innovation, a Washington nonprofit that lobbies on technology policy, published a report on August 20 asking the President to add AI to the federal critical infrastructure list. Sixteen sectors sit on that list today.
ARI recommends including in the designation companies that build and train AI models, the data centers powering them, AI chip designers and manufacturers, and the platforms selling access. A critical infrastructure designation puts one federal agency in charge of the sector, requires its companies to report attacks, and ensures the government tells those companies what it knows about threats aimed at them.
Attacks on AI infrastructure have already done damage
ARI cites two attacks as examples of the need for designation. On March 1, Iran flew drones into two Amazon Web Services data centers in the United Arab Emirates, setting fires and cutting power. Banking and food delivery apps across the UAE stopped working, and Amazon’s status page still showed problems eleven days later.
The previous July, someone offered a routine code contribution to the public repository behind Amazon Q Developer, a coding assistant used inside a programmer’s editor. Amazon merged it, and a badly protected credential in its build system handed the contributor administrator access. They planted an instruction in the next official release telling the assistant to wipe the computer it ran on and delete the customer’s cloud account. Amazon published that release to the marketplace, where the assistant was downloaded more than 964,000 times. The instruction never ran, because whoever wrote it made a syntax error.
ARI says one corrupted model could damage many industries at once
AI now runs inside operations across finance, health care, energy, and government. Those companies mostly build their own AI tools, but nearly all of those tools sit on a small number of underlying models, running in data centers owned by a handful of cloud companies.
That is the risk ARI describes. An attacker who corrupts one widely used model does not damage one company. The corruption travels into everything built on that model.
This kind of attack is hard to notice. An AI system produces different output every time it runs, so a tampered one keeps answering and looks like it is working long after its answers stopped being reliable. And currently no rule requires the companies building those models to meet a security standard or disclose a breach, so the businesses running on them cannot spot the problem themselves, and nobody has to tell them. The government cannot see it either.
A designation would assign one federal agency to the sector, set security standards those companies must meet, and require them to report attacks, so a warning reaches the businesses downstream.
“AI systems are becoming increasingly integrated across industries, including health care, finance, and manufacturing, and without formal national security standards, an attack on these systems could lead to the incapacitation of these sectors at once,” said ARI policy analyst Jessica Maksimov, who wrote the report with Terrence Kelly.
AI companies would get 72 hours to report an attack
The designation would put AI companies under the Cyber Incident Reporting for Critical Infrastructure Act of 2022, which gives companies in listed sectors 72 hours to tell the government they were attacked. AI companies currently have no federal reporting duty.
That requirement is not in force for anyone. A law of this kind takes effect only once the responsible agency writes the regulation that carries it out, and CISA, the federal cybersecurity agency, has missed its deadlines to do so. It now expects to publish this fall.
CISA and the Center for AI Standards and Innovation (CAISI), the federal office that writes AI security guidance, would then publish security standards for AI data centers. ARI wants Congress to fund a CISA team to audit them.
A short list of AI companies would get government attention first
The agency would name the systemically important AI companies whose failure would do the country the most damage. The report says government protection, security requirements, and help reducing risk should start with these companies ahead of everyone else in the sector.
The last two sectors that asked were turned down
In 2024, the President declined to label space systems or the bioeconomy, meaning goods made from biological processes, as critical infrastructure. Officials said space systems were already spread across other sectors on the list, and that the bioeconomy’s risks were not sufficiently different from the risks those sectors already cover.

