The Cybersecurity and Infrastructure Security Agency (CISA) in its regulator and standards-setter capacity, covering joint guidance on agentic-AI security, a proposed compression of the federal critical-vulnerability patch deadline, and Five Eyes-coordinated agentic-AI guidance. This page is the companion to CISA — Cybersecurity and Infrastructure Security Agency (AI Deployer), which covers CISA's role as an AI deployer (internal AI use, agentic monitoring of federal-network logs, and similar). The same organization holds an entities/ (regulator) page and a government/ (deployer) page because, under the no-duplication rule in CLAUDE.md, an org may appear in both folders when its two roles are operationally distinct: CISA's guidance authority over agentic-AI security, vulnerability-disclosure timelines, and supply-chain attestation is separate from its internal AI deployment.
Operative authorities
CISA's regulatory leverage runs through several established instruments:
- Binding Operational Directives (BODs) for federal civilian executive-branch agencies. A 3-day-patch deadline, if issued, would take this form.
- Known Exploited Vulnerabilities (KEV) catalog, which mandates remediation timelines for vulnerabilities CISA designates as actively exploited.
- Joint Cyber Defense Collaborative (JCDC), a public-private coordination vehicle and a likely path through which AI-cybersecurity-specific frameworks reach private-sector deployers.
- Sector Risk Management Agency (SRMA) role. CISA is the SRMA for several critical-infrastructure sectors and shares the role for others.
Agentic-AI guidance (2026)
CISA issued two Five Eyes-coordinated guidance documents on agentic-AI security in May 2026. On May 1, 2026, it published an agentic AI joint guide covering agentic-AI security architecture, co-published with Australia's ASD, the UK's NCSC, and Canada's CCCS (Source: covered in dev-log 2026-05-04 cluster). On May 4, 2026, CISA and the Australian Cyber Security Centre (ACSC) published joint guidance on agentic-AI deployment risks, addressing privilege creep, behavioral misalignment, and obscure event records; it was the second Five Eyes-coordinated AI-cybersecurity guidance after the May 1 document (Source: covered in dev-log 2026-05-09-0213).
The guidance is voluntary by design but has historically been cited in agency enforcement, including FTC AI-product cases. Whether the May 4 CISA + ACSC guidance acquires the force of de-facto regulation through procurement and enforcement citation within 12 months is unresolved; coverage of the May 4 guidance issued in May 2026 forecasts that it will be cited as a governance baseline in at least one FTC or DOJ enforcement action by 2027-05-31 (Source: covered in dev-log 2026-05-09-0213).
Proposed 3-day patch deadline
As of May 1, 2026, CISA was considering a 3-day federal critical-vulnerability patch deadline, compressed from the previous 15-day deadline, attributed to pressure from AI-powered hacking (Source: covered in dev-log 2026-05-04 cluster). Such a deadline would be issued as a Binding Operational Directive. The proposal is positioned as the defensive counterpart to the attack-cost economics described for Claude Mythos Preview, where the threat economics are framed as forcing the defense economics. Coverage of the proposal issued in May 2026 forecasts that a Binding Operational Directive mandating a patch window of 72 hours or less for KEV-catalog vulnerabilities will be published by 2026-11-30 (Source: covered in dev-log 2026-05-04 cluster).
Overlapping AI-cybersecurity authority
AI-cybersecurity-specific authority is distributed across several bodies: CISA (defense and mitigation), NIST CAISI (Center for AI Standards and Innovation) (pre-release evaluation), Chief Digital and Artificial Intelligence Office (CDAO) (DOD procurement), and the FTC (consumer deployment). CISA serves as the deployment-and-incident counterpart to CAISI's pre-release-evaluation role, and as the civilian-side equivalent of CDAO for non-DOD federal agencies. Per Bloomberg, May 8, 2026, a narrower cybersecurity-only AI executive order was under consideration; coverage forecasts that, if the final EO ships, it will name CISA as the operational authority by 2026-12-31, though that role could instead sit with CAISI (Source: Bloomberg, May 8, 2026). See AI and Cybersecurity, AI Pre-Release Vetting, and Procurement-Driven AI Governance.
Position on China-developed frontier models
CISA vulnerability-management official Jay Gazlay identified national-security concerns over China-developed frontier AI models and called for stronger interagency efforts against nation-state actors, in remarks published July 20, 2026 — days after Moonshot AI's Kimi K3 release intensified U.S. policy debate over Chinese open-weight models (Source: insideaipolicy.com). See Open-Weight Frontier Models.
Relationships
- regulator-counterpart-of: CISA — Cybersecurity and Infrastructure Security Agency (AI Deployer) (same org, deployer role)
- related: NIST CAISI (Center for AI Standards and Innovation) — CAISI is the pre-release-evaluation counterpart; CISA is the deployment-and-incident counterpart.
- related: Chief Digital and Artificial Intelligence Office (CDAO) — DOD procurement; CISA's civilian-side equivalent for non-DOD federal agencies.
- related: AI and Cybersecurity, AI Pre-Release Vetting, Procurement-Driven AI Governance
- related: Claude Mythos Preview — the threat actor for which CISA's guidance is the defensive response.
- related: Asd Acsc (stub — Australian Cyber Security Centre), Ncsc Uk (stub), Cccs (stub) — Five Eyes peers.
Sources
This page is a stub created during the v4.0 continuation pass (May 2026). Citations:
- May 4, 2026 CISA + ACSC joint guidance (Source: covered in dev-log 2026-05-09-0213).
- May 1, 2026 CISA agentic AI joint guide (Source: covered in dev-log 2026-05-04 cluster).
- Proposed 3-day federal critical-vulnerability patch deadline (Source: covered in dev-log 2026-05-04 cluster).
Recommend ingesting the May 4 CISA + ACSC guidance as a foundational source (queue: INGEST-cisa-acsc-agentic-ai-2026-05-04.md).