| Type | U.S. federal cybersecurity agency | |
| Parent | [[government/dhs | Department of Homeland Security]] |
| Established | November 16, 2018 (Cybersecurity and Infrastructure Security Agency Act of 2018, transferring functions from the National Protection and Programs Directorate within DHS) | |
| Acting Director (May 2026) | Madhu Gottumukkala (Acting; following the April 22, 2026 withdrawal of nominee Sean Plankey) | |
| Statutory authority | 6 U.S.C. § 651 et seq. |
The Cybersecurity and Infrastructure Security Agency (CISA) is the U.S. federal civilian agency charged with national cybersecurity. It both deploys AI inside its cyber-defense workflow and acts as a front-line responder to AI-amplified offensive cyber capability. In 2026 it became the focus of several intersecting AI-policy developments: a congressional inquiry into a senior official's use of public ChatGPT, the withdrawal of its director nominee over AI-cyber policy, its co-authorship of Five Eyes agentic-AI guidance, and proposals to compress federal patch deadlines in response to AI-powered hacking.
Mandate
CISA coordinates national defense against cyber threats to government networks and critical infrastructure across the 16 designated sectors. It runs the Known Exploited Vulnerabilities (KEV) catalog and the Federal Civilian Executive Branch (FCEB) patch-mandate process, operates the Joint Cyber Defense Collaborative (JCDC) for public-private threat coordination, and represents the United States, alongside NSA, in Five Eyes cybersecurity engagements.
AI deployment and the ChatGPT FOUO incident
CISA uses AI for vulnerability triage, threat-intelligence correlation, and general staff productivity. Its internal deployment posture drew congressional scrutiny in February 2026. Sen. Charles Grassley's February 5, 2026 letter demanded answers after Acting Director Madhu Gottumukkala uploaded at least four "for official use only" documents to a public ChatGPT instance, despite CISA being blocked from ChatGPT on government networks. Gottumukkala had obtained special access that bypassed the agency-wide block.
The incident sits at the intersection of the federal AI-adoption push (America's AI Action Plan, GSA OneGov USAI) and operational-security guardrails. According to the Grassley letter, adoption-side pressure resulted in a special-access exception to a security block for senior leadership; the episode has been cited in subsequent state-AI-procurement debates.
Director nomination withdrawal
Sean Plankey withdrew his nomination to head CISA on April 22, 2026, citing "irreconcilable differences" over AI-cyber policy direction (Source: cyberscoop.com). The withdrawal followed the dismissal of Collin Burns from CAISI four days into his role, which together point to friction inside the administration over AI-safety and AI-cyber personnel and direction. Gottumukkala remains Acting Director.
Five Eyes agentic-AI guidance
On May 1, 2026, CISA and NSA, together with cybersecurity counterparts in Australia, Canada, New Zealand, and the United Kingdom, released joint guidance on responsible adoption of agentic AI. The document is the first major Five Eyes technical-and-policy publication specifically on agentic-AI deployment, focused on the deployment-time security risks created by AI systems that act on their own initiative across enterprise environments. It is the first cross-Five-Eyes operational document to treat agent identity, agent-versus-tool delegation, and multi-agent orchestration risk as cyber-defense concerns rather than solely AI-safety concerns.
The guidance complements NIST AI Agent Standards Initiative (2026) (the CAISI-led NIST initiative on agent security and identity) and aligns with the agent-aware Generative AI v2 profile previewed by NIST on April 22, 2026. The publication places CISA at the center of allied-country agentic-AI cybersecurity coordination, paralleling NSA's traditional SIGINT role but with civilian-network scope.
Patch-deadline policy and AI-amplified offensive capability
CISA's KEV and FCEB patch-mandate process is the point at which AI-amplified offensive cyber capability translates into federal civilian-network operational policy. As of May 1, 2026, U.S. cybersecurity officials were weighing cutting the federal critical-vulnerability patch deadline to three days because of AI-powered hacking, reflecting concern over how fast frontier-model-assisted attackers can weaponize a published vulnerability (Source: reuters.com). Officials framed the proposal against capability data including the Mythos "ten-minute" attack-cost demonstration and the AISI four-month doubling rate for offensive cyber capability.
If adopted, the three-day deadline would compress the existing 15-day standard under BOD 22-01 (the FCEB binding operational directive on KEV remediation) by 80 percent, the largest single-step compression in CISA's KEV history. See AI and Cybersecurity.
Academic work bearing on the same window was published on June 2, 2026: a proof-of-concept worm driven by an open-weight language model, evaluated against a network seeded with vulnerabilities drawn from the KEV catalog, the OWASP Top 10: 2025 and MITRE ATT&CK, obtained root access on hosts carrying vulnerabilities disclosed in April and May 2026 — after the model's training cutoff — in 41 of 67 attempts, in two cases working from a single retrieval document of publicly available exploit instructions. The authors argue that "an AI worm that acts on public disclosures within days of publication could outpace more, if not most, organizations' ability to patch systems before exploitation," and note that the flaw exploited by WannaCry and NotPetya had a patch available for months before either struck. Their prototype needed roughly five days to reach half the 33-host test network, a pace set by the inference calls each target required (AI Agents Enable Adaptive Computer Worms (Guan et al., June 2026)).
Executive-order taskings and congressional oversight
President Trump's June 2, 2026 frontier-AI executive order on software vulnerabilities directs CISA, via DHS and with OMB and ONCD, to issue Binding Operational Directives expediting AI-enabled federal cyber defense and facilitating agency access to "covered frontier models." As of June 5, 2026, the House Homeland Security cyber subcommittee was exploring ways to help CISA carry out these taskings, including secure-by-design practices and open-source-software legislation, in early congressional engagement on the resourcing and authorities CISA needs to execute the order (Source: insideaipolicy.com).
CISA issued a binding operational directive on June 10, 2026 ordering civilian federal agencies to take a risk-based approach to vulnerability management as the government implements the June 2 executive order; the directive builds on the Known Exploited Vulnerabilities catalog created under BOD 22-01, and CISA officials framed it on June 11 as a response to frontier models' growing ability to leverage exploits (Source: insideaipolicy.com; insideaipolicy.com). Stakeholders backed the directive's risk-based vulnerability-management approach in June 12, 2026 reporting (Source: insideaipolicy.com). Separately, Sen. Mark Warner introduced a bill on June 11, 2026 directing CISA to update its sector-specific security plans to account for advanced AI-driven risks (Source: insideaipolicy.com).
White House officials have discussed making CISA the nexus for scanning federal networks with Anthropic's Mythos model, with one official calling CISA access "imminent" in reporting published June 11, 2026 (Source: nextgov.com). The expanded mandate would arrive against a tighter budget: the House Appropriations Committee advanced the FY2027 DHS spending bill 34–27 on June 12, 2026 with AI provisions, cutting CISA's budget by $252.7 million to $2.35 billion (Source: insideaipolicy.com). See EO — Promoting Advanced AI Innovation and Security (Trump, signed June 2, 2026).
Broader frontier-AI-cyber response
CISA's posture sits within a wider set of AI-cybersecurity guidance from federal and state regulators. The NY DFS issued a May 26, 2026 advisory on "heightened cybersecurity risks associated with certain frontier artificial intelligence models that amplify the potency, scale, and speed of identifying vulnerabilities and exploits in information systems," the first significant U.S. state-financial-regulator guidance explicitly aimed at frontier capabilities. The FBI's IC3 2025 Internet Crime Report, released May 2026, logged 22,364 AI-related cybercrime complaints with losses above $893 million for the calendar year.
Relationships
- parent: DHS — Department of Homeland Security (AI Deployer)
- co-author: Five Eyes Joint Guidance on Secure Deployment of AI Agents (May 2026) (with NSA + Five Eyes counterparts)
- adjacent-to: National Institute of Standards and Technology (NIST), NIST CAISI (Center for AI Standards and Innovation) (standards-side counterparts), New York State Department of Financial Services (NYDFS) (state-financial-regulator counterpart on frontier-AI-cyber)
- related: Sen. Grassley Letter to CISA re ChatGPT (2026-02-05), AI and Cybersecurity, Government AI Procurement, Federal AI Adoption — Patterns and Tensions, Agentic AI, Claude Mythos Preview, UK AI Safety Institute (AI Security Institute)
- regulated-by: Congress via 6 U.S.C. § 651 et seq.; oversight via Senate Homeland Security and Governmental Affairs Committee and House Homeland Security Committee