Organizations/government

CISA

US cybersecurity agency.

9 records1 defense8 policyWebsite
Jun 22, 2026
Five Eyes cyber agency heads tell leaders AI is shifting cyber risk on a timescale of months
PolicyGuidanceAustralian Signals Directorate (ACSC), Communications Security Establishment, GCSB

The heads of the Five Eyes cyber agencies issued a joint statement that AI is rapidly transforming cyber risk and that organizations must act within months, not years. They ask leaders to reduce attack surface, accelerate patching as exploitation windows shorten, replace unsupported legacy systems, strengthen identity controls, and prepare for incidents.

Jun 2, 2026
Executive Order 14409 creates classified cyber benchmarking for covered frontier models and a clearinghouse
PolicyRegulationThe White House, US Department of the Treasury, NSA

Executive Order 14409 directs Treasury, NSA and CISA to develop a classified benchmarking process to assess advanced cyber capabilities of AI models and designate covered frontier models, with a voluntary framework for pre-release government and trusted-partner access. It also orders an AI cybersecurity clearinghouse to coordinate vulnerability scanning, validation and remediation with industry, and states it does not create mandatory licensing or pre-clearance.

May 1, 2026
CISA, ASD's ACSC and international partners publish joint guidance on careful adoption of agentic AI
PolicyGuidanceCISA, NSA, Australian Signals Directorate (ACSC)

CISA and the Australian Signals Directorate, with US and international partners, published guidance on the cybersecurity risks of agentic AI services and recommended mitigations. CISA highlights expanded attack surface, privilege creep, behavioral misalignment and obscure event records as risks, and recommends avoiding broad access, starting with low-risk use cases, and folding agent security into existing risk models.

Jan 8, 2026
PNNL uses a Claude-based agent to speed adversary emulation against a water treatment plant model
DefensePaperAnthropic, Pacific Northwest National Laboratory, CISA

Anthropic reports that Pacific Northwest National Laboratory built a scaffold around Claude Sonnet 4 to automate adversary emulation against a high-fidelity cyber-physical model of a water treatment plant used for CISA. PNNL estimates attack reconstruction took three hours instead of multiple weeks; in one run the model switched to a different known privilege-escalation technique when a provided tool failed.

Dec 3, 2025
CISA, ASD and partners issue principles for securely integrating AI, including agents, into OT
PolicyGuidanceCISA, Australian Signals Directorate (ACSC), NSA Artificial Intelligence Security Center

CISA and the Australian Signals Directorate, with NSA, FBI and national cyber agencies of Canada, Germany, the Netherlands, New Zealand and the UK, published four principles for integrating AI into operational technology. The guidance explicitly covers machine learning, LLM-based AI and AI agents because of the security and safety challenges they pose in industrial environments.

Jul 23, 2025
America's AI Action Plan calls for a DHS-led AI-ISAC and CAISI evaluation of frontier cyber risks
PolicyProgramThe White House, US Department of Homeland Security, CISA

The White House AI Action Plan recommends establishing an AI Information Sharing and Analysis Center led by DHS with CAISI and the National Cyber Director, DHS guidance on AI-specific vulnerabilities, and updates to CISA incident response playbooks for AI systems. It also directs CAISI to evaluate frontier models for national security risks including cyberattacks, and to assess adversary AI systems for backdoors. As of February 2026, a CISA official described the AI-ISAC as still a pre-decisional memo.

May 22, 2025
NSA, CISA and FBI with allies publish AI Data Security best practices
PolicyGuidanceNSA Artificial Intelligence Security Center, CISA, FBI

The NSA AI Security Center, CISA, the FBI and international partners released a cybersecurity information sheet on securing data used to train and operate AI systems across the lifecycle. It recommends robust data protection, proactive risk management and stronger monitoring and threat detection, and is aimed at defense industrial base, national security system, federal and critical infrastructure operators.

Apr 15, 2024
NSA-led Five Eyes guidance on deploying externally developed AI systems securely
PolicyGuidanceNSA Artificial Intelligence Security Center, CISA, FBI

The NSA's Artificial Intelligence Security Center led joint guidance with CISA, the FBI and the national cyber centres of Australia, Canada, New Zealand and the UK on deploying and operating externally developed AI systems. It sets objectives to improve the confidentiality, integrity and availability of AI systems and to mitigate known vulnerabilities, organized around protecting, detecting malicious activity against, and responding to incidents involving AI systems.

Nov 27, 2023
UK NCSC and US CISA publish multinational Guidelines for Secure AI System Development
PolicyGuidanceUK National Cyber Security Centre, CISA

The UK NCSC published guidelines for providers of AI systems, developed with CISA and endorsed by agencies from 18 countries. The guidance is organized around four lifecycle areas: secure design, secure development, secure deployment, and secure operation and maintenance, and takes a secure-by-default approach.