The Clock is Ticking on U.S. Cybersecurity

The September 30 federal funding deadline is quickly approaching, and Congress is once again inching toward a cliff. This time, the Cybersecurity Information Sharing Act of 2015 (CISA15), a foundational cybersecurity information-sharing authority, is set to expire absent congressional action. This lapse comes just as the Administration seeks to expand coordination through its new Gold Eagle AI cybersecurity clearinghouse.

The state of U.S. cybersecurity is at a critical inflection point as industry and the U.S. government race to keep pace, coordinate threat detection, and patch software vulnerabilities in the age of frontier AI models. Over the last year alone, AI-enabled attacks have increased by 89 percent while the speed of the attacks also increased by 65 percent.[1]

The stakes are rising fast, and Congress is running out of time. With just 15 legislative days before the September funding deadline, lawmakers are on the verge of allowing one of the nation’s most effective cybersecurity tools to expire at exactly the moment government and industry are expanding cooperation against AI-enabled cyberattacks on hospitals, banks, and local utilities.

Frontier AI-model companies are working with the administration through President Trump’s Gold Eagle initiative to fight back against both individual and nation-state malicious actors.[2] As progress is made to ensure that the tools at the government’s disposal are the best in the world, Congress must ensure the legal authorities that make information sharing possible remain in place. Technology companies, critical infrastructure operators, and government agencies cannot coordinate against emerging threats if the foundation for that coordination lapses.

New and more advanced AI models are coming out at rapid pace and with each advancement comes increasingly complex questions about the capabilities of each model. Congress must ensure that the technology sector can work together with their customers to bolster the nation’s digital infrastructure, and ultimately, the American consumer. Protecting Americans requires the ability to rapidly identify threats, share intelligence, and respond before attacks spread.

The House of Representatives has made progress on a long-term reauthorization of CISA15 by including Chairman Garbarino’s Widespread Information Management for the Welfare of Infrastructure and Government Act in the National Defense Authorization Act for Fiscal Year 2027; however, Congress shouldn’t let the program lapse while they work through the legislative process. The White House made clear in their Statement of Administrative Policy that they want to use this authority. At a minimum, lawmakers must extend CISA15 before the end of September to avoid creating an unnecessary vulnerability in the nation's cyber defenses.

From hospitals and banks to electric utilities and small businesses, every state and congressional district depends on secure digital infrastructure. As AI reshapes the threat landscape, now is not the time to strip America’s cyber defenders of a proven, effective tool.


[1]CrowdStrike. (2026). 2026 global threat report: Year of the evasive adversary.

[2] Industrial Cyber. (2026). US launches Gold Eagle initiative to boost cybersecurity vulnerability coordination, bolster critical infrastructure defense.

Tags: Cybersecurity

Related