Skip to content
Research

The Invisible Backbone

AI has increasingly become an underlying infrastructure for the United States, yet the AI sector lacks formal recognition as critical infrastructure, leaving it without public-private coordination mechanisms, information sharing, asset mapping, and protection standards commensurate with AI’s increasing role in critical operations.
Download PDF

Artificial intelligence (AI) has increasingly become an underlying infrastructure for the United States, as it is embedded in government operations, national defense, critical infrastructures, and the private sector. Yet the AI sector lacks formal recognition as critical infrastructure, leaving it without public-private coordination mechanisms, information sharing, asset mapping, and protection standards commensurate with AI’s increasing role in critical operations. Simultaneously, the AI sector faces threats that existing federal frameworks were not designed to address.

First, adversarial attacks, including data poisoning, distillation, and supply chain manipulation, can exploit the characteristics of AI systems that differ from those of conventional software. Second, because only a handful of providers build the foundation models that other sectors depend on, vulnerabilities in one model can propagate across the codebases built atop it. Third, AI is growing increasingly interdependent with existing critical infrastructure, expanding the attack surface of both the AI sector and the systems it is becoming intertwined with.

To address these risks, the President must designate AI as a critical infrastructure sector. The designation would allow the U.S. government to identify a lead AI infrastructure agency, define which entities constitute the sector, establish industry-wide coordination mechanisms, and develop AI-specific national security standards. To this end, Congress should also empower the executive to set security baselines for AI infrastructure, build federal capacity to coordinate and share threat information, and invest in AI safety and security research and development.

Introduction

Artificial intelligence (AI) systems are becoming increasingly critical for strengthening U.S. national security.  Take Anthropic’s Claude Mythos model preview. The system reportedly demonstrates unprecedented AI  cyber capabilities, which are key to identifying national security risks. Anthropic claims that Mythos has identified thousands of  high- and critical-severity vulnerabilities,1 a significant jump from just a year ago when AI models were  discovering vulnerabilities in single and double digits.2 Mythos demonstrates how AI-enhanced attacks could  exploit systems while deployers, such as hospitals and utilities, race to patch newly-identified vulnerabilities.  Simultaneously, AI is growing more significant for U.S. national security and economic prosperity,  making models like Mythos valuable targets for foreign adversaries to distill, replicate, and degrade.3 

The stakes extend well beyond any single model, though. The AI systems that already support many  U.S. services remain vulnerable to attacks that could take them offline, or worse, allow them to perform  seemingly well, while malicious code covertly permeates the infrastructure’s backbone.4 Because these  vulnerabilities cross corporate and infrastructural lines, no single company can defend against them alone.  This paper argues that the AI sector must be protected as a whole, through a critical infrastructure  designation, increased public-private coordination, information sharing mechanisms, and enhanced  infrastructure security research and development (R&D).

Defining Critical Infrastructure

Before assessing whether AI meets the critical infrastructure threshold, it is necessary to understand what  “critical infrastructure” (CI) means and how the United States determines which sectors earn that designation.  First, the Critical Infrastructures Protection Act of 2001 defines critical infrastructure as systems and assets “so  vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating  impact on security, national economic security, national public health or safety, or any combination of those  matters.”5 

Second, as directed by the 2021 National Defense Authorization Act, the Cybersecurity and Infrastructure  Security Agency (CISA) proposed a decision-support framework for assessing which sectors should be classified  as critical infrastructure.6 Under this framework:

01 A Coherent Sector

A collection of assets, systems, or networks providing common functions to the economy, government, or society.

02 Debilitating if Disrupted

Disruptions would produce debilitating impacts on national security, economic security, public health, or safety.

03 A Governance Gap

Existing regulatory mechanisms, policies, and governance structures do not adequately manage sector-wide risks.

04 Coordination Pays Off

The sector would meaningfully benefit from the coordination and collaboration mechanisms a CI designation offers.

Source: CISA, FY 2021 National Defense Authorization Act Report.

Using the CISA framework, this paper defines the AI infrastructure sector, identifies its unique vulnerabilities,  maps its interdependencies with other CI sectors, and proposes policy recommendations. This paper serves  as the overture in a series that will examine national security threats to different components of the AI  infrastructure stack. 

What is the AI Sector? 

This paper defines the AI sector from an infrastructure lens, as comprising organizations, facilities,  technologies, and industries whose primary purpose is the development, training, deployment, and operation  of AI systems. This sector includes the hardware, software, and operational infrastructure  that directly perform AI computation or produce the specialized components required for it. 

The AI sector includes four primary components: brains, brawn, building blocks, and benefit delivery. The first  three facilitate AI production and services, and the last delivers these systems to customers. 

01 Brains

AI Model Development & Software

Model design, training, model weights, evaluation and alignment systems, and specialized software, developed by frontier labs and research organizations.

02 Brawn

AI Compute Infrastructure

Specialized facilities, such as data centers, and the hardware that runs AI workloads.

03 Building Blocks

AI Hardware Design & Manufacturing

Specialized chip design, advanced semiconductor production in fabrication plants, and the chip supply chain.

04 Benefit Delivery

AI Operational & Delivery Systems

The platforms and infrastructure that deploy and serve AI models at scale, translating raw capabilities into usable services.

The first three components facilitate AI production and services; the fourth delivers them to customers. Source: ARI.

The AI sector also depends on external critical infrastructure, such as energy, communications, information  technology (IT), finance, water and wastewater, and transportation. These remain distinct sectors when  assessing interdependencies and vulnerabilities. However, for the purposes of this paper, outside infrastructure  becomes part of the AI sector when it is purpose-built to perform AI computational functions or when it  becomes an inherent part of said functions during operations. For example, the communications infrastructure  that connects AI data centers forms the transit part of the AI sector,8 while transmission and on-site generation  campuses constitute the electricity portion of these facilities.  

The AI Backbone of Modern Services 

Government Services and Defense 

AI systems are increasingly integrated into CI functions, forming interdependencies as these sectors rely on  AI and AI relies on them. Between August 2022 and August 2023, AI-related federal contracts increased by  almost 150 percent to $675 million.9 U.S. government services use AI systems for enterprise-wide functions  and individual productivity. Federal agencies already deploy AI tools to carry out their mandates. The Food  and Drug Administration (FDA) uses AI systems to review drug applications, the Centers for Disease Control and  Prevention (CDC) uses them to analyze medical images for abnormalities, the Department of Transportation (DOT) uses machine learning AI to  predict flight delays, and U.S. Customs and Border Protection (CBP) deploys AI systems  to analyze border crossing  patterns.10 A 2024 Ernst & Young survey also found that 51 percent of state and local public sector employees, and 64 percent  of federal employees, use AI applications several times a week or daily.11 

Figure 01 Frequent AI Use in Government

Share of U.S. government employees who say they use AI applications several times a week or daily

Federal
64%
State & local
51%
0100%
Source: Ernst & Young, Insights into the Integration of AI in Government, 2024 pulse survey of U.S. government employees.

The U.S. military already relies on AI systems for predictive maintenance and military logistics, and  is increasingly turning to AI technologies for military planning and operations.12 In a January 2026  memorandum, Secretary of War Pete Hegseth instructed the Department of War (DOW) to implement AI tools with speed, noting that  “the risks of not moving fast enough outweigh the risks of imperfect alignment.”13 

U.S. military AI adoption is increasing. In 2026, Deputy Secretary of War Steve Feinberg designated Palantir’s  Maven Smart System (MSS) as a program of record to allow for the AI system’s eventual “enterprise-wide  integration” into the U.S. military’s command and control systems.14 The U.S. military has already deployed  AI tools on classified data to provide real-time targeting in the U.S. military operations in Iran.15 In addition,  open source reporting indicates that AI tools were used in U.S. operations to capture the former Venezuelan  president, although the exact use cases remain classified.16 The Central Intelligence Agency (CIA) is also  reportedly deploying AI systems to help analyze the plans, intentions, and capabilities of foreign nations, with  CIA Deputy Director Michael Ellis revealing that the agency recently used AI to create the CIA’s first autonomous  intelligence report.17 

The Private Sector 

AI integration is also growing across private CI sectors.18 Financial institutions, for instance, are adopting AI sys tems for fraud detection, forecasting, trading, lending, cybersecurity, and customer service.19 A 2024 Treasury  Department report notes that these institutions have relied on AI-based fraud detection for over a decade and  increasingly apply AI to cybersecurity and code generation.20 But deployment carries risks: in 2025, the Finan cial Stability Oversight Council warned that “widespread [AI] adoption” in finance must be monitored so that  agencies and institutions can manage threats from “malicious actors, as well as national security, cyber, or other  unanticipated risks.”21 

The energy sector is following suit, integrating AI into predictive grid maintenance, anomalous event  detection, and energy management and efficiency technologies to support grid reliability.22 According to a 2024  Department of Energy (DOE) report, researchers and industry actors have long used machine learning models  to analyze grid data drawn from sensors, meters, and power plants.23 The advent of generative AI now extends  these use cases to grid planning, permitting and siting, grid operations and resilience, and security. However,  the DOE researchers warn that foundation models can produce stochastic outputs without mitigation measures  for energy applications. 

In the IT sector, AI systems already write code and support cybersecurity systems.24 First, AI-assisted coding  now underpins the software and platforms on which U.S. sectors increasingly rely. A 2025 survey found that  51 percent of professional code developers use AI tools in their development processes daily.25 Microsoft’s Chief  Executive Officer, Satya Nadella, claims that AI now writes approximately 30 percent of the company’s code,  and GitHub reports that its Copilot AI tool writes an average of 46 percent of code across all programming  languages.26 

Figure 02 Security Incidents from AI-Generated Code

“Has your organization ever identified a security vulnerability introduced by AI-generated code?”

1 in 5 suffered a serious incident
Source: Aikido, State of AI in Security & Development, 2026.

Second, AI cybersecurity systems can identify malicious events or threats; detect anomalies; and, with  generative AI, proactively mitigate code vulnerabilities and analyze threat actor behavior across various  sectors.27 AI-supplemented cybersecurity use cases date back to the 1990s, when they scanned security logs  for anomalies.28 Now, with the emergence of generative AI systems, a PYMNTS report found that between  May 2023 and August 2024, the percentage of chief operating officers adopting AI-powered cybersecurity  management systems within their companies increased from 17 to 55 percent.29 Moreover, Anthropic’s Mythos  model is reportedly unearthing decade-old vulnerabilities and writing exploits at an accelerated pace that  exceeds traditional patching timelines.30 

All of these developments introduce new risks. A 2026 Aikido study found that 20 percent of surveyed  organizations experienced serious security vulnerabilities due to AI-generated code.31 And, in July 2025, an  attacker exploited a flaw in the Amazon Q Developer (a coding assistant tool that developers install in their  coding environments), injecting malicious instructions into the official product, which was distributed through  a widely used marketplace. The compromised extension had 964,000 installations.32 Ultimately, the code did not  execute only because of a syntax error in its instructions.33 

Unique Threats & Vulnerabilities 

The same integration that makes AI valuable also makes it a target, introducing new attack vectors and  vulnerabilities that are distinct from traditional cyber threats. Specifically, generative AI outputs are context specific and nondeterministic; therefore, an AI model’s degradation is difficult to identify purely based on how  it functions.34 To secure these AI systems end-to-end, developers must maintain AI safety (ensuring robust  systems are developed through the data collection, training, and deployment phases) and AI security (guarding  against external threats).35 

How might a threat actor target the AI sector? First, actors can poison the system’s training data or use prompt  injection attacks to cause unintended model behaviors, disrupt the system’s effectiveness, or extract sensitive  information.36 Similar to traditional cyberattacks, adversaries can exploit AI systems by implanting malicious  code. However, due to AI systems’ generative nature and pervasiveness in code writing, this manipulation may  go undetected if model outputs and the software they support seemingly function correctly.37 

Second, attackers can exfiltrate model weights, which store AI systems’ core intelligence and cost billions of  dollars in data, compute, and algorithms to develop.38 Compromising these weights would give attackers access  to an AI developer’s most valuable assets, enabling adversaries to exploit the technology or use it to develop  competing models.39 Similarly, attackers can use “distillation” techniques to prompt the model’s inference  application programming interface (API) with repeated queries until they expose the model’s functionality; they  can then use this information to train new models that mimic the original’s behavior.40 In April 2026, the Office  of Science and Technology Policy released National Security and Technology Memorandum 4, which identified  “deliberate, industrial-scale campaigns to distill U.S. frontier AI systems” and directed federal agencies to engage  with the private sector on information sharing and mitigation measures.41 

Third, actors can leverage global AI manufacturing and supply chain chokepoints to exploit third-party  suppliers of U.S. AI hardware.42 States can use targeted export controls, import restrictions, or sanctions on  critical minerals (e.g., China’s restrictions on gallium and germanium) to create semiconductor delivery delays  and shortages. Actors can also ship semiconductor-grade materials with minor impurities, causing chip  fabrication yields to plummet, or sabotage concentrated manufacturing clusters, such as those in East Asia, to  disrupt hardware supply chains.43 

Fourth, using side-channel attacks on AI data centers, actors can physically or remotely track emissions,  including acoustic and power fluctuations, to infer proprietary and security secrets such as encryption keys.44 According to a 2024 RAND report, building the secure data centers and hardware needed to defend against  such sophisticated attacks requires sector-wide, national-security-oriented R&D that remains underdeveloped.45 

Moreover, AI systems introduce automation bias, which can undermine a user’s ability to determine whether  AI system outputs are reliable and secure. A review of 74 studies across healthcare, aviation, and military  sectors shows that when an automated decision support system provides an output, human oversight degrades.  Therefore, AI safety and security are vital to ensuring that the systems humans increasingly rely on and trust are indeed reliable.46 

Under Threat: Why AI Is Already a Target 

Assessing a target’s risk requires weighing three factors: threat, vulnerability, and consequence. To be  considered a threat, an actor must have the intent and capability to produce harm,47 be able to identify a  sector’s exploitable vulnerabilities, and inflict consequences on the selected target. Since threat actors would not  be able to disrupt all U.S. critical infrastructure systems simultaneously and have finite resources, they would  have to set priorities. To determine targets, adversaries often consider which infrastructures would have the  greatest consequences, are the easiest to attack (most vulnerable), and bring the lowest escalation risks. 

AI tools run on foundation models that are concentrated under a handful of companies with substantially  overlapping training data. The National Institute of Standards and Technology (NIST) notes that in this  “algorithmic monoculture,” many consequential decision-making sectors use the same model or algorithm,  which can result in increased susceptibility to correlated failures.48 Therefore, compromising a foundation  model can propagate vulnerabilities across many of the systems built atop it.49 

There are already documented cases of adversaries targeting and using AI infrastructure. In March 2026,  Iran attacked Amazon Web Services (AWS) data centers in the United Arab Emirates, striking U.S. cloud  and AI chokepoints, with the state media describing the operation as strikes on “the enemy’s technological  infrastructure.”50 In addition, state-linked Shenzhen University accessed Nvidia A100 and H100 chips via AWS,  revealing their susceptibility to remote access.51 

Interdependency: Vulnerabilities & Disruptions 

Due to the AI sector’s dependence on critical infrastructures and its concentration in a handful of models, the  disruption of AI functionality through interconnected sectors, such as energy and communications, can have  cascading impacts on U.S. services. 

AI & Energy

The Energy Paper in this series identifies transmission as the most vulnerable link for AI functionality in the  energy sector. First, U.S. transmission is constrained by inadequate capacity and decade-long timelines for  permitting and building new high-voltage lines.52 Second, the U.S. grid is disaggregated across the country. This  structure limits power sharing, meaning localized generation failures cannot be easily offset by drawing power  from other regions. Third, the specialized substations and large power transformers (LPTs) that serve AI data  centers are chokepoints; these structures are typically lightly guarded and vulnerable to both physical sabotage  and cyberattacks. A successful strike on one of these could take a facility offline for months. Moreover, most AI data centers only maintain short-term  backup power, which cannot support long-term disruptions during prolonged attacks.  

Separately, grid modernization through smarter control and behind-the-meter generation introduces new cyber  vulnerabilities, as these technologies depend on the integrity of grid sensor data, making them susceptible  to attacks that can corrupt or interrupt the data flow.53 Disrupting power control systems, particularly those  used by grid operators to balance supply and demand, would give an adversary significant leverage. Based  on previous state-sponsored infiltration operations by China-linked Salt and Volt Typhoon groups, major  adversaries may already possess the capability to cause such disruptions.54 

Finally, the concentration of large AI data center loads in select regional clusters creates systemic risks. For  example, if the facilities’ protective controls disconnect unexpectedly during a grid disturbance, the sudden loss  of massive loads can destabilize entire regional power systems. This means that a single point of failure could  cascade into widespread AI service disruption.55

AI & Communications

AI systems are equally dependent on communications infrastructure. First, unlike standard internet  applications, AI clusters operate as synchronized supercomputers using specialized, lossless protocols, so even  a 0.1 percent packet loss can stall training runs.56 Sophisticated adversaries could exploit this sensitivity by  inducing latency that degrades performance in time-critical applications, such as financial systems or military operations.

Second, despite the geographic distribution of data centers,57 their traffic aggregates through a small number  of internet exchange points (IXPs) and carrier hotels, creating significant chokepoints.58 A single attack on a  high-density peering hub can simultaneously isolate multiple AI inference nodes from their users.59 Third,  fiber, electricity transmission, and transportation infrastructures frequently share physical corridors,60 meaning one event, such as a storm, construction accident, or deliberate attack, can sever these infrastructures  simultaneously.61 Even if a data center is running on backup power, it cannot deliver AI services if its external fiber links are cut.62 

How Could the Energy and Communications Sectors Be Interdicted? 

A threat actor targeting U.S. AI infrastructure would prioritize the systems whose disruption would produce  the greatest effect relative to the actor’s conflict objectives. Attacks could focus on the grid and communications  nodes that are most heavily loaded, hardest to replace, and most critical to key AI functions. In a conflict  involving maritime operations, for example, an adversary would likely target the U.S. AI systems that support  logistics, ports, and troop movement, rather than striking indiscriminately. 

To disrupt power, adversaries’ priority targets would include (1) natural gas compressors serving major data  center hubs, (2) specialized substations with LPTs,63 and (3) the software platforms managing grid performance.  To disrupt communications functions, IXPs and carrier hotels represent the highest-value chokepoints. These  attacks could be kinetic or cyber. For example, substations outside guarded facilities are physically vulnerable;  in some cases, a single attacker with a weapon can damage them.64 Adversaries do not need to instigate full  blackouts. Targeted, temporary disruptions to the grid, communications infrastructure, or behind-the-meter  systems could degrade AI functionality sufficiently to send strategic signals or restrict U.S. AI services in a conflict. 

Space and Bioeconomy: Critical, But Not CI 

The practical weight of CISA’s CI designation framework becomes clearest when applied to sectors that have  sought, and failed to receive, a designation. In 2023, the Cyberspace Solarium Commission 2.0—a think tank  created from the congressionally established U.S. national cybersecurity strategy body—recommended that space systems be designated as critical infrastructure because (1) they have been targeted in adversarial attacks  and espionage campaigns, (2) other critical infrastructure sectors depend on the technologies, (3) they exhibit  unique physical and technical characteristics, and (4) much of U.S. terrestrial infrastructure is located abroad.  Similarly, CISA proposed that the bioeconomy and space systems sectors be evaluated under the framework  above. However, the Solarium report admits that federal rules already regulate space systems, with the DOW’s  jurisdiction over defense applications and the Federal Communications Commission’s authority over space based communications systems.65 

Ultimately, the President did not designate these sectors as CI in National Security Memorandum (NSM)-22,  which renewed the U.S. critical infrastructure sector framework in 2024. Senior officials noted that this was due  to the space sector already being so ingrained into “many different sectors” that designating it as a standalone  entity did not “make sense,” and because risks to the bioeconomy “were not unique enough to merit a new  sector.”66 

While these sectors were ultimately passed over due to existing regulations and lead agencies with jurisdictions  over the systems’ core functions, no comparable authority currently governs the AI sector’s risks at the scale  its integration demands. And whereas the bioeconomy’s hazards were deemed too similar to those addressed  elsewhere to justify a standalone designation, the AI sector confronts vulnerabilities without parallels in  other sectors—training-data poisoning, the theft of model weights, distillation of proprietary systems, and a  concentration of foundation models in which a single compromise can propagate across everything built upon  it. The AI sector thus satisfies the very conditions that space and the bioeconomy could not: it lacks an existing  regulatory regime equal to its risks, and its threats are distinct enough to warrant a CI designation of its own.

Recommendations

Despite AI systems confronting unique threats, private companies lack the resources and multi-sectoral  coordination capacity necessary to secure their technologies against nation-state adversaries. The frontier AI  labs have commercial incentives to protect their intellectual property and users’ privacy against competitors,  criminal hacking groups, insider threats, and industrial espionage, but that protection stops at the firm’s  perimeter.67 U.S. government capacity can fill this gap, protecting AI infrastructure at a scale no single company  can achieve alone. To secure U.S. AI infrastructure, Americans for Responsible Innovation recommends the  following actions:  

Designate AI as a Critical Infrastructure Sector 

The President must designate the AI sector as critical infrastructure in a national security memorandum,  subjecting it to incident reporting requirements under the Cyber Incident Reporting for Critical Infrastructure  Act of 2022 (CIRCIA). The memorandum would secure the sector by:68  

01

Assigning an AI-specific Sector Risk Management Agency (SRMA) to coordinate across the federal government and with the AI industry to help manage and mitigate AI-specific risks while building U.S. governmental capacity;69

02

Incorporating AI into the biennial National Risk Management Plan that summarizes U.S. risk mitigation efforts to the President;70

03

Empowering the SRMA to work across agencies and with the private sector to create security and resilience standards across the entire relevant AI infrastructure stack;

04

Facilitating public-private engagements across interdependent CI sectors;71

05

Identifying AI-specific Systemically Important Entities (SIEs) to prioritize government resources, risk mitigation, and security standards;

06

Directing the intelligence community to conduct intelligence estimates on AI sector risks and, as permitted by law and regulation, share those with industry; and

07

Allowing the SRMA to coordinate authorities (e.g., the Defense Production Act), financing, and other capabilities that would enable executive intervention to secure essential supply chains and expedite infrastructure buildouts (e.g., through streamlined permitting).72

In addition, CISA and NIST should conduct a risk-based assessment to classify systems according to their  frontier level, intended use cases, deployed sector, and potential impact on human health, safety, and security.73 This would create a dynamic federal framework for selecting the entities that constitute the AI sector and  mitigating their vulnerabilities. 

Establish Security Baselines 

To mitigate AI data center security vulnerabilities, CISA and the Center for AI Standards and Innovation  (CAISI) should publish updated AI data center guidance establishing security baselines.74 To achieve this,  Congress can direct CISA to create a task force to audit the physical, cyber, and personnel security of AI data  centers; identify vulnerabilities; and work with AI companies to develop enforceable security standards  across the AI infrastructure stack.  

Spur AI Infrastructure Security R&D

In parallel, to build a nascent AI infrastructure safety and security R&D ecosystem, Congress should allocate  funding to the Defense Advanced Research Projects Agency (DARPA) to administer grants that create a cost effective market for the technology required to achieve AI infrastructure standards calibrated to national  security threats.75 

Taken together, these measures would give the federal government the coordination capacity that the AI  threat environment already demands, and that the private sector alone cannot supply. 

Conclusion

The AI sector already bears the hallmarks of critical infrastructure. It is interwoven with public and private services, concentrated among a handful of foundation models, and increasingly interdependent with CI sectors, meaning a single attack on the AI stack could cascade across multiple sectors at once.

The U.S. threat environment compounds these structural concerns. State-linked actors have already struck AI data centers and demonstrated sophisticated penetration capabilities, suggesting that the conditions for disruption are taking shape. Simultaneously, strategic assets, such as Mythos and similar successors, are precisely the targets that adversaries will be incentivized to attack. Every month of delay widens the gap between how much the nation relies on AI and how little it protects it. As these threats grow, the President and Congress must act to fortify U.S. AI infrastructure and expand public-private coordination in this burgeoning sector.

About the author

Jessica Maksimov

Policy Analyst

More from Jessica Maksimov →