
Responsible Innovation at the Frontier
ARI’s blueprint for federal AI governance is designed to promote safe frontier AI development in America. The blueprint is built around three governance functions any federal proposal should incorporate.
Artificial intelligence (AI) has increasingly become an underlying infrastructure for the United States, as it is embedded in government operations, national defense, critical infrastructures, and the private sector. Yet the AI sector lacks formal recognition as critical infrastructure, leaving it without public-private coordination mechanisms, information sharing, asset mapping, and protection standards commensurate with AI’s increasing role in critical operations. Simultaneously, the AI sector faces threats that existing federal frameworks were not designed to address.
First, adversarial attacks, including data poisoning, distillation, and supply chain manipulation, can exploit the characteristics of AI systems that differ from those of conventional software. Second, because only a handful of providers build the foundation models that other sectors depend on, vulnerabilities in one model can propagate across the codebases built atop it. Third, AI is growing increasingly interdependent with existing critical infrastructure, expanding the attack surface of both the AI sector and the systems it is becoming intertwined with.
To address these risks, the President must designate AI as a critical infrastructure sector. The designation would allow the U.S. government to identify a lead AI infrastructure agency, define which entities constitute the sector, establish industry-wide coordination mechanisms, and develop AI-specific national security standards. To this end, Congress should also empower the executive to set security baselines for AI infrastructure, build federal capacity to coordinate and share threat information, and invest in AI safety and security research and development.

Artificial intelligence (AI) systems are becoming increasingly critical for strengthening U.S. national security. Take Anthropic’s Claude Mythos model preview. The system reportedly demonstrates unprecedented AI cyber capabilities, which are key to identifying national security risks. Anthropic claims that Mythos has identified thousands of high- and critical-severity vulnerabilities,1 a significant jump from just a year ago when AI models were discovering vulnerabilities in single and double digits.2 Mythos demonstrates how AI-enhanced attacks could exploit systems while deployers, such as hospitals and utilities, race to patch newly-identified vulnerabilities. Simultaneously, AI is growing more significant for U.S. national security and economic prosperity, making models like Mythos valuable targets for foreign adversaries to distill, replicate, and degrade.3
The stakes extend well beyond any single model, though. The AI systems that already support many U.S. services remain vulnerable to attacks that could take them offline, or worse, allow them to perform seemingly well, while malicious code covertly permeates the infrastructure’s backbone.4 Because these vulnerabilities cross corporate and infrastructural lines, no single company can defend against them alone. This paper argues that the AI sector must be protected as a whole, through a critical infrastructure designation, increased public-private coordination, information sharing mechanisms, and enhanced infrastructure security research and development (R&D).

Before assessing whether AI meets the critical infrastructure threshold, it is necessary to understand what “critical infrastructure” (CI) means and how the United States determines which sectors earn that designation. First, the Critical Infrastructures Protection Act of 2001 defines critical infrastructure as systems and assets “so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.”5
Second, as directed by the 2021 National Defense Authorization Act, the Cybersecurity and Infrastructure Security Agency (CISA) proposed a decision-support framework for assessing which sectors should be classified as critical infrastructure.6 Under this framework:
A collection of assets, systems, or networks providing common functions to the economy, government, or society.
Disruptions would produce debilitating impacts on national security, economic security, public health, or safety.
Existing regulatory mechanisms, policies, and governance structures do not adequately manage sector-wide risks.
The sector would meaningfully benefit from the coordination and collaboration mechanisms a CI designation offers.
Source: CISA, FY 2021 National Defense Authorization Act Report.
Using the CISA framework, this paper defines the AI infrastructure sector, identifies its unique vulnerabilities, maps its interdependencies with other CI sectors, and proposes policy recommendations. This paper serves as the overture in a series that will examine national security threats to different components of the AI infrastructure stack.
What is the AI Sector?
This paper defines the AI sector from an infrastructure lens, as comprising organizations, facilities, technologies, and industries whose primary purpose is the development, training, deployment, and operation of AI systems. This sector includes the hardware, software, and operational infrastructure that directly perform AI computation or produce the specialized components required for it.
The AI sector includes four primary components: brains, brawn, building blocks, and benefit delivery. The first three facilitate AI production and services, and the last delivers these systems to customers.
AI Model Development & Software
Model design, training, model weights, evaluation and alignment systems, and specialized software, developed by frontier labs and research organizations.
AI Compute Infrastructure
Specialized facilities, such as data centers, and the hardware that runs AI workloads.
AI Hardware Design & Manufacturing
Specialized chip design, advanced semiconductor production in fabrication plants, and the chip supply chain.
AI Operational & Delivery Systems
The platforms and infrastructure that deploy and serve AI models at scale, translating raw capabilities into usable services.
The first three components facilitate AI production and services; the fourth delivers them to customers. Source: ARI.
The AI sector also depends on external critical infrastructure, such as energy, communications, information technology (IT), finance, water and wastewater, and transportation. These remain distinct sectors when assessing interdependencies and vulnerabilities. However, for the purposes of this paper, outside infrastructure becomes part of the AI sector when it is purpose-built to perform AI computational functions or when it becomes an inherent part of said functions during operations. For example, the communications infrastructure that connects AI data centers forms the transit part of the AI sector,8 while transmission and on-site generation campuses constitute the electricity portion of these facilities.
The AI Backbone of Modern Services
Government Services and Defense
AI systems are increasingly integrated into CI functions, forming interdependencies as these sectors rely on AI and AI relies on them. Between August 2022 and August 2023, AI-related federal contracts increased by almost 150 percent to $675 million.9 U.S. government services use AI systems for enterprise-wide functions and individual productivity. Federal agencies already deploy AI tools to carry out their mandates. The Food and Drug Administration (FDA) uses AI systems to review drug applications, the Centers for Disease Control and Prevention (CDC) uses them to analyze medical images for abnormalities, the Department of Transportation (DOT) uses machine learning AI to predict flight delays, and U.S. Customs and Border Protection (CBP) deploys AI systems to analyze border crossing patterns.10 A 2024 Ernst & Young survey also found that 51 percent of state and local public sector employees, and 64 percent of federal employees, use AI applications several times a week or daily.11
Share of U.S. government employees who say they use AI applications several times a week or daily
The U.S. military already relies on AI systems for predictive maintenance and military logistics, and is increasingly turning to AI technologies for military planning and operations.12 In a January 2026 memorandum, Secretary of War Pete Hegseth instructed the Department of War (DOW) to implement AI tools with speed, noting that “the risks of not moving fast enough outweigh the risks of imperfect alignment.”13
U.S. military AI adoption is increasing. In 2026, Deputy Secretary of War Steve Feinberg designated Palantir’s Maven Smart System (MSS) as a program of record to allow for the AI system’s eventual “enterprise-wide integration” into the U.S. military’s command and control systems.14 The U.S. military has already deployed AI tools on classified data to provide real-time targeting in the U.S. military operations in Iran.15 In addition, open source reporting indicates that AI tools were used in U.S. operations to capture the former Venezuelan president, although the exact use cases remain classified.16 The Central Intelligence Agency (CIA) is also reportedly deploying AI systems to help analyze the plans, intentions, and capabilities of foreign nations, with CIA Deputy Director Michael Ellis revealing that the agency recently used AI to create the CIA’s first autonomous intelligence report.17
The Private Sector
AI integration is also growing across private CI sectors.18 Financial institutions, for instance, are adopting AI sys tems for fraud detection, forecasting, trading, lending, cybersecurity, and customer service.19 A 2024 Treasury Department report notes that these institutions have relied on AI-based fraud detection for over a decade and increasingly apply AI to cybersecurity and code generation.20 But deployment carries risks: in 2025, the Finan cial Stability Oversight Council warned that “widespread [AI] adoption” in finance must be monitored so that agencies and institutions can manage threats from “malicious actors, as well as national security, cyber, or other unanticipated risks.”21
The energy sector is following suit, integrating AI into predictive grid maintenance, anomalous event detection, and energy management and efficiency technologies to support grid reliability.22 According to a 2024 Department of Energy (DOE) report, researchers and industry actors have long used machine learning models to analyze grid data drawn from sensors, meters, and power plants.23 The advent of generative AI now extends these use cases to grid planning, permitting and siting, grid operations and resilience, and security. However, the DOE researchers warn that foundation models can produce stochastic outputs without mitigation measures for energy applications.
In the IT sector, AI systems already write code and support cybersecurity systems.24 First, AI-assisted coding now underpins the software and platforms on which U.S. sectors increasingly rely. A 2025 survey found that 51 percent of professional code developers use AI tools in their development processes daily.25 Microsoft’s Chief Executive Officer, Satya Nadella, claims that AI now writes approximately 30 percent of the company’s code, and GitHub reports that its Copilot AI tool writes an average of 46 percent of code across all programming languages.26
“Has your organization ever identified a security vulnerability introduced by AI-generated code?”
Second, AI cybersecurity systems can identify malicious events or threats; detect anomalies; and, with generative AI, proactively mitigate code vulnerabilities and analyze threat actor behavior across various sectors.27 AI-supplemented cybersecurity use cases date back to the 1990s, when they scanned security logs for anomalies.28 Now, with the emergence of generative AI systems, a PYMNTS report found that between May 2023 and August 2024, the percentage of chief operating officers adopting AI-powered cybersecurity management systems within their companies increased from 17 to 55 percent.29 Moreover, Anthropic’s Mythos model is reportedly unearthing decade-old vulnerabilities and writing exploits at an accelerated pace that exceeds traditional patching timelines.30
All of these developments introduce new risks. A 2026 Aikido study found that 20 percent of surveyed organizations experienced serious security vulnerabilities due to AI-generated code.31 And, in July 2025, an attacker exploited a flaw in the Amazon Q Developer (a coding assistant tool that developers install in their coding environments), injecting malicious instructions into the official product, which was distributed through a widely used marketplace. The compromised extension had 964,000 installations.32 Ultimately, the code did not execute only because of a syntax error in its instructions.33
The same integration that makes AI valuable also makes it a target, introducing new attack vectors and vulnerabilities that are distinct from traditional cyber threats. Specifically, generative AI outputs are context specific and nondeterministic; therefore, an AI model’s degradation is difficult to identify purely based on how it functions.34 To secure these AI systems end-to-end, developers must maintain AI safety (ensuring robust systems are developed through the data collection, training, and deployment phases) and AI security (guarding against external threats).35
How might a threat actor target the AI sector? First, actors can poison the system’s training data or use prompt injection attacks to cause unintended model behaviors, disrupt the system’s effectiveness, or extract sensitive information.36 Similar to traditional cyberattacks, adversaries can exploit AI systems by implanting malicious code. However, due to AI systems’ generative nature and pervasiveness in code writing, this manipulation may go undetected if model outputs and the software they support seemingly function correctly.37
Second, attackers can exfiltrate model weights, which store AI systems’ core intelligence and cost billions of dollars in data, compute, and algorithms to develop.38 Compromising these weights would give attackers access to an AI developer’s most valuable assets, enabling adversaries to exploit the technology or use it to develop competing models.39 Similarly, attackers can use “distillation” techniques to prompt the model’s inference application programming interface (API) with repeated queries until they expose the model’s functionality; they can then use this information to train new models that mimic the original’s behavior.40 In April 2026, the Office of Science and Technology Policy released National Security and Technology Memorandum 4, which identified “deliberate, industrial-scale campaigns to distill U.S. frontier AI systems” and directed federal agencies to engage with the private sector on information sharing and mitigation measures.41
Third, actors can leverage global AI manufacturing and supply chain chokepoints to exploit third-party suppliers of U.S. AI hardware.42 States can use targeted export controls, import restrictions, or sanctions on critical minerals (e.g., China’s restrictions on gallium and germanium) to create semiconductor delivery delays and shortages. Actors can also ship semiconductor-grade materials with minor impurities, causing chip fabrication yields to plummet, or sabotage concentrated manufacturing clusters, such as those in East Asia, to disrupt hardware supply chains.43
Fourth, using side-channel attacks on AI data centers, actors can physically or remotely track emissions, including acoustic and power fluctuations, to infer proprietary and security secrets such as encryption keys.44 According to a 2024 RAND report, building the secure data centers and hardware needed to defend against such sophisticated attacks requires sector-wide, national-security-oriented R&D that remains underdeveloped.45
Moreover, AI systems introduce automation bias, which can undermine a user’s ability to determine whether AI system outputs are reliable and secure. A review of 74 studies across healthcare, aviation, and military sectors shows that when an automated decision support system provides an output, human oversight degrades. Therefore, AI safety and security are vital to ensuring that the systems humans increasingly rely on and trust are indeed reliable.46
Assessing a target’s risk requires weighing three factors: threat, vulnerability, and consequence. To be considered a threat, an actor must have the intent and capability to produce harm,47 be able to identify a sector’s exploitable vulnerabilities, and inflict consequences on the selected target. Since threat actors would not be able to disrupt all U.S. critical infrastructure systems simultaneously and have finite resources, they would have to set priorities. To determine targets, adversaries often consider which infrastructures would have the greatest consequences, are the easiest to attack (most vulnerable), and bring the lowest escalation risks.
AI tools run on foundation models that are concentrated under a handful of companies with substantially overlapping training data. The National Institute of Standards and Technology (NIST) notes that in this “algorithmic monoculture,” many consequential decision-making sectors use the same model or algorithm, which can result in increased susceptibility to correlated failures.48 Therefore, compromising a foundation model can propagate vulnerabilities across many of the systems built atop it.49
There are already documented cases of adversaries targeting and using AI infrastructure. In March 2026, Iran attacked Amazon Web Services (AWS) data centers in the United Arab Emirates, striking U.S. cloud and AI chokepoints, with the state media describing the operation as strikes on “the enemy’s technological infrastructure.”50 In addition, state-linked Shenzhen University accessed Nvidia A100 and H100 chips via AWS, revealing their susceptibility to remote access.51
Due to the AI sector’s dependence on critical infrastructures and its concentration in a handful of models, the disruption of AI functionality through interconnected sectors, such as energy and communications, can have cascading impacts on U.S. services.
AI & Energy
The Energy Paper in this series identifies transmission as the most vulnerable link for AI functionality in the energy sector. First, U.S. transmission is constrained by inadequate capacity and decade-long timelines for permitting and building new high-voltage lines.52 Second, the U.S. grid is disaggregated across the country. This structure limits power sharing, meaning localized generation failures cannot be easily offset by drawing power from other regions. Third, the specialized substations and large power transformers (LPTs) that serve AI data centers are chokepoints; these structures are typically lightly guarded and vulnerable to both physical sabotage and cyberattacks. A successful strike on one of these could take a facility offline for months. Moreover, most AI data centers only maintain short-term backup power, which cannot support long-term disruptions during prolonged attacks.
Separately, grid modernization through smarter control and behind-the-meter generation introduces new cyber vulnerabilities, as these technologies depend on the integrity of grid sensor data, making them susceptible to attacks that can corrupt or interrupt the data flow.53 Disrupting power control systems, particularly those used by grid operators to balance supply and demand, would give an adversary significant leverage. Based on previous state-sponsored infiltration operations by China-linked Salt and Volt Typhoon groups, major adversaries may already possess the capability to cause such disruptions.54
Finally, the concentration of large AI data center loads in select regional clusters creates systemic risks. For example, if the facilities’ protective controls disconnect unexpectedly during a grid disturbance, the sudden loss of massive loads can destabilize entire regional power systems. This means that a single point of failure could cascade into widespread AI service disruption.55
AI & Communications
AI systems are equally dependent on communications infrastructure. First, unlike standard internet applications, AI clusters operate as synchronized supercomputers using specialized, lossless protocols, so even a 0.1 percent packet loss can stall training runs.56 Sophisticated adversaries could exploit this sensitivity by inducing latency that degrades performance in time-critical applications, such as financial systems or military operations.
Second, despite the geographic distribution of data centers,57 their traffic aggregates through a small number of internet exchange points (IXPs) and carrier hotels, creating significant chokepoints.58 A single attack on a high-density peering hub can simultaneously isolate multiple AI inference nodes from their users.59 Third, fiber, electricity transmission, and transportation infrastructures frequently share physical corridors,60 meaning one event, such as a storm, construction accident, or deliberate attack, can sever these infrastructures simultaneously.61 Even if a data center is running on backup power, it cannot deliver AI services if its external fiber links are cut.62
How Could the Energy and Communications Sectors Be Interdicted?
A threat actor targeting U.S. AI infrastructure would prioritize the systems whose disruption would produce the greatest effect relative to the actor’s conflict objectives. Attacks could focus on the grid and communications nodes that are most heavily loaded, hardest to replace, and most critical to key AI functions. In a conflict involving maritime operations, for example, an adversary would likely target the U.S. AI systems that support logistics, ports, and troop movement, rather than striking indiscriminately.
To disrupt power, adversaries’ priority targets would include (1) natural gas compressors serving major data center hubs, (2) specialized substations with LPTs,63 and (3) the software platforms managing grid performance. To disrupt communications functions, IXPs and carrier hotels represent the highest-value chokepoints. These attacks could be kinetic or cyber. For example, substations outside guarded facilities are physically vulnerable; in some cases, a single attacker with a weapon can damage them.64 Adversaries do not need to instigate full blackouts. Targeted, temporary disruptions to the grid, communications infrastructure, or behind-the-meter systems could degrade AI functionality sufficiently to send strategic signals or restrict U.S. AI services in a conflict.
The practical weight of CISA’s CI designation framework becomes clearest when applied to sectors that have sought, and failed to receive, a designation. In 2023, the Cyberspace Solarium Commission 2.0—a think tank created from the congressionally established U.S. national cybersecurity strategy body—recommended that space systems be designated as critical infrastructure because (1) they have been targeted in adversarial attacks and espionage campaigns, (2) other critical infrastructure sectors depend on the technologies, (3) they exhibit unique physical and technical characteristics, and (4) much of U.S. terrestrial infrastructure is located abroad. Similarly, CISA proposed that the bioeconomy and space systems sectors be evaluated under the framework above. However, the Solarium report admits that federal rules already regulate space systems, with the DOW’s jurisdiction over defense applications and the Federal Communications Commission’s authority over space based communications systems.65
Ultimately, the President did not designate these sectors as CI in National Security Memorandum (NSM)-22, which renewed the U.S. critical infrastructure sector framework in 2024. Senior officials noted that this was due to the space sector already being so ingrained into “many different sectors” that designating it as a standalone entity did not “make sense,” and because risks to the bioeconomy “were not unique enough to merit a new sector.”66
While these sectors were ultimately passed over due to existing regulations and lead agencies with jurisdictions over the systems’ core functions, no comparable authority currently governs the AI sector’s risks at the scale its integration demands. And whereas the bioeconomy’s hazards were deemed too similar to those addressed elsewhere to justify a standalone designation, the AI sector confronts vulnerabilities without parallels in other sectors—training-data poisoning, the theft of model weights, distillation of proprietary systems, and a concentration of foundation models in which a single compromise can propagate across everything built upon it. The AI sector thus satisfies the very conditions that space and the bioeconomy could not: it lacks an existing regulatory regime equal to its risks, and its threats are distinct enough to warrant a CI designation of its own.
Despite AI systems confronting unique threats, private companies lack the resources and multi-sectoral coordination capacity necessary to secure their technologies against nation-state adversaries. The frontier AI labs have commercial incentives to protect their intellectual property and users’ privacy against competitors, criminal hacking groups, insider threats, and industrial espionage, but that protection stops at the firm’s perimeter.67 U.S. government capacity can fill this gap, protecting AI infrastructure at a scale no single company can achieve alone. To secure U.S. AI infrastructure, Americans for Responsible Innovation recommends the following actions:
Designate AI as a Critical Infrastructure Sector
The President must designate the AI sector as critical infrastructure in a national security memorandum, subjecting it to incident reporting requirements under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). The memorandum would secure the sector by:68
Assigning an AI-specific Sector Risk Management Agency (SRMA) to coordinate across the federal government and with the AI industry to help manage and mitigate AI-specific risks while building U.S. governmental capacity;69
Incorporating AI into the biennial National Risk Management Plan that summarizes U.S. risk mitigation efforts to the President;70
Empowering the SRMA to work across agencies and with the private sector to create security and resilience standards across the entire relevant AI infrastructure stack;
Facilitating public-private engagements across interdependent CI sectors;71
Identifying AI-specific Systemically Important Entities (SIEs) to prioritize government resources, risk mitigation, and security standards;
Directing the intelligence community to conduct intelligence estimates on AI sector risks and, as permitted by law and regulation, share those with industry; and
Allowing the SRMA to coordinate authorities (e.g., the Defense Production Act), financing, and other capabilities that would enable executive intervention to secure essential supply chains and expedite infrastructure buildouts (e.g., through streamlined permitting).72
In addition, CISA and NIST should conduct a risk-based assessment to classify systems according to their frontier level, intended use cases, deployed sector, and potential impact on human health, safety, and security.73 This would create a dynamic federal framework for selecting the entities that constitute the AI sector and mitigating their vulnerabilities.
Establish Security Baselines
To mitigate AI data center security vulnerabilities, CISA and the Center for AI Standards and Innovation (CAISI) should publish updated AI data center guidance establishing security baselines.74 To achieve this, Congress can direct CISA to create a task force to audit the physical, cyber, and personnel security of AI data centers; identify vulnerabilities; and work with AI companies to develop enforceable security standards across the AI infrastructure stack.
Spur AI Infrastructure Security R&D
In parallel, to build a nascent AI infrastructure safety and security R&D ecosystem, Congress should allocate funding to the Defense Advanced Research Projects Agency (DARPA) to administer grants that create a cost effective market for the technology required to achieve AI infrastructure standards calibrated to national security threats.75
Taken together, these measures would give the federal government the coordination capacity that the AI threat environment already demands, and that the private sector alone cannot supply.
The AI sector already bears the hallmarks of critical infrastructure. It is interwoven with public and private services, concentrated among a handful of foundation models, and increasingly interdependent with CI sectors, meaning a single attack on the AI stack could cascade across multiple sectors at once.
The U.S. threat environment compounds these structural concerns. State-linked actors have already struck AI data centers and demonstrated sophisticated penetration capabilities, suggesting that the conditions for disruption are taking shape. Simultaneously, strategic assets, such as Mythos and similar successors, are precisely the targets that adversaries will be incentivized to attack. Every month of delay widens the gap between how much the nation relies on AI and how little it protects it. As these threats grow, the President and Congress must act to fortify U.S. AI infrastructure and expand public-private coordination in this burgeoning sector.