The Cybersecurity and Infrastructure Security Agency told Congress in a briefing Friday that 62 percent of critical infrastructure operators surveyed lack documented incident response plans specific to artificial intelligence failures or adversarial manipulation of automated control systems. The unclassified summary, released publicly hours later, ranks drinking-water utilities and regional electric grids as the most exposed sectors because they deploy machine-learning tools for demand forecasting without parallel security testing.

CISA Director Jen Easterly said the agency reviewed 214 operators responsible for services affecting more than 50 million Americans. Only 81 maintained playbooks addressing model poisoning, training-data tampering, or erroneous automated shutdown commands. Easterly urged mandatory reporting when AI-assisted controls trigger unplanned outages exceeding four hours.

Findings in Detail

Water districts increasingly rely on AI to predict pipe failure and chemical dosing. CISA red teams simulated alteration of sensor feeds feeding those models at five anonymized utilities. Three systems recommended unsafe chlorine levels before human operators intervened. None of the five had tested for adversarial inputs in the prior twelve months.

Grid operators fared marginally better. Regional transmission organizations reported stronger segmentation between forecasting models and dispatch commands. CISA nonetheless documented two near-miss events in 2025 where corrupted weather forecasts briefly skewed day-ahead pricing algorithms, triggering manual overrides.

Congressional Response

Senate Homeland Security Committee leaders scheduled a July 10 hearing and requested the classified annex covering foreign-state targeting of U.S. AI supply chains. Chairman Gary Peters said voluntary guidance failed to produce baseline preparedness. Ranking member Rand Paul cautioned against unfunded mandates on municipal utilities already struggling with lead-pipe replacement deadlines.

House Energy and Commerce staff circulated draft language tying FEMA resilience grants to AI security certifications. Utility trade groups asked for two-year implementation windows and federal funding for rural districts that cannot afford specialized red teams.

Industry Position

American Water Works Association executives said members support standardized tabletop exercises but oppose prescriptive model architectures. Energy sector lobbyists highlighted existing NERC reliability standards and argued AI-specific rules should integrate with those frameworks rather than create parallel compliance tracks.

Security vendors marketing AI anomaly detection reported a surge in inquiries following the briefing. CISA plans to publish free evaluation templates in August for operators with fewer than 100 employees.

Policy Outlook

The White House national cyber directorate said it will align upcoming executive guidance with CISA findings, potentially requiring federal grant recipients to adopt incident playbooks before fiscal year end. Bipartisan staffers said standalone legislation remains unlikely before the midterms, but must-pass infrastructure bills may carry reporting requirements similar to those CISA recommended.

Operators face immediate reputational pressure from insurers, who began requesting AI security questionnaires in renewal packets issued this month. Failure to document response plans may increase premiums even without new statute.