US Agencies Test AI Tools for Critical Infrastructure Defense

The Center for Internet Security and OpenAI have launched a pilot program to help state and local governments use artificial intelligence to detect cyber threats. The initiative aims to address resource shortages in public sector security teams.
The Center for Internet Security and OpenAI have announced a joint pilot program designed to integrate artificial intelligence into the cybersecurity workflows of U.S. state, local, tribal, and territorial governments. This initiative targets critical infrastructure organizations that often struggle to keep pace with sophisticated foreign cyber threats while operating under strict budget and staffing constraints. The program seeks to determine how AI can assist these defenders in identifying risks more efficiently and responding to incidents with greater speed.
According to reports from GN technics/ai (en-US), the pilot will involve a diverse group of organizations, including members of the Multi-State Information Sharing and Analysis Center community. These participants vary in size and cybersecurity maturity, providing a broad test case for the technology. The goal is not merely to adopt new tools, but to understand the practical impact of AI on daily security operations, such as prioritizing alerts and improving overall cyber hygiene.
AI assists in prioritizing security actions
In practical terms, the AI systems will help security teams sift through large volumes of data to identify and validate potential vulnerabilities. By automating the initial analysis, the technology allows human analysts to focus on the most critical threats rather than getting bogged down by routine monitoring. This approach is intended to reduce the time it takes to remediate issues, thereby closing security gaps before attackers can exploit them.
However, this integration comes with significant trade-offs. Relying on AI for decision-making requires a high degree of trust in the model's accuracy and transparency. If the system fails to flag a critical threat or generates false positives, the consequences for public services could be severe. The pilot is designed to evaluate these risks, ensuring that the technology enhances human judgment rather than replacing it.
Focus on under-resourced public teams
A central motivation for the partnership is the widening gap between advanced threats and limited public sector resources. Many local governments do not have the staff or budget to maintain large, dedicated security operations centers. OpenAI and CIS aim to level the playing field by providing smaller teams with access to frontier AI capabilities. This includes training and support to ensure that these tools are used effectively and securely.
The pilot is guided by the operational experience of the MS-ISAC community, which has decades of knowledge regarding incident response in the public sector. By grounding the AI deployment in real-world scenarios, the initiative hopes to produce implementation guidance that is practical and scalable. This focus on real-world application is crucial for ensuring that the technology serves the needs of actual defenders rather than existing as a theoretical solution.
Balancing innovation with security risks
As AI becomes more embedded in critical infrastructure, organizations must navigate the tension between innovation and accountability. The pilot program will assess how to maintain transparency and resilience while adopting these new tools. CIS emphasizes a risk-based approach, urging participants to weigh the benefits of AI against potential vulnerabilities introduced by the technology itself.
The outcome of this pilot will be a set of lessons learned and recommendations for future adoption across the public sector. While the technology offers the promise of faster detection and response, it also demands rigorous testing and oversight. The success of this initiative will depend on its ability to provide clear, actionable insights that strengthen the security posture of communities across the country without introducing new, unmanaged risks.






