Congress mandates AI-era security plans for power grids, hospitals, banks
S. 4728 — Combat Emerging Threats to Critical Infrastructure Act of 2026 · Filed by Mark Warner (D-VA) · Introduced Jun 10, 2026 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill requires the federal government's cybersecurity agency (CISA) to update and maintain detailed security plans for 16 critical infrastructure sectors—from energy and finance to healthcare and water systems—with specific focus on emerging threats from artificial intelligence, quantum computing, cloud systems, and social engineering. The agency must report these plans to Congress every two years and coordinate with relevant federal agencies and industry partners to address technology-driven vulnerabilities.
Why we flagged it
The bill's core function is to mandate systematic updating and biennial reassessment of federal sector-specific cybersecurity plans, with explicit focus on emerging technology threats (AI, quantum, cloud). It is a governance and planning instrument, not a regulatory carve-out or appropriation.
What the text implies
- The bill does not appropriate funds or specify enforcement mechanisms; agencies must absorb planning costs within existing budgets, potentially diverting resources from other cybersecurity work.
- Sector-specific plans are not made public by statute—only reported to Congress—meaning the public has limited visibility into what vulnerabilities are identified or how they are being addressed.
The full analysis lists 5 implications of this text.
Who stands to gain
cybersecurity software and services vendors; cloud infrastructure providers; AI/ML security tool developers