The bill aims to speed and broaden federal cyber support and information sharing with non‑Federal critical infrastructure—especially small and rural entities—by enabling faster read‑ins, technical assistance, AI use, and clearer policies, at the tradeoff of potential privacy/exposure risks, weaker mandatory sharing consistency, and added compliance burdens for smaller organizations.
Owners/operators of non‑Federal critical infrastructure (utilities, small businesses, state/local governments) gain a one‑time security 'read‑in' so designated personnel can access federal cyber threat intelligence faster, improving their ability to detect and respond to attacks.
Non‑Federal entities, especially small and rural infrastructure owners, get voluntary technical assistance from federal agencies to help them use cyber threat indicators and defensive measures, increasing practical support for improving cybersecurity.
Organizations using AI for cybersecurity (tech firms, utilities, hospitals) gain legal clarity that AI tools developed or deployed for defense are permissible, reducing uncertainty and encouraging adoption of automated defenses.
State and local governments and private infrastructure operators may see less consistent or slower interagency information sharing because some previously mandatory sharing/issuance duties were converted to permissive actions.
Nonprofits, hospitals, and small businesses face elevated risk that sensitive data could be exposed if one‑time read‑ins or expanded AI uses are implemented without robust vetting and safeguards.
Small and rural entities could face increased compliance costs and time burdens because broader definitions (AI, IoT/OT/edge) plus added outreach/reporting obligations expand what they must track and implement.
Based on analysis of 2 sections of legislative text.
Updates the Cybersecurity Act to add AI and critical infrastructure definitions, expand voluntary federal assistance, allow limited one‑time read‑ins, and make some sharing permissive.
Official title: To reauthorize the Cybersecurity Act of 2015, and for other purposes.
Introduced September 2, 2025 by Andrew R. Garbarino · Last progress September 2, 2025
Amends the Cybersecurity Act of 2015 to expand and reorganize key definitions (including explicit references to artificial intelligence and critical infrastructure) and to change how the federal government and non‑federal entities share cyber threat indicators and defensive measures. It adds authority for voluntary federal technical assistance to non‑federal entities, permits the government to provide one‑time security read‑ins/clearances to selected individuals identified by critical infrastructure owners/operators, and makes several sharing rules permissive rather than mandatory while requiring updated public policies and guidance.