Six weeks after Iranian-affiliated hackers disrupted water utilities across at least seven states, a bipartisan group of House lawmakers has introduced its own answer to the crisis. Rep. Josh Gottheimer, D-N.J., filed the AI Cyber Defense Act on September 21, alongside Republican Reps. Don Bacon of Nebraska and Zach Nunn of Iowa and Democratic Reps. Hilary Scholten of Michigan and Greg Landsman of Ohio, according to CyberScoop. The bill would direct DHS and CISA to run a $100 million pilot giving critical infrastructure operators free access to frontier AI models — a deliberately different model from the administration's own competing pilot, which leans on volunteered private-sector help rather than appropriated federal funds.
The Bill: A $100 Million, Federally Funded AI Pilot
Formally titled H.R. 10519, "To direct the Secretary of Homeland Security, acting through the Director of the Cybersecurity and Infrastructure Security Agency, to establish a Critical Infrastructure AI Cyber Defense Pilot Program," the bill was referred to the House Committee on Homeland Security the same day it was introduced. It would authorize $100 million from 2027 through 2031 — money that still requires a separate appropriations vote before any utility sees a dollar — for a CISA-run program that gives critical infrastructure owners and operators free access to frontier AI models plus technical assistance for finding and fixing vulnerabilities. Priority would go to nonprofit, publicly owned, rural, and small-sized organizations, the exact profile of most of the utilities hit this summer.
Gottheimer, who co-chairs the House Democratic Commission on Artificial Intelligence and is the top Democrat on the House Intelligence Committee's cyber subcommittee, framed the bill around cost. "It's expensive to bring the AI in to analyze your system and find those vulnerabilities," he said, adding that federal funding for critical infrastructure "has an uncertain future" and that many local communities "just don't have the resources they need to pay for AI tokens to do the patching they need." He also flagged the technology's dual-use risk: "The same technology that can help a small town's IT guy find and patch a gap in cybersecurity can also help a hostile government find a hundred more it hasn't even discovered yet. AI didn't create this threat, but it's accelerated it, and our defenses have to keep up."
The AI Cyber Defense Act travels with a companion bill, the Securing Our Critical Infrastructure Act, which would create a dedicated rapid-response and threat-notification service inside CISA built specifically for small and medium water and electric utilities — a single point of contact to alert them the moment an active threat is detected. Gottheimer separately sent a letter to CISA, the EPA, and the FBI demanding an immediate surge of incident-response teams and technical assistance to every water and wastewater utility hit by the summer campaign.
The Water Attacks That Forced the Issue
The legislative push traces directly back to a wave of intrusions that began in late July 2026, when officials in Minnesota reported that hackers had targeted roughly 30 water systems in the state over a two-day span. The campaign quickly widened: by mid-August, water providers in at least seven states — with some officials citing as many as a dozen — had been targeted, prompting the EPA, FBI, CISA, and NSA to issue a joint advisory urging the entire water sector to lock down its systems immediately.
Investigators linked the intrusions to Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command, specifically the group tracked as CyberAv3ngers or Shahid Kaveh, which has a documented history of targeting water-sector operational technology going back over a decade. The actors went after internet-exposed programmable logic controllers — including Rockwell Automation and Allen-Bradley MicroLogix 1100 and 1400 series devices, alongside equipment from Schneider Electric and Siemens — modifying passwords to lock out legitimate operators and disconnecting controllers outright. The effects were tangible: Minnesota's Braham had to shut down its treatment plant for several hours, operators in New Jersey's Cape May County were forced to run valves and pumps manually, and a Georgia pump station shutdown caused a drop in water pressure. Federal officials said no attack degraded water quality to the point of endangering consumers, but the intrusions exposed how thin the cybersecurity margins are at the roughly 150,000 public water systems nationwide — 97 percent of which serve small communities that often have only a handful of employees and no dedicated cybersecurity staff.
The response was complicated by a public dispute over attribution: President Trump publicly dismissed the Iran assessment and instead blamed Minnesota Gov. Tim Walz, deepening concerns in Congress that the executive branch's response was not unified. That friction is part of why Gottheimer and his co-sponsors chose to move legislation rather than simply wait on the administration.
Two Pilot Programs, One Problem
Gottheimer's bill isn't the only AI-for-water-cybersecurity pilot in motion. In early September, the White House's Office of the National Cyber Director launched Project Watershed 250 in Texas, pairing Texas Cyber Command, Gov. Greg Abbott's office, and federal partners EPA and CISA with a dozen private companies — including Microsoft, Amazon Web Services, Google Cloud, Palo Alto Networks, Dragos, Cloudflare, and Abnormal AI — that volunteered cybersecurity testing, vulnerability assessments, red-team exercises, and AI tools to Texas water utilities at no cost for the pilot's duration.
The structural difference is the point of Gottheimer's bill. Watershed 250 runs on donated corporate time and technology, with no dedicated federal appropriation behind it and no guarantee those companies keep participating once the pilot period ends. The AI Cyber Defense Act would instead put a standing, appropriated $100 million program at CISA, open to eligible utilities nationwide rather than a single state, specifically to remove the cost barrier regardless of whether private vendors keep volunteering. Gottheimer's framing leans directly into concerns that the Trump administration's cuts to CISA's budget in its second term have left the agency with less capacity to support struggling utilities on its own — an argument for a funded federal backstop rather than a goodwill-dependent industry partnership.
Why This Matters
The two competing pilots reflect a real disagreement in Washington about how the federal government should help under-resourced critical infrastructure operators adopt AI-driven defense tools: through direct appropriations, or through convening private industry to donate access. Both approaches share the same underlying problem they're trying to solve — a water sector built decades ago for reliability, not cybersecurity, now facing adversaries who can automate the search for exploitable gaps faster than small utilities can patch them. Until Congress and the administration converge on one model, or fund both, water and electric utilities are left watching two federal pilots develop in parallel with no clear signal about which one, if either, will still be funded and available to them next year.
What Comes Next
- Committee review: H.R. 10519 sits with the House Committee on Homeland Security as of September 21, 2026, with no hearing yet scheduled.
- Appropriations: Even if the bill passes, the $100 million authorization still requires a separate appropriations vote before CISA can spend it.
- Companion legislation: The Securing Our Critical Infrastructure Act would need to advance alongside it to stand up the promised rapid-response and notification service.
- Watershed 250 continues regardless: ONCD's Texas pilot is already running and officials have signaled interest in expanding the state-by-state model if it shows results, independent of what Congress does.
- Direct agency pressure: Gottheimer's letter to CISA, the EPA, and the FBI seeks immediate incident-response support for affected utilities without waiting on either pilot program to stand up.
Sources
- CyberScoop — After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program
- Rep. Gottheimer's Office — After Attacks in Jersey, Gottheimer Announces Bipartisan Federal Actions to Protect Water, Electric Systems, and Families from Cyber Attacks
- CyberScoop — 'Watershed 250' test program in Texas looks to private sector for water cybersecurity help
- EPA — EPA, FBI, CISA, NSA Issue Joint Cybersecurity Advisory to Water System Regarding Iranian-Affiliated Cyber Attacks