Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CISA’s 2023–2024 Roadmap for Artificial Intelligence sets out how the agency planned to use AI for cyber defense while protecting AI systems and critical infrastructure from cyber threats and malicious use. Its dedicated infrastructure effort emphasizes threat assessment, mitigation advice, industry coordination, exercises, risk-management support, and information sharing through JCDC.AI. Released in November 2023, it is an agency plan—not a step-by-step security standard for operators.

What is CISA’s AI roadmap?

The Cybersecurity and Infrastructure Security Agency released its 2023–2024 Roadmap for Artificial Intelligence in November 2023. CISA described it as a guide to managing AI risks while harnessing AI’s potential for cybersecurity. The roadmap is organized around five lines of effort:

  1. Use AI responsibly to support CISA’s mission. Apply AI in ways that assist the agency’s cybersecurity and infrastructure work.
  2. Assess and assure AI systems. Examine AI systems and promote confidence in their security and reliability.
  3. Protect critical infrastructure from malicious use of AI. Assess threats and help develop mitigations in partnership with government and industry.
  4. Collaborate and communicate. Coordinate AI-related work and share information with relevant partners.
  5. Expand AI expertise in the workforce. Build the knowledge needed to carry out the other efforts.

The plan is deliberately two-sided: CISA aims to use AI to strengthen cyber defense and to reduce risks from AI systems and from adversaries using AI against infrastructure.

How does the roadmap address critical infrastructure?

Its infrastructure-focused effort calls for CISA to assess AI-related threats and recommend mitigations alongside government agencies and industry partners that develop, test, and evaluate AI tools. The roadmap describes a program of coordination and preparedness rather than a single technical control or a quantified promise to eliminate risk.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Engage industry regularly so infrastructure organizations and AI developers can share concerns and inform risk-management work.
  • Run tabletop exercises focused on AI-enhanced attacks to help partners consider how such scenarios could affect response and coordination.
  • Support AI risk-management practices and provide decision-support materials for organizations making security choices.
  • Coordinate through JCDC.AI, an operational effort intended to share information about threats, vulnerabilities, and mitigations affecting AI systems.

That approach connects AI security with infrastructure resilience: an AI-related incident may involve a model or its data, but its consequences can extend to the systems and services that depend on them.

What does this mean for infrastructure operators?

The roadmap is not, by itself, a compliance checklist or a substitute for sector-specific requirements. For an operator, its practical value is as a direction for organizing AI risk work: consider the system’s full lifecycle, identify the threats relevant to its use, test safeguards, and plan how to detect and respond to incidents. The right depth of assurance depends on the system’s role and the consequences of failure.

1. Assess the system across its lifecycle

Include design and procurement, development or configuration, deployment, operation, and retirement. Identify the AI components, data, services, suppliers, and infrastructure dependencies involved. Revisit the assessment when the system, its data, or its operating environment changes.

2. Match threat analysis to the use case

Consider relevant risks such as model manipulation, compromised data, prompt attacks, supply-chain exposure, disruption of supporting infrastructure, or adversarial misuse. A system used for decision support may need different safeguards from one that directly influences an operational process.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Set an assurance level before deployment

Document the controls and evidence needed for the system’s role. Depending on its risk, that may include security testing, independent review, adversarial or red-team exercises, and monitoring. Record who accepts residual risk and who can pause, restrict, or roll back the system if safeguards fail.

4. Control and monitor the deployed system

Deployment controls should protect the confidentiality, integrity, and availability of the AI system, its data, and related services. Establish ways to detect suspicious activity, misuse, and changes in performance such as model drift; define how alerts are investigated and how access or functionality can be limited during an incident.

5. Plan incident response and coordination

Set out how security teams, operational owners, suppliers, and relevant sector partners will share information and coordinate response. Exercises based on AI-enhanced attacks can expose gaps in responsibilities, escalation paths, and recovery plans before an actual incident occurs.

These steps translate themes in CISA’s roadmap and related guidance into an operator’s planning process; they are not presented as a universal control set that guarantees safety or compliance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What AI security practices does CISA emphasize?

CISA’s related materials place secure-by-design and assurance across development, deployment, and operation, with recommendations that include red-team testing. Joint guidance also emphasizes deployment controls that help organizations protect, detect, and respond to malicious activity affecting AI systems, associated data, and services.

CISA’s stated technology interests span more than model behavior. They include adversarial-AI countermeasures, zero-trust applications, AI-powered cyber defense, hardware security for AI training and inference, AI system assurance, prompt engineering, and machine-learning drift detection. The range matters because AI security can depend on the surrounding infrastructure, access controls, data handling, and monitoring—not only on the model itself.

How should organizations choose an implementation approach?

There is no single roadmap-defined implementation for every organization. Use these decision points to tailor the work to the system and its operating environment:

  • Lifecycle stage: Identify whether the immediate need is secure design, development controls, deployment safeguards, operational monitoring, or retirement planning.
  • Threat focus: Prioritize plausible threats, from data compromise and prompt attacks to supply-chain exposure or infrastructure disruption.
  • Assurance depth: Scale from documented controls to independent testing, red-team exercises, continuous monitoring, and rehearsed incident response as potential impact increases.
  • Operating setting: Account for whether the organization is federal, state or local government, tribal or territorial government, a private-sector infrastructure operator, or an AI provider.
  • Coordination model: Decide which work belongs to the internal security team and when to coordinate with sector partners, CISA, or a collaborative effort such as JCDC.AI.

For broader resilience planning, CISA’s resilience branch also offers assessment and planning services concerning infrastructure systems, dependencies, and regional resilience.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the roadmap does—and does not—measure

The roadmap’s stated measurement approach counts publications and engagements that support shared awareness of emerging AI-related risks and advances in AI risk-management practices. That tracks activity and information sharing; it is not a numerical measure of how much the roadmap has reduced AI or critical-infrastructure risk. No authoritative numerical outcome demonstrating such a reduction is established in the cited materials.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.