Cybersecurity and Infrastructure Security Agency (CISA)
- Type
- Government body
- Place
- United States — United States (federal), DHS component
- Last checked
- 2026-09-22
- Next check due
- 2027-03-21
Ways to reach them
- Report a cyber incident to CISA
- CISA Central
- CISA 24/7 incident line888-282-0870
- Homepage
What it does
Operational cyber-defence agency for federal civilian networks and critical infrastructure. Issues joint guidance on securing AI systems and on agentic AI governance (2026), runs CISA Central for incident intake, and administers CIRCIA incident-reporting rules for covered entities. Powers are largely voluntary/advisory toward the private sector, with administrative subpoena authority for vulnerability identification and binding operational directives that bind FEDERAL agencies only — not AI developers.
Its powers
investigate
Honest assessment
CISA's incident intake is genuinely staffed and 24/7 — a credible report of an AI-enabled intrusion or a compromised AI system will be actioned. But CISA has no authority over how frontier models are trained or released; framing a frontier-risk concern as a CISA incident report will be closed as out of scope. Its AI guidance documents are produced with industry partners and occasionally take comment via the Federal Register; that is the policy lever, the incident line is the operational one.
Notes
Note the practical caveat on CISA's own site: email is not secure and CISA prefers its structured reporting forms.