"Artificial intelligence systems now control infrastructure that keeps societies functioning, yet regulatory frameworks remain fragmented and incomplete."
Executive Summary
Artificial intelligence has transitioned from experimental technology to operational necessity within critical infrastructure sectors globally. An estimated 40% of all cyberattacks are now AI-driven, while AI systems simultaneously manage essential services spanning energy, water, transportation, and communications networks. This duality creates unprecedented governance complexity. The EU AI Act entered into force on 1 August 2024 and will be fully applicable on 2 August 2026, establishing the world's first comprehensive regulatory framework. Meanwhile, the United States pursues sector-specific guidance through frameworks like NIST's AI RMF Profile on Trustworthy AI in Critical Infrastructure, released on April 7, 2026, to guide critical infrastructure operators towards specific risk management practices. However, none of the agencies fully addressed the six activities establishing a foundation for effective risk assessment and mitigation of potential AI risks. Policymakers must urgently establish coordinated frameworks addressing three distinct risk categories: attacks using AI, attacks targeting AI systems, and failures in AI design and implementation.
Key Takeaways
- AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity face strict high-risk classification under emerging regulations
- By 2030, 25% of new domestic energy demand will come from data centers, creating acute infrastructure dependencies that complicate regulatory oversight
- 87% of respondents identified AI-related vulnerabilities as the fastest-growing cyber risk over 2025, demonstrating accelerating threat evolution
- One software suite with persistent and unpatched vulnerabilities, ICONICS SCADA, is embedded in over 70% of Global 500 companies, highlighting systemic exposure in operational technology environments
- Regulatory fragmentation across jurisdictions creates compliance complexity while potentially leaving critical gaps in protection for essential services
Strategic Context
The intersection of artificial intelligence and critical infrastructure represents a fundamental transformation in how societies deliver essential services. However, this transformation occurs against a backdrop of geopolitical fragmentation and divergent regulatory philosophies. The transition into 2026 places infrastructure and regulation at the core of the AI agenda, as policy priorities include scaling infrastructure, accelerating innovation, and expanding AI use.
Three parallel governance tracks have emerged. Europe has established binding regulations through the AI Act, categorizing systems by risk level and imposing mandatory requirements. High-risk use-cases include AI safety components in critical infrastructures such as transport, where failure could put the life and health of citizens at risk. Meanwhile, nearly 90% of federal agencies are already using or intending to use AI in the United States, though comprehensive federal legislation remains absent. Instead, the US relies on sector-specific guidance and voluntary frameworks.
Asia-Pacific jurisdictions pursue hybrid approaches. South Korea passed an AI Basic Act with enforcement scheduled for January 22, 2026, aiming to become the first in Asia to have a comprehensive framework. China implements sector-specific regulations alongside centralized oversight mechanisms. This regulatory patchwork creates significant challenges for multinational operators of cross-border infrastructure systems.
Nevertheless, geopolitics remains the top factor influencing overall cyber risk mitigation strategies in 2026, as state-sponsored attacks increasingly target infrastructure vulnerabilities. The convergence of operational technology and information technology within infrastructure systems expands attack surfaces while regulatory frameworks struggle to keep pace with technical change. Operational technology systems controlling equipment from hospitals and power grids to train switches and oil pipelines often contain proprietary code unable to be modernized without taking critical systems offline, creating structural barriers to both security improvements and regulatory compliance.
Problem Definition
The core policy challenge lies in developing regulatory frameworks that simultaneously protect critical infrastructure, enable beneficial AI innovation, and remain technologically neutral amid rapid evolution. This challenge manifests across three dimensions: technical complexity, jurisdictional fragmentation, and implementation capacity.
Technical complexity stems from AI's dual nature as both vulnerability and defense mechanism. CISA's cross-sector analysis establishes foundational analysis of cross-sector AI risks across three distinct types: Attacks Using AI, Attacks Targeting AI Systems, and Failures in AI Design and Implementation. Each category demands different regulatory approaches. Attacks using AI leverage machine learning to enhance threat capabilities, while attacks targeting AI exploit vulnerabilities in training data or model architectures. Design failures introduce systemic risks through inadequate testing or inappropriate deployment contexts.
Jurisdictional fragmentation creates parallel but incompatible regulatory requirements. Organizations operating infrastructure across multiple regions must navigate divergent definitions, compliance obligations, and enforcement mechanisms. The US Attorney General was directed to form an AI Litigation Task Force to challenge state AI laws inconsistent with the goal of United States global AI dominance, with the Secretary of Commerce identifying by March 11, 2026, potentially unconstitutional state laws. This federal-state tension compounds international regulatory divergence.
Implementation capacity represents the most immediate constraint. Although agencies submitted sector risk assessments to DHS as required, none fully addressed the six activities establishing a foundation for effective risk assessment. Even well-designed frameworks fail without adequate resources, expertise, and coordination mechanisms. Critical infrastructure operators face overlapping regulations that increase compliance burden without proportionate security improvements. Moreover, legacy systems and procurement cycles operate on timelines misaligned with AI development velocity, creating persistent gaps between regulatory intent and operational reality.
Analysis
Effective AI governance in critical infrastructure requires analyzing both the technical landscape and the institutional mechanisms available to manage evolving risks. Current evidence reveals significant gaps between regulatory ambition and implementation effectiveness.
Risk Assessment Deficiencies
Systematic analysis reveals fundamental weaknesses in how jurisdictions assess AI risks to infrastructure. DHS guidance for assessments did not have agencies fully measure how much harm an attack could cause or the probability of attacks, with the new template not fully addressing activities for identifying potential risks including the likelihood of a risk occurring. Without probability and impact assessments, risk prioritization becomes arbitrary and resource allocation inefficient.
Furthermore, risk assessment frameworks often fail to account for cascading dependencies between infrastructure sectors. AI failures in electricity distribution can trigger water treatment disruptions, which subsequently impact healthcare facilities and communications networks. However, most regulatory frameworks evaluate sectors in isolation rather than modeling systemic interdependencies.
Classification Challenges
Determining which AI systems qualify as high-risk remains contentious and technically complex. A study of 106 enterprise AI systems found that 18% were high-risk, 42% low-risk, and 40% unclear if high or low risk, with unclear systems mainly within critical infrastructure, employment, law enforcement, and product safety, while 33% of startups believed their systems would be classified as high-risk compared to the 5-15% assessed by the European Commission. This classification uncertainty creates regulatory risk and may deter innovation or encourage strategic misclassification.
Systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, and supply of water, gas, heating and electricity are classified as high-risk since their failure or malfunctioning may put at risk the life and health of persons at large scale. However, distinguishing safety components from operational efficiency tools proves difficult in practice, particularly as AI systems increasingly serve multiple functions simultaneously.
Infrastructure Sovereignty and Dependency
AI deployment in critical infrastructure creates new forms of strategic dependency that traditional regulatory frameworks do not adequately address. AI infrastructure sovereignty can be defined as the capability to design, operate, and control AI infrastructure within environmental, economic, and geopolitical constraints without excessive dependence on external actors. This definition shifts sovereignty from abstract policy concept to concrete engineering problem rooted in physical limits and control authority.
By 2030, 25% of new domestic energy demand will come from data centers, creating profound implications for energy security and grid stability. Infrastructure operators increasingly depend on AI systems for operational efficiency, yet those systems require massive computational resources hosted by a small number of technology providers. Because of immense resource requirements, only a handful of companies currently have the capacity to develop and deploy advanced AI systems at scale. This concentration creates single points of failure and potential leverage for geopolitical coercion.
Cybersecurity Convergence
The convergence of AI capabilities with infrastructure cybersecurity creates bidirectional vulnerabilities. AI helps cyber criminals develop more believable spam and infiltrative malware, with spoof messages featuring proper grammar and structure, while AI can create malware that adapts and evolves to evade detection, gather information about targets, find vulnerabilities and craft highly targeted attacks through automated, streamlined methods. Simultaneously, leading organizations and critical infrastructure are at greater risk due to the sophistication of AI in evading detection.
Defensive applications offer promise but introduce operational complexities. AI-powered threat detection systems can identify anomalies and respond at machine speed, yet they also generate false positives that overwhelm security teams and create alert fatigue. Moreover, adversarial machine learning techniques can poison training data or manipulate inputs to evade AI-based defenses, creating an escalating arms race between attackers and defenders.
Implementation Barriers
Even jurisdictions with comprehensive frameworks face significant implementation challenges. Overlapping regulations and conflicting parameters in infrastructure sector cybersecurity requirements greatly increase time and labor spent in compliance and approval processes, reduce available resources for cyber defense operations, and deter operators from initiating complex but necessary software improvements. This regulatory burden paradoxically reduces security by diverting resources from protective measures to compliance documentation.
Legacy technology compounds these challenges. Critical infrastructure operators often maintain decades-old operational technology that cannot easily integrate modern AI systems or security controls. However, replacement cycles for infrastructure assets span years or decades, creating persistent gaps between regulatory requirements and technical feasibility. Bridging this gap requires transition mechanisms that current frameworks largely omit.
Policy Recommendations
Addressing AI governance challenges in critical infrastructure requires coordinated action across multiple policy domains. The following recommendations provide concrete pathways toward more effective and coherent frameworks.
- Establish International Baseline Standards
Create multilateral agreements establishing minimum safety and security requirements for AI systems in critical infrastructure. These standards should focus on outcome-based requirements rather than prescriptive technical specifications, allowing flexibility for innovation while ensuring consistent baseline protection. Mapping templates connecting ISO/IEC 42001 controls to NIST AI RMF functions can ensure key controls are not overlooked, with automated crosswalks simplifying evidence collection. International standards bodies should develop conformity assessment procedures enabling mutual recognition of compliance certifications across jurisdictions.
- Implement Tiered Risk Management Requirements
Adopt risk-based regulatory approaches that calibrate requirements to system criticality and deployment context. Guidelines should support establishment of policies, processes, and procedures to anticipate, identify, and manage benefits and risks of AI at all points in the AI lifecycle. High-consequence systems managing life safety or large-scale service delivery should face stringent pre-deployment testing, ongoing monitoring, and incident reporting obligations. Lower-risk optimization and efficiency applications should face lighter-touch transparency and documentation requirements. Risk classification methodologies should incorporate cascading effects and interdependencies between infrastructure sectors.
- Create Regulatory Sandboxes for Infrastructure AI
Establish controlled testing environments where infrastructure operators and AI developers can pilot novel systems under regulatory supervision without full compliance burden. These sandboxes should permit experimentation with technologies not yet addressed by existing frameworks while generating evidence to inform future policy development. Sandbox participation should require detailed data sharing on system performance, failures, and near-misses to build collective knowledge. Successful sandbox graduates should receive expedited pathways to full deployment authorization.
- Mandate Transparency and Incident Reporting
Require mandatory disclosure of AI system capabilities, limitations, and operational parameters for systems deployed in critical infrastructure. Guidance should help critical infrastructure owners and operators integrate AI into operational technology systems securely, balancing benefits with unique risks to safety, security, and reliability. Operators should maintain detailed technical documentation accessible to regulators and, where appropriate, to other stakeholders. Establish protected channels for reporting AI system failures, near-misses, and security incidents without fear of punitive enforcement action. Aggregate and analyze incident data to identify systemic vulnerabilities and emerging threat patterns.
- Strengthen Public Sector Capacity
Invest substantially in regulatory agency expertise, technical infrastructure, and coordination mechanisms. Despite its central role in safeguarding critical infrastructure, the public sector reports markedly lower confidence in national preparedness, with about 23% of public-sector organizations reporting insufficient cyber resilience capabilities. Governments should recruit AI specialists, establish dedicated units for infrastructure AI oversight, and create cross-agency coordination bodies. Provide infrastructure operators with technical assistance, best practice guidance, and threat intelligence sharing. Develop public-sector AI competence centers that can conduct independent system evaluations and support smaller operators lacking internal expertise.
- Harmonize Compliance Requirements
Streamline overlapping regulations to reduce compliance burden without compromising protection. Map existing requirements across cybersecurity, safety, privacy, and sector-specific regulations to identify redundancies and conflicts. Establish unified compliance interfaces where operators can satisfy multiple regulatory obligations through coordinated processes. Create safe harbor provisions for organizations implementing recognized best practices and standards. Regularly review and update requirements to remove obsolete provisions and address emerging risks.
- Develop Adaptive Governance Mechanisms
Design regulatory frameworks with built-in mechanisms for rapid evolution as AI capabilities advance. Establish sunset provisions requiring periodic review and reauthorization of regulations. Create fast-track processes for updating technical standards and guidance documents without lengthy legislative or rulemaking procedures. Empower regulatory agencies with sufficient discretion to interpret principles-based requirements in light of technological change while maintaining accountability through transparency and stakeholder consultation.
- Address AI Infrastructure Dependencies
Develop policies ensuring critical infrastructure resilience against AI supply chain disruptions. Assess concentration risks in AI model providers, computing infrastructure, and specialized hardware. Establish requirements for operational continuity plans addressing scenarios where AI systems become unavailable. Regions constrained by limited grid capacity, carbon-intensive generation, water stress, or insufficient fiber connectivity face structural barriers to AI deployment, while regions coordinating clean energy supply, efficient cooling, and high-capacity optical transport gain durable advantages. Encourage development of domestic AI capabilities for strategic infrastructure applications while maintaining interoperability with global systems.
Conclusion
The integration of artificial intelligence into critical infrastructure represents an irreversible transformation that demands urgent and sophisticated policy responses. Current regulatory frameworks, though improving, remain inadequate to the scale and complexity of risks emerging at the intersection of AI capabilities and infrastructure vulnerabilities. Less than 45% of all CEOs from the private sector are confident in their country's ability to respond to major cyber incidents targeting critical infrastructure, revealing fundamental confidence gaps in preparedness.
Success requires moving beyond fragmented national approaches toward coordinated international frameworks that balance innovation imperatives with safety requirements. Policymakers must act decisively to establish clear rules, build institutional capacity, and create adaptive mechanisms that evolve alongside technology. The window for proactive governance is narrowing as AI systems assume greater operational control over infrastructure essential to economic prosperity and social stability. Future resilience depends on frameworks established today that treat infrastructure AI governance not as a technical subspecialty but as a central challenge of contemporary statecraft and strategic planning.
Cite This Report
Institutional Citation Tool
Research & Analysis Q&A
What makes AI systems in critical infrastructure high-risk?
AI systems are classified as high-risk when used as safety components in managing critical digital infrastructure, road traffic, or supply of water, gas, heating or electricity, where failure could endanger life and health at large scale.
How does the EU AI Act regulate critical infrastructure?
The EU AI Act, which became fully applicable on August 2, 2026, requires high-risk AI systems in critical infrastructure to undergo conformity assessments, maintain technical documentation, implement risk management systems, and report serious incidents.
What is the NIST AI Risk Management Framework?
The NIST AI RMF is a voluntary US framework using four functions (Govern, Map, Measure, Manage) to help organizations manage AI risks throughout the lifecycle, with a dedicated profile for critical infrastructure released in April 2026.