AI Has Changed the Critical Infrastructure Threat Equation
Key Highlights
- The EO mandates the development of binding operational directives to harden critical infrastructure against AI-enabled cyber threats, emphasizing vulnerable sectors like hospitals and utilities.
- Financial agencies, including the Treasury, are tasked with creating an AI cybersecurity clearinghouse and adjusting tax policies to incentivize cybersecurity investments as capital expenses.
- Adoption of proven cybersecurity standards from the nuclear industry is recommended to streamline compliance and enhance defense mechanisms across sectors.
- The government recognizes the need for industry collaboration, with voluntary participation expected to become a near-future requirement to ensure comprehensive protection.
- Addressing technical challenges, the EO highlights hardware-enforced domain separation and secure distribution of AI tools as key to preventing vulnerabilities.
The June 2026 White House Executive Order (EO) Promoting Advanced Artificial Intelligence Innovation and Security sparked much discussion about American innovation and signaled the Trump Administration’s intent to keep regulation light. A more interesting story that received less attention lies in the Binding Operational Directives (BODs) directed by the Order’s text.
In particular, the Order directs development of a concrete plan to harden domestic critical infrastructure against AI-enabled threats. Under one of the mandates, the Cybersecurity and Infrastructure Security Agency (CISA) is tasked with leading creation of a BOD to “facilitate access to cybersecurity tools and services including…operators of critical infrastructure such as rural hospitals, community banks, and local utilities.” Explicitly calling out those highly vulnerable targets is a clear acknowledgment that the government recognizes the threat and the urgency of protecting these essential resources.
It also acknowledges industry’s unique role in the landscape. Unlike in many countries, U.S. critical infrastructure is a heterogeneous mix of public, public-private, and private sector ownership and control. There is a historical belief that this diversity provides a degree of protection, perceived or real, because of the difficulty of executing a common attack across disparate environments.
The current state of AI tools undermines this sense of security through diversity. If an AI model can analyze and exploit a breadth of attack surfaces within a compressed timeframe, then just one advanced model can turn the tables and force cyber defenders to parse and remediate a myriad of attacks without the benefit of coordination and common patches. The EO language is consequently framed towards critical infrastructure with the federal government as a supporting champion.
Getting From Order to Action
Interestingly, the Order directs financial agencies to get involved. One mandate requires the Secretary of the Treasury to lead the formation of an AI cybersecurity clearinghouse, in voluntary collaboration with the AI industry and critical infrastructure operators. It requires coordinating with CISA and other agencies to manage the end-to-end software vulnerability lifecycle, centralize intelligence, and provide the kind of practical assistance a community bank or regional hospital needs.
While it may seem unusual to put that responsibility under the Treasury, it suggests an intention to leverage financial mechanisms to encourage investment in advanced cyber protections. One expedient option is to change tax policy about what gets categorized as a capital expense (CapEx) vs. an operational expense (OpEx). Under current accounting rules, investment in critical infrastructure cyber defense is treated as OpEx. Because critical infrastructure pricing is bureaucratically regulated, this disincentivizes spending on future threats that would require rate increases for ratepayers today. By changing the policy to categorize cybersecurity investment as CapEx, the Treasury could readily offer strong financial motivation for operators to bolster their defenses against AI-based attacks.
The Order also directs the Office of Management and Budget, in coordination with CISA, to assess grant and loan opportunities that will support operators’ implementation of advanced AI vulnerability detection. Given that the Administration is adopting a financial flows centralization trend through the Consolidating Procurement EO14240, Modernizing Payments EO14247, and other actions, appointing OMB and Treasury as leaders in critical infrastructure protection allows the government to centralize levers like grants, loans, and tax policy that operators need.
Operators must now decide how to respond. Decision-making will be expedited by providing cybersecurity standards for them to adopt. Fortunately, best practice standards already exist and have long been used in the nuclear industry. A common architectural baseline, proven methodologies, and compliance accreditation and approval processes are already in place. Leveraging them, rather than having each critical infrastructure sector create its own, will relieve the burden of the typical normalization process, where panels and committees negotiate hundreds of decisions. The nuclear industry stands alone on its record of cyber defense, and we would be wise to adopt their standards as the baseline for all critical infrastructure.
Compliance Down the Road
While the Order makes industry collaboration voluntary, it is reasonable to expect compliance to become a near-future requirement. AI is enabling bad actors to develop new exploits and execute new attacks at unprecedented pace. Congressman Josh Gottheimer, Co-Chair of the House Commission on AI, recently stated that “Powerful AI frontier models that exhibit dangerous capabilities…must be shared with the government and relevant critical infrastructure entities before they are released to the public. While this process can’t be bureaucratic, it shouldn’t be optional.”
The implementation challenge is real but manageable. Distributing powerful AI capabilities securely across a wide range of operators with varying technical sophistication requires careful attention to the boundaries where networks meet. Hardware-enforced domain separation plays a role in ensuring that the channels for delivering them do not themselves become vulnerabilities. That is a solvable engineering problem, and tools exist to address it.
The June 2 EO acknowledges that AI security is not just a federal government problem. The explicit inclusion of soft targets like hospitals, utilities and community banks signals that the government knows where vulnerabilities lie and where adversaries will direct their efforts. This important first step is worth building on.
About the Author

Scott Orton
CEO, Owl Cyber Defense
Scott Orton is the CEO of Owl Cyber Defense Solutions, LLC, where he brings over 25 years of industry expertise in supporting the U.S. intelligence community, Department of Defense and critical infrastructure sectors in securing sensitive and critical data. Scott has an extensive background in anti-tamper and has managed programs to develop and field the latest secure processing technologies for militarily critical weapon systems.
