CIS Launches OpenAI Pilot to Test AI Cyber Defense for Local Governments

The program promises faster risk triage and remediation support for under-resourced public defenders. Its value will depend on whether those claims translate into practical guidance across organizations with very different security capabilities.

By 2 min read
CIS Launches OpenAI Pilot to Test AI Cyber Defense for Local Governments
CIS Launches OpenAI Pilot to Test AI Cyber Defense for Local Governments

Listen to this story

The audio brief

About 0:47
0:000:47
Read transcript
The Center for Internet Security has begun a pilot with OpenAI to test whether artificial intelligence can help public-sector cyber teams identify and prioritize security problems faster. The participants include state, local, tribal and territorial governments, along with critical-infrastructure organizations connected to the MS-ISAC community. That mix is important: these are not identical customer environments. They differ in size, region and cybersecurity maturity, so the pilot will test how the technology performs across uneven defenses. The work will focus on identifying and validating security findings, deciding which ones matter most, supporting remediation, and strengthening basic cyber hygiene. The need is clearest at the local level. A 2024 survey found that 80 percent of local governments had fewer than five dedicated cybersecurity employees. States met the cited maturity benchmark more often than local governments—46 percent compared with 35 percent. For a small team, faster triage could free up time. But the opposite risk is just as practical: an AI system could generate more findings than an understaffed office can investigate. No performance results are available yet. CIS says it will publish implementation guidance, lessons learned and recommendations for future public-sector and critical-infrastructure use. The pilot follows CISA’s ended cooperative agreement with CIS for MS-ISAC, adding institutional context to the effort. The key question is whether AI reduces workload in real organizations, rather than simply finding more problems.

Story brief

3 key points

Center for Internet Security is testing OpenAI technology with a mixed group of state, local, tribal and territorial governments and critical-infrastructure organizations. The pilot will assess AI-assisted identification, validation, prioritization and remediation of security findings, then publish implementation guidance. Its significance is less about a proven product than a real-world test under severe staffing...

  1. 01

    Participants span organizations with different sizes, regions and cybersecurity maturity levels, rather than one standardized customer environment.

  2. 02

    A 2024 survey found 80% of local governments had fewer than five dedicated cybersecurity employees; maturity benchmarks were met by 46% of states versus 35% of locals.

  3. 03

    CIS plans to publish implementation guidance, lessons learned and recommendations for future public-sector and critical-infrastructure adoption.

The Center for Internet Security has started a pilot with OpenAI to test whether AI can help public-sector cyber teams find and prioritize security problems faster. The promise is targeted at organizations facing complex threats and tight resources; the evidence the program is meant to produce is still ahead.

A trial across uneven defenses

The AI Cyber Defense Pilot brings together U.S. state, local, tribal and territorial governments and critical-infrastructure organizations, including members of the MS-ISAC community. CIS says the group will include organizations of different sizes, regions and levels of cybersecurity maturity, making this a test across very different operating conditions rather than a deployment to one uniform customer base.

Participants will use OpenAI technology to identify, validate and prioritize security findings; support remediation; and advance cyber hygiene and other security practices. Put simply, the pilot centers on identifying potential weaknesses, deciding their priority, and supporting remediation.

Turning findings into useful work

Those gaps explain the appeal of tools that can sift through potential risks. A city or county office may have a single IT or security employee handling daily tasks and projects, CIS member-programs manager Tyler Scarlotta told StateScoop. That leaves limited time to formalize security practices, even before a new AI workflow is added.

CIS frames the pilot as a way to learn where AI can improve decision-making and speed response while helping teams focus on the risks that matter most. That is an aspiration, not a reported performance result. The important practical question is whether the technology can make limited staff more effective without creating a new stream of findings that those same staff must sort through.

Guidance is part of the product

The initiative is not limited to the participating organizations. CIS says it will produce implementation guidance, lessons learned and recommendations intended to inform later adoption of AI-powered cybersecurity capabilities in public-sector and critical-infrastructure settings. That makes the pilot’s eventual output as consequential as its software use: smaller governments need a workable path for applying results, not merely evidence that a tool can perform a task.

The experiment also arrives after the Cybersecurity and Infrastructure Security Agency ended its cooperative agreement with CIS for MS-ISAC the previous year, according to StateScoop, and shifted toward grants, free tools and direct assistance. Against that backdrop, the pilot is a concrete attempt to extend defensive capacity—but it has not yet established which AI uses will prove reliable, scalable or worth the operational effort.

Sources

  1. cisecurity.orgCenter for Internet Security Launches AI Cyber Defense Pilot to Strengthen State and Local Government Cybersecurity
  2. statescoop.comCenter for Internet Security launches AI cyber defense pilot for state and local governments | StateScoop

Loading discussion...