Artificial Intelligence & Machine Learning
,
Next-Generation Technologies & Secure Development
,
The Future of AI & Cybersecurity
California Bets on AI Defense as Federal Cyber Funding Dries Up

California vowed to build artificial intelligence into the systems that defend its power, water and transportation networks in what state officials are describing as a first-in-the-nation program.
See Also: OnDemand | Security Operations in the Age of AI
Gov. Gavin Newsom on Monday directed agencies to establish an “AI Cyber Defense Program” within the California Cybersecurity Integration Center. The governor also ordered agencies to extend AI-enabled defenses to local governments and critical infrastructure operators and designate an AI cybersecurity officer at every state agency.
Ann Cleaveland, executive director of the UC Berkeley Center for Long-Term Cybersecurity, said states have no choice but to arm defenders with the same AI that attackers are already using. “You can’t put defenders at a disadvantage by withholding AI tools that are available to attackers,” Cleaveland told ISMG. States need them, she said, “to keep up with the speed at which AI models can find vulnerabilities.”
Not every state can afford expensive cybersecurity tooling – especially with the federal government contributing less and less to state-level cybersecurity. Federal funding for the Multi-State Information Sharing and Analysis Center ended in late 2025, pushing monitoring and threat intelligence that thousands of state and local governments received at no cost toward paid models. The State and Local Cybersecurity Grant Program – funded with $1 billion under the Bipartisan Infrastructure Law – is nearing the end of its current phase. The House has extended its authorization but not the Senate.
“It’s a lot to ask of states to fill these gaps, and we need federal support to be reinstated and expanded,” Cleaveland said. “States are where the action is happening now.”
A suspected Iran-linked operation has targeted more than 30 municipal water systems in Minnesota, part of a campaign now reported in at least a dozen states. The FBI, Environmental Protection Agency and CISA warned last week that attackers are going after internet-exposed industrial controllers at water and wastewater utilities (see: Hackers Disrupt Controls at Minnesota Water Utilities).
Cal-CSIC, where the new program will sit, is the state’s threat intelligence and incident coordination hub and reports to the California Governor’s Office of Emergency Services. Cal OES Director and state Homeland Security Advisor Caroline Thomas Jacobs said in a statement that attacks can knock out “water, power, transportation and emergency communications,” and that the program will help partners detect threats sooner.
The state said the center will use AI for vulnerability detection, network hardening and incident response. It has not said which models or vendors will be used across the program.
Newsom’s previous 2023 and 2026 AI executive orders set the state’s framework for government AI use, and Senate Bill 53, signed in 2025, required the largest frontier developers to publish safety frameworks and report certain critical safety incidents to the state.
