The Cybersecurity and Infrastructure Security Agency (CISA) recently released a draft report emphasizing the importance of securing artificial intelligence (AI) systems in critical infrastructure. As AI technologies continue to transform sectors from healthcare to energy, CISA underscores a key message: AI systems, like traditional software, must be transparent, auditable, and reproducible to support a more resilient software supply chain.

These recommendations not only highlight the need for clear AI governance but also offer guidelines to address the unique security challenges AI models pose.

CISA's focus on transparency involves AI systems being understandable and interpretable, helping to identify risks throughout the AI lifecycle. This includes fostering auditability and ensuring that systems can be monitored for unexpected behaviors or vulnerabilities. Additionally, reproducibility is vital, enabling the AI's decision-making processes to be reliably repeated and verified - a step toward minimizing the potential for malicious or biased outcomes. By prioritizing these attributes, CISA aims to embed security-by-design principles into AI systems, mirroring efforts for traditional software and supply chain security practices.

These AI-focused measures are part of CISA's broader effort to establish a "Secure by Design" foundation, ensuring that organizations prioritize cybersecurity from the start rather than as an afterthought. As critical infrastructure operators implement AI solutions, these guidelines serve as essential steps to future-proof against the evolving threat landscape. With these recommendations, CISA is leading the charge toward robust, transparent, and secure AI systems that are resilient to both known and emerging risks.

In alignment with CISA’s goals, the AI Integrity and Safe Use Foundation (AISUF) advances AI security through its framework for AI safety and transparency, particularly within critical infrastructure. By promoting industry standards and providing resources on best practices, AISUF supports the secure deployment of AI systems that adhere to these essential principles. Together, CISA’s recommendations and AISUF’s initiatives push the boundaries of AI security, paving the way for robust, transparent, and resilient AI ecosystems.