September 25, 2026
By Brandon Heiner and Robert Mayer
Brandon Heiner
Robert Mayer
We’ve all seen the headlines and read the threads – warnings that the next generation of AI systems may be able to find and exploit vulnerabilities autonomously, at machine speed and with little human direction. The Trump Administration has even noted that it’s open to sharing information about emerging threats posted by AI with other governments. But that effort will only be as strong as the information-sharing framework we maintain here at home.
Congress recently took an important bipartisan step by extending the Cybersecurity Information Sharing Act of 2015 through December 11. That action provides valuable continuity and reflects the broad recognition on both sides of the aisle that real-time cyber threat sharing is essential to confronting fast-moving threats, including those increasingly enabled by AI. Now Congress has an opportunity to build on that common-sense momentum and provide the long-term certainty this successful framework needs.
CISA 2015 is not an abstract piece of legislation. It provides the legal scaffolding that gives companies and the federal government confidence to share cyber threat indicators and defensive measures lawfully, responsibly, and at the speed today’s threats require, without fear of antitrust exposure, regulatory second-guessing, or unwarranted liability. That framework helps make the public-private partnership at the heart of America’s cyber defense work at the necessary speed and scale. Internet service providers, equipment vendors, financial institutions, and federal agencies all rely on the confidence CISA 2015 provides to share what they are seeing on their networks quickly and candidly.
The good news is that long-term reauthorization has strong bipartisan support. Members of both parties recognize the value of preserving a framework that has helped government and industry work together for more than a decade. Bipartisan legislation has already been introduced to extend these protections for another 10 years, providing a strong foundation for Congress to finish the job.
And the timing matters. The threat landscape has only accelerated. Nation-state actors, ransomware syndicates, and increasingly sophisticated AI-enabled attacks are probing critical infrastructure, including the communications networks that everything else depends on, on a near-constant basis. The faster these threats move, the more important it becomes for defenders to be able to share what they are seeing quickly and confidently.
That is why long-term certainty matters. Cybersecurity partnerships are built on trust, and companies need confidence that the legal protections supporting lawful and responsible information sharing will remain in place as they build those practices into their security operations. A long-term reauthorization would provide that stability while allowing government and industry to focus their attention where it belongs: identifying threats, sharing actionable information and strengthening America’s collective cyber defenses.
This is exactly the kind of question USTelecom will be putting to some of the people most responsible for answering it. On September 29, our Cybersecurity Leadership Summit will bring together White House National Cyber Director Sean Cairncross with senior technology and cybersecurity officials from AT&T, Verizon, Lumen, and T-Mobile for a candid conversation about the state of America’s cyber defenses. CISA 2015’s future will be part of that discussion, alongside a broader look at today’s threat landscape, what providers most need policymakers to understand, what keeps cybersecurity leaders up at night, and, just as important, what gives them hope about the country’s cyber posture going forward.
Congress has already demonstrated that CISA 2015 can bring lawmakers together around a shared goal. The recent bipartisan extension was an important step. Now lawmakers have an opportunity to build on that progress and provide the durable, long-term framework government and industry need to continue sharing cyber threat information with the confidence, speed, and responsibility today’s threat environment demands.
Brandon Heiner is SVP, Government Affairs, USTelecom – The Broadband Association and Robert Mayer is SVP, Cybersecurity and Innovation, USTelecom – The Broadband Association