California Governor Gavin Newsom announced the AI Cyber Defense Program, deploying AI (artificial intelligence) to detect and counter emerging threats against the state’s critical infrastructure. The move expands on his earlier executive order on AI governance and reflects mounting pressure to harden defenses as attackers increasingly use AI-powered tactics.
The AI Cyber Defense Program aims to strengthen protections for state assets and critical infrastructure against emerging artificial intelligence-enabled cyber threats. The initiative directs state agencies to establish the program within the California Cybersecurity Integration Center, where AI will be used for vulnerability detection, network hardening, and incident response. The state also plans to expand access to advanced cybersecurity capabilities, including AI-enabled defenses, for local governments and critical infrastructure partners.
The initiative requires every California state agency to designate an AI cybersecurity officer as the state prepares for increasingly capable AI-driven cyber threats. The governor’s office said recent testing has demonstrated that advanced AI systems can independently conduct sophisticated cyber operations, while adversaries are using AI to make attacks cheaper and more effective. The program intends to improve the state’s ability to detect threats sooner, strengthen defenses and respond to incidents affecting essential services such as water, power, transportation and emergency communications.
“The digital environment is rapidly evolving before our eyes. Attacks are faster, more sophisticated, and more frequent, putting at risk the basic systems families count on,” Newsom said in a Monday media statement. “California can either wait for the next crisis, or we can build the kind of defenses this moment demands. We are choosing to build.”
“Artificial intelligence is transforming both the opportunities and the risks in government cybersecurity. California is taking a proactive approach—harnessing AI to strengthen our defenses while preparing for the emerging threats these technologies can create,” said Nick Maduros, secretary at California’s Government Operations Agency. “This initiative will help state agencies, local governments, and critical infrastructure partners better detect, prevent, and respond to cyber incidents, ensuring the essential services Californians rely on remain secure, resilient, and reliable.”
“Cyberattacks can disrupt the essential services Californians rely on every day, including water, power, transportation, and emergency communications,” said California Governor’s Office of Emergency Services Director and state Homeland Security Advisor Caroline Thomas Jacobs. “This new program will help Cal OES and our partners detect threats sooner, share information more efficiently, strengthen defenses, and respond faster, helping keep these critical services safe and reliable for communities across California.”
The Governor’s actions come as cyber threats grow more complex and federal administration continues rollbacks of key federal support. Federal officials recently warned that municipal water systems in Minnesota were targeted in a suspected Iran‑linked cyber operation affecting more than 30 utilities, underscoring that basic services are squarely in the sights of foreign adversaries.
To strengthen California’s preparedness, the Governor is directing agencies to establish an AI Cyber Defense Program within the California Cybersecurity Integration Center to leverage AI for vulnerability detection, network hardening, and incident response to strengthen the state’s cybersecurity posture and protect critical infrastructure. He is also expanding access to advanced cybersecurity capabilities for local governments and critical infrastructure partners, including AI-enabled defenses, and designating an AI Cybersecurity Officer in every state agency.
These actions build on Governor Newsom’s 2023 and 2026 Executive Orders establishing California’s comprehensive framework for the responsible, ethical, and transparent use of artificial intelligence. Together, they represent the next phase of California’s AI leadership, ensuring that as AI capabilities accelerate, public-sector preparedness keeps pace.
Newsom’s actions build on a series of moves over the last several years to make California a leader in safe, responsible innovation. Recent and prior steps include signing Senate Bill 53, the Transparency in Frontier Artificial Intelligence Act, in 2025, requiring the largest frontier AI developers to publicly disclose their safety frameworks, report certain critical safety incidents to the state and protect whistleblowers who call out serious risks.
The state also released Cal-Secure, California’s first statewide cybersecurity roadmap, and updated it to Cal-Secure 2.0 in 2026, giving agencies a practical playbook to strengthen defenses against sophisticated and AI-enabled cyber threats, with clear priorities across workforce, coordination and technology, including increased use of AI-enabled cybersecurity tools. California expanded the role of the California Cybersecurity Integration Center (Cal-CSIC) as the state’s hub for cyber threat intelligence, incident coordination and support to critical infrastructure operators, now including the new AI-focused defense initiative announced.
Newsom has also supported responsible AI-driven economic growth while seeking to ensure its benefits reach workers and small businesses, including by signing a first-of-its-kind Executive Order on AI’s economic and labor impacts. The state launched Engaged California, its first-ever statewide deliberative democracy effort, to assess the economic and labor impacts of AI on Californians and give every resident a seat at the table in shaping state AI policy.
California has taken additional steps to protect residents’ privacy, including legislation requiring browsers to allow Californians to opt out of third-party sales of their data at one time rather than on each website. The state also developed the Delete Request and Opt-out Platform (DROP) to help Californians opt out of the sale of their information by data brokers, while pushing back against federal privacy violations and adopting best practices to minimize data collection and maximize protections. The state also launched the Innovation Council and Emerging Tech Accelerator to partner with experts from across the country to inform AI policy and leverage AI to improve government service delivery.
At the same time, several national programs that state and local governments have relied on are being scaled back. The Trump administration’s proposed budget for Fiscal Year 2027 would cut the Cybersecurity and Infrastructure Security Agency by roughly US$707 million, or about 30% from earlier funding levels, reducing capacity for field support, incident response and defensive tools.
Federal funding for the Multi-State Information Sharing and Analysis Center ended in late 2025. For more than two decades, MS-ISAC provided around-the-clock monitoring, threat intelligence and incident coordination to thousands of state, local, Tribal and territorial governments at no direct cost. Those services are now transitioning to paid models, putting strain on smaller jurisdictions.
Meanwhile, the State and Local Cybersecurity Grant Program, created with a $1 billion appropriation under the Bipartisan Infrastructure Law, is nearing the end of its current funding phase. Although Congress has advanced bipartisan legislation to keep the program authorized, long-term funding remains uncertain.
Last week, New York Governor Kathy Hochul announced more than $9 million in cybersecurity grants for 153 local government projects aimed at strengthening the defenses of drinking water and sewer systems across the state. Hochul announced that the funding, awarded through the Strengthening Essential Cybersecurity for Utilities and Resiliency Enhancements (SECURE) grant program, will support cybersecurity assessments and implementation efforts as communities work to protect critical water services from increasingly sophisticated cyber threats.

Anna Ribeiro
Industrial Cyber News Editor. Anna Ribeiro is a freelance journalist with over 14 years of experience in the areas of security, data storage, virtualization and IoT.