Why It Matters
A recent Congressional Research Service (CRS) report examining the FY2026 National Defense Authorization Act reveals how lawmakers are embedding cybersecurity mandates and artificial intelligence governance requirements directly into military operations and procurement. The legislation includes restrictions on AI systems from adversary nations, mandatory secure communications upgrades for senior officials, and new oversight structures for AI development and deployment. These provisions signal Congress’s determination to address emerging national security threats while maintaining control over how the Pentagon integrates new technologies into defense strategy.
The Big Picture
The FY2026 NDAA contains dozens of cyber and AI provisions organized across five subtitles addressing operations, cybersecurity, information technology, artificial intelligence, and reporting requirements.
Section 1511 requires the Pentagon to acquire secure phones with encryption and enhanced cybersecurity protections within 90 days of enactment, targeting senior officials and personnel handling sensitive national security functions. Section 1512 mandates a comprehensive cybersecurity and governance policy for all AI and machine learning systems within 180 days, specifically addressing risks including data poisoning, jailbreaks, counterfeit parts, and unauthorized access.
Section 1533 establishes a cross-functional AI model assessment team, while Section 1534 creates an AI sandbox task force for safe experimentation with emerging technologies. Section 1535 creates an AI Futures Steering Committee to coordinate long-term AI strategy across the Department of Defense.
Section 1532 prohibits the Department of Defense from using or acquiring covered AI systems from China, Russia, North Korea, and Iran, explicitly naming DeepSeek and High Flyer as prohibited systems. Case-by-case waivers are permitted for research and national security functions. Section 6604 directs the intelligence community to remove DeepSeek from all intelligence community systems.
Section 1507 prohibits eliminating certain cyber red teams and assessment capabilities without Congressional certification. Section 1506 directs attention to behavioral health and work stress of Cyber Mission Force personnel. Section 1531 directs a reassessment of the Department of Defense’s high-performance computing roadmap to address resource demands from AI workloads. The National Security Agency received its own directive: Section 6601 directs the NSA director to develop security guidance protecting AI systems against theft or sabotage by nation-state adversaries, including identification of vulnerabilities in the AI and cybersecurity supply chain.
Congress also addressed commercial surveillance tools. Section 5304, a sense-of-Congress provision that carries no binding legal force, expresses the chamber’s concern that the growing commercial spyware market threatens journalists, human rights groups, and civil society. The provision states the U.S. will oppose the misuse of such capabilities.
The Bottom Line
The Cybersecurity Information Sharing Act (CISA), which enables voluntary cyber threat information sharing between the private sector and federal government, was extended only until September 30, 2026, through the Consolidated Appropriations Act rather than through the defense bill itself. Lawmakers did not include a full reauthorization in the FY2026 NDAA, meaning a legislative fight over the program’s future looms within months.
Congress will need to act again before the extension expires, potentially using CISA reauthorization as leverage in broader cybersecurity negotiations. This reflects a broader pattern in the FY2026 NDAA: while lawmakers embedded specific operational mandates for AI governance and secure communications, they deferred longer-term policy questions to future legislative sessions, signaling both urgency around near-term threats and uncertainty about how to structure permanent AI oversight.
Access the Legis1 platform for comprehensive political news, data, and insights.
Spot something wrong? Report an issue with this article
