AI is no longer only something governments regulate. California is beginning to build artificial intelligence directly into the institutional architecture of public-sector cyber defense.
By Vladimir Tsakanyan, Ph.D.
Director, Center for Cyber Diplomacy and International Security (CCD-IS)
For most of the artificial-intelligence policy debate, governments have approached AI primarily as regulators.
The central questions have concerned transparency, privacy, model safety, accountability, competition and the responsibilities of companies developing increasingly capable systems.
California is now confronting a different question:
How should government defend itself when artificial intelligence becomes part of the cybersecurity environment?
Over a period of just three weeks, California took several steps that, viewed together, suggest the beginnings of a new institutional model.
On July 31, the state launched Cal-Secure 2.0, an updated statewide cybersecurity roadmap intended to strengthen resilience while adapting California’s security posture to emerging technologies and changing threats.
On August 10, California announced an AI Cyber Defense Program within the California Cybersecurity Integration Center, or Cal-CSIC. The initiative calls for AI-enabled cybersecurity capabilities for state government, local governments and critical-infrastructure partners and directs every state agency to designate an AI Cybersecurity Officer.
Then, on August 21, Mike Marshall was appointed California’s State Chief Information Security Officer at the Department of Technology.
None of these actions alone represents a transformation of cybersecurity governance.
Taken together, however, they reveal something important:
AI cybersecurity is beginning to acquire its own institutional architecture inside government.
From AI Regulation to Operational Defense
California has already built an extensive policy agenda around artificial intelligence.
But cybersecurity creates a different governance problem.
AI can help defenders analyze large volumes of security information, identify vulnerabilities, prioritize alerts, inspect code and accelerate response. At the same time, increasingly capable systems can assist malicious actors with reconnaissance, vulnerability discovery, code generation and other elements of cyber operations.
The same technology can therefore increase capacity on both sides of the security equation.
California’s August initiative recognizes this dual-use reality.
Rather than addressing AI only through rules imposed on developers and users, the state is beginning to incorporate AI into its own defensive structure.
That distinction matters.
The policy question is shifting from:
How should government regulate artificial intelligence?
toward a second question:
How should government itself operate securely when both defenders and attackers can use increasingly capable AI?
The answer will require more than purchasing new software.
It requires institutions.
The AI Cybersecurity Officer May Be the Most Important Experiment
The most interesting element of California’s initiative may not be an AI model at all.
It may be a job title.
Requiring every state agency to designate an AI Cybersecurity Officer introduces a specialized point of responsibility for risks that increasingly cross traditional organizational boundaries.
Cybersecurity has historically been managed through information-security organizations. AI governance, meanwhile, often involves technology leadership, procurement, privacy, legal teams, data governance and program managers.
Those responsibilities increasingly overlap.
An agency deploying an AI system may need to determine what information that system can access, which external services it can communicate with, what actions it can perform, how its outputs are monitored, how incidents are detected and who has authority to stop it.
These are simultaneously AI-governance and cybersecurity questions.
California’s approach suggests that governments may eventually need organizational structures specifically designed for that convergence.
Whether the AI Cybersecurity Officer becomes a meaningful operational authority or simply an additional administrative designation will depend on implementation.
But the institutional idea is significant.
Governments are beginning to recognize that AI security may require clearly assigned responsibility rather than being distributed informally among existing technology offices.
California Is Becoming an AI Operator as Well as an AI Policymaker
There is another reason this development matters.
California is not creating this cybersecurity architecture while standing outside the AI ecosystem.
It is increasingly becoming an AI user itself.
In June, California announced a statewide arrangement providing access to Anthropic’s Claude through state technology procurement infrastructure. The state said the California Department of Technology and Cal OES would use Claude tools for cyber defense, including scanning, triaging and patching state code.
That creates a more complicated governance relationship.
The state is simultaneously becoming:
an AI policymaker, an AI customer, an AI operator and an AI-security authority.
These roles cannot remain completely separate.
A procurement decision can create a cybersecurity dependency.
A cybersecurity control can determine which AI capabilities an agency may safely deploy.
A model’s access to government data can become a privacy and security question.
And reliance on external AI providers raises longer-term questions about resilience, interoperability and institutional dependence.
AI governance is therefore moving from abstract principles into the architecture of government itself.
Critical Infrastructure Changes the Stakes
California’s August 10 announcement extends the initiative beyond state agencies.
The AI Cyber Defense Program is intended to expand capabilities for local governments and critical-infrastructure partners as well.
That makes the initiative more than an internal government IT modernization project.
Critical infrastructure connects cybersecurity to physical society.
Water systems, energy networks, transportation, communications and emergency services increasingly depend on digital systems. A serious cyber incident affecting them can rapidly become a public-safety, economic and political event.
AI changes this environment primarily through speed and scale.
Defenders already face volumes of alerts, vulnerabilities and network activity that exceed what human analysts can manually process.
If offensive cyber operations become more automated as well, governments face an increasingly difficult asymmetry: machine-assisted attacks cannot indefinitely be countered through exclusively manual defensive processes.
The logical response is not autonomous defense without human supervision.
It is machine-speed analysis combined with accountable human authority.
That distinction should become a central principle of AI cybersecurity governance.
AI can accelerate detection, prioritization and technical analysis.
Humans must continue to determine acceptable risk, operational authority, escalation thresholds and accountability.
Cybersecurity Governance Is Becoming AI Governance
This convergence has broader implications.
For years, cybersecurity policy and AI policy developed largely as separate disciplines.
Cybersecurity concentrated on networks, vulnerabilities, identity, infrastructure and incident response.
AI governance concentrated on models, data, transparency, bias, safety and accountability.
That separation is becoming increasingly artificial.
An AI system with access to government databases, cloud services, development environments or operational tools is simultaneously an AI-governance object and a cybersecurity asset.
Its security cannot be evaluated solely by asking whether the underlying model is safe.
Governments must also ask:
What systems can it reach?
What credentials can it use?
What information can it retrieve?
What actions can it execute?
How is its behavior logged?
Who can override it?
And what happens if the model, its provider or the infrastructure supporting it becomes unavailable or compromised?
These questions move AI governance directly into the territory of security architecture.
California’s emerging framework provides an early example of that institutional convergence.
The Federal-State Dimension
California’s approach also intersects with a larger American debate over AI governance.
The federal government has increasingly emphasized the importance of a national AI policy framework. A December 2025 presidential action directed federal officials to pursue a more uniform national approach to AI regulation, and the White House subsequently released a national legislative framework in March 2026.
At the same time, states remain responsible for enormous operational environments of their own.
They run public-benefit systems, licensing platforms, transportation infrastructure, emergency-management capabilities, health programs and databases containing highly sensitive information.
Local governments operate another layer of essential digital infrastructure.
That means even a highly centralized national AI policy cannot eliminate the need for state-level AI security capacity.
The emerging division may ultimately resemble other areas of American cybersecurity:
Washington establishes elements of national strategy, national-security policy and interstate coordination, while states develop the operational resilience required to protect the systems they actually administer.
California’s experiment is therefore relevant beyond California.
It may provide an early indication of how federated AI cybersecurity governance develops in the United States.
Cyber Diplomacy Begins With Domestic Resilience
There is also a cyber-diplomatic dimension.
Cyber diplomacy is usually discussed at the international level: negotiations over responsible state behavior, attribution, sanctions, confidence-building measures, cybercrime cooperation and the application of international law.
But diplomatic credibility ultimately rests on domestic capacity.
International norms cannot keep a municipal network online during an intrusion.
Diplomatic condemnation cannot restore a compromised water system.
Attribution alone cannot protect an emergency-services network from disruption.
Those instruments matter, but they operate alongside resilience.
A government that can absorb cyber pressure without suffering severe disruption has more political flexibility in deciding how to respond. A government whose essential services are highly vulnerable faces greater pressure during a crisis.
Domestic cybersecurity capacity therefore becomes part of the strategic foundation of cyber diplomacy.
California’s program illustrates this relationship at the subnational level.
Strengthening the ability of state agencies, local governments and critical-infrastructure partners to withstand AI-enabled cyber threats does not replace national cyber diplomacy.
It strengthens the environment in which that diplomacy operates.
The Dependency Problem
There is, however, another side to AI-enabled defense.
The more governments rely on advanced AI systems for cybersecurity, the more those systems themselves become critical infrastructure.
This creates a new dependency chain.
Government may depend on a cybersecurity platform.
That platform may depend on an AI model.
The model may depend on a commercial provider.
The provider may depend on cloud infrastructure, specialized hardware, software supply chains and external data services.
A defensive capability can therefore introduce new concentrations of risk.
This is why AI-enabled cybersecurity cannot be evaluated solely by asking whether a particular model improves detection or accelerates code analysis.
Governments also need to examine continuity, vendor concentration, access controls, auditability, data handling and what happens when a provider or service becomes unavailable.
The strategic objective should not be maximum AI adoption.
It should be resilient AI adoption.
That difference is fundamental.
Related CyberCenter Analysis
This development extends two recent CyberCenter arguments.
In “The Cyber Arms Race Has Entered the AI Model,” I examined how increasingly capable models can move beyond cybersecurity assistance toward direct vulnerability discovery and exploitation.
California’s initiative represents the defensive institutional response to that technological trajectory.
And in “The Vulnerability State: Who Controls the AI Infrastructure of Cybersecurity?”, I examined the strategic dependency created when cybersecurity itself increasingly relies on externally controlled AI infrastructure.
California now provides a practical case study of both dynamics.
Governments are adopting AI because the technology may improve cyber defense.
But adopting it also requires new governance structures capable of controlling the dependencies and risks that AI introduces.
The two problems cannot be separated.
A Model Worth Watching, Not Yet a Model Proven
It would be premature to describe California’s approach as a successful template.
The AI Cyber Defense Program is new.
The practical authority of agency AI Cybersecurity Officers remains to be demonstrated.
The effectiveness of AI-enabled defensive tools will have to be measured against operational outcomes rather than announcements.
And extending advanced capabilities across a large state bureaucracy, local governments and critical-infrastructure organizations will involve significant technical and organizational challenges.
But policy significance does not require declaring success in advance.
The important development is that the institutional problem has been recognized.
California is beginning to organize government around the proposition that AI cybersecurity requires dedicated responsibility, centralized coordination and operational capability.
That is worth watching.
Conclusion: Defending Government at Machine Speed
The most consequential change in AI policy may eventually occur outside the legislation that receives the most attention.
It may occur inside government institutions.
As artificial intelligence becomes embedded in software development, cybersecurity, public services and critical infrastructure, governments will increasingly have to decide not merely how AI should be regulated, but how public institutions themselves should be reorganized around it.
California’s recent moves provide an early answer.
Create dedicated responsibility.
Integrate AI into cyber defense.
Connect state agencies with local governments and critical infrastructure.
Strengthen centralized coordination.
And treat AI security as an operational governance problem rather than only a technology-policy issue.
The ultimate test will be implementation.
But the direction is increasingly clear.
The next generation of AI governance will not be defined only by governments writing rules for machines.
It will also be defined by whether governments can securely operate — and defend society — when machines become part of the security environment itself.
Vladimir Tsakanyan, Ph.D. is Director of the Center for Cyber Diplomacy and International Security (CCD-IS). His research focuses on cyber diplomacy, cybersecurity policy, international security, AI governance and the intersection of technology and state power.
Primary Sources
California Governor’s Office, California launches next phase of state cybersecurity plan as AI changes threat landscape, July 31, 2026.
California Governor’s Office, Governor Newsom announces new AI cyber defense program to protect California’s critical infrastructure, August 10, 2026.
California Governor’s Office, Governor Newsom announces appointments 8.21.26, August 21, 2026.
California Governor’s Office, Governor Newsom announces a first-of-its-kind partnership, providing Anthropic tools to state agencies and improving services for Californians, June 29, 2026.
White House, Ensuring a National Policy Framework for Artificial Intelligence, December 11, 2025.
White House, National AI Legislative Framework, March 20, 2026.


Leave a comment