← My Government dashboard

Government Watch

Dossier Legislative introduced 18-nov-2025
Bill introduced in Congress — not yet passed by either chamber, and not law.

PILLAR Act

Key claim: The PILLAR Act extends the State and Local Cybersecurity Grant Program through FY2035, expands eligible systems to operational technology and AI systems maintained by state, local, or tribal governments, restricts purchases to CISA-aligned products, and increases the federal cost share for multifactor authentication and identity tools.

Abstract

(HR5078 · 119th Congress) Protecting Information by Local Leaders for Agency Resilience Act or the PILLAR Act This bill extends the State and Local Cybersecurity Grant Program through FY2035, expands the scope of the program, and imposes certain limits on the use of grant funds. (The program provides grants to states and Indian tribes to address cybersecurity risks to government information systems.) The bill expands the scope of systems that may be secured using grant funds to include operational technology systems and specifies that systems using artificial intelligence are included. Such systems must be maintained, owned, or operated by or on behalf of state, local, or tribal governments. The bill also specifies that grant funds may not be used to purchase software, hardware, or related products or services that do not align with relevant guidance provided by the Cybersecurity and Infrastructure Security Agency (CISA). Further, the bill increases the federal share of costs available to entities that implement or enable multifactor authentication and identity and access management tools for critical infrastructure by a specified date. The bill requires annual reports by grant recipients to include a description of recipients’ progress in assuming the cost of continuing cybersecurity programs after grant funds are fully expended. The Government Accountability Office must periodically review the program. This effort must include a review of artificial intelligence adoption across a sample of grants. Finally, CISA must implement an outreach plan to inform local governments, including governments in rural areas or areas with small populations, about CISA’s no-cost cybersecurity offerings. Latest action (2025-11-18): Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

Why this matters

The PILLAR Act folds AI systems and operational technology into the primary federal cybersecurity grant vehicle for state, local, and tribal governments, meaning subnational AI deployments will increasingly be shaped by CISA-aligned procurement conditions and identity/MFA cost-share incentives. For developers and platforms selling to SLTT customers, CISA alignment becomes a de facto market gate; for users and agencies, AI adoption gets tied to a mandated GAO review and cybersecurity baseline rather than standalone AI policy.

Source

Link

Briefing card

PILLAR Act
Stage: introduced · congress · 18-nov-2025

The PILLAR Act extends the State and Local Cybersecurity Grant Program through FY2035, expands eligible systems to operational technology and AI systems maintained by state, local, or tribal governments, restricts purchases to CISA-aligned products, and increases the federal cost share for multifactor authentication and identity tools.

Cross-references (0)

None recorded — doctrine links and citations appear here as scans and citation sweeps find them.

External: congress:119-hr-5078:introduced

Ask about this finding

Replies are grounded in the abstract and metadata above. The model will quote directly when possible and say so if a question isn't covered.

Stages other doctrine resolution introduced proposed rule passed chamber executive action final rule enacted district opinion circuit opinion opinion

build build 392 · ea9c128-dirty · 2026-08-09