Senate Stalemate Leaves Federal Cyber Data-Sharing Law Expired

Permanent liability protections for companies sharing cyber threat information expired at the end of fiscal 2025 and have only been renewed through short-term funding measures. A long-term reauthorization has bipartisan support but is blocked by Senate Homeland Security Chairman Rand Paul, who wants an amendment addressing free speech. If Democrats take the Senate, lawmakers may seek a revised version that accounts for AI-related cyber risks.
The Cybersecurity Information Sharing Act of 2015 grants companies liability and antitrust protections when they share cyber threat indicators with federal agencies or one another. Its permanent authority ended with fiscal 2025, so Congress has kept it alive only through short-term funding measures.
Senate Homeland Security Chairman Rand Paul has blocked a long-term extension while seeking an amendment barring government efforts to restrict speech through FBI contacts with social media firms. Ranking member Gary Peters sponsors bipartisan bills extending the program through fiscal 2035; one would make protections retroactive and rename it. The House Homeland Security Committee voted unanimously last year to advance a bill by Chairman Andrew Garbarino.
The lapse may leave companies less certain about liability protections, potentially discouraging some from sharing cyber threat data with agencies or peers. That could weaken collective defenses against attacks affecting businesses, government networks, and the public. Because renewals now ride on short-term funding measures, affected organizations may face recurring uncertainty. If lawmakers later revise the law for AI-related risks, future information-sharing rules could change how firms and agencies cooperate.