If not renewed, CISA 2015 protections end in the US on September 30. This article appears in the September issue of Global Finance Magazine. Companies that share cybersecurity information with their peers have until Sept. 30, 2026, before the limited liability granted by the Cybersecurity Information Sharing Act of 2015 runs out, exposing them to potential regulatory scrutiny and penalties. Under the Act, non-federal entities may share anonymized cyberattack and response information with other non-federal entities and the federal government via the Automated Indicator Sharing (AIS) program operated by the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA). In July, 23 industry associations that represented the financial services, energy, technology, transportation, healthcare, and retail sectors wrote to Speaker of the House Michael Johnson (R-LA) requesting an extension to the Act since it is “a foundational component of the nation’s cybersecurity.” However, some view AIS as a relic of an earlier era of cyberdefense that provides machine-readable cyber threat indicators and defensive measures against malicious IP addresses, file hashes associated with malware distribution, and known malicious web links. “It was a failure from the get-go, and it accomplishes nothing,” Milton Mueller, a professor of cybersecurity policy at Georgia Institute of Technology’s Jimmy and Rosalynn Carter School of Public Policy, told Global Finance. “No one will notice when it’s gone.” A web post by Mueller earlier this year cited a DHS Office of Inspector General (OIG) report stating that non-federal participants using AIS fell to fewer than 90 in 2024 from a high of 304 in late 2022. The report also noted that alert volume on the platform dropped 93% between 2020 and 2022. Though there was a surge in alerts, to 10 million from 1 million, the OIG found that 89% of the data came from a single