DeploymentCognitive automation2026-01-28
CISA's statutory AI inventory lists critical-infrastructure network anomaly detection as deployed and its Security Operation Center anomaly detection as inactive
Security analyst (SOC)occupation page →Event date / reported
2026-01-28
Evidence stage
DeploymentAn employer has put it into production. Can move the baseline — weighted by scale and how similar the setting is.
Tasks this bears on
Working the alert queue
Going through hundreds of alerts a shift and deciding which two are worth looking at.
Automating✓ Evidence-backed
Where this applies
One agency, and only the unclassified, non-sensitive use cases it is required to publish under the Advancing American AI Act — classified work is outside the inventory by construction, so absence from this list is not absence from the agency. It is CISA's own statement about its own operations, and CISA runs a security operations centre rather than selling tooling to others, which is why this is recorded as an employer deployment rather than vendor material. Two things sit side by side and both belong on this page: network anomaly detection over critical infrastructure and automated detection of personal data inside cybersecurity data are listed under Deployment, while the use case named Security Operation Center (SOC) Network Anomaly Detection is listed under Inactive, next to confidence scoring for threat indicators. The inventory records status, not reasons: it does not say why the SOC use case stopped, whether something replaced it, how many analysts any of this touches, or what it cost. Statuses read from the 2025 annual update published 28 January 2026.
What this means
A deployment record on working the alert queue, and the first observation on this page rather than a prediction: the agency that defends US federal networks runs machine anomaly detection over critical infrastructure in production, and publishes that it does because the law requires it to.
What it does not yet show
The same inventory lists the use case actually named after a security operations centre as inactive, so this is not evidence that a SOC's own queue has been automated at this agency. Status is all the inventory records — not why anything stopped, not what replaced it, not how many analysts are involved, and nothing at all about classified work, which the inventory excludes by construction.
What you can check
Open the inventory and read the status column before the use case names. The interesting line is not the deployed one, it is that the entry named Security Operation Center (SOC) Network Anomaly Detection sits under Inactive while adjacent cyber use cases sit under Deployment — then ask your own team the same question: which detection automations were switched on, and which were quietly switched off.
Does it change the assessment?
No. The impact index is never moved by a single event. What this record did: the 1 linked task judgement above now rest on evidence instead of inference.
Source
DHS AI Use Case Inventory — CISA(依《Advancing American AI Act》公布的法定清单) · verified 2026-09-15 · Claude Opus 5 (agent) · interpreted 2026-09-15 · Claude Opus 5 (agent)
Primary source — published by the party that did this, or the authority of record. No co-signature needed.