I have recently written about who pays the real price when civic infrastructure fails. This piece is about what is accelerating toward those same communities right now, and why the window to act is narrowing faster than most civic leaders understand.
For most of the past two decades, launching a sophisticated cyberattack required meaningful resources: technical expertise, time, and the operational capacity to probe targets manually and at some cost. That constraint shaped who got targeted and how often. Organizations with limited security budgets were vulnerable, but the volume of attacks they faced was bounded by the effort required to launch them. Civic organizations built their exposure tolerance inside that reality. Municipal IT departments, county health networks, nonprofit social service organizations all made decisions about staffing, tools, and response capacity while operating in an environment where sophisticated attacks required sophisticated attackers. Now, artificial intelligence has changed that calculus entirely, and it has done so across three categories of threat simultaneously.
The first is infrastructure-targeted attack. AI now allows bad actors to scan thousands of municipal systems automatically, looking for configuration gaps in water systems, utilities, transit networks, and emergency dispatch. What previously required a skilled attacker to probe a single target manually now runs at scale, continuously, without human oversight. The organization that could not afford a full-time security team is now being targeted by automated systems that operate continuously, 24/7, against every vulnerability they find, and the gap that existed only in theory has become a gap that is actively being exploited.
The second is social engineering at volume. The deepfakes conversation is real but narrow. The larger consequence of AI for civic organizations is that phishing communications, voice calls, and identity impersonation can now be generated at scale with a credibility that was previously impossible to achieve outside of targeted state-sponsored operations. For an organization serving vulnerable populations, the attack does not need to breach the network. It only needs one person to act on what looks like a legitimate message from a benefits office, a housing authority, or a health clinic, and the harm that follows is immediate, personal, and often invisible until it is too late.
The third is identity and access manipulation, which is the category most people underestimate. Voter records, patient systems, and public benefits databases are not abstract targets. They are the operational infrastructure of daily civic life for people who have no fallback when those systems fail. AI-enabled identity fraud does not require breaching an institution from the outside. It can impersonate legitimate users and strip access from within. For a resident navigating a public benefits system, losing account access is not a technical inconvenience. It can suspend their housing assistance, interrupt their healthcare enrollment, or remove their ability to participate in elections.
Here is what sits beneath all three, a development most civic leaders have not yet been asked to account for: quantum computing. The encryption protecting voter records, hospital systems, and benefits databases today was designed for a pre-quantum world. When quantum decryption becomes accessible, and the timeline is measured in years rather than decades, those protections fail. The organizations with the resources and institutional infrastructure to upgrade will do so. The organizations that cannot are the same ones that have been carrying every other gap in this story, and they will carry this one too unless the accountability conversation changes before the capability does.
This acceleration happened at the same moment the federal government formally shifted cybersecurity responsibility onto those same organizations and withdrew the subsidized support infrastructure that had partially offset their exposure — a policy consequence that deserves its own examination, and will get one.
That said, this is not an argument for panic: it is an argument for precision about what is actually changing and who bears the cost of that change first.
Thirty years at the intersection of technology and civic infrastructure has produced one consistent observation: the organizations closest to daily community life are always the last to be protected and the first to absorb the consequences. Artificial intelligence has not created that asymmetry. It has accelerated it at a speed that outpaces the planning cycles most civic leaders operate inside. What the moment requires is civic leadership that understands these are not IT problems waiting for an IT solution. They are civic problems with a civic accountability chain. The mayor who does not know whether their city's emergency dispatch encryption is quantum-ready is not behind on technology. They are behind on governance. The nonprofit board that has never asked what happens to constituent data when their network goes down has not missed a security briefing. They have missed a leadership obligation.
I serve on the U.S. Department of Homeland Security's CISA Critical Infrastructure Partnership Advisory Council. The communities I am describing are the ones the national policy conversation is nominally about but structurally failing. The federal acknowledgment of that gap is real and documented. What fills it belongs to local leaders, and to the constituents who have standing to demand answers from them.
The question worth asking your civic leaders right now is not whether they have a cybersecurity vendor. It is whether they know what they are protecting, who is responsible for protecting it, and what happens to the people they serve when that protection fails.