Data Infrastructure Risk Reduction Act
In committee: it can still change before the session ends.
- Stage
- In committee
- Started in
- House
- Latest action
- May 8, 2026
What it does
The Data Infrastructure Risk Reduction Act would require the Secretary of Homeland Security, in coordination with the Secretary of Defense and the Cybersecurity and Infrastructure Security Agency, to identify data centers that should be treated as critical infrastructure within 180 days of enactment. The bill mandates an assessment of the security of power and water supplies—particularly above-ground transmission lines and substations—connected to these data centers, as well as the potential impacts of data centers located near residential communities. Based on this review, the Secretary must submit to Congress a strategy with recommendations to defend data centers from external breaches by malefactors and to protect surrounding communities and residential areas. The bill defines "data center" and "critical infrastructure" using existing statutory definitions from the Energy Independence and Security Act of 2007 and the USA PATRIOT Act, respectively.
AI summary · The lawmakers haven’t published an official summary of this bill yet, so 52 wrote this one from the bill’s text.
Where it stands
Introduced (Done)
Committee (Current step)
Floor (Not started)
Law (Not started)
What moved
Who is involved
Sponsors
The lawmakers who put their names on it, lead sponsors first.
In the news
Reporting that may mention this subject. Possible matches are labeled.
Loading coverage…
Where it goes next
While a bill can still move, the questions are about people and money.