TL;DR · 30-second read
The Short Version
The US House of Representatives passed a bill to help small, local electric companies defend against hackers. These include rural power cooperatives, which are owned by the customers they serve, and city-owned utilities.
The bill allows up to $250 million over five years. That averages about $50 million a year, spread across the whole country. It is permission to spend, not money in the bank yet.
Why care? The huge computer warehouses behind artificial intelligence run on the same power grid as everyone else, and these small utilities say they have the fewest people guarding it.
On June 29, 2026, the U.S. House of Representatives passed the Rural and Municipal Utility Cybersecurity Act, a bipartisan bill from Rep. Mariannette Miller-Meeks (IA-01) and Rep. Jennifer McClellan (VA-04), according to a press release from Miller-Meeks’ office. The bill reauthorizes the Rural and Municipal Utility Advanced Cybersecurity Grant and Technical Assistance Program and authorizes $250 million over five years to help rural electric cooperatives and municipal utilities deploy cybersecurity technology, share threat information and respond to incidents.
The bill passed alongside three other grid-security measures from the House Energy & Commerce Committee, has the backing of the National Rural Electric Cooperative Association and the American Public Power Association, and now moves to the Senate.
Executive Summary
The House has voted to extend a federal program that gives grants and technical help to the smallest operators on the U.S. electric grid: rural electric cooperatives, which are member-owned, and municipal utilities, which are owned by cities and towns. The authorization is $250 million over five years, an average of $50 million a year if spread evenly.
The premise, stated plainly in the release, is that these utilities face the same sophisticated threats as large investor-owned utilities while operating with limited cybersecurity staff and budgets. That makes them the segment of the grid where defensive capacity is thinnest by the sponsors’ own account.
For the data center and AI infrastructure industry, the bill matters less for its dollar figure than for what it signals: Congress is treating the security of the entire power delivery chain, not only its largest nodes, as a national concern at a time when electricity reliability has become a gating factor for computing buildout. Whether the money actually flows depends on the Senate and, later, on appropriators.
A $250 Million Ceiling, Not a $250 Million Check
The most important word in the release is “authorizes.” In federal budgeting, an authorization sets the maximum Congress permits a program to spend; the actual dollars are decided separately each year through appropriations bills. An authorization of $250 million over five years therefore establishes a ceiling of roughly $50 million a year on average, not a guaranteed stream of grants. Programs are routinely funded below their authorized levels, and some are not funded at all in a given year.
The bill also has not become law. It passed the House and now needs Senate action, which Miller-Meeks urged be swift, followed by the President’s signature. Until then, utilities planning security upgrades cannot budget around the reauthorized program, and the practical effect on any given cooperative or municipal system remains prospective.
Measured against the problem the release describes, the scale is modest. A national pool averaging $50 million a year is meant to support grants, technical assistance and information sharing across every eligible rural and municipal utility in the country. That is a meaningful subsidy for a small utility that has no dedicated security team, but it is not sized to remake the security posture of an entire segment of the grid on its own.
Why the Least-Resourced Utilities Matter to AI’s Power Supply
The release never mentions data centers or artificial intelligence, so the connection has to be drawn carefully. What the release does establish is a resource gap: rural cooperatives and municipal utilities “often operate with limited cybersecurity personnel and resources despite serving millions of Americans and supporting critical infrastructure,” and they face “the same sophisticated cyber threats with far fewer resources.” By the sponsors’ own framing, these are the parts of the grid where cyber defense is thinnest.
That matters to AI infrastructure because computing capacity is ultimately limited by reliable electricity. Data center developers searching for available power increasingly look beyond the largest utility territories, and wherever a facility connects, its uptime depends on the security of the utility delivering its electricity. A campus’s own firewalls do nothing if the operational systems of the utility serving it are compromised. The mechanism is straightforward: the security of a data center’s power supply is bounded by the security of the utility that supplies it, and the bill targets the class of utility that its sponsors say is least equipped.
The link should not be overstated. A breach at a small distribution utility typically affects its own service territory rather than cascading across the national grid, and how much data center load sits on cooperative or municipal systems is not quantified in the release. The relevance to any specific operator therefore depends on where its facilities are sited. For operators served by these utilities, however, the program’s success is a direct input to their own reliability risk.
One Bill in a Four-Part Grid-Security Package
Energy & Commerce Chairman Brett Guthrie described the measure as one of “four bills” addressing security planning, Department of Energy leadership for confronting threats, tools for utilities, and collaboration between grid operators and the federal government. Read together, the package treats grid cybersecurity as a portfolio of planning, leadership, funding and information-sharing problems rather than a single funding gap.
That framing aligns with how large power consumers already think about risk. A grant for a small utility’s security software is most valuable when paired with timely threat intelligence and a clear federal point of contact during an incident. The release does not detail the other three bills, so how they fit together in practice remains to be seen as they move through the Senate.
The support of the National Rural Electric Cooperative Association and the American Public Power Association is notable but expected, since their members are the intended recipients. Their backing indicates that eligible utilities see demand for the program; it is not independent evidence of how effective the grants have been to date.
What Power Buyers and Developers Should Watch
For companies siting data centers or other large loads, the practical takeaway is to treat a utility’s cybersecurity posture as part of site diligence, alongside capacity, interconnection timelines and rates. Questions about whether a prospective utility has participated in federal cyber programs, what monitoring it runs on its operational systems and how it shares threat information are reasonable to raise early.
For investors and policy watchers, the next markers are Senate action and, if the bill becomes law, the appropriations figure attached to it. Those two steps, not the House vote, will determine whether the $250 million authorization turns into money in the hands of utilities.
Background
The Rural and Municipal Utility Advanced Cybersecurity Grant and Technical Assistance Program is administered by the U.S. Department of Energy and was established under the 2021 bipartisan infrastructure law to help smaller utilities improve their cyber defenses. The June 2026 House bill would reauthorize it for another five years.
Rural electric cooperatives and municipal utilities make up a large share of U.S. utilities by count, though each is typically much smaller than an investor-owned utility. Their limited scale often means they have few or no dedicated cybersecurity staff, a gap federal programs like this one aim to close as grid threats and electricity demand both grow. Source: House Passes Miller-Meeks Bill to Strengthen Cybersecurity for Rural and Municipal Utilities, press release from the office of Rep. Mariannette Miller-Meeks announcing House passage of the Rural and Municipal Utility Cybersecurity Act.Sources

