News Events Research
Industry Insights
Opinion Podcasts MeriTV
This page is not built out yet. If you are seeing this page, please contact an administrator.

Crypto-Agility Isn’t Optional: What The Federal QRC Migration Requires

By: Adam Everspaugh, PhD, Cryptographic Advisor, Keeper Security

With the clock ticking on federal deadlines for Quantum-Resistant Cryptography (QRC) adoption, U.S. agencies are deep in the planning stages of a monumental cryptographic transition. While the focus is often on selecting the right quantum-resistant algorithms, the unexpected downfall of the HAWK signature scheme reveals a more fundamental requirement for a successful migration. True security in the post-quantum era will not come from a single, perfect algorithm, but from the ability to rapidly swap, update and deploy cryptographic primitives as the landscape evolves. This “crypto agility” is no longer a theoretical nice-to-have; it’s the core principle that will determine the success or failure of the federal QRC mandate.

Algorithm Choice Alone Isn’t Enough

Crypto-agility is as fundamental to a secure QRC strategy as the quantum-resistant algorithm choice itself. In practice, this requires maintaining an inventory of where and how cryptographic algorithms are used across an organization’s environments, and ensuring that update pathways exist before an emergency migration is required. A hybrid cryptographic approach – running a battle-hardened, classic cryptographic algorithm in conjunction with a newer, quantum-resistant algorithm – reflects the same principle.

HAWK, a third-round quantum-resistant signature candidate in the National Institute of Standards and Technology (NIST) standardization process, was recently shown to contain a previously unknown mathematical symmetry that cuts its effective key strength in half. The HAWK team has since confirmed the result and formally withdrawn the candidate from standardization. Systems built to swap or patch cryptographic primitives without a full re-architecture absorb findings like this far more easily than those locked into a single scheme.

NIST standards finalization has never guaranteed permanence nor security. Two of the three standardized quantum-resistant algorithms rely on the same lattice algebra foundation as HAWK, and it’s reasonable to assume that AI-assisted cryptanalysis will be effective on those algorithms as well.

A Credible Migration Plan

Executive Order 14412, signed in June 2026, requires United States federal agencies to transition to quantum-resistant cryptography for key establishment by December 31, 2030, and quantum-resistant digital signatures by the end of 2031. The order required that a migration lead be assigned for each agency by July 2026 and full migration plans are due to the Office of Management and Budget (OMB) this month.

A high-level understanding of the post-quantum migration process is key, moving systematically from initial Inventory and Strategy through Implementation, into a Phased Rollout, and finally establishing continuous Monitoring and Response. As federal agencies navigate this complex trajectory under tight deadlines, several critical pitfalls frequently threaten success.

First, many organizations falter early by attempting to execute an entirely manual inventory phase. Without leveraging modern automation to dynamically scan vendors, active directories and internal codebases for legacy public-key cryptography, agencies risk missing hidden vulnerabilities. Furthermore, a key strategic misstep is selecting a strategy or vendor that doesn’t permit phased roll-out of hybrid QRC and permit rapid response when a QRC algorithm vulnerability is found. The latter is much harder and more consequential than the former.

Crypto-Agility in Practice

EO 14412 sets the deadlines. Meeting them depends on whether the underlying architecture is built for crypto-agility. Here are the criteria for determining if an agency’s transition is crypto-agile:

  • Phased rollout: products, servers, data and users can move in phases, not all at once. Individual phases can be rolled-back immediately if they break during rollout.
  • Mixed-fleet: individual products, servers, data and users can interoperate during the phased rollout.
  • Rapid deployment: implementation and rollout should be measured in weeks or months, not years. If changes take years, then a vulnerability in a QRC algorithm will persist for years, and that isn’t an acceptable security posture in most settings.
  • Rapid response: Once rollout is underway, how quickly can a new ciphersuite be rolled out or rolled back? Responses should be possible in weeks.

The nightmare scenario is a complex, fragile and time-intensive rollout. Consider what this looks like in practice: seven months into an 18-month migration, an agency’s systems and data exist in a split state with some still relying on legacy cryptography (State A) and others upgraded to a hybrid quantum-resistant algorithm (State B). The goal is a clean migration from A to B.

Then, disaster strikes. A critical vulnerability is discovered in the new quantum-resistant algorithm, forcing the agency to abandon it for an entirely different, secure ciphersuite (State C). Suddenly, the migration path fractures. Instead of a single, orderly transition, IT teams must simultaneously manage three chaotic, in-flight data conversions: legacy to hybrid (A ? B), hybrid to the new patch (B ? C) and legacy straight to the new patch (A ? C). If the deployment process is rigid and slow, this mid-flight pivot exponentially increases system complexity, dramatically drags out timelines and vastly raises the risk of catastrophic data corruption.

Crypto-agility avoids this. It’s easy to say but hard to do, and the optimal strategy varies by setting. This is a reminder that no algorithm, and no plan, survives contact with reality. Crypto-agility allows an agency to keep moving every time the ground shifts.

My Cup of IT: Midterms, AI, & The East India Company

Here come the midterms. Remember when government regulated business?

Adorable.

Welcome to the Post-Government Era — where Uncle Sam’s bringing a butter knife to an AI  tech regulation gunfight. Who’s zooming who?

The Magnificent Seven are worth $25 trillion. Throw in Anthropic and OpenAI – tech will soon best US $32.5 trillion GDP.

And unlike governments, these companies don’t have borders.

They operate globally. Move capital globally. Hire globally. Optimize taxes globally. And, when regulations get inconvenient, they can move faster than a federal procurement officer to change the rules and the government, anywhere.

Sound familiar?

It should. Think East India Company – a private corporation that ran the Indian subcontinent. At its peak, the Company had armies, controlled territory, and wielded more power than the governments to which it was supposed to answer.

Today’s tech giants are our kingmakers.

They control the chips, clouds, models, data, and capital driving the next economy. And they’re flexing political muscle, too. Tech companies and AI interests are pouring millions into lobbying and political action committees. Elon Musk has become a walking case study in the new math of money, technology, and political influence – remember X picking his nose in the Oval?

So Washington wants to regulate AI? Good luck.

The government still makes the rules.

The problem is increasingly that somebody else has the resources to write them.

Closing the Data and Trust Gaps with Explainable AI

By: Brian Gilkey, Vice President North America, Decision Intelligence, Cognyte

Federal law enforcement agencies strive for one thing in their criminal investigations – faster data analysis. It yields faster time to actionable intelligence and faster case resolution. Analysts are swimming in investigative data today but procuring and implementing AI for automated analysis remain major challenges for federal agencies.

These are challenges of their own making. Long-ingrained processes and investigative methodologies manifested in procurement and workflow pipelines that confine valuable data into silos built around point solutions, creating islands of intelligence in an ocean of investigative data.

AI doesn’t thrive in this environment. It demands rich, connected, consolidated data sets to deliver its full analytical value. In this light, adopting AI and automated analysis was always going to be an uphill climb in investigative applications.

The agencies that overcome these challenges will make giant leaps in making their communities safer. The promise of AI is that profound.

WHAT’S THE HOLD-UP?

Federal law enforcement no longer needs convincing that AI will be essential to modern investigations. It’s a directive framed in U.S. federal policy. OMB Memorandum M-25-21 directs agencies to accelerate responsible AI adoption while maintaining public trust and applying risk-management practices to high-impact AI. It also calls on agencies to strengthen data governance, traceability, interoperability and security as they scale AI use.

AI automation is a known need among federal agencies. The risk is that AI adoption will continue moving at institutional speed while investigative data grows at machine speed.

Intelligence data today is successfully – but slowly – gathered with point tools. From mobile forensics tools that pull data from lawfully seized mobile devices to geo forensics tools like automated license plate recognition (ALPR), point solutions are often great at what they do but they aren’t designed to interact or integrate. Public records databases and OSINT (open-source intelligence) can likewise be brought to bear in agency investigations, but this data is consistently confined to silos.

Individually, these data sources are enormously valuable, but they can’t be understood in isolation. Investigators and analysts don’t have the background or bandwidth to master these point tools or synthesize these silos. A patchwork of manual processes is applied where AI automation should shoulder the burden.

According to a recent survey, more than half (53%) of law enforcement agencies say that their inability to access relevant data sources is the top technological pain point causing delays in resolving investigations. These delays can directly impact public safety.

Public-sector investment in advanced, AI-driven law enforcement technology is accelerating. Federal agencies know they need AI automation – and they’re prime candidates to exploit AI and ML models for meaningful benefit.

There’s one last hurdle agencies must overcome. What’s missing – and what’s needed – is trust.

There’s a lingering resistance to deploying AI tools that handle sensitive, high-stakes data, and in particular concerns pertaining to Explainable AI – the ability to understand how an AI-generated lead was reached and trace it back to source data so investigators can validate it under legal and regulatory scrutiny.

The G7 Interior and Security Ministers, including the United States, adhere to law enforcement principles that stipulate automated AI processes should generally be “human interpretable” and “logically reconstructable.” Crucially, these principles affirm that automated processes should support rather than replace human decision-making.

A modern, purpose-built, AI-driven decision intelligence platform can fuse and analyze decentralized, unstructured data – including mobile forensics and geo forensics data – and allow analysts to look deeply into massive data sets to verify where investigative data was sourced and confirm that the source itself is reliable. This attribution capability is essential – and it’s achievable today.

Security standards are likewise in place today governing how and where this data can be processed by AI analytics. PII (Personally Identifiable Information) and CJI (Criminal Justice Information), for example, are tightly controlled per defined security policies and mandates, and these systems have traditionally been deployed on premises.

Vast, well-defined, fenced-in investigative data sets like these are perfect environments for AI analysis to thrive. Here AI doesn’t reach beyond the guardrails, and it doesn’t interact with the web where data distortions can introduce hallucinations. AI can be trusted to conform to strict security standards; the security perimeter is non-negotiable.

Under these tightly controlled conditions, AI safeguards are built in. Additional safeguards are put in place by analysts themselves. There’s accountability – explainability – at every stage in the workflow, and human experts never lose oversight.

AUTOMATION WITH ACCOUNTABILITY

Federal law enforcement agencies increasingly recognize that AI is essential to keeping pace with the investigative data deluge. What’s needed is the institutional urgency to turn that recognition into operational reality, and decision intelligence platforms that unlock the value of point tools in a unified way.

Agencies can preserve strict data security, maintain attribution to source intelligence and keep human experts firmly in control while giving machines the work humans can’t perform at scale, searching millions of records, connecting disparate data points and surfacing relationships at speeds no analyst could approach.

This approach lets expert investigators do what they do best – interrogate the findings, follow the evidence, apply context and judgment, and make informed decisions that accelerate case resolution.

The technology and safeguards are ready. Procurement practices and investigative workflows must now catch up.

 

Brian Gilkey, Cognyte

Brian Gilkey is a prominent figure in the homeland security, law enforcement and intelligence analytics space. He is currently the Vice President, North America at Cognyte. He has over 25 years of experience in the intelligence, investigative technology and threat-assessment world. He regularly collaborates with North American law enforcement command staff, federal agencies and multi-agency task forces to modernize investigations and intelligence gathering. His expertise includes counterterrorism, cross-border human trafficking interdiction, narcotics/weapons smuggling analysis and intelligence-led major event security planning.

The Oracle in the HR Room

Nothing says “federal IT modernization” quite like awarding Oracle a $395.8 million HR contract, while Oracle-related HR systems are making headlines for all the wrong reasons.

OPM just handed Oracle a 10-year deal to build the government’s first governmentwide HR platform. One system. More than 100 legacy systems consolidated. Roughly 2 million federal employees.

Sounds like real progress.

Then there’s the massive FBI HR records breach…

The reported breach isn’t just about employee records. It potentially puts agents’ names, addresses, Social Security numbers and family information in the hands of hackers. For an FBI agent, that’s not an HR problem. That’s a front-door problem.

Imagine spending your day investigating threats to America — terrorists, drug cartels, organized crime — and then wondering whether your kids, spouse, or home address just became part of somebody else’s target list.

That’s the part of “consolidation” that doesn’t fit neatly into a PowerPoint.

Mandiant says ShinyHunters exploited a vulnerability in Oracle PeopleSoft, and the FBI is investigating the incident.

Now, before everyone starts throwing keyboards: That does not establish that Oracle caused the FBI breach. And it certainly doesn’t prove the new OPM platform is vulnerable.

But the timing?

Let’s just say the cybersecurity folks may want a little more than the usual “trust but verify.”

One HR platform — two million federal employees — one enormous target. And, AI tools turbocharging hacking.

Welcome to federal IT modernization 2.0.

A Workload-First AI Infrastructure Strategy for Federal Agencies

By: Paul Perez, SVP & Senior Technology Fellow, Office of the CTO & Dell Federal

Federal agencies can scale AI securely by adopting a workload-first infrastructure strategy that pairs accelerated compute, governed data, and a repeatable deployment model.

Key takeaways

  • Federal agencies are expanding AI across mission environments, with 85% of federal chief AI officers saying AI will transform agency operations by 2030 in ways they have not yet imagined.
  • Scaling AI requires a workload-first infrastructure path that connects investments to mission value, reduces complexity, and supports secure, repeatable deployment.
  • Together, Dell Technologies and NVIDIA provide a platform and reference design that help agencies build a common foundation for priority AI workloads.

Federal leaders have identified where AI can add value, and according to MeriTalk’s 2025 Federal CAIO Outlook, 85% of federal chief AI officers (CAIOs) say AI will transform agency operations by 2030 in ways they have not yet imagined. The focus now is moving those efforts from early pilots into secure, governed production.

Which AI workloads are federal agencies prioritizing?

The focus now is practical: scaling the workloads that can improve mission performance, strengthen operations, and help teams make faster decisions. For federal organizations, those workloads span agentic AI, geospatial intelligence, high-performance computing (HPC), modeling and simulation for science, data engineering, mission intelligence, cybersecurity, and zero trust support.

Each workload carries its own data, performance, security, and governance requirements. Agentic AI requires persistent inference and token budget planning. Geospatial intelligence depends on large imagery, mapping, and location datasets. HPC and modeling environments require accelerated computing and scalable infrastructure. Cybersecurity workloads require trusted data, rapid analysis, and strong control.

A workload-first approach helps agencies identify what each AI effort needs to succeed before they make infrastructure decisions. Once agencies understand the requirements of each workload, they can make infrastructure decisions that support performance, security, governance, and scale.

What infrastructure does federal AI scale require?

Scaling federal AI requires a full-stack infrastructure – accelerated compute, high-speed networking, scalable storage, and enterprise AI software – working together with governed data, security, and compliance.

That foundation must also support AI wherever mission data and users reside. Some workloads may run at the edge. Others may require data center-scale inference or high-performance computing. Hybrid environments will remain essential for agencies balancing agility, data control, latency, and cost.

Repeatability matters, so agencies do not have to build a new architecture for every AI workload. A common foundation can help teams move faster, apply consistent governance, and support multiple AI pathways, from deskside development and edge deployments to data center-scale inference and high-performance workloads.

Repeatability becomes especially important as agencies move AI into production environments where security, governance, and integration requirements become part of day-to-day operations.

Scaling securely

As agencies expand AI, they are also confronting practical implementation challenges. According to MeriTalk’s 2025 Federal CAIO Outlook, top barriers are insufficient funding or resources, lack of internal AI expertise, data quality and accessibility issues, and difficulty integrating with legacy systems.

A repeatable operating model can help address those barriers. It gives teams a more consistent way to select, deploy, monitor, govern, and scale AI models. It also helps align infrastructure decisions with mission requirements instead of treating AI as a series of disconnected point solutions.

The Dell AI Factory with NVIDIA provides agencies a platform for operationalizing AI across Dell infrastructure and services, integrated with NVIDIA accelerated computing, NVIDIA networking, NVIDIA AI Enterprise software, and NVIDIA NIM inference microservices. Paired with the NVIDIA AI Factory for Government reference design, it supports a repeatable approach to scaling agentic AI responsibly, securely, and efficiently. With this foundation in place, agencies can evaluate AI success by the operational and mission results it delivers.

Measuring mission value

For agencies, AI value is measured in practical gains. Did the agency save time? Improve services? Reduce risk? Control costs? Accelerate decisions?

Those questions are especially important as agencies move from isolated AI efforts to production workloads. Infrastructure choices shape how quickly teams can deploy, how securely they can operate, and how predictably they can manage cost.

With the Dell AI Factory with NVIDIA and the NVIDIA AI Factory for Government reference design, agencies can scale priority AI workloads with greater confidence. The result is a secure, repeatable foundation for return on mission – one that helps federal teams turn AI potential into operational progress. Learn more: https://www.delltechnologies.com/assetlink/doc/en-us/meritalk-dell-nvidia-ai-moves-missions-forward-ebook-dl2bqz-original.pdf.

Federal AI: How Governed Mission Data Enables Secure, Scalable AI

By: Daniel Carroll, Field CTO, Dell Federal

AI depends on data that is visible, governed, and usable. For federal agencies, data control is the foundation for scaling AI securely and responsibly.

Key takeaways

  • AI-ready infrastructure starts with governed mission data: where it lives, how it is classified, who can access it, and which workloads can responsibly use it.
  • Secure AI provides a decision framework for determining which workloads require greater control and which can run in shared, hybrid, or cloud-connected environments.
  • IDC found that 69% of government organizations globally have or plan to implement secure AI within 12 months.

AI can only deliver value when agencies can use the right data in the right way. For federal organizations, that starts with visibility: knowing where data lives, how it is classified, how it moves, who can access it, and which AI workloads can responsibly use it. As agencies scale AI beyond early pilots, governed mission data becomes the foundation for trusted, secure, and repeatable AI operations.

Where is the data foundation for AI most important?

This foundation is especially important for priority workloads such as agentic AI, geospatial intelligence, data engineering, mission intelligence, cybersecurity, and high-performance computing, all of which depend on data that is visible, governed, and usable.

Unstructured or siloed data can reduce model accuracy, create compliance gaps, and require costly pre-processing before AI can use it. These are common challenges in federal environments where data spans legacy systems, classification levels, and geographically distributed networks. A strong data foundation helps agencies turn information into governed datasets that support analytics, automation, and decision-making.

Once agencies understand the data foundation behind each workload, they can apply governance controls that match the sensitivity, purpose, and operating environment of the AI system.

How do federal agencies govern AI access?

As agencies expand AI, governance must be built into how each workload is deployed, monitored, and scaled. That means protecting data, overseeing models, supporting auditability, applying zero trust, managing inference operations, monitoring agent behavior, and tracking token consumption and workload utilization. Clear policies and continuous monitoring help agencies keep AI transparent, controlled, trusted, and aligned with mission requirements.

Confidential compute can support this foundation by helping protect sensitive data and models while they are being processed. NVIDIA Confidential Computing, for example, uses hardware-enforced trusted execution environments to ensure that AI model weights and input data remain encrypted even during processing – an important capability for federal agencies handling classified or personally identifiable information.

What is secure AI and why does it matter to federal agencies?

Dell Technologies defines secure AI as the ability to govern, develop, and operate the AI lifecycle with authority over data, compute, models, and policy. Secure AI gives agencies a useful decision framework for data, infrastructure, and model control.

IDC found that 69% of government organizations globally have or plan to implement secure AI within 12 months. For secure AI, strong data governance, quality, and control is the most critical AI platform element.

Secure AI does not require an all-or-nothing architecture. Instead, it helps organizations determine which workloads require greater control – such as those involving sensitive data, strict compliance needs, or mission-critical operations – and which can responsibly use shared, hybrid, or cloud-connected environments for temporary capacity, specialized services, or broader flexibility.

By matching each workload to the right level of control, agencies can shape the infrastructure foundation to keep data, models, and workloads aligned with mission requirements.

How does on-premises infrastructure improve data control?

Bringing AI closer to governed mission data can reduce unnecessary data movement, strengthen control, and support the economics of high-volume AI workloads. Bringing inference on premises can reduce AI costs by 28% to 90%+ for persistent workloads, according to a Signal65 two-year cost model comparing Dell AI Factory with NVIDIA against cloud application programming interfaces. On-premises infrastructure also helps agencies align infrastructure with the demands of AI at scale: data quality, legacy integration, workforce readiness, security, governance, token demand, and cost predictability.

The Dell AI Factory with NVIDIA provides the platform agencies can use to operationalize AI across Dell infrastructure and services, integrated with NVIDIA accelerated computing, NVIDIA networking, NVIDIA AI Enterprise software, and NVIDIA NIM inference microservices. The NVIDIA AI Factory for Government reference design provides guidance for government-grade AI factory architecture, including security, compliance, orchestration, observability, and workload support.

Together, this approach helps agencies build AI on governed mission data and scale priority workloads with greater confidence. The result is a secure, repeatable foundation for return on mission – saving time, improving services, reducing risk, controlling costs, and accelerating decisions. Learn more: https://www.delltechnologies.com/assetlink/doc/en-us/meritalk-dell-nvidia-ai-moves-missions-forward-ebook-dl2bqz-original.pdf.

My Cup of IT: AI-pocalypse “Gates” Yawn – Uncle Sam’s Drafting A Manual

Bill “Cassandra” Gates has a warning about AI. And, yes, we should consider it as more than an effort to distract from the Epstein files.

The tech prophet bleats AI will transform work, eliminate jobs, and disrupt everything from health care to education. So, what’s the biggee? Think Nepalese flood – America ain’t moving fast enough to prepare for what comes next.

That should make Federal IT leaders sit up.

The Beltway loves an AI strategy. We have frameworks. Roadmaps. Task forces. Working groups. Probably a subcommittee studying whether we need another working group.

Meanwhile, like the flood waters, AI’s on the move in government and our society. Federal agencies are already putting AI to work. Cybersecurity. Data analysis. Customer service. Software development. Decision support.

The opportunity is enormous – but so is the risk.

If AI can make government faster, great. But faster bad decisions are still bad decisions. Just with better latency.

Gates has suggested creating “Human Reserved” areas where people remain firmly in control. That’s worth debating – quickly – particularly for national security, health care, benefits, and other high-consequence decisions.

For America, the stakes are bigger than federal IT.

The countries that lead in AI will win. The Hill doesn’t get it. While they’re looking for a new roadmap, they wouldn’t know if they have it the right way up anyway.

Turn Asset Visibility Into Mission Readiness

Federal missions depend on far more than laptops, servers, and software. Agencies also manage facilities systems, operational technology, Internet of Things devices, laboratory equipment, cameras, radios, sensors, vehicles, supplies, cloud resources, and more.

Yet information about agency assets often remains divided across network tools, procurement systems, spreadsheets, warehouse applications, and facilities platforms. One system may show that an asset was purchased, while another tracks its location or condition. Security teams may identify a vulnerability without knowing who owns the asset, which mission relies on it, or whether a replacement is already planned.

Bringing that information together helps agencies turn asset visibility into operational readiness.

See the complete asset environment

Effective asset management starts with a clear view of what the agency owns, operates, and depends on.

That view should extend across IT, facilities, operational technology, field resources, and cloud environments. It should also provide the context teams need to understand:

  • Where an asset is located
  • Who owns or manages it
  • What condition it is in
  • Which services and missions it supports
  • What risks or lifecycle actions require attention

This context is increasingly important as physical and digital environments converge. An HVAC system, camera, sensor, or laboratory instrument may be managed as a facilities asset. Once connected to a network, however, it also becomes part of the agency’s attack surface.

A complete asset picture gives operational, security, and mission teams a shared foundation for decisions.

Manage the full asset lifecycle

Visibility delivers greater value when it supports action throughout the asset lifecycle.

Incomplete or outdated information can lead to excess purchases, shortages, reactive maintenance, unused software, and equipment that remains in service beyond its intended life. It can also make budget planning harder and increase security and compliance risk.

ServiceNow Enterprise Asset Management supports physical assets from planning and acquisition through deployment, maintenance, refresh, and retirement. Agencies can improve inventory control, coordinate maintenance, track utilization, manage warehouse operations, and strengthen capital planning.

ServiceNow IT Asset Management extends that discipline to hardware, software, and cloud resources. By connecting cost, performance, usage, and lifecycle data, agencies can make better decisions about when to repair, replace, redeploy, reclaim, or retire assets.

Connect asset insight to action

Asset information is most useful when it flows directly into the work teams need to perform.

A broken HVAC system may require a work order, technician assignment, replacement parts, approvals, service history, and follow-up documentation. A vulnerable device may require discovery, prioritization, remediation, and audit evidence. An underused software license may need to be reclaimed before the next renewal.

ServiceNow connects these activities through digital workflows across IT, facilities, procurement, field service, security, and compliance.

The ServiceNow Configuration Management Database and common data model help agencies normalize and connect information from multiple sources. Workflow Data Fabric brings trusted data from existing systems into ServiceNow workflows and artificial intelligence (AI) agents, giving teams the context to make decisions and act in real time.

By connecting asset data to the work it triggers, agencies can reduce manual data calls, improve coordination, and make more confident decisions about the resources their missions depend on.

Read the issue brief to learn how ServiceNow can help agencies connect asset visibility, lifecycle management, security, and AI to strengthen mission readiness.

Agentic AI Tokenomics: Why Federal Agencies Need an Infrastructure-First Token Strategy

By: Paul Perez, SVP & Senior Technology Fellow, Office of the CTO & Dell Federal

Always-on agents change the economics of AI. Federal agencies need workload placement strategies that account for token demand, inference costs, data control, and mission requirements.

Key takeaways

  • Agentic AI can deliver major productivity gains, but persistent agents can consume far more tokens than standard chat interactions.
  • According to Signal65 research, agentic workloads can use 4x to 15x more tokens than standard chat interactions, and autonomous agents may drive up to 1,000x more inference demand than reasoning AI.
  • A token-smart infrastructure strategy helps agencies decide where workloads should run based on mission sensitivity, data gravity, latency, governance, and cost predictability.

Agentic AI – AI systems that retrieve information, reason through multi-step tasks, call tools, and generate outputs autonomously over time – introduces a new layer of infrastructure planning because agents run continuously.

Agents work across tasks and workflows. They can retrieve information, reason through steps, call tools, coordinate actions, and generate outputs over time. As federal agencies embed agents into mission workflows, token demand becomes tied to operational activity and to the infrastructure decisions that support it.

How do agentic AI agents drive token demand?

Tokenomics – the economics of how AI systems create and consume tokens – is a practical planning issue for agencies moving agentic AI into production. Each activity consumes tokens, and token use scales with the frequency, duration, and complexity of the work they support. That makes placement a core infrastructure decision, not a downstream cost consideration.

Where should agencies run agentic AI workloads?

Workload placement matters because AI cost, performance, security, and governance are all connected. Agencies need to decide where each workload should run based on the data it uses, the latency it requires, the sensitivity of the mission, and the predictability of demand.

Cloud can be useful for testing, temporary capacity, or specialized needs. It gives teams flexibility as they explore new models, validate use cases, and manage variable workloads. But always-on agents can quickly increase token use and costs, especially when workloads are persistent and high volume.

For those workloads, agencies may need more control over where inference happens. Bringing AI closer to governed mission data can reduce unnecessary data movement, strengthen control, and improve cost predictability. It can also help teams align infrastructure decisions with mission sensitivity, data gravity, compliance needs, and long-term cost predictability.

How can agencies predict and control AI costs?

Cost predictability becomes clearer when agencies look beyond experimentation and model the cost of persistent operations. Signal65 found that agentic workloads can use 4x to 15x more tokens than standard chat interactions, and autonomous agents may drive up to 1,000x more inference demand than reasoning AI.

In a modeled two-year analysis conducted by Signal65, Dell AI Factory with NVIDIA infrastructure reduced the cost of persistent AI agent deployments by 28% to 90%+ compared to cloud-based AI application programming interfaces.

For federal agencies, token demand should be part of infrastructure planning from the start. Teams need to understand how often agents will run, how many steps they will take, which models they will use, and where inference should happen before selecting cloud, on-premises or hybrid deployment.

How do agencies scale AI responsibly?

A token-smart strategy supports both cost control and responsible scale. It helps agencies decide which workloads belong in cloud environments, which should run closer to mission data, and which require a hybrid approach.

It also reinforces the need for governance. As AI moves into production, agencies must govern model selection, inference operations, agent behavior, token consumption, and workload utilization. Clear policies and monitoring help teams keep AI aligned with mission requirements.

The Dell AI Factory with NVIDIA provides agencies a platform for operationalizing AI across Dell infrastructure and services, integrated with NVIDIA accelerated computing, NVIDIA networking, NVIDIA AI Enterprise software, and NVIDIA NIM inference microservices. Paired with the NVIDIA AI Factory for Government reference design, it supports a repeatable approach to scaling agentic AI responsibly, securely, and efficiently.

Agentic AI can help agencies save time, improve services, and accelerate decisions. Tokenomics helps ensure those gains are supported by infrastructure choices that keep performance, governance, and economics aligned. Learn more: https://www.delltechnologies.com/assetlink/doc/en-us/meritalk-dell-nvidia-ai-moves-missions-forward-ebook-dl2bqz-original.pdf.

My Cup of IT: Cyber Vigilantes Wanted

Uncle Sam is looking for a few good hackers.

Time for a quick double-click on something that may have slipped past you in all the news. The Trump administration just opened the door to a new kind of cyber warfare: private-sector cyber vigilantes.

On Aug. 12, President Trump signed a National Security Presidential Memorandum directing the government to create a program for vetted private companies to conduct offensive cyber operations against foreign cyber-enabled criminal organizations.

Think ransomware gangs. Scam networks. Cybercrime factories.  The mission is simple: Find them. Follow them. Disrupt them.

The memo calls for private-sector participation in cyber surveillance and “cyber effects” operations. Translation: Government wants private-sector cyber muscle in the fight.

And the clock is ticking. The administration has 60 days to establish the framework. Before you sign up to hang ‘em high – know companies will face vetting, oversight, and approval requirements.

Still, this is a big shift. For years, the federal cyber playbook has focused on protecting networks, sharing threat intelligence, and chasing criminals through traditional law enforcement channels.

Now Washington is asking:

What if we take the fight to them?

Of course, there is a small catch.

Cyber vigilantes need rules.

Attribution can be messy. Criminal infrastructure can sit on innocent systems. And a cyber operation aimed at a ransomware gang can have consequences far beyond the keyboard. And, what happens if those assailants turn out to be our allies?

So welcome to the new federal cyber frontier.

Uncle Sam isn’t just hiring defenders – it’s deputizing a cyber posse.

My Cup of IT: AI Protests, Plugs, & Politics

AI is moving from pilot project to procurement problem. The Army is already facing a protest over a $450 million contract award that allegedly relied on AI in the acquisition process. Translation: AI may be helping agencies buy technology — and soon it may be helping lawyers protest those purchases.

Meanwhile, NIST wants to put AI to work on the National Vulnerability Database. The agency issued a request for information looking at how AI could improve vulnerability assessment, risk management, and remediation. That is a pretty good use case: fewer spreadsheets, more finding the holes before somebody else does.

Then there’s the Hugging Face breach. Security experts are warning that AI could dramatically accelerate exploitation of newly disclosed vulnerabilities. One former NSA cyber chief called it among the most consequential hacks in recent years. Federal agencies should take note. AI is not just changing defense. It is changing the speed of offense, too.

And the China cyber story isn’t going away. A House investigation found Chinese telecom companies maintained footholds involving U.S. networks, data centers, and connectivity despite federal restrictions.

Bottom line: Speed, Safety, and Sino Switches.

My Cup of IT: Federal IT Gets Real About AI, Cloud and the Cost of ‘Efficiency’

The federal IT beat had a busy week. Again.

GSA is changing the playbook. Instead of waiting years for standards and policy reviews, GSA is testing technology first. Then it feeds the lessons learned back into the standards process. CIO David Shive says the old approach could take two to three years. OneGov has already signed more than two dozen tech companies and identified $1.18 billion in savings. Apparently, “move fast” has finally found a government office.

VA is also trying to move faster. A new memo says vendors don’t need FedRAMP certification before competing for VA business. The security bar stays put. The bureaucratic speed bumps are supposed to come down. VA still requires a rigorous ATO process — targeted at 60 days.

Then there’s the DOGE Wall of Receipts. GAO says the wall reported $110 billion in savings as of July 7. But some numbers don’t add up. One example: DOGE claimed $1.7 billion in savings from a DoD health IT contract. GAO says the contract wasn’t terminated. No savings. No receipt. Awkward.

And finally, FEMA’s workforce numbers deserve attention. More than 4,300 employees left in FY 2025, a 55% increase over the prior year. GAO says FEMA made workforce cuts without adequate strategic planning.

So this week’s lesson?

Modernize faster. Secure smarter. And check the receipt.

Why the Future of Federal Tech Relies on Workforce Readiness

By: Elise Hauser, Senior Product Marketing Manager, Public Sector at Pluralsight

Among federal agencies, AI budgets are exploding and cyber modernization is a top-line priority across civilian and defense missions alike. But innovation and readiness are two different things, and right now, there’s a gap between them.

Agencies can buy tools, but they can’t scale them without people who know how to manage  them. The skills shortage is throttling AI and delaying cyber readiness. Improving your team’s readiness is what turns AI pilots into production and compliance mandates into mission capability. Cross-skilling is the key to getting there.

3 trends impacting tech readiness in federal agencies

Three key trends are making the tech skills gap in federal agencies even more apparent: the move from AI pilots to production, AI and cybersecurity overlap, and DoD mandates.

AI: The move from pilots to production

Federal AI adoption has grown rapidly. Obligated federal AI spending grew from $675 million to $7.2 billion between 2024 and 2026 (a 966% increase), while potential contract value climbed even faster. Agencies reported thousands of individual AI use cases. And the policy backdrop reinforced the pace, from the 2025 AI Action Plan to the Department of Defense’s AI Acceleration Strategy.

It’s clear that agencies have adopted AI in isolated pilots. The challenge now is scaling those capabilities into production across complex mission environments and embedding AI into core systems and workflows.

But the AI talent shortage, workforce capacity constraints, a risk-averse culture, and low public trust impede progress. In other words, the constraint on federal AI isn’t the technology or the budget. It’s having a workforce that’s ready to deploy, govern, and sustain it.

AI and cybersecurity are converging

AI and security have merged into a single discipline, and it’s affecting both sides of the fight at once.

AI strengthens cyber defense

On defense, agencies are turning to AI to do what human analysts can’t do at scale. AI-driven monitoring and automated response let agencies analyze behavioral patterns continuously, flag anomalies in real time, and execute containment actions faster than humans alone could.

By shifting from reactive defense to anticipatory risk management, agencies can identify and neutralize threats before they escalate. This is the difference between a security posture that responds to breaches and one that prevents them.

AI enhances threat actors’ capabilities

The same capability that strengthens defense also arms adversaries. Threat actors are using AI to accelerate reconnaissance, generate convincing phishing and social-engineering content at scale, probe for vulnerabilities, and adapt their tactics faster than traditional defenses can keep up.

The result is an escalating speed contest between the defender’s AI and the attacker’s. Falling behind on AI capability is no longer just an efficiency problem—it’s a direct security exposure.

AI systems create new attack surfaces

As agencies rush to deploy AI into core workflows, they introduce risks that legacy security models were never designed to address. This includes sensitive data flowing into and out of models without adequate visibility, model inputs that can be manipulated, and misleading outputs.

If agencies adopt AI without proper governance, they create new risks while trying to modernize. Securing AI has become as important as securing with AI.

DoD 8140: Turning mandates into readiness

Under DoD Manual 8140.03, every military, civilian, and contractor role performing cyber work in a covered position must be qualified against a specific DoD Cyber Workforce Framework (DCWF) work role—a mapped set of knowledge, skills, and abilities (KSAs) at a defined proficiency level.

The DCWF categorizes cyber work into seven workforce elements spanning 73 work roles, each with its own required KSAs. Personnel must reach foundational qualification within nine months of assignment and residential qualification within twelve, with continuous professional development required to stay qualified.

The critical shift in 8140 is the move from certified to qualified. Contract solicitations now reference DCWF work roles and proficiency tiers rather than legacy certification levels, and organizations must demonstrate documented learning pathways, assessed proficiency, and auditable workforce data. A one-time certification sprint doesn’t satisfy that. A durable, role-mapped upskilling capability does.

Build readiness with cross-skilling

Whether it’s pushing AI to production, handling AI security, or maintaining DoD 8140 compliance, one common theme emerges: There aren’t enough qualified people. (The Pentagon alone faces a shortage of roughly 20,000 cyber professionals).

External hiring alone can’t close a gap this large. And while some agencies are shifting to internal upskilling and cross-skilling to develop qualified talent from the workforce they already have, not enough are taking advantage of this opportunity yet.

But here’s the thing: upskilling and cross-skilling works.

According to GovCon, targeted upskilling in cloud security and AI defense has been shown to cut time-to-fill for cybersecurity roles by 40% while improving retention by 30% within a single year. It’s not a stopgap for the talent shortage—it’s the most durable answer to it.

It develops qualified cybersecurity professionals from the people agencies already have, moves faster than a hiring cycle, helps institutional knowledge, and improves retention by giving employees a path forward.

Perhaps most importantly, it improves your agency’s ability to address new developments like AI initiatives and DoD 8140 requirements. That’s the readiness layer: continuously updated, role-aligned upskilling that sits beneath every federal tech initiative and determines whether it actually reaches production.

It’s what turns AI pilots into deployed systems, threat intelligence into anticipatory defense, and 8140 mandates into mission capability. Tools and budgets are necessary, but they don’t act on their own. A qualified workforce is what converts investment into outcomes.

Build your agency’s tech readiness

Closing the readiness gap takes the ability to see where skills stand today, map them to the roles the mission requires, and build proficiency in a measurable way.

Pluralsight pairs curated learning paths across AI, cloud, and security with Skill IQ assessments and hands-on labs that develop and validate real capability, unlike static certifications. Our platform also gives leaders the analytics to track workforce readiness as skills and requirements evolve.

Whether your goal is DoD 8140 qualification (our partnership with Cyberstar brings the full readiness lifecycle into a single workflow) or cross-skilling your people ahead of the next wave of technology, Pluralsight can help you innovate faster while meeting regulatory demands.

The agencies that will lead aren’t the ones with the biggest AI budgets or the fastest modernization. They’re the ones building the readiness layer that makes all of it work.

Interested in how a readiness-first approach can accelerate your agency’s AI, cybersecurity, and 8140 goals? Explore Pluralsight’s public sector solutions.

The First Federal Guidance on AI Agents Is Here. Most Agencies Can’t Meet It Yet.

By: Larry Kovalsky, Director, Federal Solutions Engineering, Netskope

In May 2026, the Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA), together with Five Eyes partners, published the first guidance written specifically for agentic artificial intelligence (AI): Careful Adoption of Agentic AI Services. Its core instruction: before granting an AI agent access to data or systems, know exactly what that agent can reach, and revisit that inventory as its footprint changes. Agent permissions had mostly been governed by general zero trust principles applied after the fact. This guidance makes it explicit: knowing what an agent can reach is now a named federal security requirement, not an implied one.

Few agencies can currently produce that inventory on demand.

The stakes showed up months before the guidance did. In August 2025, attackers stole OAuth tokens belonging to Drift, an AI sales chat agent built by Salesloft and connected into customer Salesforce instances. Those tokens carried the same broad, rarely revisited access Drift used for its own workflows. The attackers used that access to exfiltrate data from more than 700 organizations, then mined it for further credentials. The Federal Bureau of Investigation (FBI) and CISA issued a joint advisory in September 2025. Nobody had to breach Drift itself. They only needed the access that already reached further than any single workflow required.

That kind of overreach has a name: authority drift. It is what happens when an AI agent’s permission footprint expands past what was originally approved, until no one can account for everything it can reach. It grows through inheritance, when an agent picks up the access of whatever system it connects to; through integration, when a developer connects it to a new tool that solves an immediate problem; and through convenience, since broad access is faster to configure than scoped access and nobody revisits it once the agent is working. No process evaluates the aggregate, which is why an agent’s footprint six months in can bear little resemblance to what was approved on day one.

The Blind Spot Behind Authority Drift

Part of why authority drift goes unnoticed is architectural. Continuous verification in zero trust deployments is tuned to reassess human signals: behavior, location, device posture, not what an autonomous agent does with access it already holds.  An AI agent authenticates once, then acts on its own for the rest of the session, calling Application Programming Interfaces (APIs) and invoking tools with credentials that stay valid throughout, without generating a signal built to trigger a re-check. The risk shows up mid-session, in agent actions those checks were never built to interpret. Prompt injection is the clearest version: an attacker embeds instructions in a document or email that an agent reads and treats as legitimate.

Model Context Protocol (MCP) compounds the blind spot: MCP traffic doesn’t resemble the traffic most inspection tools were built to see, so a malicious connection can move through unnoticed, and an agency that can’t see that traffic can’t map what an agent is actually reaching.

Why CISA and NSA Felt the Need to Say This Now

The new guidance did not emerge in a vacuum. In November 2025, Anthropic disclosed that a Chinese state-sponsored group it designated GTG-1002 had used an AI coding agent to run a largely autonomous cyberespionage campaign against roughly 30 government and industry targets. The agent executed most of the operation on its own, with humans stepping in only at a handful of decision points, and lateral movement that would normally take a skilled attacker days happened in a fraction of that time, because the agent was already authorized to reach most of what it needed: an agent with more reach than its task required, the exact condition the new guidance is aimed at closing.

The Data Shows Agencies Aren’t There Yet

A May 2026 survey of 275 federal civilian and defense IT and security leaders, conducted by Market Connections and sponsored by Netskope, found that only 11 percent of agencies report AI fully integrated into their zero trust architecture, and just 24 percent report high or complete visibility into API-driven AI interactions, the channel through which agents act autonomously. Yet 78 percent agree that AI agents and tools should be treated as managed entities within a zero trust environment, not exceptions to it. That disconnect between near-consensus and 24 percent visibility is what the CISA/NSA guidance is now asking agencies to close, and what EO 14028 and OMB M-22-09 already require in principle: continuous verification before granting access, not a one-time approval that persists indefinitely.

Closing the Gap Takes More Than a Better Spreadsheet

A static inventory taken at deployment tells an agency almost nothing about an agent’s risk three months later. Meeting the new guidance takes three things working together:

  1. A current, continuously updated map of what each agent can actually reach, not what it was provisioned to reach at launch.
  2. Agents restricted to a fixed, defined set of tools and data sources rather than broad standing access, what OWASP calls least agency.
  3. An enforcement point that can scope access down without waiting for the next scheduled review cycle.

Skip enforcement and the first two just produce a report nobody can act on in time. Skip mapping and the rest is guesswork. Mapping also has to stay selective, or alert fatigue will undo it within a quarter.

Overexposed access like this usually surfaces because an attacker finds it first, not because a process was built to catch it in advance. Agencies now have federal guidance telling them to ask what their agents can reach before the next incident forces the question. Whether they can currently answer it is another matter.

Agentic AI Raises the Stakes for Federal Identity Governance

By: Nick Apostolu, Manager, Product Marketing, Industries, Okta

Federal agencies already struggle to govern identities distributed across cloud platforms, legacy systems, contractors, and mission partners. The rise of agentic artificial intelligence (AI) is making that problem more urgent by introducing autonomous software that can retrieve data, call application programming interfaces, and take actions on behalf of users – often with limited human supervision.

These agents can automate complex workflows and support faster service delivery. But they add a new category of identity to environments where agencies may already lack a complete view of who or what can access sensitive information.

The National Institute of Standards and Technology’s National Cybersecurity Center of Excellence (NCCoE) is examining how existing identity standards and practices can be applied to software and AI agents. Early this year, the center published a draft concept paper on software and AI agent identity and authorization.

The potential NCCoE project would explore standards-based methods to identify agents, manage their permissions, authorize their actions, and connect those actions to an accountable person or organization. Although the work is in its early stages, it reflects growing federal recognition that autonomous software cannot be governed as an invisible extension of a human user.

Unlike a conventional application or service account, an AI agent may independently choose among tools, retrieve records, generate content, deploy code, or initiate transactions. If an agency cannot identify the agent, determine who owns it, understand its delegated authority, or see which data it can reach, the agent becomes another poorly governed privileged identity.

The Cybersecurity and Infrastructure Security Agency and international partners highlighted the governance risks associated with agentic AI on May 1 with guidance on its careful adoption. The guidance warns that agentic AI can create expanded attack surfaces, privilege creep, behavioral risks, and gaps in activity records. It recommends beginning with controlled deployments, limiting access to sensitive resources, and bringing agents under existing cybersecurity and risk management processes.

Agentic AI can amplify identity sprawl

For agencies, agentic AI is not a separate security problem. It exposes and intensifies weaknesses in existing identity governance.

Human and non-human identities are already scattered across directories, cloud platforms, privileged-access systems, application-specific accounts, and on-premises infrastructure. That fragmentation – often described as identity sprawl – can leave security teams with an incomplete view of access privileges, ownership, and emerging threats.

Separate identity systems can also produce inconsistent policies and records. Security teams may need to correlate logs from multiple environments before determining whether an account has been compromised, retained access after a personnel change, or accumulated privileges that are no longer necessary.

From our work with public-sector organizations at Okta, we see the identity challenge becoming more difficult as agencies add cloud services, automated workloads, and AI-enabled tools. Federal agencies cannot effectively manage access risk when they cannot consistently identify, govern, and monitor the entities operating across their environments.

The problem extends beyond authentication. Agencies must manage the full identity lifecycle, including provisioning access, monitoring behavior, modifying permissions, reviewing entitlements, and promptly removing access when an employee, contractor, application, service account, or agent no longer needs it.

Federal zero trust and digital identity policies already establish identity as a core security control. Critically, it must be continuously managed. If it is not, an agency may strongly authenticate a user while continuing to grant access through obsolete group memberships, duplicate accounts, or permissions retained after a job change. The same problem can apply to an AI agent whose initial access was approved but whose role, integrations, or capabilities have since expanded.

Reducing identity sprawl requires agencies to maintain an authoritative record for every user, device, workload, service account, and AI agent, with a defined owner, purpose, privilege level, and review or expiration point. Provisioning and deprovisioning should be automated where possible, and access policies should apply consistently across cloud and on-premises environments.

AI agents add several specific requirements. Agencies need to define which systems and datasets each agent may access, whether the agent can delegate authority, which actions require human approval, and how the agent’s activity will be logged and reviewed.

Privileges should be narrowly scoped and reassessed whenever an agent’s mission, model, tools, or integrations change. An agent should not inherit a human user’s full range of permissions simply because it performs a task on that person’s behalf.

Agencies also need sufficient records to reconstruct an agent’s actions after a security incident or unexpected result. Those records should show which identity initiated the activity, what authority was delegated, which systems were accessed, and whether the agent remained within its approved boundaries.

The practical test is whether an agency can quickly determine what an entity is, who is responsible for it, which resources it can reach, why that access exists, what actions it has taken, and how its access can be suspended.

As federal systems become more autonomous, the ability to answer those questions will determine whether agencies can adopt new capabilities without creating unmanaged risk faster than their teams can address it.

To learn more about overcoming identity sprawl, read Okta’s e-book.

The White House Elevated the Push for Cybersecurity. Now the Hard Work Begins.

By: Tom Guarente, Vice President, External & Government Affairs, Armis by ServiceNow

The White House recently issued a directive designated as National Security Presidential Memorandum 12 (NSPM-12), which includes helpful provisions to elevate cybersecurity protection across the federal government. The directive signals a seriousness about cybersecurity from the highest levels of the federal government, but agencies’ implementations of this guidance will ultimately determine its success.

NSPM-12 can help to focus agency attention on the dire need for protections in the age of agentic AI. It offers new, actionable and outcome-based models to encourage agency commitments to make necessary cybersecurity protection actions a reality. The language seems to support putting wood behind the arrow to ensure agency leaders are taking these cybersecurity responsibilities seriously.

For example, it elevates the federal government cybersecurity discussion by outlining responsibility for security assessments and recommendations across the government as part of the authority of the National Manager of the National Security Systems (NSS), operating under the Director of the National Security Agency (NSA). This directive will light a fire under agencies that are currently not conducting effective assessments. Organizations are assessing the utility of their own cybersecurity frameworks based on checklists they have created themselves. Having a third party do that may be more effective.

But it begs the question: who has assessment responsibility today? And what criteria for assessment are they using? If we give another authority responsibility to assess agencies, we have to make sure it doesn’t conflict with assessments conducted by other arms of the federal government that believe they have that authority and responsibility. Redundancy inhibits the creation of a resilient and responsive security model.

NSPM-12 also states that “each agency shall maintain and annually update an inventory of all NSS owned or operated by that agency.” As agencies implement this, they must address the lack of consistency and visibility in environments, along with the patchwork of protections, as a foundational element in the drive for consistency in the approach.

To its credit, the directive calls for greater consistency and uniformity of cyber standards across both civilian and defense organizations. It points out that defense organizations are doing many things better than civilian agencies as far as cybersecurity and encourages civilian agencies to follow the Pentagon’s example and embrace those same protections. This call for consistency across the federal government is extremely important.

Perhaps most importantly, the directive raises the level of attention and importance of cybersecurity. Cybersecurity should be viewed in the same realm as national security and our national defense. Government organizations, Congress and the U.S. population at large must understand that a cyberattack against our critical infrastructure can have just as devastating an effect on the country as a military attack. We must treat cyber threats as the national security threats they are.

Given the stakes and possibility of severe national emergencies resulting from a cyberattack, federal government policymakers and legislators must take immediate action. To date, we’ve heard a lot of discussion, but we’ve been short on tangible action by Congress and federal leaders. If we don’t get on top of safeguarding environments now, it will be too late. We have to stop talking about the threat of AI and put resources behind defending against attacks and developing a proactive defense. This directive can help to instill that mindset across agencies.

This isn’t a technology issue; it’s a national security issue with existential stakes at risk. Therefore, it is imperative that Congress and the White House act immediately. Funding and resources will be an essential component to determine whether the objectives of the directive succeed. Congressional appropriators should not fund agencies that are not compliant with cybersecurity requirements. If Congress threatens to hold back funding, you can bet agencies will take immediate steps toward compliance.

At the end of the day, NSPM-12 is about two things: the funding to support cybersecurity protections and how we measure those outcomes. The challenge now is how to make these commitments of support actionable to protect our country’s safety and security.

The Failure of the Joint Force’s Roles and Responsibilities in Missile Defense

From February to May 2026, Iran launched a sustained campaign of ballistic missiles, cruise missiles, and drones against U.S. forces across the Middle East. Iranian strikes hit 20 American forward operating bases and facilities in eight countries. They killed seven U.S. service members, wounded hundreds more, and destroyed at least 15 aircraft and multiple high-value missile defense radars. Pentagon officials estimate the damage at nearly $30 billion; internal assessments place the cost closer to $50 billion.

Even those numbers fail to capture the real loss.

The United States did not just lose equipment. It lost decades of forward military posture—airfields, logistics hubs, command nodes, and diplomatic access built over generations. When a base loses mission capability, the United States writes off every dollar invested in it, every year of labor, and every host-nation agreement that sustained it. Forward power projection depends on forward bases remaining operational. When those bases fail, deterrence fails with them.

Iran did not surprise the United States. Nor did Tehran defeat American forces through superior technology or resources. Instead, Iran exploited a structural failure inside the U.S. Joint Force—one senior leaders have documented, debated, and ignored for decades.

The United States did not lose these bases because Iran proved stronger. It lost them because capabilities and functions for defending them are fragmented between different owners.

Department of Defense policy assigns ground-based air and missile defense to the U.S. Army, a division of labor dating back to the Key West Agreement of 1948. At the same time, the U.S. Air Force Air Component Commander owns area air defense of bases themselves: the aircraft, personnel, fuel, equipment, and command infrastructure that make forward operations possible. This split creates a fatal incentive mismatch. The Army controls the defense mission but bears no operational consequence when an air base falls. The Air Force absorbs the losses but holds no authority over all capabilities and functions defending of its own bases.

That misalignment is not theoretical. In 2004 and 2005, the Army withdrew from its obligation to defend air bases under an existing joint service agreement, citing resource constraints. The Department of Defense took no corrective action. No one restored accountability. The Joint Force postponed the reckoning until 2026—when Iran collected the debt in full.

During the campaign, this failure played out in real time. Missile defense systems existed, but commanders failed to integrate them with air base operations. Passive defenses and active interceptors were not integrated. Radar coverage focused on high-altitude ballistic threats while low-altitude cruise missiles, drones, and even manned aircraft exploited the gaps. In one striking case, an Iranian fighter aircraft designed in the 1960s flew below radar coverage and bombed a U.S. base. That was not a fluke. It was the predictable outcome of doctrine that concentrated exquisite defenses on narrow threat sets while leaving cheaper, lower-altitude avenues exposed.

Iran also attacked the missile defense architecture itself. Iranian planners struck high-value radar systems early, blinding interceptors before they could engage. U.S. forces failed to relocate those sensors, failed to harden them adequately, and treated fixed emplacements as permanent rather than vulnerable. Years of combat observation from Ukraine had already exposed these vulnerabilities. U.S. forces ignored those lessons.

Worse still, the missile defense enterprise failed to learn during the fight. The system collected enormous amounts of real-world combat data but did not convert it into improved defensive performance. A defense enterprise that cannot adapt under fire does not defend anything. It simply absorbs punishment while waiting for the next strike. Doctrine did not cause this failure. On paper, roles and responsibilities remain clear.

Joint Force Commanders assign Air Component Commanders to plan and execute integrated air and missile defense. Army missile defense commands embed with Air Operations Centers to synchronize defenses. The Joint Force understands these relationships. What it lacks is an enforcement mechanism that compels institutions to execute the responsibilities they already claim.

Deterrence through strength requires more than capability. It requires accountability. When forward bases fall, deterrence collapses. When responsibility diffuses across bureaucratic seams, failure becomes inevitable.

The lesson of 2026 does not demand more interceptors or radars—though the force needs both. It demands structural reform. The Department of Defense must align authority, responsibility, capability, and consequence. Services must answer for the missions they own. Combatant commanders must possess enforceable control over integrated base defense. Missile defense cannot remain a bureaucratic orphan divided among institutions that do not share risk.

America’s adversaries have already mapped these seams. Iran exploited them deliberately and effectively. If the United States refuses to fix them now, the next conflict will not serve as a warning. It will establish a new playbook.

Access the full whitepaper here – https://www.missiledefenseadvocacy.org/alerts/mdaa-alert-the-failure-of-the-joint-forces-roles-and-responsibilities-in-missile-defense/

About the writer:

Mr. Riki Ellison is the Founder and Chairman of the Missile Defense Advocacy Alliance, a non-profit organization launched in 2002 with a singular purpose and mission to drive for the deployment, development, and evolution of missile defense. Since its founding, the organization has emerged as the expert voice on missile defense in the world.

Ellison has been in attendance of over 307 missile defense tests, 821 U.S. and Allied base visits, and has advocated for missile defense in all 50 states and 34 countries.

Building Cybersecurity into the Foundation of AI Export Controls

By: Darren Guccione, CEO and Co-Founder, Keeper Security 

As the federal government tightens controls on advanced semiconductors and AI-enabled technologies, export policy is evolving from a trade mechanism into a technology security framework – one that must incorporate cybersecurity and identity assurance by design.

Without technically enforceable cybersecurity requirements, restricted AI hardware remains vulnerable to diversion through credential compromise, insider misuse or unauthorized administrative access, even when physical transfer restrictions are in place.

Export compliance must extend beyond where hardware is shipped to include how access is authenticated, authorized, monitored and logged throughout its licensed lifecycle – including installation, configuration, maintenance, remote administration and decommissioning.

Cybersecurity as a National Security Control Mechanism

The evolving AI export regime seeks to protect U.S. technological leadership by ensuring that advanced chips and compute resources cannot be diverted to adversarial use. True security requires that export controls be enforced through continuous identity verification, privileged access controls and real-time monitoring. This ensures restricted AI technologies cannot be accessed, operated or administered outside approved conditions. Identity governance, zero-trust architectures and continuous verification make export restrictions technically enforceable, not just legally binding.

Export enforcement touches every entity with operational control over covered hardware, including manufacturers, exporters, integrators, cloud operators, data center administrators, maintenance providers and any remote management personnel interacting with licensed systems.

From an enforcement perspective, organizations must demonstrate who has access to restricted hardware, what privileges they hold, where they are connecting from and whether those actions align with approved license conditions.

Defining “Trust” in a Technology Supply Chain

In today’s landscape, organizations must demonstrate trust through continuously enforced identity, access and encryption controls that withstand audit and regulatory scrutiny. Objective verification frameworks such as FedRAMP, NIST AI RMF, FIPS 140-3 validated encryption, ISO 27001, 27017 and 27018, and SOC 2 Type 2 compliance provide measurable proof of security.

Trust, in the export context, means producing verifiable evidence of compliance, not merely attesting to intent.

Integrating Encryption Resilience and Future-Proofing Integrating Encryption Resilience and Future-Proofing

As AI technologies and data exchanges become targets of geopolitical competition, encryption must evolve alongside regulation. Quantum Resistant Cryptography (QRC) provides long-term protection against emerging threats and is essential for federal agencies finalizing their post-quantum strategies. Once operational at scale, quantum computers will render current public-key cryptography obsolete. The risk is already present through “harvest now, decrypt later” attacks, in which adversaries capture encrypted data today to decrypt them once quantum technology matures.

Encouraging adoption of QRC within trusted entities helps protect sensitive export data over the long term and aligns export control with federal post-quantum security strategies.

Operationalizing Oversight Through Verification and Research

Export oversight should include continuous operational verification, not just transactional license approval. 

Effective export compliance programs should incorporate:

  • Annual audits and attestations verifying cybersecurity compliance
  • Independent validation of zero-trust, PAM and encryption standard implementations
  • Retention of access logs and session records for regulatory review

Recent global research shows that organizations adopting PAM and zero-trust models achieve measurable security outcomes. More than 53% report improved protection of sensitive data and 47% report strengthened compliance postures. These outcomes demonstrate that modern PAM doesn’t just mitigate risk – it improves operational efficiency and supports compliance objectives.

This evidence-based model can guide policymakers in codifying cybersecurity maturity as a precondition for technology export eligibility.

Strengthening AI Leadership Through Secure Exports

When export rules are reinforced by continuous identity verification, privileged access controls and encryption resilience, compliance becomes measurable and enforceable – not declarative. Without enforceable identity, access and encryption controls, export restrictions risk failing in practice, creating opportunities for credential compromise, unauthorized access and misuse of licensed systems.

This approach safeguards U.S. technological competitiveness, fortifies allied cooperation and ensures that “trusted” truly means secure in the era of AI-driven global competition.

The Importance of FedRAMP for a FITARA 2.0

By: David Epperson, Knox Systems Federal Advisory Board Member
Former Deputy CIO of the Executive Office of the President

First CIO & CISO of CISA

A new iteration of the Federal Information Technology Acquisition Reform Act, or FITARA 2.0, will be coming because the federal IT mission demands it. First passed in 2014, FITARA was designed to improve how federal agencies buy, manage and govern information technology. Over time, the FITARA Scorecard has become Congress’s primary oversight tool for assessing agency performance across IT management, modernization and cybersecurity. While the scorecard has evolved over the past decade, a more substantial refresh is needed to keep pace with cloud adoption, cybersecurity risk and the rise of artificial intelligence.

One of the most important reasons to pass FITARA 2.0 is to update the criteria the scorecard assesses so they are less subjective and more tangibly measurable. While its domains incorporate cost, schedule, performance and cybersecurity data, some areas still depend too heavily on process maturity and subjective risk characterization. In an era of escalating cyber threats and rapidly emerging AI systems, that is no longer sufficient.

Historically, scorecard methodologies and authorization processes have often emphasized documentation, procedure maturity and reported compliance status more than continuous, objective measurement of whether risk is actually being reduced. That gap matters. The next generation of oversight should move beyond subjective risk characterization and toward evidence-based validation, measurable control performance and continuous monitoring. This is especially important with emergent artificial intelligence technologies that lack deterministic reliability.

A Critical New Domain

Growing federal adoption of AI obliges its inclusion in any updated FITARA scorecard. Among other criteria, the scorecard will need to measure attributes such as AI accuracy, robustness, level of drift and level of bias. It will also need metrics for explainability of results, which, although harder to define, is essential for enabling confidence in an AI system’s output. That is especially relevant for agentic AI, as the government looks to adopt it for tasks traditionally performed by entry-level personnel in the name of cost reduction and mission acceleration.

A successful model for government purposes will be based on the use case to which it is applied. For example, the Federal Emergency Management Agency might value lack of bias higher than raw accuracy to help ensure emergency supplies are not distributed inequitably during a crisis. Given the nature of AI models, prioritizing bias reduction may create some minimal tradeoff with other criteria, such as accuracy. Alternatively, the Department of War would undoubtedly prioritize high accuracy to ensure any intended military targets are absolutely correct.

Whatever the use case, engendering agency trust in a model will require objective third-party validation by a new group of qualified validating organizations, likely outside of government. Because those organizations may touch highly sensitive data, the tools they use will need to meet rigorous federal cloud security requirements, often including FedRAMP Moderate or High authorization or certification, depending on the sensitivity of the data and mission. Without FedRAMP authorization or certification at the appropriate impact level, a validating entity will struggle to gain the confidence and trust of model developers or their agency customers.

Accelerating Delivery While Ensuring Security

The prospect of pursuing FedRAMP authorization can be intimidating. Since its inception, achieving authorization has often involved an expensive and lengthy process. While very large companies can sustain the effort, smaller companies often find the financial burden and years-long timeframe prohibitive. Because many authorization paths have required agency sponsorship and an associated level of effort, agency investment has also been required. For example, dedicating headcount previously designated for different projects, or contracting for outside help, can quickly cost an agency hundreds of thousands of unbudgeted dollars and lost bandwidth.

New mechanisms are becoming available to help address these challenges. Last year, GSA’s FedRAMP office introduced FedRAMP 20x, a cloud-native, automation-focused approach that uses Key Security Indicators and machine-readable evidence to accelerate authorization. The initial phase focused on Low authorizations and did not require an agency sponsor, with later phases intended to expand the model. While FedRAMP 20x is a valuable modernization path, questions remain about how consistently KSI evidence will be generated, validated and compared across providers as the model scales beyond the initial pilot phases.

An alternative is the landing zone model, a commercial platform-as-a-service where SaaS providers can deploy their applications into a pre-FedRAMP authorized cloud boundary, inheriting existing, approved security controls and authority to operate instead of having to recreate them. Integrated automation enables continuous environmental monitoring and validation to sustain compliance. This model enables both speed to mission for federal agencies and speed to market for SaaS providers, removing the sponsorship requirement while ensuring the highest levels of security. It is a cost-effective, highly streamlined option that can save providers years of time and millions of dollars.

Landing zones will not only quickly increase the number of secure SaaS applications available for mission support, they will also ensure that organizations validating FITARA 2.0 compliance have innovative, reliable and trustworthy tools to do so. In an environment where modernization and speed are imperative, this innovative approach will advance both without compromising security.

Eliminating Silos in IT/OT Cybersecurity Is a Funding Challenge, Not a Technical One

By: Tom Guarente, vice president of external and government affairs, Armis

In light of ever-increasing cyber threats from nation-state adversaries, including major spying campaigns like Salt Typhoon, the need for strong cybersecurity protection has never been more urgent. Given the reported deployment of offensive cyber measures in U.S. military operations, we should expect adversaries to counter with their own deployments.

Noting that the recently released White House “Cyber Strategy for America” appropriately focuses on securing critical infrastructure, our current reality of converged technologies necessitates a more holistic and proactive security model. While this has been an elusive goal because the federal government often lacks the mechanisms needed to fund and deploy effective security tools across both IT and operational technology (OT), the strategy appears to take a much-needed approach. While the government has traditionally focused most of its cyber operations on IT, it has begun to recognize the need to address OT, which has not been nearly as well protected.

Agencies are often stymied in their attempts to broadly apply cybersecurity across both IT and OT due to funding silos and other bureaucratic hurdles. Organizational silos often prevent government security leaders from acquiring the same cybersecurity tools as Fortune 500 enterprises. Not only are agencies siloed from one another, but organizations that manage their own cyber initiatives often find it difficult to share lessons with peers in other branches of the same department.

For example, we have seen one organization with a very mature Facilities Related Control System (an OT system used for building management, controlling electricity operations, etc.) that had been broken in half and organized by geography, each part with its own funding lines, initiatives, contract vehicles and products. This somewhat random division has made it difficult for leadership to apply the necessary tools and controls across the organization to protect systems and users from cyber threats.

Within organizations, divisions also exist between components responsible for IT (often the CIO’s team) and those responsible for OT (often the CSO’s team). These silos prevent organizations from procuring common tools for cybersecurity protection across the entire enterprise. Even when the need for such tools has been identified, organizations often cannot identify the funding mechanisms to justify a procurement. OT is segregated from the IT side with different funding lines, preventing buyers with access to IT-related funding from using it to buy an OT security tool – at least not without navigating a drastic amount of red tape to get that procurement across the finish line. And if they do, purchasing multiple point solutions introduces more complexity into an environment.

Policy decrees and executive orders mandating OT security improvements are essential catalysts, yet they frequently falter at the implementation level due to an “unfunded mandate” gap. While higher-level directives establish necessary requirements, they rarely provide the financial or structural frameworks required by lower-level offices to execute them. To be effective, these orders must evolve beyond compliance checklists to include comprehensive frameworks for longevity and continuity. This requires a dual-track funding model that covers initial capital for acquisition as well as dedicated, multi-year budgetary support for operational and expert staffing.

To bolster at-scale deployment, the plan should also include support structures, such as mobile “tiger teams” or shared-service models that provide specialized technical expertise to under-resourced offices, ensuring that OT security solutions are not only deployed but sustained throughout their lifecycle.

Bridging the gap between policy and protection means that agencies need to establish a standardized baseline for assessing converged technologies well before deployment. However, these baseline requirements will remain toothless without a radical overhaul of the procurement and authorization pipeline. Currently, processes like FedRAMP and DoD-specific cybersecurity authorizations are often opaque and sluggish, offering little transparency into optimization or timelines.

This state of gridlock suggests that these authorization bodies are understaffed and under-resourced – themselves victims of the broader funding crisis, rendering high-level security talking points irrelevant if the administrative machinery cannot process the solutions at the speed of the threat. If these authorizations are to remain a mandatory prerequisite, the FedRAMP process should adopt a model defined by clear milestones and predictable iterative outputs.

To secure critical infrastructure at scale, agency leaders must transition from ad-hoc procurement to programmatic, congressionally-funded initiatives. An effective catalyst for modernization could be the establishment of new enterprise-wide contract vehicles similar to the Global Enterprise Modernization Software and Support (GEMSS) contract, awarded in 2022. That contract gave a broad range of military organizations unlimited access to software licenses, technical support and network modernization services. By pre-negotiating pricing and centralizing funding at the department level, these types of agreements can lower the barrier to entry for individual agencies and offices.

When solution sets are structured, priced and funded for “too good to miss” enterprise adoption, they give mission owners the leverage they need to bypass traditional silos. Ultimately, these large-scale programs do more than cut costs. They promote a standardized security posture that becomes an indispensable utility, ensuring that OT defense is treated as a permanent capability.

Talking points are not enough. Agency leaders have to put money behind what they say their priorities are and increase efficiencies in delivering on those priorities when it comes to securing both IT and OT environments. We should all work together to operationalize the Cyber Strategy for America and create a new approach to protecting our nation.

The FedRAMP High Supply Crisis Is a Federal Security Problem – Not a Procurement Footnote

Federal agencies spent $11 billion on cloud services in 2024. Roughly 40 percent of that spending supported high-impact systems, platforms carrying national security operations, law enforcement coordination, emergency services, healthcare records, and financial infrastructure. The data on those systems cannot tolerate compromise. And yet the cloud market built to protect it is dangerously thin.

As of early 2025, the FedRAMP Marketplace listed approximately 80 cloud service offerings at the High impact level. Only 48 held full authorization. That gap between what agencies need and what the market can actually deliver at the required security tier is not an abstract compliance concern. It is a procurement bottleneck that is forcing real tradeoffs with the federal government’s most sensitive data.

What FedRAMP High Actually Requires

The FedRAMP program classifies cloud services at three impact levels: Low, Moderate, and High, based on the potential consequences of a security breach. FedRAMP High authorization requires 421 security controls drawn from NIST SP 800-53 Rev 5, nearly 30 percent more than the 325 controls at the Moderate baseline. Those additional controls are not bureaucratic overhead. They address advanced encryption requirements, physical access restrictions, enhanced personnel security vetting, and continuous monitoring capabilities calibrated for sophisticated adversaries.

The gap between Moderate and High is not a paperwork gap. It reflects a fundamentally different threat model, one designed for data that, if compromised, could endanger lives, disrupt national security operations, or undermine critical infrastructure.

Because High-authorized options don’t exist across many use cases, agencies often default to general-purpose productivity tools operating at the Moderate tier. That workaround may solve a procurement problem. It creates a security one.

The Threat Environment Agencies Are Actually Operating In

The argument for FedRAMP High-level security is no longer theoretical. The threat data from the past year makes the case in operational terms.

The CrowdStrike 2026 Global Threat Report documented an 89 percent increase in AI-enabled adversary attacks year-over-year, with the average eCrime breakout time dropping to just 29 minutes. Cloud-conscious intrusions rose 37 percent. Perhaps most concerning, 82 percent of all detections were malware-free, meaning traditional signature-based defenses are insufficient against the methods adversaries are now using routinely. State-nexus actors, particularly China-aligned groups, increased targeting of edge devices by 38 percent, using valid credentials and native tools to blend into normal operations while moving laterally toward sensitive data.

For agencies operating at the High impact level, these are adversaries specifically targeting the types of data that FedRAMP High was designed to protect. The 2026 World Economic Forum Global Cybersecurity Outlook reinforces the picture: 65 percent of large organizations now identify third-party and supply chain vulnerabilities as their greatest barrier to cyber resilience, up from 54 percent the prior year. When agencies exchange sensitive data across fragmented platforms operating at different authorization levels, every seam between those systems becomes an attack surface.

General-purpose cloud tools authorized at the Moderate tier were not designed for this threat environment. Deploying them for high-impact workloads is a structural mismatch that no configuration policy can fully close.

The CMMC Dimension: A Defense Industrial Base in Distress

FedRAMP High’s significance extends well beyond federal agencies. For the defense industrial base, the authorization gap creates a compounding compliance crisis.

CMMC Level 2 requires defense contractors to demonstrate 110 security practices derived from NIST SP 800-171. FedRAMP High’s 421 controls map directly to those requirements, and when a vendor achieves FedRAMP High authorization, its customers inherit those validated controls rather than building and validating each one independently. That inheritance can compress CMMC compliance timelines by 50 percent or more. Given the state of DIB readiness, that compression is urgently needed.

A survey of 209 defense industrial base organizations found that only 46 percent consider themselves prepared for CMMC Level 2 certification. Fifty-seven percent have not completed a NIST 800-171 gap analysis. Sixty-two percent lack adequate governance controls. The CyberSheath 2025 State of the DIB report puts the broader picture in even starker terms: only 1 percent of defense contractors feel fully prepared for CMMC audits, down from 4 percent the previous year. The median SPRS score across the DIB sits at 60, a full 50 points below the required threshold of 110.

Critical controls remain widely undeployed. Seventy-nine percent of DIB organizations lack vulnerability management capabilities. Seventy-eight percent lack patch management. Seventy-four percent lack data loss prevention. Seventy-three percent have not implemented multi-factor authentication. These are not edge cases; they are the majority of organizations now operating under CMMC requirements embedded in active defense contracts.

FedRAMP High control inheritance does not solve every problem in this picture. But it changes the compliance calculus fundamentally, converting a multi-year infrastructure build into an architecture decision.

The Multi-Framework Compliance Argument

Federal agencies and defense contractors in 2026 are not confronting a single regulatory obligation. They are managing simultaneous compliance deadlines across CMMC 2.0 for defense contracts, HIPAA for healthcare data, PCI DSS 4.0 for payment processing, and ISO 27001 as a global baseline, among others. Addressing each framework independently multiplies cost, timeline, and implementation risk.

At the control level, the overlap is substantial. An encryption architecture validated for FedRAMP High simultaneously satisfies CMMC encryption practices, HIPAA’s technical safeguards, PCI DSS cryptographic requirements, and ISO 27001 Annex A controls. A platform that unifies these controls under a single architecture eliminates the redundancy inherent in framework-by-framework compliance programs. Survey data supports the operational difference this makes: organizations with completed gap analyses follow documented encryption standards at nearly twice the rate of those without, 77 percent versus 42 percent.

According to a 2025 data workflows survey, 75 percent of government respondents require FedRAMP for their data exchanges, and 69 percent use FIPS 140-3 validated cryptographic modules. When a single platform’s control inheritance satisfies requirements across multiple frameworks simultaneously, multi-framework compliance shifts from a program management problem to an architecture decision.

The FedRAMP 20x Factor: Why Waiting Is a Strategy With Real Costs

The FedRAMP program is undergoing significant modernization through the FedRAMP 20x initiative, and the timeline has direct implications for agencies and contractors making cloud security decisions today.

Phase 1 completed with a Low baseline pilot demonstrating authorization in under two months. Phase 2, active through Q1 2026, involves a Moderate pilot with 13 participants. Wide-scale adoption for Low and Moderate authorizations is expected in Phase 3, targeting Q3 through Q4 2026. But the FedRAMP 20x High baseline pilot is not expected until Q1 through Q2 2027, with the legacy Rev 5 authorization pathway expected to sunset in Q3 through Q4 2027.

Organizations that delay action are not waiting for a better option. They are accepting a multi-year gap in high-security cloud capabilities during the period when adversary activity is accelerating most rapidly.

What Agencies and Contractors Should Do Now

Audit your FedRAMP authorization landscape. Identify which cloud services your agency or organization relies on, at which impact levels they are authorized, and where mission-critical data flows through platforms operating below the High threshold. If your most sensitive data exchange is running through Moderate-authorized tools, you have a structural architecture gap, not a configuration problem.

Map framework overlaps before building framework-specific programs. Organizations pursuing CMMC, HIPAA, PCI DSS, and ISO 27001 simultaneously should identify control overlaps early and invest in platforms that satisfy multiple frameworks from a single implementation.

Evaluate FedRAMP High In Process providers now. The FedRAMP authorization journey moves through Ready, In Process, and Authorized stages. “In Process” is not a planning status. It signals that controls have been implemented, independently assessed by a certified third-party assessment organization, and are under active federal review. Agencies and contractors that engage providers during the In Process stage gain architecture lead time. Waiting for the Authorized designation means competing for capacity alongside every organization that also waited.

Consolidate data exchange channels under unified governance. With 82 percent of detections now malware-free, attackers are exploiting gaps between systems rather than targeting individual platforms. Every separate tool for email, file sharing, SFTP, and managed file transfer is a seam in your security architecture. Unified governance under a single policy engine and audit log is not an administrative preference; it is an operational security requirement.

The compliance clock is not slowing down. CMMC requirements are embedded in contracts now. DORA enforcement began in January 2025. HIPAA penalties exceed $100 million annually. The federal agencies and defense contractors that act on FedRAMP High inheritance today will be the ones positioned to compete, win contracts, and demonstrate the security posture their missions and regulators demand. The others will still be building.

Danielle Barbour is Senior Director of Product Marketing, Compliance at Kiteworks. She brings experience across medtech, insurance, and software industries and holds an MBA from Saint Mary’s College of California.

How More Tightly Focused Software Development Initiatives Will Unlock Innovation Across Government

By: Roman Chanclor, Aerospace & Defense Lead, Mendix, a Siemens company

The Department of Defense has been quick to embrace the potential of artificial intelligence (AI) as a tool to help with software development across its mission areas, but hurdles – many related to acquisition – prevent the department from achieving the full benefits promised by new technology. The Pentagon stands on the cusp of a revolutionary wave of technology that may bring with it previously unmatched capabilities if its leadership embraces the culture shift necessary to make that happen.

Traditionally, the Pentagon and federal government in general lacked the skills to successfully deploy these capabilities. This is not a reflection on the people who develop code for the government but more about the way the government undertakes software development projects. It tends to focus attention on building out large-scale software modernization initiatives focused specifically on broadly deployed applications. Often, they need every developer in the organization focused on this instead of on more innovative software development efforts.

Consequently, developers in government cultivate skill sets focused on specific applications which aren’t transferable to others. This creates brain drain issues in which developers get bored of working on the same types of systems and end up leaving the government.

Government budgetary cycles and “low cost, technically acceptable” procurement strategies exacerbate this because they provide no incentive for innovation. As budgets zero out at the end of every year regardless of whether agencies implement savings or not, agency leaders have no incentive to improve efficiency. This leads them to continue with business as usual at the expense of innovation.

Low-code platforms can boost innovation that gets put on hold when large-scale software projects take precedence over smaller-scale advances. These platforms can span across multiple systems of record, delivering a true composable development environment and a low-cost way to tackle backlogs of applications.

Agencies can start with a very small application that’s able to deliver value within the first six weeks of deployment. Starting with smaller projects allows governments to test ideas, gather feedback and iterate without committing massive resources upfront. This contrasts with traditional “waterfall” methods that often lead to delays and failures. It also increases speed and agility by shrinking development timelines from months to weeks or days by enabling rapid prototyping and deployment. For instance, agencies can begin with simple workflows or apps for specific pain points, like digitizing forms or automating approvals, and expand based on success.

In addition, this approach creates cost efficiencies and reduces backlog, because smaller development efforts translate into targeted investments, avoiding the high failure rates of monolithic projects. It also empowers non-technical staff by democratizing development, allowing business users and domain experts to create solutions without relying solely on IT teams. This fosters collaboration, innovation and a broader talent pool.

Consequently, agencies can build up the skill sets they need, so developers can subsequently become teachers inside of their own agencies and share those skill sets as they grow the user community. Then, after an agency scales up, the integration capabilities become reusable. As new use cases come up, they can easily be integrated into the platform.

Pentagon acquisition reform provides a step in the right direction. The department’s new acquisition strategy looks to the private sector to build more capabilities and offer platforms and solutions based on software-as-a-service (SaaS) and platform-as-a-service (PaaS) to the government while holding vendors accountable with things like outcome-based contracting. A good example of this is the Space Force’s Front Door website, in which vendors and others can contribute ideas to benefit the service.

The department should forego “lowest cost technically acceptable” procurements, which often fail to deliver value. If you want a Ferrari, you’re going to have to pay the bill for a Ferrari. The department also should augment the old guard from the procurement world with younger professionals who may be likely to bring new approaches to acquisition challenges.

The revolutionary advances promised by AI and low-code development technologies offer countless opportunities for innovation at the Department of Defense/War. Although various components within the department have already begun taking advantage of these opportunities, a culture shift regarding acquisition and deployment of technology is needed before this can happen on a broader scale. Embracing acquisition reform and low-code solutions can unlock innovation at the Pentagon and across government.

Transforming Federal Cybersecurity Through Private Sector Innovation

By: Darren Guccione, CEO and co-founder, Keeper Security

The United States is at a pivotal moment in its efforts to defend against modern cyber threats. Advanced Persistent Threats (APTs) from nation-states and organized cybercriminals continue to grow in both sophistication and scale, while many federal agencies operate with legacy acquisition models that struggle to keep pace with today’s threat environment.

Closing this gap is a national security imperative. A unified approach – where federal agencies and the private sector work side by side – is essential to staying ahead of adversaries that innovate relentlessly. Recent updates to the Federal Acquisition Regulation (FAR) represent a meaningful step forward, modernizing how agencies procure and deploy commercial cybersecurity solutions built to defend against contemporary threats. Reforms to the FAR  are streamlining how technology providers deliver solutions to the federal government. By prioritizing true Commercial Off-the-Shelf (COTS) offerings, these changes reduce friction for agencies seeking proven, enterprise-grade capabilities already in use across the private sector. 

Notably, the updated framework enables vendors to offer standardized, pre-vetted FedRAMP Software-as-a-Service (SaaS) solutions as recognized COTS products. This eliminates the need to engineer and maintain separate, dedicated government infrastructure, allowing agencies to benefit from the pace of commercial innovation rather than remaining tethered to static, isolated environments.The General Services Administration’s OneGov acquisition strategy reinforces this shift by consolidating procurement pathways for FedRAMP-authorized SaaS offerings. Through a unified, pre-vetted marketplace, agencies can move away from fragmented, agency-specific contracts and adopt modern security tools with greater speed and consistency.

These reforms also enable agencies to move beyond lengthy, prescriptive Requests for Proposals and toward outcome-based procurement. Instead of specifying how a solution must be built, agencies can focus on the results it must deliver, such as reducing credential compromise, improving access visibility or enforcing least-privilege controls across complex environments. Recent updates to simplified acquisition procedures further support this agility, increasing the Simplified Acquisition Threshold to $350,000 and the Commercial Simplified Threshold from $7.5 million to $9 million. Together, these changes empower agencies to adopt modern cybersecurity capabilities at the speed required to defend critical systems.

A core component of OneGov is the ability for agencies to engage in low-risk pilot and proof-of-concept programs through a centralized marketplace. These initiatives allow agencies to evaluate pre-vetted solutions in real-world environments before committing to full-scale deployment. For federal teams, this approach reduces risk, accelerates stakeholder buy-in and uncovers integration considerations early. For industry partners, it creates a clearer, more collaborative path to delivering measurable value in support of agency missions.

As agencies gain greater flexibility in choosing solutions that best support their workforces, it is critical that vendors meet the highest standards of security and compliance.  FedRAMP and GovRAMP authorization, along with alignment to frameworks such as NIST, SOC 2 and ISO 27001, signals a vendor’s long-term commitment to protecting sensitive government data. Achieving these benchmarks requires integrating security controls directly into the product development lifecycle – not bolting them on later. High-assurance, zero-trust solutions that deliver visibility, scalability and continuous monitoring are foundational to protecting federal systems and critical infrastructure.

Cybersecurity is national security. Sustained collaboration between government and the private sector is essential to anticipating emerging threats and countering increasingly capable adversaries. The latest procurement reforms create a clearer path for commercial innovation to strengthen federal defenses, provided agencies and industry act decisively and with shared purpose. By modernizing acquisition models and embracing proven, secure commercial technologies, the federal government can build a more resilient digital foundation – one that protects critical missions today while adapting to the threats of tomorrow.

Evolving Zero Trust and Embedded AI – Federal Government Cybersecurity Predictions for 2026

By: Venkat Sundaram, Netskope

Although concepts like artificial intelligence (AI) and zero trust have existed in some form for years or even decades, we’re witnessing a continued evolution of both when applied to cybersecurity. This presents opportunities for the Department of War/Defense but also creates new challenges which will come to a head in 2026.

With that in mind, there are a few developments we can expect to see in the coming year.

Prediction: The Pentagon will integrate behavioral analytics into zero trust efforts.

2026 will present the most critical period in the department’s zero trust implementation journey, marking the last full year before the mandated deadline to achieve targeted zero trust goals. While the department made notable progress focusing on zero trust for access, it will turn its attention to the context of data usage and automation/orchestration aspects of zero trust in 2026.

Consequently, the Pentagon will also shift its technical priorities from foundational zero trust capabilities to investment in advanced behavioral analytics tools, leveraging machine learning to ultimately detect anomalous user activity and assign dynamic risk scores to flag activities that indicate suspicious behavior. We expect the department to specifically target the deficiencies in automated data tagging, risk-based application access and automation. The goal should be to trigger adaptive policy controls when risk increases, moving the department beyond static perimeter-based allow/deny controls.

The zero trust framework will require analysis of events, activities and behaviors to derive context and apply AI and machine learning (ML). This effort focuses on achieving a highly personalized model that improves detection and reaction times for making real-time access decisions. Specifically, this involves implementing User and Entity Behavior Analytics (UEBA) to baseline activity and identify anomalies.

Prediction: The expansion of zero trust principles into operational technology (OT), weapons systems and tactical environments will hit technical speed bumps. 

The Pentagon has explicitly included OT and weapons systems in its zero trust implementation requirements. However, because legacy OT infrastructure frequently operates on models of implicit trust and security implementations must strictly avoid overriding or interrupting essential safety functions, the department requires a modern, data-centric approach to address trust based on dynamic policy and continuous verification rather than static network perimeters.

Addressing this complexity will consume significant 2026 DOW/DOD resources, especially as the department begins piloting new zero trust standards for OT, such as the Navy’s planned Block 2 advanced zero trust implementation. These implementations will force the integration of AI-driven monitoring and automated response to create a comprehensive, resilient, and proactive cybersecurity framework. The operationalization of the zero trust pillars related to visibility, analytics, automation and orchestration mandates the deployment of AI/ML to analyze behavioral telemetry and execute Security Orchestration, Automation, and Response (SOAR) workflows. This integration will transform the department’s posture from reactive defense to anticipatory risk management, establishing the information enterprise envisioned in the zero trust strategy.

Prediction: The Pentagon will accelerate the push to embed AI across its security landscape.

The Pentagon’s rapid pace of AI adoption will gain even more speed in 2026. This acceleration will be spurred by the need to streamline the Risk Management Framework and facilitate faster deployment of software through the Continuous Authorization to Operate (cATO) process.

The department will leverage AI and machine learning to drive automation and orchestration decisions across the zero trust pillars. These efforts will automate and standardize the governance processes necessary to secure the software supply chain and rapidly integrate innovative commercial technology.

These efforts will also provide the AI-derived policy automation necessary to maintain dynamic security monitoring and receive real-time alerts automatically. This remains a challenge due to siloed domains and manual interventions in conventional architectures.

The evolution of zero trust and AI advancement will present both opportunities and challenges to the Pentagon in the coming year. Going forward, the department should focus on unifying security functions and enforcing dynamic, context-aware authorization across hybrid environments and migrating away from legacy security stacks.

This means leveraging AI/ML embedded within the platform’s engine to enable adaptive access control, fundamentally shifting the DOW/DOD from static “allow/deny” decisions to real-time risk calculation. This capability will directly address the department’s need for continuous authentication while mitigating insider threats.

Unlocking AI’s Potential in High-Assurance Environments

By: Supermicro Experts

AI unlocks productivity gains for government organizations just as it does for enterprises—from service delivery to risk detection to day-to-day mission operations. According to Gartner, more than 60% of government organizations are expected to prioritize business process automation by 2026, up from 35% in 2022 (1). The Office of Management and Budget (OMB) has issued mandates requiring federal agencies to assess AI maturity and scale AI adoption. (2)

However, this transformation requires more than enthusiasm—it requires infrastructure purpose-built for compliance, security, and repeatability. Government agencies face hurdles such as data accessibility, lengthy authorization processes, complex procurement cycles, and scalability limitations. Many existing AI solutions are designed for commercial settings, making them difficult to adapt to the additional safeguards, processes, and protections required for federal use.

A 2025 GAO report found that 10 of 12 government agencies identified existing federal data privacy policies as a major challenge to deploying AI solutions. These limitations slow adoption, increase cost, and delay productivity gains that AI promises to deliver.

Purpose-Built for Secure, Compliant AI

The NVIDIA AI Factory for Government reference design directly addresses these challenges. It provides a proven blueprint for deploying AI infrastructure that meets or exceeds the highest federal assurance standards.

At its core, the design integrates NVIDIA AI Enterprise software, NVIDIA Blackwell accelerated computing and NVIDIA networking with NVIDIA-Certified Systems and NVIDIA-Certified Storage from trusted collaborators like Supermicro. This collaboration promotes predictable performance, validated compatibility, and enterprise-grade reliability across the full AI stack—from hardware to software to management.

The software stack includes government-ready software containers, built to align with the requirements of FedRAMP High and similar sovereign use cases. These components incorporate:

  • STIG-hardened configurations and requirements for containers, where applicable.
  • FIPS 140-3 validated cryptographic modules for secure data protection.
  • Continuous monitoring and remediation against vulnerabilities, including those identified by CISA’s Known Exploited Vulnerabilities (KEV) list.
  • A Secure Software Development Lifecycle (SDLC) incorporating controls consistent with SOC 2, ISO 27001, and equivalent global standards.

These features enable agencies to deploy AI confidently, knowing their systems are designed from the ground up for regulated, high-security environments.

Accelerating Time-to-Value with Trusted Design

The NVIDIA AI Factory for Government offers more than technology—it provides a framework for repeatable, validated deployment. By leveraging NVIDIA’s structured approach and recommended designs, organizations can accelerate the path from proof-of-concept to operational AI, reducing both risk and time-to-value.

The reference design has been optimized to help ensure consistent operation, faster resolution times, and predictable outcomes. It simplifies deployment in environments where compliance, security, and uptime are paramount—whether for law enforcement, disaster response, healthcare and benefits delivery, financial management, or national security operations.

For agencies seeking to modernize securely, the NVIDIA AI Factory for Government represents a major step forward. It brings together advanced hardware, hardened software, and proven deployment practices to help organizations deliver AI-enabled capabilities faster and more confidently.

Supermicro’s Leadership Role: Delivering Performance and Flexibility at Scale

As a global leader in accelerated computing infrastructure, Supermicro provides the building blocks that make large-scale AI deployment possible. Supermicro’s NVIDIA-Certified Systems, built on the latest NVIDIA Blackwell architecture, delivers optimized density, efficiency, and performance. These systems are optimized to run Agentic AI, Physical AI, and HPC workloads simultaneously—helping agencies consolidate infrastructure while maintaining compliance and control.

Supermicro’s modular architecture supports scalable deployments—from a few servers to entire AI data centers—allowing agencies to grow their compute capabilities as mission requirements evolve. Combined with NVIDIA AI enterprise software and partner ecosystem, this approach reduces complexity, lowers total cost of ownership, and shortens time-to-deployment for mission-critical applications.

Building the Foundation for Trusted AI

The public sector’s future success depends on its ability to operationalize AI responsibly, securely, and at scale. With sensitive workloads and mission-critical data, federal agencies must adopt architectures that are as resilient as they are intelligent.

The NVIDIA AI Factory for Government, powered by Supermicro NVIDIA-Certified Systems, enables agencies to do exactly that. By combining the performance of NVIDIA AI infrastructure with Supermicro’s flexible, energy-efficient platforms, the collaboration empowers agencies to deploy AI factories built for trust, compliance, and continuous innovation.

This collaboration extends beyond technology—it represents a shared commitment to supporting government missions with solutions that are secure by design and ready for tomorrow’s challenges. Supermicro and NVIDIA are accelerating the era of secure AI modernization, helping agencies unlock new levels of performance, agility, and mission impact.

For more information, please visit https://www.supermicro.com/en/accelerators/nvidia and https://www.supermicro.com/en/featured/rtx-pro-6000-systems.

Citations

1) https://www.gartner.com/en/newsroom/press-releases/2024-04-16-gartner-announces-the-top-government-technology-trends-for-2024

2)https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-22-Driving-Efficient-Acquisition-of-Artificial-Intelligence-in-Government.pdf

Accelerate Agentic AI in the Federal Government: Top Takeaways

Agentic AI is beginning to shift how federal agencies deliver on mission, moving beyond isolated prompts and pilots toward systems that can plan, act, and adapt alongside human teams. That shift is coming fast, and leaders are looking for practical, defensible ways to apply the technology in real programs.

Drawing on advice from Dell Technologies and NVIDIA’s new training, “Accelerate Agentic AI in the Federal Government,” here are 10 ideas for CXOs, mission owners, and systems integrators who are planning and deploying agentic AI in their organizations. The goal: cut through the noise and focus on the operational moves that matter most for readiness, security, and measurable mission outcomes.

  1. Move from prompts to purpose.

Agentic AI replaces “Summarize this memo” with “Achieve this mission goal,” letting coordinated software agents plan, act and self-evaluate until success is reached.

  1. Assess readiness – the real runway.

Validate executive sponsorship, data stewardship and AI-ready infrastructure before coding a single line.

  1. Start small, win fast.

Use value-stream mapping to spot high-volume, low-risk tasks (help-desk triage, HR onboarding, procurement streamlining) and launch a “small agent, big impact” pilot.

  1. Be smart about your solicitation.

Focus on outcomes, not features, to keep momentum and money focused on mission impact. Build in explainability, accountability, security and other guardrails – don’t bolt them on later. And, advancements are coming fast, don’t constrain yourself to today’s technology.

  1. Think product, not project.

Build modular stacks – a reasoning model, agent orchestrator, enterprise connectors and memory, and an observation/evaluation loop – that let you evolve capabilities with technology advancements, as well as mission and policy changes.

  1. Secure and govern by design.

Pair guardrails with red and blue teaming to harden agents against bias, drift and jailbreaks.

  1. Spin a GenAI data flywheel.

Use microservices to feed usage insights back into data curation and model tuning, squeezing more accuracy and efficiency from every interaction.

  1. Elevate the workforce.

Deploy agents to multiply throughput and surface insights, freeing staff for high-value tasks. Implement targeted upskilling to turn staff into AI managers, and AI stewards.

  1. Follow a five-phased roadmap.

Baseline ? Pilot ? Scale ? Govern ? Upskill keeps agencies out of pilot sprawl and locks in measurable value

  1. Put agents under continuous observation and improvement.

Instrument every layer – from reasoning model to connectors – with telemetry and evaluation. Build pause-and-approve gates based on risk and confidence so human reviewers can authorize actions. Use the observation/evaluation loop to capture reviewer feedback as training signals so agents improve while staying aligned with mission policy and security standards.

The Agentic AI training for federal practitioners offers a deeper look at architectures, safeguards and early implementation patterns. It’s designed to help practitioners:

  • Strengthen security
  • Simplify development
  • Accelerate adoption

As agencies weigh where to begin, the training offers practical guidance to support informed, efficient planning.

Why Congress Must Reauthorize the Technology Modernization Fund

By: Tim Cook, executive director, Center for Procurement Advocacy

As we approach the close of 2025, Congress faces a critical deadline that will shape the future of federal technology: The reauthorization of the Technology Modernization Fund (TMF). This is not just a budgetary line item—it is a strategic investment in the security, efficiency, and responsiveness of government services that millions of Americans depend on every day.

Despite annual federal IT spending exceeding $100 billion, a significant portion still goes toward maintaining outdated legacy systems. These systems are costly, vulnerable, and ill-equipped to meet the demands of a modern digital government. The COVID-19 pandemic exposed these weaknesses in stark terms, as agencies struggled to deliver essential services under unprecedented conditions.

The TMF was created to break this cycle. Authorized by Congress on a bipartisan basis, the fund empowers agencies to reimagine how they use technology to fulfill their missions. Its innovative funding model—guided by a board of federal technology leaders—ensures that resources are directed toward high-impact projects that improve mission delivery and can scale across government.

Since its inception in 2017, the TMF has received over 100 project submissions from 43 agencies, requesting more than $2.1 billion in funding. This demand underscores the urgency and potential for meaningful modernization. Projects funded through TMF have already delivered measurable improvements in cybersecurity, citizen services, and operational efficiency.

But time is running out. Without congressional action, the TMF will expire on December 12, 2025. We strongly support passage of the Modernizing Government Technology (MGT) Reform Act (H.R. 2985), which would reauthorize the TMF for seven years and add guardrails and transparency measures to ensure continued success. This legislation mirrors a bill that passed the House last Congress with strong bipartisan support.

Reauthorizing the TMF is not just good policy—it is essential for national security, fiscal responsibility, and public trust. Modern, secure, and efficient IT systems are the backbone of government services, from processing veterans’ benefits to safeguarding sensitive data. Every dollar invested in modernization reduces long-term costs and strengthens resilience against cyber threats.

The TMF enjoys broad support from industry and advocacy organizations because it works. It accelerates innovation, enhances accountability, and delivers results that matter to the American people. Congress must act now to ensure that this vital program continues to drive progress across the federal enterprise.

The choice is clear: reauthorize the TMF and keep government technology moving forward.

Make Cybersecurity a Key Ingredient of Modernization

By: Tom Guarente, vice president of external and government affairs, Armis

Recently, I was privileged to sit down with a high-ranking member of a key oversight committee who asked me what actions I thought Congress should take to address some of the country’s biggest cybersecurity challenges. I suggested they should begin by conducting a hearing that would publicly bring many of these challenges to light.

I was somewhat taken aback – but not necessarily surprised – by the response. I was told the committee had an IT modernization hearing scheduled next, but would hold a cybersecurity hearing in the months ahead.

That exchange captured the essence of the challenge we face in improving cybersecurity within the federal government. By viewing cybersecurity issues as separate from technology modernization, we are missing an opportunity to address the issue more effectively by integrating the two.

The federal government needs a new mindset to ensure that IT modernization proceeds with cybersecurity as a key ingredient, not an afterthought. Agencies must think beyond IT and bake cybersecurity into their program requirements from the onset. The government cannot continue down yesterday’s path of addressing modernization with cybersecurity merely being an afterthought or “check box” item.

Solicitations from many agencies at times may bake cybersecurity into their modernization programs, but tend to address yesterday’s needs and requirements, leaving out the critical nature of a growing threat surface with converged technologies.

The upcoming program to modernize the National Air Traffic Control System and improve and secure the nation’s airport/transportation infrastructure can serve as a model for this new approach. The Federal Aviation Administration (FAA) should ensure that cybersecurity is integrated into its overall modernization plans from the start. This involves ensuring the security of an infrastructure that goes well beyond traditional managed assets, such as IT, and now includes a myriad of devices (cameras, scanners, automated doors, etc.).

Doing so is critical given the urgency of ensuring safe air travel, and failure to do so could literally result in the loss of life. Here are four steps the government can take to move in this direction:

  • Start thinking beyond IT: The FAA initiative encompasses nearly all aspects of its operation, including communications, surveillance, automation, and facilities. The agency must look beyond IT to ensure cyber protection for all assets associated with these operations, with complete visibility and control into IT, operational technology (OT), the internet of things (IoT), and unmanaged assets to address traditionally overlooked security blind spots.
  • Ensure real-time capabilities: Within any acquisition, cybersecurity must be viewed as a critical element and not a separate component. We’ve already seen examples of federal government initiatives that aim to bridge this gap, including the Pentagon’s Cybersecurity Maturity Model Certification (CMMC) for defense contractors and various Software Bill of Materials (SBOM) efforts to secure the modern software supply chain. Every decision made for a new procurement should take into account how it will deploy tools to identify and monitor threats in real time, in terms of how those tools interact in the environment.
  • Promote solutions that create cyber awareness: Agencies should deploy capabilities to identify anomalies in the behavior of assets within their environment. This means tools to measure modernization efforts through quantifiable risk reduction metrics; passive/active discovery and integration with existing security infrastructure; and asset discovery for maintaining an accurate inventory of systems and components.
  • Encourage a mindset for making quick decisions: Today, the alerts and complexities of the government’s growing threat surface call for integrating AI functionality that gives personnel relevant, real-time information on which they can take action. Integrating new technologies can often introduce unfamiliar skill sets and more complexity. Consequently, agencies should embrace a holistic and outcomes-based approach to remediating vulnerabilities that incorporates and supports human decision-making, all the while narrowing the decision window where action is required.

Government modernization should proceed with cybersecurity as a key ingredient, not an afterthought. The FAA and other agencies have an opportunity to serve as an example on how to do this correctly by thinking beyond IT and baking cybersecurity into their program requirements with real-time solutions that quickly identify and counter risks to their environments.

How Spectro Cloud’s PaletteAI Secure helps agencies scale AI securely, compliantly, and confidently

The rapid rise of AI is transforming enterprise applications and infrastructure at incredible speed. It is reshaping the marketplace of tools, software, and hardware, from sovereign clouds to the edge.

From a toolchain perspective, the AI ecosystem is exploding. Thousands of offerings are emerging, with more introduced every day. Additionally, developers are rapidly updating their software to support AI. According to Gartner, 80% of applications are expected to be rewritten to embed AI over the next several years.

On the hardware and infrastructure front, the story is the same. Massive GPU investments and rising AI infrastructure costs dominate budgets. Yet many GPUs sit underutilized due to over-provisioning and inefficient resource sharing.

For government agencies and regulated industries, this complexity makes it harder to maintain strict compliance, data sovereignty, and Zero Trust security standards, making the path to scalable, secure AI even steeper.

Team friction and ‘shadow IT’

Every team involved in AI initiatives faces pressure to prove value fast. Yet the drive for innovation from AI practitioners often clashes with IT’s need for visibility, compliance, and control — especially in government and regulated industries where security and accountability are critical.

This tension often leads to Shadow IT – ad hoc deployments outside enterprise guardrails –  creating fragmented security, data risk, and limited visibility for platform and governance teams.

Design patterns such as AI factories and secure multi-tenancy are emerging to restore order, but implementing them securely and at scale remains difficult given the diversity of AI use cases and rapid tool evolution. For government and regulated sectors, the stakes are even higher: breaches, misconfigurations, or model exposure can have mission-level consequences. Compliance frameworks like FIPS 140-3 and Zero Trust are not optional, they are essential.

So… what’s the answer?

Organizations need a unified foundation that brings together platform and practitioner teams in one place. A solution that accelerates innovation while maintaining control and compliance.

The right tool must deliver speed and flexibility for AI teams while ensuring the visibility, policy enforcement, and governance IT requires.

In short, agencies and enterprises need a secure AI platform that can operate across any environment, data center, edge, or cloud, with the same level of assurance, compliance, and performance.

And this is exactly what Spectro Cloud delivers with our new PaletteAI and PaletteAI Secure platforms.

Meet PaletteAI Secure

PaletteAI Secure is a new platform from Spectro Cloud for deploying and managing secure AI workloads at scale. It creates a unified environment for both platform and practitioner teams, combining speed, security, and policy-driven governance across every layer of the AI stack.

PaletteAI Secure gives enterprises a consistent, repeatable foundation for building AI environments. It connects the full lifecycle: design, deploy, and manage across data center, cloud, and edge.

Platform teams use PaletteAI Studio, a specialized interface inside PaletteAI Secure, to design and publish AI stack templates pre-integrated with NVIDIA AI Enterprise components such as NeMo, NIM, DOCA, and Run:ai. These templates include the full infrastructure stack—operating system, Kubernetes, networking, and more—providing a consistent base for AI workloads.

Practitioners can customize and deploy these templates within approved guardrails, accelerating innovation while maintaining compliance and operational consistency.

Built-in automation handles provisioning, scaling, and updates, while unified governance and observability deliver visibility across environments.

PaletteAI Secure adds hardened security and compliance layers, FIPS 140-3 validation, and zero-trust enforcement at the infrastructure level.

PaletteAI Secure provides the foundation for building secure AI factories, enabling organizations to apply consistent Zero Trust controls and policy enforcement as they scale AI production across data centers, edge, and sovereign clouds.

Platform teams define compliant blueprints spanning every layer of the stack: FIPS-validated OS and Kubernetes, secured storage and networking, and trusted AI tools.

AI teams deploy freely within those secure boundaries. This design provides freedom with governance, giving regulated organizations the ability to scale AI confidently without compromising compliance.

Multiple layers of security and compliance

FIPS compliance

PaletteAI Secure adheres to FIPS 140-3, the standard for cryptographic security, and a mandatory requirement for sensitive government data workloads. Every layer, from the operating system to the workload, uses validated encryption modules and meets strict auditing requirements. This ensures that AI data remains secure from ingestion to inference, maintaining confidentiality throughout the AI lifecycle.

Zero Trust AI

PaletteAI Secure implements Zero Trust principles across the AI stack, ensuring that access is always verified and data is continuously protected. Using NVIDIA BlueField DPUs and the DOCA Platform Framework (DPF), the platform enforces isolation and encryption. These technologies help maintain strict boundaries between workloads and networks, providing consistent security and compliance for AI environments across all deployment locations.

SAINA: Secure AI-Native Architecture

Spectro Cloud’s Secure AI-Native Architecture (SAINA) defines how Zero Trust is implemented across PaletteAI Secure. Building on the same NVIDIA BlueField DPU and DOCA Platform Framework (DPF) foundation, SAINA acts as a guiding framework that unifies security, governance, and performance for deploying secure AI factories.

It turns Zero Trust principles into practical outcomes—isolating workloads, verifying access, and protecting data throughout its lifecycle. SAINA also enables secure multi-tenancy and network isolation, ensuring users and workloads remain isolated even in shared environments.

For government and defense organizations, it delivers consistent, compliant, and resilient security across data centers, edge, and sovereign clouds.

Backed by a proven security heritage

The U.S. military, defense, and government agencies have long trusted Spectro Cloud. PaletteAI Secure builds on the legacy of Palette VerteX, which powers secure Kubernetes management in classified and FedRAMP-authorized environments.

Spectro Cloud’s compliance portfolio includes FIPS 140-3 (certificate #5061), DoD STIG, ISO 27001:2022, and SOC 2 Type 2 certifications.

These credentials demonstrate its  commitment to protecting critical workloads across sectors such as defense, healthcare, and energy. Trusted by security-driven organizations worldwide, Spectro Cloud delivers consistent protection for regulated and tactical deployments alike.

Learn more

To learn more about PaletteAI Secure, its security certifications, and the full range of compliance and security features it offers, visit palette-ai.com/secure.

Fix the Foundation: How Hybrid Cloud and Trusted Data Enable Government AI

By Dario Perez, VP Federal Civilian and SLED, Cloudera

Artificial intelligence presents a transformative opportunity for government, from enhancing national defense readiness to improving citizen services and enabling data-driven decision-making at scale. However, to move from promising pilots to scalable, mission-aligned deployments, agencies must focus on what lies beneath the surface: trusted data and infrastructure.

Cloud adoption has been underway in the Federal government for over 15 years, and every agency has made meaningful progress. However, as the Forrester State of Cloud in Government, 2025 report highlights, realizing the expected value of cloud remains a significant challenge. While many agencies have migrated workloads to the cloud, environments often remain fragmented, hybrid strategies are underdeveloped, and legacy systems continue to limit how data is accessed, analyzed, and secured. These gaps directly undermine an agency’s ability to make data actionable, especially at the scale and speed that AI demands.

At the same time, expectations from agency leadership are rising. CIOs and IT teams face growing pressure to demonstrate meaningful operational returns on AI investments – quickly. But AI isn’t a box to check or a tool to bolt on. It requires a deliberate, step-wise approach rooted in three fundamentals: clearly defining the mission problem; ensuring access to accurate and trusted data; and modernizing the infrastructure to enable secure and reliable access to data wherever it may be.

To enable mission-based AI decision making, government agencies must rethink their modernization strategies. In practice, that means developing and implementing a data strategy that encompasses both cloud and on-premises data centers into integrated hybrid multi-cloud environments.

This approach shifts agencies from fragmented datasets to governed, action-ready data ecosystems, taking one-off pilots and transforming them into AI deployments that directly support core agency goals.

Hybrid Multi-Cloud: The Foundation for Modernization and AI Readiness 

Managing agency data via a single pane of glass through a hybrid multi-cloud environment is no longer a compromise – it’s a strategic enabler. Today’s tools provide the flexibility and control needed to manage data as a critical strategic asset without disrupting operations.

For government agencies, hybrid multi-cloud offers a practical and scalable path to AI readiness by:

  • Enabling gradual modernization. Keep mission-critical processes as they are and make incremental movements without disrupting continuity.
  • Staying in compliance. Agencies can’t afford downtime or risks to the data assets in their care. A hybrid cloud strategy aligns with security and compliance mandates, including FedRAMP and DoD IL5/6.
  • Offering strategic roll-out. A hybrid cloud strategy allows agencies to prioritize and deploy workloads across on-prem, public cloud, and edge environments as needed.

Early adopters have already leveraged hybrid multi-cloud environments for various agency use cases, including:

  • Accessing real-time analytics in field operations, ensuring that agencies are aligned, synced, and acting on the best available information.
  • Training AI models in multi-cloud environments, offering controlled visibility far beyond what was possible when data was siloed and hard to access.
  • Maintaining operational continuity across disconnected or contested networks, powering confidence and resilience across the board.

By designing infrastructure with hybrid multi-cloud in mind, agencies can ensure interoperability, scalability, and resilience – all key attributes to realizing their AI-driven missions. To scale AI beyond prototypes, the public sector needs more than cloud capacity. They need control and clarity.

Trustworthy, Reliable Data: The Core Enabler of AI Readiness

Once the infrastructure is in place, the next imperative is ensuring the data is usable, trusted, and well-managed. Poor data quality, governance gaps, and silos are still among the top barriers to successful AI deployment because AI outputs are only as strong as their inputs.

As such, for AI to work at scale, government agencies need to prioritize:

  • Comprehensive audits. Who accessed the data, including when, why, and how. Tracking data lineage and ensuring accuracy is possible through metadata and audit tools.
  • End-to-end traceability. Where did the data come from, and were any filters, parameters, or prioritizations added along the way? If so, can they be trusted and defended? Modern data “lakehouses” are the preferred architecture for AI as they support unified structured and unstructured data and streaming data across environments and support AI training without forcing risky or inefficient data movement.
  • Visibility through a single pane of glass. Accounting for distributed data means they need observability and control from a unified point.

With well-governed, high-quality data, agencies reduce the risk of model drift, bias, or unreliable insights, and increase their ability to confidently act on AI outputs. But as AI expands across mission-critical functions, data security becomes the thread connecting every part of the infrastructure.

Security and Trust: The Prerequisite for Cross-Domain AI

Before full deployment at scale, government agencies must review touchpoints and patch vulnerabilities. Public trust and mission success both depend on building AI that is not only powerful, but also secure by design.

That means:

  • Adopting zero-trust architectures that enforce strict identity and access controls, even inside the perimeter.
  • Encrypting all data, regardless of whether it’s at rest and in motion, while applying segmentation to reduce the blast radius in the event of a breach.
  • Building secure-by-design AI pipelines that allow for testing and deployment while offering a way to monitor for drift.

In a crisis, there’s no time to engineer collaboration on the fly. Secure cross-domain interoperability must be built in from the start. By bringing AI to the data, instead of moving data across environments, agencies reduce exposure while preserving speed and mission relevance.

AI is reshaping how government agencies operate, but only if the foundations are solid. Success depends not on speed, but on sequencing: modernizing infrastructure, governing data, and securing every layer of the AI pipeline.

Agencies that take a step-wise, mission-aligned approach – starting with hybrid cloud, followed by trusted data practices and secure data access – will be best positioned to scale AI effectively. This isn’t just about technology. It’s about transforming how government agencies deliver value, build public trust, and advance their missions.

With a thoughtful roadmap in place, AI can move from isolated experiments to enterprise-wide transformation.

1 2 3 … 21