Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Four things agencies need to get right before AI outpaces their security programs

Дата публикации: 11-08-2026 22:02:07

Without defined ownership and oversight processes for AI tools themselves, governance gaps compound the security gaps.

Основное содержимое страницы с новостью.

Without defined ownership and oversight processes for AI tools themselves, governance gaps compound the security gaps.

Sam Rizzo

August 11, 2026 6:02 pm

4 min read

The comforting assumption has been that artificial intelligence would cut both ways, arming defenders as fast as attackers. That assumption is breaking down. The same models that can scaffold and generate production code faster than any team could by hand are increasingly capable of finding and exploiting unpatched vulnerabilities just as quickly. These are two sides of the same underlying technological advancement, moving in parallel.

Washington has clearly taken notice. Over the past several months, the administration has acted on multiple fronts to formalize how the United States government reviews, adopts and monitors frontier AI. In June, Executive Order 14409, “Promoting Advanced Artificial Intelligence Innovation and Security,” directed agencies to harden systems against AI-enabled threats on an aggressive timeline. On the procurement side, the General Services Administration’s proposed AI Terms of Service would establish new guidance for how agencies acquire and govern novel AI tools. And on the standards side, the National Institute of Standards and Technology has published a preliminary Cyber AI Profile mapping AI-specific risks onto its widely adopted Cybersecurity Framework, and its Center for AI Standards and Innovation (CAISI) has launched a dedicated initiative to standardize security practices for AI agents.

As both the policy and technology landscapes rapidly evolve, the operational question in front of every agency chief information officer and chief information security officer is the same: How do you adopt AI fast enough to keep pace without putting at risk the guardrails that make adoption safe in the first place? That’s the test the next year will put in front of federal, state and local IT leaders alike.

The AI challenges agencies should anticipate now

AI is generating code faster than review teams can validate it. In some cases, code reaches production before quality and security checks catch up. This creates new risks for agencies that assume AI output is secure by default.

Fast, repeatable cybersecurity in the era of AI requires policy as code, compliance as code and strong vulnerability remediation. Rolling out agents without these maturity standards creates application-security risk and remediation gaps. Agencies also need a clear framework for how AI systems are approved, monitored and retired. Without defined ownership and oversight processes for AI tools themselves, governance gaps compound the security gaps.

This shift raises the bar for every government agency, not just those directly named in any single mandate. Four areas deserve immediate attention:

  1. AI is not a solution in a vacuum. Agencies that treat it as an addition to established security practices, rather than a replacement for them, are positioned to capture AI’s speed advantage while maintaining the compliance and audit posture their missions depend on.
  2. AI creates more outputs faster, but system maturity is the bottleneck to watch. AI generates far more production code than teams once managed, and development, security and operations (DevSecOps) maturity determines both whether that code meets compliance standards and whether existing processes can absorb the added capacity, speed, quality and security demands.
  3. Agencies cannot expect AI to generate policy-conformant, guidance-compliant solutions without external verification and validation. Agentic AI introduces risks beyond traditional software that compound when an agent has access to sensitive data, exposure to untrusted content, and the ability to communicate externally. Two questions sit at the center of that risk for most agencies. What can an agent actually do with a given dataset and does that access stay within a single classification level? The foundation of responsible AI governance calls for oversight to track which agent took which action, under whose approval, with a complete record of what it touched. Agencies that let oversight lag behind the pace of AI output will create exposure that may be hard to see until it surfaces in an audit or an incident.
  4. AI is accelerating how work gets done, but governance and cybersecurity requirements remain in kind, even as they scale. The frameworks agencies already rely on – patch management, access controls, change management, audit logging – extend to AI systems. Modernizing at the pace AI demands means applying those same disciplines earlier and more continuously and treating AI governance as infrastructure. Agencies that establish clear policies for AI use, output validation, and model oversight now will be better positioned as frontier-model oversight moves from framework to enforcement.
The threat has evolved and so too must the response

Agentic AI raises the ceiling for both attackers and defenders, but attackers can act on theirs immediately, while defenders’ speed depends on governance that can’t wait for a settled policy picture. Agencies are best served by leaning into the DevSecOps tooling and security guardrails they already operate within and trust. The agencies that pair AI adoption with real governance, validation, and security discipline now will be the ones positioned to adapt as the frontier AI rules and technology continue to develop.

Sam Rizzo is senior director of public policy at GitLab.

Copyright © 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1AI Agents Are Creating a New Enterprise Security Gap0503-07-2026
2Governance Is a Developer Experience Problem06.7505-08-2026
3Stop automating inefficiency and scale AI the right way 0525-06-2026
4AI Agent Governance: Securing Autonomous Agents in Production010.4124-07-2026
5Shadow AI in government: Why unsanctioned tools demand a governance response08.128-07-2026
6AI-generated code has made security debt a governance problem08.7813-07-2026
7Cyber training will enable government to successfully harness AI while staying secure5709-07-2026
8The AI safety test is becoming a safety risk010.3709-08-2026
9The Right Way to Regulate AI09.1205-08-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 8.04. Источник: federalnewsnetwork.com.