Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

The missing component of government AI deployment: Trust

Дата публикации: 12-08-2026 21:30:50

The agencies that build verification into their AI architecture now will be best positioned to bring the most capable AI systems to the missions that matter.

Основное содержимое страницы с новостью.

At a recent AFCEA NOVA Naval IT Day, Marine Corps Chief Information Officer Colin Crosby didn’t parse words when he described the Pentagon’s direction. The secretary of defense, he said, has directed the department to become “an AI-first warfighting force.”

In other words, artificial intelligence is not an add-on to existing strategies. It’s a serious statement of intent, reflecting where the broader federal government is headed. The mandate is clear, but what often goes overlooked is what it actually takes to trust an AI system with the information that matters most: classified intelligence, mission-critical operational data, sensitive law enforcement records and more.

When it comes to cybersecurity, both model performance and data privacy policy matter. But they don’t address a more fundamental problem that stems from how AI computing actually works. Traditional cybersecurity has built strong protections for data at rest and data in transit. Encryption on disk and across the network is a problem that has been solved with mature standards. But more than any technology before it, AI introduces data in use, or the moment a model is actively processing information in memory.

For commercial organizations, this might be a risk management concern. But for agencies trying to create an AI-first warfighting posture, it could be the difference between a system that can credibly handle classified or mission-critical data and one that cannot.

A different kind of threat
A worst-case insider scenario for an AI system running on government infrastructure isn’t necessarily a sophisticated external hack. It could be a system administrator with legitimate, elevated access to the infrastructure hosting an AI workload who uses that access to read what the model is processing in memory: the data, the model’s internal computations, the output it just generated. Or it could be a compromised credential that grants an attacker the same administrative visibility as a legitimate insider.

Neither scenario requires defeating a firewall or utilizing malware in any conventional sense. The access is, in a strict technical sense, “legitimate.” Administrative privilege is supposed to allow a system administrator to inspect the systems they manage. The problem is that on most infrastructure today, “inspecting the system” and “reading the sensitive data an AI model is actively processing” are the same action, because that data exists in plaintext in memory the moment computation begins.

So for commercial enterprises, this could be a serious risk, but for government agencies operating in classified or otherwise restricted environments, it should be disqualifying. An intelligence analysis workflow or a weapons system AI component can’t rely on the assumption that every administrator with system access will behave appropriately or that every credential will remain uncompromised. The consequences of being wrong are too significant.

Air-gapped environments don’t fully solve the problem
A natural instinct is to address sensitive AI workloads by isolating them with air-gapped networks, no external connectivity and tightly controlled physical access. All of this is necessary, but it’s not sufficient on its own.

An air gap addresses network-based attacks, but not what happens inside the system once someone with legitimate or compromised access is standing in front of it. A system with no internet connection can still be accessed by an administrator with a console login, for example. The air gap is a perimeter control, but has no say in whether the data inside that perimeter is protected from the people and systems operating within it.

This is the gap modern hardware-based security approaches are designed to close. They’re gaining particular traction in defense and intelligence, which have always taken insider risk and credential compromise threats seriously.

Hardware as the root of trust
Architectures are evolving, shifting trust from software-driven policy to the silicon itself. Modern processors, including specialized chips from the major manufacturers used in AI infrastructure, support what are known as trusted execution environments (TEEs): physically isolated regions of the processor where code and data are processed while remaining encrypted in memory, even during active computation. Inside one of these protected environments, the host operating system, a hypervisor managing the underlying virtualized infrastructure, or even an administrator with full system privileges and every credential available can’t read the contents.

This directly addresses the rogue administrator and compromised credential scenarios. Even if an attacker obtains every level of access a system theoretically allows, there’s still a category of access the hardware itself will not grant to anyone, including the system’s own infrastructure operators.

The second component that makes this work is cryptographic attestation, in which the hardware generates a signed report proving its own identity, the integrity of the firmware, and the exact software running inside the protected environment before any sensitive data or cryptographic key is released to it. This report is signed using a key embedded in the actual chip itself, meaning it cannot be forged at the software level. A relying party, whether an automated policy system or a human security officer, can independently verify the report and mathematically confirm that the environment is exactly what it claims to be.

For agencies that must obtain an authorizing official’s approval before a system can process classified information, this distinction is important. Conventional security controls are typically demonstrated through documentation and periodic audits. Attestation produces even better evidence: a continuously generated, tamper-evident, hardware-signed record of what was running, in what state, at the moment sensitive data was processed. That is a much stronger basis for an authorization decision than a policy document saying the right controls are in place.

The agencies that verify will lead in AI

Federal agencies don’t need to choose between deploying capable AI systems and maintaining the security posture their missions require. The technical foundation to do both exists: hardware-enforced isolation to protect data during active computation, cryptographic attestation for verifiable proof, and architectures designed to operate without external connectivity when the mission demands it.

What’s needed is a clearer understanding that data in use is a distinct and serious category of risk, separate from the protections for data at rest and in transit that most security programs were built around. As AI moves deeper into the systems supporting national security and other classified missions, establishing that the underlying infrastructure can be verified, not just trusted, will define mission-ready deployments.

The agencies that build verification into their AI architecture now, rather than retrofitting it later, will be best positioned to bring the most capable AI systems to the missions that matter.

Anand Kashyap is CEO and co-founder of Fortanix.

Copyright © 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Cyber training will enable government to successfully harness AI while staying secure5709-07-2026
2Why AI Citation Registries Are Emerging as a Practical Path Forward for Government Agencies0707-05-2026
3It Takes a Village: Why Government AI Attribution Cannot Be Solved Alone0526-05-2026
4Stop automating inefficiency and scale AI the right way 0525-06-2026
5Beyond the Hype: How AI Can Reshape Government Operations01028-05-2026
6Rethinking federal statistics in the AI era07.2913-07-2026
7What Does the AI-Ready Gov Workforce Look Like?022.512-06-2026
8AI-ready data: Preparing government data for an AI-driven world013.218-02-2025
9Federal zero trust faces challenges with AI agents0502-07-2026
10Lawsuit over Army’s use of AI in contract award could increase transparency around proposal evaluations07.7111-08-2026

Классификация: Наука. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 6.31. Источник: federalnewsnetwork.com.