Without defined ownership and oversight processes for AI tools themselves, governance gaps compound the security gaps.
Without defined ownership and oversight processes for AI tools themselves, governance gaps compound the security gaps.
August 11, 2026 6:02 pm
4 min read
The comforting assumption has been that artificial intelligence would cut both ways, arming defenders as fast as attackers. That assumption is breaking down. The same models that can scaffold and generate production code faster than any team could by hand are increasingly capable of finding and exploiting unpatched vulnerabilities just as quickly. These are two sides of the same underlying technological advancement, moving in parallel.
Washington has clearly taken notice. Over the past several months, the administration has acted on multiple fronts to formalize how the United States government reviews, adopts and monitors frontier AI. In June, Executive Order 14409, “Promoting Advanced Artificial Intelligence Innovation and Security,” directed agencies to harden systems against AI-enabled threats on an aggressive timeline. On the procurement side, the General Services Administration’s proposed AI Terms of Service would establish new guidance for how agencies acquire and govern novel AI tools. And on the standards side, the National Institute of Standards and Technology has published a preliminary Cyber AI Profile mapping AI-specific risks onto its widely adopted Cybersecurity Framework, and its Center for AI Standards and Innovation (CAISI) has launched a dedicated initiative to standardize security practices for AI agents.
As both the policy and technology landscapes rapidly evolve, the operational question in front of every agency chief information officer and chief information security officer is the same: How do you adopt AI fast enough to keep pace without putting at risk the guardrails that make adoption safe in the first place? That’s the test the next year will put in front of federal, state and local IT leaders alike.
The AI challenges agencies should anticipate nowAI is generating code faster than review teams can validate it. In some cases, code reaches production before quality and security checks catch up. This creates new risks for agencies that assume AI output is secure by default.
Fast, repeatable cybersecurity in the era of AI requires policy as code, compliance as code and strong vulnerability remediation. Rolling out agents without these maturity standards creates application-security risk and remediation gaps. Agencies also need a clear framework for how AI systems are approved, monitored and retired. Without defined ownership and oversight processes for AI tools themselves, governance gaps compound the security gaps.
This shift raises the bar for every government agency, not just those directly named in any single mandate. Four areas deserve immediate attention:
Agentic AI raises the ceiling for both attackers and defenders, but attackers can act on theirs immediately, while defenders’ speed depends on governance that can’t wait for a settled policy picture. Agencies are best served by leaning into the DevSecOps tooling and security guardrails they already operate within and trust. The agencies that pair AI adoption with real governance, validation, and security discipline now will be the ones positioned to adapt as the frontier AI rules and technology continue to develop.
Sam Rizzo is senior director of public policy at GitLab.
Copyright © 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | AI Agents Are Creating a New Enterprise Security Gap | 0 | 5 | 03-07-2026 |
| 2 | Governance Is a Developer Experience Problem | 0 | 6.75 | 05-08-2026 |
| 3 | Stop automating inefficiency and scale AI the right way | 0 | 5 | 25-06-2026 |
| 4 | AI Agent Governance: Securing Autonomous Agents in Production | 0 | 10.41 | 24-07-2026 |
| 5 | Shadow AI in government: Why unsanctioned tools demand a governance response | 0 | 8.1 | 28-07-2026 |
| 6 | AI-generated code has made security debt a governance problem | 0 | 8.78 | 13-07-2026 |
| 7 | Cyber training will enable government to successfully harness AI while staying secure | 5 | 7 | 09-07-2026 |
| 8 | The AI safety test is becoming a safety risk | 0 | 10.37 | 09-08-2026 |
| 9 | The Right Way to Regulate AI | 0 | 9.12 | 05-08-2026 |