{"slug": "ai-hackers-are-getting-faster-the-government-may-not-be-ready", "title": "AI hackers are getting faster. The government may not be ready", "summary": "Agentic AI systems such as Anthropic's Mythos and OpenAI's GPT 5.6 can find and exploit vulnerabilities far faster than human hackers, prompting the U.S. government to limit public release of these models. However, major cuts to the Cybersecurity and Infrastructure Security Agency and the General Services Administration's FedRAMP office have left the Trump administration ill-prepared, according to four former government officials. A former federal chief information officer warned that AI removes constraints around skill and time, enabling commodity attacks that will do more damage sooner.", "body_md": "Agentic [AI](https://www.fastcompany.com/section/artificial-intelligence) systems threaten cybersecurity as we know it. A new generation of cyber-capable models, including Anthropic’s Mythos and OpenAI’s GPT 5.6, can find and exploit vulnerabilities in computer systems far faster than human hackers. The technology is so powerful that it has spooked the U.S. government, which has moved to limit, or completely pause, the public release of these models.\n\nHow well prepared is the Trump administration to secure the government’s computing resources? The rise of agentic AI systems comes in the aftermath of major cuts to the Cybersecurity and Infrastructure Security Agency, which is operating with a [fraction of its former staff](https://www.fastcompany.com/91411935/cybersecurity-trump-cisa-doge-krebs-black-hat). Another agency, the General Services Administration, houses a critical body called FedRAMP, short for the Federal Risk and Authorization Management Program, which sets security review standards for companies providing cloud systems for government data and software. That group has also been reformulated and [slimmed down](https://fedscoop.com/gsa-fedramp-20x-automation-private-sector/) under the Trump administration.\n\nBoth organizations have begun to address the cybersecurity risks posed by agentic AI. CISA has [issued guidance](https://www.cisa.gov/resources-tools/resources/principles-secure-integration-artificial-intelligence-operational-technology), and the FedRAMP office has spent the past year revising its requirements for technology companies, including Amazon Web Services, Google, Microsoft, and Palantir, that host or interact with government cloud services. This work has resulted in new reporting requirements, and the office expects to institute additional requirements in the coming months. A government spokesperson assures *Fast Company* that “federal agencies’ cloud services meet rigorous security standards and are continuously tested as cybersecurity threats evolve, especially AI and agentic systems.”\n\nBut four former government officials tell *Fast Company* that preparing for the risks posed by AI agents will remain a major challenge. “I’d be a lot more confident about all of this is the Trump administration hadn’t forced out so many of the best IT and cyber professionals at CISA and other agencies,” says a former federal chief information officer.\n\nThe risks to government systems are significant, given the vast array of critical services and stores of sensitive data hosted on the U.S. government’s cloud systems. The government is hardly immune to cyberattacks, and its assets are prime targets for hackers.\n\nThe former CIO says their biggest concern is the scale of attacks made possible by agentic AI. Although high-profile incidents receive considerable attention—one recent example involved an OpenAI agent independently breaking into Hugging Face’s systems—simpler AI-powered “commodity attacks will do more damage sooner.” Some agencies are more prepared than others, the former official warns.\n\nThese are attacks that a human and a [“reasonably skilled” hacker](https://www.fastcompany.com/91569927/this-latest-frightening-ransomware-attack-was-orchestrated-entirely-by-an-llm) could carry out, but that are typically time-constrained. They might include targeted spear-phishing campaigns or efforts to find vulnerabilities in multifactor authentication. “AI removes the constraints around skill and time,” the former federal CIO adds.\n\nA former agency chief technology officer says that “CISA has work to do” and that rules created by organizations such as FedRAMP are “better than nothing.” The former CTO adds: “I would say no one is ready just yet because the managerial techniques for the new world [of agentic AI] are being developed.”\n\nAnother complication is that the U.S. government largely does not build its own cloud systems. Instead, government officials set standards that allow technology companies, including Palantir, Google, and Amazon, to sell access to their cloud services to federal agencies. This creates a sort of divided responsibility. One former White House AI expert explains that although the government’s systems are primarily managed by commercial companies, their security also depends on how individual agencies configure them. Amazon Web Services might adequately protect its own systems, for example, while government agencies could still introduce vulnerabilities when implementing them.\n\n“Vendors are paid to deliver a platform, not to keep an agency’s environment correctly configured over time,” the former White House expert explains. “Nobody in that arrangement is contractually on the hook for the ongoing security posture, so nobody really owns it.” It will be far easier for malicious AI agents operating at scale to identify and exploit those misconfigurations.\n\nAsked whether the government’s cloud systems are secure and prepared for AI, a former Department of Homeland Security official tells *Fast Company* that the rise of agentic, cyber-capable systems makes it even more important for the government to deploy AI defensively. The government has made some AI tools widely available to federal employees, but it has also, at times, completely banned certain providers from government use.\n\n“Any agency not adopting agentic AI coding tools and connecting them to their security surfaces are actually starting to fall behind,” the source cautions.", "url": "https://wpnews.pro/news/ai-hackers-are-getting-faster-the-government-may-not-be-ready", "canonical_source": "https://www.fastcompany.com/91581090/ai-hackers-are-getting-faster-the-government-may-not-be-ready", "published_at": "2026-07-29 18:51:07+00:00", "updated_at": "2026-07-29 19:24:58.419180+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-policy", "ai-agents"], "entities": ["Anthropic", "OpenAI", "Cybersecurity and Infrastructure Security Agency", "General Services Administration", "FedRAMP", "Amazon Web Services", "Google", "Microsoft"], "alternates": {"html": "https://wpnews.pro/news/ai-hackers-are-getting-faster-the-government-may-not-be-ready", "markdown": "https://wpnews.pro/news/ai-hackers-are-getting-faster-the-government-may-not-be-ready.md", "text": "https://wpnews.pro/news/ai-hackers-are-getting-faster-the-government-may-not-be-ready.txt", "jsonld": "https://wpnews.pro/news/ai-hackers-are-getting-faster-the-government-may-not-be-ready.jsonld"}}