cd /news/ai-policy/closing-federal-security-gaps-in-an-… · home topics ai-policy article
[ARTICLE · art-105143] src=nextgov.com ↗ pub= topic=ai-policy verified=true sentiment=· neutral

Closing federal security gaps in an era of AI-enabled attacks

Government agencies face heightened risk from AI-enabled attacks that compress the time between intrusion and impact, yet many still manage IT, cybersecurity, data, and AI through separate leadership structures, according to a commentary urging alignment. The piece cites the National Cyber Strategy and a June 2026 executive order on AI as policy pushes, and recommends auditing AI attack surfaces, mandating recovery testing, and deploying autonomous self-healing architecture to build resilience.

read4 min views1 publishedAug 20, 2026
Closing federal security gaps in an era of AI-enabled attacks
Image: Nextgov (auto-discovered)

COMMENTARY | Agencies that align IT, security, data and AI leadership can be prepared for the speed and scale of tomorrow’s AI threats. #

AI-enabled attacks are shrinking the time between intrusion and operational impact. Yet many government agencies manage IT infrastructure, cybersecurity, data and artificial intelligence (AI) through separate leadership structures.

The organizational divide creates risk. When attackers target sensitive data and move at machine speed, agencies cannot afford fragmented decisions about how information is managed, protected and recovered. They also cannot afford a false sense of security on cyber resilience across silos.

Recent policy moves, including the National Cyber Strategy and a new executive order on AI, are pushing agencies in that direction. The challenge now is execution. Agencies that align IT, security and data leadership will be in a stronger position to limit damage and maintain operations as AI-driven threats continue to evolve.

**Closing security gaps between teams **

Government IT, security, data and AI leaders often operate with different priorities.

IT teams focus on availability. Security teams focus on reducing risk. Data and AI leaders focus on expanding access and accelerating adoption.

Attackers can exploit organizational gaps as effectively as technical vulnerabilities, especially when agencies don’t know they exist. Therefore, agencies should build cross-functional collaboration into their governance, architecture and operating processes from the beginning.

Shifting from prevention to recovery

No interconnected government environment can be made breach-proof, particularly as adversaries use automation to identify vulnerabilities and accelerate attacks.

Therefore, prevention and compliance do not equal security. Most breached organizations are compliant. True resilience means preparing for failure. Agencies should assume systems will crash, break or be hacked. They should design operations to withstand damage, restore trusted data and resume services quickly.

The strategic focus should expand beyond perimeter defense to include continuous preparation for compromise and rapid cyber recovery. Security teams should regularly test their technology and conduct exercises that evaluate how well their people and processes respond to an increasingly hostile cyber environment.

Furthermore, deploying AI without strict data governance multiplies internal risks. These models need dedicated incident response plans. For example, data poisoning corrupts training data to manipulate outputs. If security teams cannot trust the data, the AI becomes a liability.

AI cannot deliver reliable results without resilient data. Therefore, data resilience should become a foundation of responsible AI adoption.

Building a cyber recovery playbook

Government executives should treat data governance and recovery as strategic priorities rather than back-office IT functions.

Three actions can help agencies prepare for AI-enabled threats:

Audit and reduce the AI attack surface: Map data footprints. Before production, cyber defense and red teams should use threat modeling to evaluate deployment risks and secure underlying data integrity.Mandate recovery testing, not just prevention: Perimeter defenses fail. True resilience requires testing the ability to restore operations after data compromise. Run adversarial simulations to ask:Can we recover quickly from an active directory compromise?Can we recover this key system 10 times in a day? How do we validate that our backup data has not been impacted?

Deploy autonomous, self-healing architecture: Long-term survival requires shifting funding toward autonomous cyber recovery capabilities. The goal is to build self-healing environments that can isolate threats, purge compromised data and maintain operations.

Closing the gap through responsible AI governance

Agencies should reference the National Institute of Standards and Technology AI Risk Management Framework to map, measure, manage and govern AI risks, as well as The Cybersecurity and Infrastructure Security Agency's (CISA) CI Fortify initiative. CI Fortify helps critical infrastructure operators isolate networks and maintain essential services during severe cyberattacks.

Cross-functional AI oversight boards should include Chief Information Officers, Chief Information Security Officers, legal counsel and data leaders. Joint oversight can reduce shadow AI, clarify accountability and ensure security teams are involved before new systems connect to production environments.

Agencies should also establish authorized development environments where teams can test AI systems without exposing operational networks or sensitive data.

Cybersecurity success should not be measured by the absence of detecting attacks. The more meaningful test is whether an agency can protect trusted data, sustain critical services and recover before disruption becomes mission failure.

Agencies that align IT, security, data and AI leadership can be prepared for the speed and scale of tomorrow’s AI threats.

Travis currently serves as the Public Sector CTO at Rubrik helping organizations become more cyber and data resilient. Prior to Rubrik, Travis held several leadership roles including the Chief Technology and Strategy Officer at BluVector, CTO at Tychon, Federal CTO at FireEye, a Principal at Intel Security/McAfee and Leader at the Defense Information Systems Agency (DISA).

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of Rubrik.

NEXT STORY: CMMC Works. Now let’s sharpen it.

── more in #ai-policy 4 stories · sorted by recency
── more on @national cyber strategy 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/closing-federal-secu…] indexed:0 read:4min 2026-08-20 ·