# Closing federal security gaps in an era of AI-enabled attacks

> Source: <https://www.nextgov.com/ideas/2026/08/closing-federal-security-gaps-era-ai-enabled-attacks/415549/>
> Published: 2026-08-20 20:30:00+00:00

# Closing federal security gaps in an era of AI-enabled attacks

## COMMENTARY | Agencies that align IT, security, data and AI leadership can be prepared for the speed and scale of tomorrow’s AI threats.

AI-enabled attacks are shrinking the time between intrusion and operational impact. Yet many government agencies manage IT infrastructure, cybersecurity, data and artificial intelligence (AI) through separate leadership structures.

The organizational divide creates risk. When attackers target sensitive data and move at machine speed, agencies cannot afford fragmented decisions about how information is managed, protected and recovered. They also cannot afford a false sense of security on cyber resilience across silos.

Recent policy moves, including the [National Cyber Strategy ](https://www.whitehouse.gov/wp-content/uploads/2026/03/president-trumps-cyber-strategy-for-america.pdf)and [a new executive order on AI,](https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/) are pushing agencies in that direction. The challenge now is execution. Agencies that align IT, security and data leadership will be in a stronger position to limit damage and maintain operations as AI-driven threats continue to evolve.

**Closing security gaps between teams **

Government IT, security, data and AI leaders often operate with different priorities.

IT teams focus on availability. Security teams focus on reducing risk. Data and AI leaders focus on expanding access and accelerating adoption.

Attackers can exploit organizational gaps as effectively as technical vulnerabilities, especially when agencies don’t know they exist. Therefore, agencies should build cross-functional collaboration into their governance, architecture and operating processes from the beginning.

**Shifting from prevention to recovery**

No interconnected government environment can be made breach-proof, particularly as adversaries use automation to identify vulnerabilities and accelerate attacks.

Therefore, prevention and compliance do not equal security. Most breached organizations are compliant. True resilience means preparing for failure. Agencies should assume systems will crash, break or be hacked. They should design operations to withstand damage, restore trusted data and resume services quickly.

The strategic focus should expand beyond perimeter defense to include continuous preparation for compromise and rapid cyber recovery. Security teams should regularly test their technology and conduct exercises that evaluate how well their people and processes respond to an increasingly hostile cyber environment.

Furthermore, deploying AI without strict data governance multiplies internal risks. These models need dedicated incident response plans. For example, data poisoning corrupts training data to manipulate outputs. If security teams cannot trust the data, the AI becomes a liability.

AI cannot deliver reliable results without resilient data. Therefore, data resilience should become a foundation of responsible AI adoption.

**Building a cyber recovery playbook**

Government executives should treat data governance and recovery as strategic priorities rather than back-office IT functions.

Three actions can help agencies prepare for AI-enabled threats:

**Audit and reduce the AI attack surface:** Map data footprints. Before production, cyber defense and red teams should use threat modeling to evaluate deployment risks and secure underlying data integrity.**Mandate recovery testing, not just prevention:** Perimeter defenses fail. True resilience requires testing the ability to restore operations after data compromise. Run adversarial simulations to ask:*Can we recover quickly from an active directory compromise?**Can we recover this key system 10 times in a day?** How do we validate that our backup data has not been impacted?*

**Deploy autonomous, self-healing architecture:** Long-term survival requires shifting funding toward autonomous cyber recovery capabilities. The goal is to build self-healing environments that can isolate threats, purge compromised data and maintain operations.

**Closing the gap through responsible AI governance**

Agencies should reference the [National Institute of Standards and Technology AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) to map, measure, manage and govern AI risks, as well as The Cybersecurity and Infrastructure Security Agency's (CISA)[ CI Fortify ](https://www.cisa.gov/topics/industrial-control-systems/ci-fortify)initiative. CI Fortify helps critical infrastructure operators isolate networks and maintain essential services during severe cyberattacks.

Cross-functional AI oversight boards should include Chief Information Officers, Chief Information Security Officers, legal counsel and data leaders. Joint oversight can reduce shadow AI, clarify accountability and ensure security teams are involved before new systems connect to production environments.

Agencies should also establish authorized development environments where teams can test AI systems without exposing operational networks or sensitive data.

Cybersecurity success should not be measured by the absence of detecting attacks. The more meaningful test is whether an agency can protect trusted data, sustain critical services and recover before disruption becomes mission failure.

Agencies that align IT, security, data and AI leadership can be prepared for the speed and scale of tomorrow’s AI threats.

*Travis currently serves as the Public Sector CTO at Rubrik helping organizations become more cyber and data resilient. Prior to Rubrik, Travis held several leadership roles including the Chief Technology and Strategy Officer at BluVector, CTO at Tychon, Federal CTO at FireEye, a Principal at Intel Security/McAfee and Leader at the Defense Information Systems Agency (DISA).*

*The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of Rubrik.*

**NEXT STORY:**
[
CMMC Works. Now let’s sharpen it.
](/ideas/2026/08/cmmc-works-now-lets-sharpen-it/415465/?oref=ng-next-story)
