Agencies Need Real-Time Visibility to Keep Pace With AI Risks
Officials say static inventories cannot keep pace with AI and are calling for continuous monitoring and stronger risk management.
Cybersecurity officials urged agencies to strengthen visibility into their systems as artificial intelligence becomes increasingly embedded across the federal technology ecosystem.
Nick Marinos, managing director for cybersecurity and IT at the Government Accountability Office (GAO), said many agencies still lack a comprehensive understanding of their AI inventories.
That lack of visibility creates cybersecurity risks because agencies can only protect the systems and technologies they know are operating within their environments.
Since 2022, agencies have been required to report their AI use cases. Marinos cited a 2024 GAO report in which they spoke with federal agencies about this effort. Agency officials were not confident in the final numbers they reported because of industry’s rapid push to include AI in their products and services.
The accelerated adoption of AI from industry meant that some companies added AI tools to software automatically, which is difficult for agencies to track, he added.
The Office of Management and Budget (OMB) as a part of updates to the 2025 inventory created the new category, consolidated reporting, for the limited set of common tasks that rely on commercial off-the-shelf (COTS) products.
OMB said the added category results from the increased integration of AI into software applications. By creating this new category, OMB aims to keep burdens associated with inventorying low so agencies can focus on high-impact applications. Marinos said this return to risk management fundamentals is what agencies should focus on as AI adoption grows.
“Overlaying those foundational elements of knowing what it takes to manage risk, not eliminate it, is where we should focus,” said Marinos. “If you look at a lot of the AI safety bills, it’s really more about stepping away from thinking that ‘we’re going to address all the vulnerabilities,’ and more so thinking ‘how can we close the [gap] as much as possible.’ Then, we need to think about how can we quickly respond when there is an incident, too.”
Those inventories, however, are not dynamic. Agencies need dynamic inventories that are continuously updated and monitored in near real time, said Willie Hicks, global field CTO at Dynatrace. Static inventories updated only once or twice a year cannot keep pace with the speed at which AI technologies and threats are evolving.
“AI is changing by the hour. Agencies must have a very strong lens into what those AI agents and AI models are doing,” said Hicks. “You have to have observability and visibility into that. There is a lot of room for improvement because I think we’re really focused on building those AI lists, and not really looking deeply into what the AI itself is doing.”
National Institute of Standards and Technology (NIST) Cybersecurity Lead Victoria Yan Pillitteri said agencies should consider how existing risk management practices can address the challenges of securing AI.
“We have to consider what that new risk profile is, what are the new threat surfaces, what new attacks could be as a result,” said Pillitteri. “We are building the airplane as we are flying it, which is why in a lot of our work at NIST, we both provide a current best practice and our methodology.”
Pillitteri and Marinos also emphasized that collaboration and information sharing among federal agencies and industry partners will be critical to managing emerging AI risks.
“If industry isn’t talking, or if the government isn’t trying to facilitate that communication, then as a nation, we aren’t well prepared to protect,” said Marinos.
Doppel Field CTO Dylan DeAnda said agencies must adopt a more collaborative mindset and share threat information with federal and industry partners.
“Accountability, enforcement, standards and telemetry — all of those things should be coming together in a concert-like effect, as well as at the sub-layers or the substrates where you’ve got the operational and tactical teams that are doing the mission day to day,” said DeAnda. “You need to see that entire overview to understand how the battlefield is shaping around you.”
This is a carousel with manually rotating slides. Use Next and Previous buttons to navigate or jump to a slide with the slide dots
-
GSA Reveals PQC Priorities to Secure Identity Management
Following a White House executive order, GSA's PQC priorities tackle digital identity and building access systems from quantum threats.
2m read -
What Battery Recycling Could Tell Us About AI's Role in Experimentation
A Genesis Mission project tests how AI agents can reduce physical experiments and accelerate critical mineral recovery from used batteries.
4m read -
AI Summit
The 2027 AI Summit convenes government and industry leaders to examine the next generation of artificial intelligence shaping federal missions.
Washington, D.C. -
Federal AI Forum 2027
The Federal AI Forum 2027 brings together federal AI leaders for an AI in government conference on responsible AI, data and workforce readiness.
Reston, VA