A new generation of agentic AI systems can find and exploit vulnerabilities in computer systems faster than human hackers, and the U.S. government has moved to limit or pause the public release of these models. The technology arrives just as the agencies responsible for defending federal networks have been cut back, leaving government cloud systems - which hold vast stores of sensitive data and critical services - exposed to a new scale of automated attack.
Agency cuts cloud the response
The Cybersecurity and Infrastructure Security Agency (CISA) is operating with a fraction of its former staff after major cuts. The General Services Administration's FedRAMP office, which sets security review standards for cloud providers like Amazon Web Services, Google, Microsoft, and Palantir, has also been reformulated and slimmed down under the Trump administration. Four former government officials told Fast Company that preparing for the risks posed by AI agents will remain a major challenge.
A former federal chief information officer said, "I'd be a lot more confident about all of this if the Trump administration hadn't forced out so many of the best IT and cyber professionals at CISA and other agencies."
Guidance and new requirements take shape
CISA has issued guidance on AI-related threats, and the FedRAMP office has spent the past year revising its requirements for technology companies that host or interact with government cloud services. A government spokesperson said that "federal agencies' cloud services meet rigorous security standards and are continuously tested as cybersecurity threats evolve, especially AI and agentic systems." The revised requirements include new reporting obligations, and the office expects to add more in the coming months.
For security teams inside government, keeping pace with these changes is increasingly urgent. Specialized training resources such as AI for Cybersecurity Analysts help professionals build the skills to assess and respond to automated threats.
Commodity attacks will scale fast
The former CIO's biggest concern is the scale of attacks that agentic AI makes possible. High-profile incidents - like an OpenAI agent independently breaking into Hugging Face's systems - draw attention, but the more immediate danger comes from simpler, AI-powered commodity attacks. These are typically spear-phishing campaigns or attempts to find weaknesses in multifactor authentication that a reasonably skilled human could execute, but that are normally constrained by time.
"AI removes the constraints around skill and time," the former federal CIO said. Some agencies are better prepared than others, but the overall threat surface is expanding quickly.
Why this matters for government professionals
The government's cloud systems hold everything from citizen data to national security information, and they are prime targets for hackers. With agentic AI lowering the barrier to attack, the same tools that limit public release of powerful models will not stop determined adversaries from using similar capabilities. Government IT and security teams are now operating with fewer experienced colleagues while facing a larger, faster-moving threat. The quality of agency preparation - and the speed of adopting new FedRAMP requirements - will determine how well federal networks hold up.
Your membership also unlocks: