{"id":137906,"date":"2026-08-12T22:03:10","date_gmt":"2026-08-12T22:03:10","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/137906\/"},"modified":"2026-08-12T22:03:10","modified_gmt":"2026-08-12T22:03:10","slug":"the-missing-component-of-government-ai-deployment-trust","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/137906\/","title":{"rendered":"The missing component of government AI deployment: Trust"},"content":{"rendered":"<p>At a recent AFCEA NOVA Naval IT Day, Marine Corps Chief Information Officer Colin Crosby didn\u2019t parse words when he\u00a0<a href=\"https:\/\/federalnewsnetwork.com\/ask-the-cio\/2026\/06\/5-initiatives-driving-the-marines-to-be-an-ai-first-force\/\" target=\"_blank\" rel=\"noopener nofollow\">described the Pentagon\u2019s direction<\/a>. The secretary of defense, he said, has directed the department to become \u201can AI-first warfighting force.\u201d<\/p>\n<p>In other words, artificial intelligence is not an add-on to existing strategies. It\u2019s a serious statement of intent, reflecting where the broader federal government is headed. The mandate is clear, but what often goes overlooked is what it actually takes to trust an AI system with the information that matters most: classified intelligence, mission-critical operational data, sensitive law enforcement records and more.<\/p>\n<p>When it comes to cybersecurity, both model performance and data privacy policy matter. But they don\u2019t address a more fundamental problem that stems from how AI computing actually works. Traditional cybersecurity has built strong protections for data at rest and data in transit. Encryption on disk and across the network is a problem that has been solved with mature standards. But more than any technology before it, AI introduces data in use, or the moment a model is actively processing information in memory.<\/p>\n<p>For commercial organizations, this might be a risk management concern. But for agencies trying to create an AI-first warfighting posture, it could be the difference between a system that can credibly handle classified or mission-critical data and one that cannot.<\/p>\n<p>]]><\/p>\n<p>A different kind of threat<br \/>A worst-case insider scenario for an AI system running on government infrastructure isn\u2019t necessarily a sophisticated external hack. It could be a system administrator with legitimate, elevated access to the infrastructure hosting an AI workload who uses that access to read what the model is processing in memory: the data, the model\u2019s internal computations, the output it just generated. Or it could be a\u00a0<a href=\"https:\/\/federalnewsnetwork.com\/commentary\/2026\/05\/when-ai-becomes-the-insider-rethinking-federal-risk-in-2026\/\" target=\"_blank\" rel=\"noopener nofollow\">compromised credential<\/a>\u00a0that grants an attacker the same administrative visibility as a legitimate insider.<\/p>\n<p>Neither scenario requires defeating a firewall or utilizing malware in any conventional sense. The access is, in a strict technical sense, \u201clegitimate.\u201d Administrative privilege is supposed to allow a system administrator to inspect the systems they manage. The problem is that on most infrastructure today, \u201cinspecting the system\u201d and \u201creading the sensitive data an AI model is actively processing\u201d are the same action, because that data exists in plaintext in memory the moment computation begins.<\/p>\n<p>So for commercial enterprises, this could be a serious risk, but for government agencies operating in classified or otherwise restricted environments, it should be disqualifying. An intelligence analysis workflow or a weapons system AI component can\u2019t rely on the assumption that every administrator with system access will behave appropriately or that every credential will remain uncompromised. The consequences of being wrong are too significant.<\/p>\n<p>Air-gapped environments don\u2019t fully solve the problem<br \/>A natural instinct is to address sensitive AI workloads by isolating them with air-gapped networks, no external connectivity and tightly controlled physical access. All of this is necessary, but it\u2019s not sufficient on its own.<\/p>\n<p>An air gap addresses network-based attacks, but not what happens inside the system once someone with legitimate or compromised access is standing in front of it. A system with no internet connection can still be accessed by an administrator with a console login, for example. The air gap is a perimeter control, but has no say in whether the data inside that perimeter is protected from the people and systems operating within it.<\/p>\n<p>This is the gap modern hardware-based security approaches are designed to close. They\u2019re gaining particular traction in defense and intelligence, which have always taken insider risk and credential compromise threats seriously.<\/p>\n<p>Hardware as the root of trust<br \/>Architectures are evolving, shifting trust from software-driven policy to the silicon itself. Modern processors, including specialized chips from the major manufacturers used in AI infrastructure, support what are known as trusted execution environments (TEEs): physically isolated regions of the processor where code and data are processed while remaining encrypted in memory, even during active computation. Inside one of these protected environments, the host operating system, a hypervisor managing the underlying virtualized infrastructure, or even an administrator with full system privileges and every credential available can\u2019t read the contents.<\/p>\n<p>]]><\/p>\n<p>This directly addresses the rogue administrator and compromised credential scenarios. Even if an attacker obtains every level of access a system theoretically allows, there\u2019s still a category of access the hardware itself will not grant to anyone, including the system\u2019s own infrastructure operators.<\/p>\n<p>The second component that makes this work is cryptographic attestation, in which the hardware generates a signed report proving its own identity, the integrity of the firmware, and the exact software running inside the protected environment before any sensitive data or cryptographic key is released to it. This report is signed using a key embedded in the actual chip itself, meaning it cannot be forged at the software level. A relying party, whether an automated policy system or a human security officer, can independently verify the report and mathematically confirm that the environment is exactly what it claims to be.<\/p>\n<p>For agencies that must obtain an authorizing official\u2019s approval before a system can process classified information, this distinction is important. Conventional security controls are typically demonstrated through documentation and periodic audits. Attestation produces even better evidence: a continuously generated, tamper-evident, hardware-signed record of what was running, in what state, at the moment sensitive data was processed. That is a much stronger basis for an\u00a0authorization decision\u00a0than a policy document saying the right controls are in place.<\/p>\n<p>The agencies that verify will lead in AI<\/p>\n<p>Federal agencies don\u2019t need to choose between deploying capable AI systems and maintaining the security posture their missions require. The technical foundation to do both exists: hardware-enforced isolation to protect data during active computation, cryptographic attestation for verifiable proof, and architectures designed to operate without external connectivity when the mission demands it.<\/p>\n<p>What\u2019s needed is a clearer understanding that data in use is a distinct and serious category of risk, separate from the protections for data at rest and in transit that most security programs were built around. As AI moves deeper into the systems supporting national security and other classified missions, establishing that the underlying infrastructure can be verified, not just trusted, will define mission-ready deployments.<\/p>\n<p>The agencies that build verification into their AI architecture now, rather than retrofitting it later, will be best positioned to bring the most capable AI systems to the missions that matter.<\/p>\n<p>Anand Kashyap is CEO and co-founder of Fortanix.<\/p>\n<p>]]><\/p>\n<p class=\"article-copyright\">Copyright<br \/>\n                            \u00a9\u00a02026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.\n                    <\/p>\n","protected":false},"excerpt":{"rendered":"At a recent AFCEA NOVA Naval IT Day, Marine Corps Chief Information Officer Colin Crosby didn\u2019t parse words&hellip;\n","protected":false},"author":2,"featured_media":69467,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,68129,25,41117,68130,46440,68131],"class_list":["post-137906","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-anand-kashyap","tag-artificial-intelligence","tag-colin-crosby","tag-credential-and-access-management","tag-cryptography","tag-fortanix"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/137906","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=137906"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/137906\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/69467"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=137906"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=137906"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=137906"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}