<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:nb="https://www.newsbreak.com/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Nextgov/FCW - All Content</title><link>https://www.nextgov.com/</link><description>Federal technology and cybersecurity news and best practices.</description><atom:link href="https://www.nextgov.com/rss/all/" rel="self"></atom:link><language>en-us</language><lastBuildDate>Fri, 21 Aug 2026 16:38:00 -0400</lastBuildDate><item><title>Compliance theater is over: What FedRAMP 20x means for every vendor selling to government</title><link>https://www.nextgov.com/ideas/2026/08/compliance-theater-over-what-fedramp-20x-means-every-vendor-selling-government/415580/</link><description>COMMENTARY | Attacks now move faster than human-paced patch cycles can keep up with and a compliance program built around periodic reviews will not catch them.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Hemant Baidwan</dc:creator><pubDate>Fri, 21 Aug 2026 16:38:00 -0400</pubDate><guid>https://www.nextgov.com/ideas/2026/08/compliance-theater-over-what-fedramp-20x-means-every-vendor-selling-government/415580/</guid><category>Ideas</category><content:encoded>&lt;![CDATA[&lt;p&gt;Pete Waterman &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/after-hugging-face-breach-fedramp-chief-tells-slow-patch-vendors-stay-out-government/414972/?oref=ng-skybox-hp"&gt;did not mince words&lt;/a&gt; at Carahsoft&amp;#39;s FedRAMP Summit last month. Speaking about vendors that claim they lack the resources to fix a known, exploitable vulnerability within days, the FedRAMP director said plainly he does not want them in the federal marketplace. After nearly two decades building and authorizing systems for federal customers, I cannot remember the last time a FedRAMP official drew a line that clearly. It is the right line and well overdue.&lt;/p&gt;

&lt;p&gt;Waterman&amp;#39;s warning was not out of the clear blue as he pointed directly to the recent Hugging Face incident in which AI models operating in a sealed test environment found an unknown flaw, escaped the environment and used stolen credentials to reach a production system before anyone caught it. The lesson is the one the vendor community needs to hear. Attacks now move faster than human-paced patch cycles can keep up with and a compliance program built around periodic reviews will not catch them.&lt;/p&gt;

&lt;p&gt;Waterman&amp;#39;s comments are a direct challenge to how many government software vendors are still organized with security functioning as a separate review layer that evaluates work after it ships rather than alongside it.&lt;/p&gt;

&lt;p&gt;There is a version of FedRAMP authorization that treats compliance as a paperwork exercise. A security team writes policy while a separate engineering team ships code, and a Plan of Actions and Milestones, the government&amp;#39;s formal document for tracking open security issues, gets worked down once a quarter when someone remembers to look at it. Waterman named this directly, saying vendors will not meet the government&amp;#39;s expectations if compliance staff sit apart from the engineers who build and maintain the product.&lt;/p&gt;

&lt;p&gt;The FedRAMP 20x vulnerability detection and response requirements are specific. Providers are expected to begin reducing risk from serious, internet-facing vulnerabilities within two to four days depending on severity. The system&amp;#39;s security state must be verified at least every three days. Under the current baseline, that means responding to findings on hard timelines and not whenever the next release cycle comes through. None of that is achievable on a quarterly schedule. It is only achievable if the team shipping your product is the same team fixing your security findings.&lt;/p&gt;

&lt;p&gt;Continuous authorization requires continuous delivery. If your infrastructure is defined as code, your software containers are scanned on every build and your deployment pipeline can push a fix to production the same day a critical finding lands, then you are not choosing between moving fast and staying compliant. The pipeline becomes part of the security control itself.&lt;/p&gt;

&lt;p&gt;In practice, this means three things:&lt;/p&gt;

&lt;ol&gt;
	&lt;li aria-level="1"&gt;&lt;strong&gt;Automated, frequent scanning.&lt;/strong&gt; Production environments need to be scanned regularly, with findings routed directly to the engineering team responsible for the fix and not into a queue that a compliance analyst reviews weeks later.&lt;/li&gt;
	&lt;li aria-level="1"&gt;&lt;strong&gt;The deployment pipeline as the system of record for change management. &lt;/strong&gt;Modern automated deployment tools are not obstacles to federal change control requirements. When properly configured they generate the exact evidence trail those requirements ask for.&lt;/li&gt;
	&lt;li aria-level="1"&gt;&lt;strong&gt;Deadline-driven remediation, not calendar-driven remediation.&lt;/strong&gt; Critical findings get worked against hard timelines. If a vendor cannot sustain that pace then the conversation needs to happen before a system goes live and not after.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Vendors who will struggle with FedRAMP 20x are the ones treating security as a gate at the end of the process. Those who will succeed treat the pipeline itself as the control where every code change gets scanned, every container gets verified and every fix ships through the same automated path as every new feature.&lt;/p&gt;

&lt;p&gt;The practical guidance coming out of last month&amp;#39;s event&amp;nbsp;is straightforward. Audit your patching timeline now! If your process for moving a critical fix from discovery to production takes more than two to four days that gap needs to close before FedRAMP 20x enforcement tightens further. That is not a future-state problem. It is a today problem,&amp;nbsp;and the Hugging Face incident is the clearest evidence yet of why it matters.&lt;/p&gt;

&lt;p&gt;FedRAMP authorization built on a modern automated delivery foundation is not just faster to achieve. It is the only version of authorized that will hold up against threats moving at machine speed.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Hemant Baidwan is the Chief Information Security Officer at Knox Systems, where he leads enterprise cybersecurity strategy and the development of AI-driven, cloud-native security platforms. Previously, he served as the CISO and Acting Deputy Chief Information Officer at the U.S. Department of Homeland Security (DHS), where he was responsible for securing one of the largest and most complex civilian federal environments.&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/21/GettyImages_2204596345/large.jpg" width="618" height="284"><media:credit>Javier Ghersi/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/21/GettyImages_2204596345/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Tech bills of the week: Overseeing algorithm-set rental prices; and halting federal overreach in data center construction</title><link>https://www.nextgov.com/policy/2026/08/tech-bills-week-overseeing-algorithm-set-rental-prices-and-halting-federal-overreach-data-center-construction/415569/</link><description>Legislation introduced this week seeks to police the use of algorithmic price-setting for home rentals and rein in how the federal government influences new data center construction.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alexandra Kelley</dc:creator><pubDate>Fri, 21 Aug 2026 15:33:00 -0400</pubDate><guid>https://www.nextgov.com/policy/2026/08/tech-bills-week-overseeing-algorithm-set-rental-prices-and-halting-federal-overreach-data-center-construction/415569/</guid><category>Policy</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;strong&gt;Monitoring algorithms used in setting rent&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A new bill seeks to compel any entity&amp;nbsp;creating rental rates to reveal when algorithms are involved in setting prices for home rentals by leveraging the authorities of the Federal Trade Commission.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.congress.gov/bill/119th-congress/house-bill/10110/text"&gt;The Housing Price Transparency Act&lt;/a&gt;, introduced by Rep. Kathy Castor, D-Fla., on Monday, requires firms and organizations overseeing home rental prices to report their use of pricing algorithms that aid in developing, determining and setting housing and rental costs.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The bill would apply existing restrictions stipulated in the Federal Trade Commission Act to algorithmic rental price setting. Violations of the bill, or failure to disclose the use of algorithms in rental prices, would fall under section 18(a)(1)(B) surrounding &amp;ldquo;unfair or deceptive acts or practices.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Recourse is also offered to victims of such violations. States are eligible to bring a civil action on behalf of the plaintiffs and seek damages, restitution or other compensation. The FTC itself is also granted the right to enforce the bill&amp;rsquo;s provisions.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Limiting federal, lawmaker influence over new data centers&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Rep. Tom Barrett, R-Mich., introduced two bills&amp;nbsp;on Thursday that look to grant states more autonomy in new data center construction as part of the AI compute boom, focusing on preventing the federal government from overriding local zoning laws and ensuring lawmaker transparency.&lt;/p&gt;

&lt;p&gt;The &lt;a href="https://barrett.house.gov/sites/evo-subsites/barrett.house.gov/files/evo-media-document/protecting-local-control-of-data-centers-act.pdf"&gt;Protecting Local Control of Data Centers Act&lt;/a&gt; focuses on prohibiting federal agencies from overriding state and local land-use zoning and permitting laws related to data centers. Federal agencies would also not be able to use federal funds allocated towards data center construction to force state and local governments to surrender their authority.&lt;/p&gt;

&lt;p&gt;The &lt;a href="https://barrett.house.gov/sites/evo-subsites/barrett.house.gov/files/evo-media-document/no-data-center-ndas-act.pdf"&gt;No Data Center NDAs Act&lt;/a&gt; targets lawmakers who have signed non-disclosure agreements related to data center operations. Under the proposal, sitting lawmakers would not be able to sign NDAs that prohibit the discussion of possible or planned data center locations and resource consumption. Should this bill be passed into law, the House Ethics Committee and the Select Committee on Ethics of the Senate would both be tasked with implementing and overseeing the new NDA restrictions.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Families in my district are rightly concerned about the effect data centers could have on their utility bills, as well as the land and water in their neighborhood. They deserve to know all the facts and have the final say over any proposed project,&amp;rdquo; Barrett &lt;a href="https://barrett.house.gov/media/press-releases/barrett-introduces-bills-protect-local-communities-data-center-overreach"&gt;said in a press release&lt;/a&gt;. &amp;ldquo;That starts with stopping federal overreach and preventing the secrecy pledges that have plagued Michigan and undermined the power of local residents.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/21/GettyImages_1399560076/large.jpg" width="618" height="284"><media:credit>Jarmo Piironen/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/21/GettyImages_1399560076/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Counties and cities sue over counterterrorism grant rule changes</title><link>https://www.nextgov.com/defense/2026/08/counties-and-cities-sue-over-counterterrorism-grant-rule-changes/415574/</link><description>The four local governments said the Department of Homeland Security’s efforts to tie the grants to election security measures were unconstitutional, as states run elections, not the feds.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Chris Teale</dc:creator><pubDate>Fri, 21 Aug 2026 13:00:00 -0400</pubDate><guid>https://www.nextgov.com/defense/2026/08/counties-and-cities-sue-over-counterterrorism-grant-rule-changes/415574/</guid><category>Defense</category><content:encoded>&lt;![CDATA[&lt;p&gt;A group of four cities and counties announced a lawsuit &lt;a href="https://protectdemocracy.org/work/protecting-public-safety-and-the-integrity-of-u-s-elections/"&gt;this week&lt;/a&gt; challenging the Trump administration&amp;rsquo;s efforts to tie counterterrorism grants to election rule changes.&lt;/p&gt;

&lt;p&gt;Harris and El Paso Counties in Texas; the Metropolitan Government of Nashville and Davidson County, Tennessee; and the City of Columbus, Ohio announced they would sue the Department of Homeland Security in federal court over its announcement &lt;a href="https://www.route-fifty.com/public-safety/2026/07/feds-tie-counterterrorism-grants-election-security-measures/414774/"&gt;last month&lt;/a&gt; that states must implement various election security measures before they can receive homeland security grants.&lt;/p&gt;

&lt;p&gt;The announcement from the Federal Emergency Management Agency came in its funding opportunity for the $1 billion Homeland Security Grant Program and said states would need to take what FEMA called &amp;ldquo;critical, common-sense steps to protect U.S. elections,&amp;rdquo; to receive funds.&lt;/p&gt;

&lt;div class="related-articles-placeholder"&gt;[[Related Posts]]&lt;/div&gt;

&lt;p&gt;Those steps included submitting a plan to use hand-marked paper ballots; a manual audit of at least 5% of all ballots cast after every federal election; reconciling the number of voters who participated in each federal election with the number of ballots cast; and using the U.S. Citizenship and Immigration Services&amp;rsquo; Systematic Alien Verification for Entitlements system to verify the citizenship status of everyone listed in the state voter registration database and those who work at polling places or operating election systems.&lt;/p&gt;

&lt;p&gt;Local leaders said those requirements were unconstitutional and unacceptable, especially as they could result in FEMA holding onto 20% of a state&amp;rsquo;s award under the grant program, or even cancelling an award altogether.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Local election offices already face some of the toughest oversight and requirements designed to keep their operations safe and secure,&amp;rdquo; El Paso County Attorney Christina Sanchez said in a statement. &amp;ldquo;Imposing additional requirements is both costly and burdensome, while our law enforcement agencies rely on this funding to purchase critical equipment that helps protect and save lives.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://protectdemocracy.org/wp-content/uploads/2026/08/DHS-Complaint.pdf"&gt;The lawsuit&lt;/a&gt;, filed in U.S. District Court in Washington, D.C., said FEMA&amp;rsquo;s conditions are arbitrary and illegal and violate both the Administrative Procedure Act and the Constitutional separation of powers. The complaint notes that Congress, not the executive branch, has exclusive authority to set the terms of federal spending, and that the states and Congress, not the executive branch, have the power to make rules for federal elections.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Congress did not create the [grant program] to empower the federal government to control state and local election procedures,&amp;rdquo; the complaint says. &amp;ldquo;Yet the Administration has now hijacked the program to do just that.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The plaintiffs also argued that the new conditions on grant funding could throw the upcoming midterm elections into &amp;ldquo;chaos.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;FEMA has offered no reasoned explanation for how overhauling state election administration serves HSGP&amp;rsquo;s counterterrorism mission, and it has ignored the legal, financial, and logistical chaos these conditions will inflict on state and local governments that are suddenly told &amp;mdash; only months before an election &amp;mdash; that they must transform how their elections are run,&amp;rdquo; the complaint says.&lt;/p&gt;

&lt;p&gt;This latest gambit from FEMA to influence election administration comes as Republicans in Congress have tried and failed to pass the SAVE America Act, which would codify many of these same rules and others. President Donald Trump has also &lt;a href="https://www.route-fifty.com/people/2026/07/trump-empties-out-election-commission-leadership-just-months-midterms/414721/"&gt;fired two members&lt;/a&gt; of the Election Assistance Commission while another resigned, and the Trump administration has &lt;a href="https://www.route-fifty.com/people/2026/02/cowards-state-leaders-condemn-trump-admin-election-actions/411119/"&gt;taken legal action&lt;/a&gt; to try to obtain voter data from secretaries of state, though it has so far been &lt;a href="https://www.democracydocket.com/news-alerts/judge-tosses-justice-department-maryland-voter-roll-lawsuit-0-9/"&gt;unsuccessful in court&lt;/a&gt; against states opposed to those measures.&lt;/p&gt;

&lt;p&gt;The administration also &lt;a href="https://www.route-fifty.com/cybersecurity/2026/05/senator-warns-cisa-election-security-pullback-could-leave-midterms-vulnerable/413385/"&gt;cut staff&lt;/a&gt; at the Cybersecurity and Infrastructure Security Agency and &lt;a href="https://www.route-fifty.com/cybersecurity/2026/02/its-not-over-cyber-info-sharing-center-begins-next-chapters-after-losing-federal-funding/411633/"&gt;ended federal funding&lt;/a&gt; for the Elections Infrastructure Information Sharing and Analysis Center. The move to tie grant funding to election-related demands has echoes of an executive order Trump &lt;a href="https://www.whitehouse.gov/presidential-actions/2025/03/preserving-and-protecting-the-integrity-of-american-elections/"&gt;signed last year&lt;/a&gt; that sought to impose documentary proof of citizenship requirements and restrict mail-in ballots. A U.S. District Court has since issued a permanent injunction against major provisions of that order.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;This partisan pushback is nothing new,&amp;rdquo; a FEMA spokesperson said in an email. &amp;ldquo;We fully expected opposition to common-sense measures designed to protect election security and safeguard the integrity of American democracy. Election security is national security, and protecting our critical infrastructure remains a top priority for the Trump Administration. Concerns over voting processes, data security, and registration practices have made it clear that action is required. This year, states must take critical, common-sense steps to protect U.S. elections before receiving their full Homeland Security Grant Program awards. These new requirements will preserve election integrity.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The complaint against FEMA&amp;rsquo;s new rules urges the judge to declare them unlawful and unenforceable and prevent the agency and DHS from imposing election-related requirements on the counterterrorism grant program.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;FEMA has no authority to impose those conditions &amp;mdash; not under its governing statute and not under the Constitution,&amp;rdquo; the complaint says. &amp;ldquo;Congress authorized FEMA to help jurisdictions protect critical infrastructure from terrorist and cyberattacks. It did not authorize FEMA to decide who may vote, how ballots must be counted, or how states maintain their voter rolls. Never before has FEMA purported to regulate how states and counties run elections. Such a transformative assertion of federal authority in an area of traditional state control requires clear congressional authorization that FEMA does not have.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/21/20260821_Lawsuit_Melissa_Ross-2/large.jpg" width="618" height="284"><media:credit>Melissa Ross via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/21/20260821_Lawsuit_Melissa_Ross-2/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>House Democrats ask GAO to review CISA workforce cuts</title><link>https://www.nextgov.com/people/2026/08/house-democrats-ask-gao-review-cisa-workforce-cuts/415552/</link><description>Lawmakers want Congress’ watchdog to assess what capabilities were lost after the cyber agency shed roughly one-third of its staff.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Fri, 21 Aug 2026 08:00:00 -0400</pubDate><guid>https://www.nextgov.com/people/2026/08/house-democrats-ask-gao-review-cisa-workforce-cuts/415552/</guid><category>People</category><content:encoded>&lt;![CDATA[&lt;p&gt;Five House Democrats are asking Congress&amp;rsquo; investigative arm to examine how significant staffing cuts at the Cybersecurity and Infrastructure Security Agency have affected the government&amp;rsquo;s ability to defend federal networks and critical infrastructure.&lt;/p&gt;

&lt;p&gt;The lawmakers are calling on the Government Accountability Office &amp;mdash; the top congressional watchdog that audits and evaluates federal programs &amp;mdash; to examine the impact of personnel and program reductions enacted at CISA since President Donald Trump returned to the White House, according to a letter first seen by &lt;em&gt;Nextgov/FCW&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;The request, addressed to acting Comptroller General Orice Williams Brown, is led by Reps. James Walkinshaw, D-Va., Delia Ramirez, D-Ill., and Bennie Thompson, D-Miss., the ranking member on the House Homeland Security Committee. Ramirez is the top Democrat on the panel&amp;rsquo;s cybersecurity subcommittee, where Walkinshaw also serves. Reps. Seth Magaziner, D-R.I., and LaMonica McIver, D-N.J., who also serve on the cyber panel, joined the request.&lt;/p&gt;

&lt;p&gt;The lawmakers say CISA has lost nearly a third of its workforce &amp;ldquo;at precisely the moment when our adversaries are accelerating attacks against critical infrastructure,&amp;rdquo; leaving Congress without a clear picture of which capabilities were lost and whether remaining teams can keep pace with growing cyber and physical threats.&lt;/p&gt;

&lt;p&gt;The concerns have grown during the war with Iran, as CISA and the FBI help utilities navigate&lt;a href="https://www.nextgov.com/cybersecurity/2026/08/cisa-still-finds-water-system-controls-exposed-online-amid-multistate-hacks/415266/"&gt; cyberattacks affecting at least 12 states&lt;/a&gt; that some U.S. officials suspect may be tied to Tehran.&lt;/p&gt;

&lt;p&gt;The lawmakers are asking GAO to examine how CISA&amp;rsquo;s workforce has changed over the past five years, including its size, composition, geographic distribution and reliance on contractors. They also want the watchdog to identify which programs were affected by the reductions and what consequences CISA and its industry and government partners have reported.&lt;/p&gt;

&lt;p&gt;The letter further asks GAO to evaluate what data CISA uses to make workforce decisions and whether its human capital strategy aligns with its current and future mission needs.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Little is known about the impact of these workforce reductions on CISA&amp;rsquo;s programs and services,&amp;rdquo; the lawmakers write, arguing it&amp;rsquo;s unclear whether the agency is positioned to replace the skills it has lost.&lt;/p&gt;

&lt;p&gt;After this story was published, GAO spokesperson Sarah Kaczmarek confirmed receipt of the request and said the office &amp;ldquo;has a process it goes through to determine whether we do work and when, which we are working through right now.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;CISA is now attempting to rebuild parts of its workforce after layoffs, voluntary departures and other personnel actions reduced staffing from roughly 3,300 employees to about 2,200. Acting Director Nick Andersen has said the agency plans to hire about 330 people, while Homeland Security Secretary Markwayne Mullin has said CISA may need roughly 600 additional staff and that hiring could take a year or more.&lt;/p&gt;

&lt;p&gt;Walkinshaw &lt;a href="https://www.nextgov.com/people/2026/06/lawmaker-warns-administrations-fetishization-silicon-valley-startups/414516/"&gt;previously told&lt;/a&gt; &lt;em&gt;Nextgov/FCW&lt;/em&gt; that restaffing the agency would be &amp;ldquo;a very difficult thing to do,&amp;rdquo; noting that cyber personnel have seen colleagues pushed out and their work publicly criticized by administration officials.&lt;/p&gt;

&lt;p&gt;The workforce picture has also been complicated by internal DHS transfers. CISA&amp;rsquo;s former acting director&lt;a href="https://www.nextgov.com/people/2026/02/cisas-acting-chief-says-70-staff-were-reassigned-other-dhs-offices-last-year/411359/"&gt; told lawmakers in February&lt;/a&gt; that about 70 agency employees were reassigned to other DHS offices, while just over 30 moved into CISA.&lt;/p&gt;

&lt;p&gt;At the same time, the administration&amp;rsquo;s fiscal 2027 budget request calls for&lt;a href="https://www.nextgov.com/cybersecurity/2026/04/trump-proposes-cutting-cisa-election-security-program-fy27-budget/412672/"&gt; eliminating roughly 870 CISA positions&lt;/a&gt;, including cutting staff tied to election security, stakeholder engagement and workforce development. House appropriators have since&lt;a href="https://appropriations.house.gov/news/press-releases/committee-approves-fy27-homeland-security-appropriations-act"&gt; advanced a bill&lt;/a&gt; that would provide CISA with about $400 million more than the White House requested and set aside $31 million for critical hires. The measure has not received a House floor vote, and the Senate has not released its version, leaving the agency&amp;rsquo;s final funding and staffing levels unsettled.&lt;/p&gt;

&lt;p&gt;The cuts were part of the Trump administration&amp;rsquo;s broader push to&lt;a href="https://www.nextgov.com/cybersecurity/2025/06/cisa-projected-lose-third-its-workforce-under-trumps-2026-budget/405726/"&gt; shrink the federal workforce&lt;/a&gt;, but CISA has drawn particular scrutiny over its past election security work.&lt;/p&gt;

&lt;p&gt;That fight dates back to Trump&amp;rsquo;s first term, when he&amp;nbsp;&lt;a href="https://www.nextgov.com/cybersecurity/2025/04/former-cyber-official-chris-krebs-leave-sentinelone-bid-fight-trump-pressure/404634/"&gt;fired CISA&amp;rsquo;s first director, Chris Krebs&lt;/a&gt;, after Krebs rejected Trump&amp;rsquo;s false claims that the 2020 election had been stolen from him. Republicans have concurrently accused the agency of censoring conservative speech when it worked with social media platforms to flag election- and COVID-related misinformation in and around the 2020 race.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Editor&amp;#39;s note: This article has been updated to include comment from GAO.&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/20/GettyImages_2255714973/large.jpg" width="618" height="284"><media:description>Congressman James Walkinshaw (D-VA) speaks at a press conference with other Democratic members of House Homeland Security Committee outside the U.S. Capitol in Washington, DC on January 14, 2026.</media:description><media:credit>Nathan Posner/Anadolu via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/20/GettyImages_2255714973/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>VA boosts EHR modernization contract with Oracle by $17B</title><link>https://www.nextgov.com/modernization/2026/08/va-boosts-ehr-modernization-contract-oracle-17b/415548/</link><description>The modified agreement raises the contract’s total value to just under $27 billion.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Edward Graham</dc:creator><pubDate>Thu, 20 Aug 2026 16:36:00 -0400</pubDate><guid>https://www.nextgov.com/modernization/2026/08/va-boosts-ehr-modernization-contract-oracle-17b/415548/</guid><category>Modernization</category><content:encoded>&lt;![CDATA[&lt;p&gt;Oracle&amp;rsquo;s contract with the Department of Veterans Affairs for the agency&amp;rsquo;s new electronic health record system will increase by almost $17 billion as part of a modified agreement, according to an award notice &lt;a href="https://sam.gov/workspace/contract/opp/0817db124a424e0b840dacb2e18cdd7b/view"&gt;posted&lt;/a&gt; on SAM.gov on Wednesday.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;VA first contracted with Cerner in 2018 to upgrade its health record system. Oracle subsequently acquired Cerner in 2022 and rebranded the combined unit as Oracle Health.&lt;/p&gt;

&lt;p&gt;The announcement comes after VA &lt;a href="https://www.nextgov.com/modernization/2026/08/va-seeks-extend-its-oracle-health-record-contract-through-2031/415380/?oref=ng-author-river"&gt;published a notice last week&lt;/a&gt; detailing plans to extend its EHR modernization contract with Oracle for an additional three one-year optional ordering periods. The award increase will now bump up the contract&amp;rsquo;s total value from just under $10 billion to roughly $27 billion.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Specifically, this modification will increase the overall contract ceiling and extend the Period of Performance,&amp;rdquo; last week&amp;rsquo;s contract modification documents said. &amp;ldquo;This action is necessary to continue [electronic health record modernization] deployment activities and associated support services until all VA Medical Centers (VAMCs) and related facilities have fully transitioned to the EHR system.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The agency&amp;rsquo;s modernization project &amp;mdash; part of a broader federal effort to deploy a streamlined, interoperable EHR across VA, the Pentagon, the Coast Guard and the National Oceanic and Atmospheric Administration &amp;mdash; has been beset by cost overruns, technical glitches and usability concerns since the first software go live occurred in 2020.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Ongoing issues ultimately led to VA and Oracle renegotiating their contract in May 2023, with the deal being modified from an additional five-year term to five one-year terms. The latest modified agreement now has the ability to cover work through May 2031.&lt;/p&gt;

&lt;p&gt;VA said extending its agreement with Oracle was necessary because &amp;ldquo;unanticipated complexities&amp;rdquo; slowed software deployments, which resulted in the contract&amp;rsquo;s ceiling being reached &amp;ldquo;sooner than originally planned.&amp;rdquo; The agency added that it &amp;ldquo;anticipates using the remaining ceiling by the first quarter of fiscal year 2027.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;VA paused most deployments of the new EHR system in April 2023 to remedy the problems slowing software rollouts across its network of 164 medical facilities. The agency announced plans at the tail end of the Biden administration in December 2024 to restart system go-lives at four Michigan-based medical sites in mid-2026.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Current VA Secretary Doug Collins &amp;mdash; who has called the EHR modernization project a priority &amp;mdash; subsequently added nine additional medical facilities to VA&amp;rsquo;s 2026 deployment schedule, bringing the total number of site rollouts this year to 13. VA officials previously said they are hoping to finish EHR system deployments at every one of the agency&amp;rsquo;s medical facilities &lt;a href="https://www.nextgov.com/modernization/2025/06/va-official-touts-progress-ehr-modernization-project/406113/"&gt;by 2031&lt;/a&gt;.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/20/GettyImages_1689131337/large.jpg" width="618" height="284"><media:credit>Sven Hoppe/picture alliance via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/20/GettyImages_1689131337/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Closing federal security gaps in an era of AI-enabled attacks</title><link>https://www.nextgov.com/ideas/2026/08/closing-federal-security-gaps-era-ai-enabled-attacks/415549/</link><description>COMMENTARY | Agencies that align IT, security, data and AI leadership can be prepared for the speed and scale of tomorrow’s AI threats.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Travis Rosiek</dc:creator><pubDate>Thu, 20 Aug 2026 16:30:00 -0400</pubDate><guid>https://www.nextgov.com/ideas/2026/08/closing-federal-security-gaps-era-ai-enabled-attacks/415549/</guid><category>Ideas</category><content:encoded>&lt;![CDATA[&lt;p&gt;AI-enabled attacks are shrinking the time between intrusion and operational impact. Yet many government agencies manage IT infrastructure, cybersecurity, data and artificial intelligence (AI) through separate leadership structures.&lt;/p&gt;

&lt;p&gt;The organizational divide creates risk. When attackers target sensitive data and move at machine speed, agencies cannot afford fragmented decisions about how information is managed, protected and recovered. They also cannot afford a false sense of security on cyber resilience across silos.&lt;/p&gt;

&lt;p&gt;Recent policy moves, including the &lt;a href="https://www.whitehouse.gov/wp-content/uploads/2026/03/president-trumps-cyber-strategy-for-america.pdf"&gt;National Cyber Strategy &lt;/a&gt;and &lt;a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/"&gt;a new executive order on AI,&lt;/a&gt; are pushing agencies in that direction. The challenge now is execution. Agencies that align IT, security and data leadership will be in a stronger position to limit damage and maintain operations as AI-driven threats continue to evolve.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Closing security gaps between teams&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Government IT, security, data and AI leaders often operate with different priorities.&lt;/p&gt;

&lt;p&gt;IT teams focus on availability. Security teams focus on reducing risk. Data and AI leaders focus on expanding access and accelerating adoption.&lt;/p&gt;

&lt;p&gt;Attackers can exploit organizational gaps as effectively as technical vulnerabilities, especially when agencies don&amp;rsquo;t know they exist. Therefore, agencies should build cross-functional collaboration into their governance, architecture and operating processes from the beginning.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Shifting from prevention to recovery&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;No interconnected government environment can be made breach-proof, particularly as adversaries use automation to identify vulnerabilities and accelerate attacks.&lt;/p&gt;

&lt;p&gt;Therefore, prevention and compliance do not equal security. Most breached organizations are compliant. True resilience means preparing for failure. Agencies should assume systems will crash, break or be hacked. They should design operations to withstand damage, restore trusted data and resume services quickly.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The strategic focus should expand beyond perimeter defense to include continuous preparation for compromise and rapid cyber recovery. Security teams should regularly test their technology and conduct exercises that evaluate how well their people and processes respond to an increasingly hostile cyber environment.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Furthermore, deploying AI without strict data governance multiplies internal risks. These models need dedicated incident response plans. For example, data poisoning corrupts training data to manipulate outputs. If security teams cannot trust the data, the AI becomes a liability.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;AI cannot deliver reliable results without resilient data. Therefore, data resilience should become a foundation of responsible AI adoption.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Building a cyber recovery playbook&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Government executives should treat data governance and recovery as strategic priorities rather than back-office IT functions.&lt;/p&gt;

&lt;p&gt;Three actions can help agencies prepare for AI-enabled threats:&lt;/p&gt;

&lt;ul&gt;
	&lt;li aria-level="1"&gt;&lt;strong&gt;Audit and reduce the AI attack surface:&lt;/strong&gt; Map data footprints. Before production, cyber defense and red teams should use threat modeling to evaluate deployment risks and secure underlying data integrity.&lt;/li&gt;
	&lt;li aria-level="1"&gt;&lt;strong&gt;Mandate recovery testing, not just prevention:&lt;/strong&gt; Perimeter defenses fail. True resilience requires testing the ability to restore operations after data compromise. Run adversarial simulations to ask:
	&lt;ul&gt;
		&lt;li aria-level="2"&gt;&lt;em&gt;Can we recover quickly from an active directory compromise?&amp;nbsp;&lt;/em&gt;&lt;/li&gt;
		&lt;li aria-level="2"&gt;&lt;em&gt;Can we recover this key system 10 times in a day?&lt;/em&gt;&lt;/li&gt;
		&lt;li aria-level="2"&gt;&lt;em&gt;How do we validate that our backup data has not been impacted?&lt;/em&gt;&lt;/li&gt;
	&lt;/ul&gt;
	&lt;/li&gt;
	&lt;li aria-level="1"&gt;&lt;strong&gt;Deploy autonomous, self-healing architecture:&lt;/strong&gt; Long-term survival requires shifting funding toward autonomous cyber recovery capabilities. The goal is to build self-healing environments that can isolate threats, purge compromised data and maintain operations.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Closing the gap through responsible AI governance&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Agencies should reference the &lt;a href="https://www.nist.gov/itl/ai-risk-management-framework"&gt;National Institute of Standards and Technology AI Risk Management Framework&lt;/a&gt; to map, measure, manage and govern AI risks, as well as The Cybersecurity and Infrastructure Security Agency&amp;#39;s (CISA)&lt;a href="https://www.cisa.gov/topics/industrial-control-systems/ci-fortify"&gt; CI Fortify &lt;/a&gt;initiative. CI Fortify helps critical infrastructure operators isolate networks and maintain essential services during severe cyberattacks.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Cross-functional AI oversight boards should include Chief Information Officers, Chief Information Security Officers, legal counsel and data leaders. Joint oversight can reduce shadow AI, clarify accountability and ensure security teams are involved before new systems connect to production environments.&lt;/p&gt;

&lt;p&gt;Agencies should also establish authorized development environments where teams can test AI systems without exposing operational networks or sensitive data.&lt;/p&gt;

&lt;p&gt;Cybersecurity success should not be measured by the absence of detecting attacks. The more meaningful test is whether an agency can protect trusted data, sustain critical services and recover before disruption becomes mission failure.&lt;/p&gt;

&lt;p&gt;Agencies that align IT, security, data and AI leadership can be prepared for the speed and scale of tomorrow&amp;rsquo;s AI threats.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Travis currently serves as the Public Sector CTO at Rubrik helping organizations become more cyber and data resilient. Prior to Rubrik, Travis held several leadership roles including the Chief Technology and Strategy Officer at BluVector, CTO at Tychon, Federal CTO at FireEye, a Principal at Intel Security/McAfee and Leader at the Defense Information Systems Agency (DISA).&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of Rubrik.&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/20/GettyImages_2255930768/large.jpg" width="618" height="284"><media:credit>J Studios/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/20/GettyImages_2255930768/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>FDA considers doctor-like ‘competency-based’ tests for medical generative AI</title><link>https://www.nextgov.com/artificial-intelligence/2026/08/fda-considers-doctor-competency-based-tests-medical-generative-ai/415541/</link><description>The Trump administration released ideas for regulating large language models used in health care as companies roll out chatbots to help patients manage mental health, diabetes and other medical conditions.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christian Robles</dc:creator><pubDate>Thu, 20 Aug 2026 12:42:00 -0400</pubDate><guid>https://www.nextgov.com/artificial-intelligence/2026/08/fda-considers-doctor-competency-based-tests-medical-generative-ai/415541/</guid><category>Artificial Intelligence</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Food and Drug Administration wants the public to weigh in on whether chatbots should pass &amp;ldquo;competency-based&amp;rdquo; tests &amp;mdash; similar to exams doctors must take &amp;mdash; before they are marketed as medical devices.&lt;/p&gt;

&lt;p&gt;FDA&amp;rsquo;s medical device center &amp;ldquo;is considering a competency-based approach to premarket evaluation of GenAI-enabled devices that is also inspired, at a high level, by how human clinicians are evaluated and credentialed, but would be adapted for the technical, practical, and legal considerations applicable to the regulation of medical devices,&amp;ldquo; according to a &lt;a href="https://www.regulations.gov/document/FDA-2026-N-7874-0001"&gt;discussion draft&lt;/a&gt; the agency published Tuesday.&lt;/p&gt;

&lt;p&gt;FDA would test the final, user-facing generative AI product rather than foundational models and subcomponents, the agency wrote. The test would specifically check if the generative AI product &amp;ldquo;demonstrates the clinical knowledge, analytic capabilities, safety behavior, communication, and generalizability to support reasonable assurance of safety and effectiveness of the device for its intended use,&amp;rdquo; the agency added. The tests could involve scoring rubrics and expert adjudication.&lt;/p&gt;

&lt;p&gt;But the rigor of the tests would depend on the risk profile of a generative AI product, the FDA wrote. The product&amp;rsquo;s risk profile could take into account whether a product steers a user toward an action or provides information and the consequences of a user relying on a faulty generative AI output, according to a proposed FDA framework.&lt;/p&gt;

&lt;p&gt;Testing alone might not be sufficient, so FDA could also collect real-world evidence to ensure a generative AI product is working as intended, according to the discussion paper.&lt;/p&gt;

&lt;p&gt;FDA is not the first to consider a testing regime for generative AI. Over the past year, &lt;a href="https://jamanetwork.com/journals/jama-health-forum/fullarticle/2845631#google_vignette"&gt;multiple academics&lt;/a&gt; have proposed policies requiring generative AI products to pass licensure exams like the ones doctors must pass to practice medicine. The American Medical Association, the largest U.S. doctors&amp;rsquo; group, is &lt;a href="https://www.linkedin.com/posts/american-medical-association_digitalhealth-ai-healthpolicy-activity-7449552667812732928-t4KV?utm_source=share&amp;amp;utm_medium=member_desktop&amp;amp;rcm=ACoAACrvpykBQkpXcuDi7_fqjQYXDADvK69TVqw"&gt;also mulling&lt;/a&gt; whether AI licenses are the right path forward.&lt;/p&gt;

&lt;p&gt;But FDA&amp;rsquo;s exploration of generative AI testing is notable because it&amp;rsquo;s the latest step the agency has taken to determine the best way to regulate the emerging technology.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The fact that large language models can constantly evolve and their outputs can vary wildly are among the reasons FDA has found it difficult to regulate generative AI. An &lt;a href="https://www.fda.gov/medical-devices/digital-health-center-excellence/fda-digital-health-advisory-committee"&gt;FDA advisory committee&lt;/a&gt; met in 2024 and 2025 to help the agency begin addressing those regulatory challenges. FDA has also published several requests for information about AI and recently &lt;a href="https://www.statnews.com/2026/08/05/federal-regulators-invite-industry-closed-door-meetings-clinical-ai/"&gt;convened health AI companies&lt;/a&gt; to guide its thinking.&lt;/p&gt;

&lt;p&gt;The agency is giving the public until Oct. 19 to comment on the generative AI discussion draft. Agency officials maintain that the paper is not a policy statement or representative of future draft regulations.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;FDA intends to lead boldly, but with transparency and genuine intellectual humility. With this paper, we are putting our ideas into the public square and inviting challenge and input from the broader ecosystem so that we can refine these concepts before translating them into policy. The guidance we ultimately develop will be stronger for our having done so,&amp;rdquo; wrote Rick Abramson, the director of FDA&amp;rsquo;s Digital Health Center of Excellence, &lt;a href="https://www.linkedin.com/posts/rick-abramson-md-mhcds-facr-72666198_fda-has-released-a-discussion-paper-on-considerations-activity-7495480004441485312-YYEu/?utm_medium=ios_app&amp;amp;rcm=ACoAABS9-M4BbN1oVB-4q5KUu66VESLYmLsMSqU&amp;amp;utm_source=social_share_send&amp;amp;utm_campaign=share_via"&gt;on LinkedIn&lt;/a&gt;.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/20/GettyImages_2278014569/large.jpg" width="618" height="284"><media:credit>Westy72/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/20/GettyImages_2278014569/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>What Trump’s tech strategy means for the military, deterring China, and the future of AI </title><link>https://www.nextgov.com/defense/2026/08/what-trumps-tech-strategy-means-military-deterring-china-and-future-ai/415531/</link><description>The strategy includes key provisions to encourage innovation—but also has a glaring omission.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Patrick Tucker</dc:creator><pubDate>Wed, 19 Aug 2026 17:52:00 -0400</pubDate><guid>https://www.nextgov.com/defense/2026/08/what-trumps-tech-strategy-means-military-deterring-china-and-future-ai/415531/</guid><category>Defense</category><content:encoded>&lt;![CDATA[&lt;p&gt;The newest White House tech &lt;a href="https://www.whitehouse.gov/wp-content/uploads/2026/08/NSSTS-082026.pdf"&gt;strategy&lt;/a&gt; pushes faster development of emerging technologies for the military, gives defense innovators more room to experiment, and will broaden the federal market for young defense tech startups. But it also doubles down on a particular approach to developing AI&amp;mdash;one that favors a handful of well-connected U.S. tech companies at the expense of other innovative approaches. That could benefit China and slow the U.S. military from getting the tools commanders actually want.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Here&amp;rsquo;s a breakdown of the winners and losers.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Winners: swarms, deployed AI, faster military technology&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The strategy puts a big emphasis on new, tech-driven approaches to warfare, particularly the use of drones and even drone swarms alongside manned and legacy assets. Specifically, it calls for &amp;ldquo;optimal combinations of lower-cost (and sometimes lower-tech or attritable) platforms that can be deployed in larger numbers and complement more limited numbers of sophisticated platforms.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Over the last decade, efforts to field autonomous aircraft alongside fighter jets or ships, for instance, have been &lt;a href="https://theaviationgeekclub.com/the-reasons-why-usaf-temporary-paused-ngad-program/"&gt;uneven&lt;/a&gt; at &lt;a href="https://www.doncio.navy.mil/Chips/ArticleDetails.aspx?ID=4552"&gt;best&lt;/a&gt;&amp;mdash;even when the Pentagon changed its talking points on the necessity for large numbers of low-cost drones&amp;mdash;constrained by programs&amp;#39; internal buying policies and previous commitments to other programs&amp;#39; investments. The Replicator program provides a vivid example, hailed as an essential pathfinder but receiving only &lt;a href="https://www.potomacofficersclub.com/the-dod-is-eyeing-a-billion-dollars-for-the-replicator-program-for-its-first-two-years/"&gt;$1 billion&lt;/a&gt; in funding.&lt;/p&gt;

&lt;p&gt;The new strategy sets specific &amp;ldquo;priority areas&amp;rdquo; for new military research and spending: undersea, space, and AI and autonomy. These priorities are the most relevant to &amp;ldquo;deterrence in the Indo-Pacific&amp;rdquo;&amp;mdash;as in, preventing China from launching a major conflict. Within those priority areas, it lists &amp;ldquo;multi-agent systems and swarm intelligence&amp;rdquo; and various uses of autonomy, from robotics to command and control, as &amp;ldquo;critical.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The strategy also takes square aim at policies and practices that slow down military buying of new technologies. Building off other executive orders, it pushes Pentagon buyers to bypass traditional acquisitions in favor of a &amp;ldquo;mix&amp;rdquo; of contract types, such as performance-based contracts and other transaction authorities, or OTAs. It also resets the tone for military purchasing toward &amp;ldquo;faster non-traditional approaches that may involve higher risk but offer high potential reward,&amp;rdquo; something that commanders, younger defense tech leaders, and even lawmakers have long pushed for.&lt;/p&gt;

&lt;p&gt;Perhaps most importantly, it also takes steps to actually grow the market for younger defense tech players beyond just the military. It takes aim at foreign military sales rules and export controls &lt;a href="https://www.defenseone.com/technology/2026/05/us-investors-warm-ukrainian-defense-startups-export-laws-slow-cooperation/413446/"&gt;that hobble&lt;/a&gt; the sale of much defense tech to allies. That will be especially important for newer defense companies trying to secure early-stage investment to survive. And it calls for other federal agencies to build &amp;ldquo;streamlined pathways&amp;rdquo; for smaller companies to at least get their foot in the door, even via partnerships that don&amp;rsquo;t offer young companies much more than access to federal infrastructure, such as &amp;ldquo;Cooperative Research and Development Agreements (CRADAs) and Agreements for Commercializing Technology (ACTs).&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Losers: open weights, small AI&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;While the strategy champions smaller, more innovative players in defense, it also weighs in on the debate about what the future of AI should look like and comes down on the side of Big Tech companies that are pushing a specific, energy-intensive, and deeply unpopular future of AI over emerging strategies favored increasingly by researchers. China will benefit from the oversight, Michael Schiffer, a partner at Scalare Advisors and former Deputy Assistant Secretary of Defense for East Asia, wrote on Tuesday for&lt;a href="https://www.justsecurity.org/153033/ai-america-china-technological-power/"&gt; Just Security.&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In its section on critical technologies for support, the strategy lists &amp;ldquo;Foundation models, including large language, multimodal, and world systems.&amp;rdquo; The section also includes niche tech areas like brain-computer interfaces but omits entirely open-weight models and open-source software development.&lt;/p&gt;

&lt;p&gt;Here&amp;rsquo;s why that&amp;rsquo;s important:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.ibm.com/think/topics/foundation-models"&gt;Foundation models&lt;/a&gt;, such as today&amp;rsquo;s large language models from companies like OpenAI and Anthropic, represent just one potential method for building AI tools&amp;mdash;one that relies heavily on pushing as much data through as much computational infrastructure as possible to achieve something that looks like &amp;ldquo;reasoning,&amp;rdquo; but that&amp;rsquo;s really just plain old probability calculation.&lt;/p&gt;

&lt;p&gt;Anthropic co-founder Dario Amodei helped to &lt;a href="https://www.scribd.com/document/821176100/Scaling-Laws-for-Neural-Language-Models"&gt;transform&lt;/a&gt; that concept from a research effort into a massive endeavor to acquire computational resources and data as quickly as possible. Amodei explained it &lt;a href="https://www.dwarkesh.com/p/dario-amodei"&gt;simply&lt;/a&gt; in a 2023 discussion with Dwarkesh Patel. &amp;ldquo;It turns out that raw scale&amp;mdash;more compute and more data&amp;mdash;drives capabilities far more powerfully than complex algorithmic inventions or hand-crafted architectural changes.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;A small handful of frontier AI labs, and their big cloud computer backers, are in a literal race for company survival because there&amp;rsquo;s only so much power, so many chips to continue to pursue &amp;ldquo;raw scale.&amp;rdquo; If, as Amodei says, just having more &amp;ldquo;more compute&amp;rdquo; and &amp;ldquo;more data&amp;rdquo; means having the best performing models, then whoever has the most of those resources can push out any competitor.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;It&amp;rsquo;s no wonder the AI race has become a &lt;a href="https://wjarr.com/sites/default/files/fulltext_pdf/WJARR-2026-0011.pdf"&gt;concentration of wealth and power&lt;/a&gt;, in just a handful of labs with their large cloud compute backers. No wonder, also, that public perception of AI has plummeted: just 18 percent of Americans believe it will be a positive force for the United States, one new poll &lt;a href="https://www.annenbergpublicpolicycenter.org/opposition-to-local-data-centers-rises-sharply-annenberg-survey-finds/"&gt;found&lt;/a&gt;. But the foundation model approach does have its fans: large-scale U.S. cloud providers &lt;a href="https://thenewstack.io/microsoft-frontier-forward-deployed/"&gt;who have invested billions&lt;/a&gt; in foundation model labs.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The very way the strategy frames the issue plays to the idea that AI has one future and that winning the AI race or achieving dominance means favoring a handful of players. But it&amp;rsquo;s also a theme that plays out in many of the White House&amp;rsquo;s policies and executive orders around AI.&lt;/p&gt;

&lt;p&gt;Meanwhile, alternative approaches to building AI are emerging. Rather than race to build more data centers and find more data to throw at the problem of AI, they use parameters that already exist that are freely available, called &lt;a href="https://opensource.org/ai/open-weights"&gt;open weight &lt;/a&gt;models, as opposed to closed weights that are protected intellectual property. And they use those in &lt;a href="https://arxiv.org/abs/2606.13715"&gt;conjunction&lt;/a&gt; with &lt;a href="https://arxiv.org/abs/2604.02178"&gt;alternative architectures&lt;/a&gt; that make using those models more energy efficient. Many of these &lt;a href="https://arxiv.org/abs/2603.07685"&gt;alternative approaches&lt;/a&gt; to building AI perform almost as well as what Anthropic and OpenAI are offering, and have the potential to do so at far lower energy costs.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Why it matters to the military&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The finite amount of compute power, data, and good will when it comes to AI could become a &lt;a href="https://www.defenseone.com/technology/2025/06/declining-public-trust-ai-national-security-problem/406309/"&gt;strategic problem&lt;/a&gt; for the U.S. military. If public sentiment undermines congressional and financial support for research and development in the field, officials &lt;a href="https://media.defense.gov/2024/Oct/26/2003571790/-1/-1/0/2024-06-RAI-STRATEGY-IMPLEMENTATION-PATHWAY.PDF"&gt;fear&lt;/a&gt;, the country might lose its AI edge to China, which has openly &lt;a href="https://www.defenseone.com/technology/2025/06/declining-public-trust-ai-national-security-problem/406309/"&gt;declared its intention&lt;/a&gt; to pull ahead.&lt;/p&gt;

&lt;p&gt;In the meantime, frontier-AI models also create tactical and operational problems for the militaries that use them. Troops and military units in the field &lt;a href="https://www.defenseone.com/technology/2026/05/smaller-easier-smarter-what-special-operations-forces-need-ai-now/413748/"&gt;can&amp;rsquo;t count on the connectivity&lt;/a&gt; that tools based on large models need. And in a new report for the Carnegie Endowment for International Peace, Jake Steckler &lt;a href="https://carnegieendowment.org/research/2026/08/confronting-the-barriers-to-ai-diffusion-in-the-us-military"&gt;writes&lt;/a&gt;, &amp;ldquo;Ukraine&amp;rsquo;s computational architecture, consisting of Western cloud access, domestic data centers, and forward-deployed compute nodes, is already straining as it integrates more AI into targeting and coordination.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Open-weight models don&amp;rsquo;t appear in the new strategy, though it does list niche and far-fetched concepts like brain-computer interfaces as &amp;ldquo;critical.&amp;rdquo; That&amp;rsquo;s a huge oversight and a potential gift to China, argues Schiffer.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;China&amp;rsquo;s advances in open-weight AI have exposed the limits of a U.S. strategy built too heavily on the idea of denying them access to American technology and American markets,&amp;rdquo; he said.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/19/GettyImages_629843762-2/large.jpg" width="618" height="284"><media:description>Donald Trump shakes Peter Thiel's hand during a meeting with technology executives, December 14, 2016.</media:description><media:credit>Drew Angerer / Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/19/GettyImages_629843762-2/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>AI is already on the job, and Census is keeping count</title><link>https://www.nextgov.com/artificial-intelligence/2026/08/ai-already-job-and-census-keeping-count/415528/</link><description>New U.S. Census Bureau data shows that AI is quickly becoming a routine workplace tool, while government leaders are finding that training, guardrails and employee-led experimentation can help turn everyday use into meaningful adoption.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Breeden II</dc:creator><pubDate>Wed, 19 Aug 2026 17:19:00 -0400</pubDate><guid>https://www.nextgov.com/artificial-intelligence/2026/08/ai-already-job-and-census-keeping-count/415528/</guid><category>Artificial Intelligence</category><content:encoded>&lt;![CDATA[&lt;p&gt;Most people probably associate the U.S. Census Bureau with the massive effort to count everyone in the country once every 10 years. But Census researchers are hardly sitting around waiting for the next decennial tally. The agency constantly surveys Americans about how they live, work and even play. The resulting information helps government agencies set policy, support programs and track how conditions across the country are changing.&lt;/p&gt;

&lt;p&gt;And lately, that changing world includes a lot of artificial intelligence.&lt;/p&gt;

&lt;p&gt;In March, the Census Bureau&amp;rsquo;s Household Trends and Outlook Pulse Survey asked U.S. workers whether they were using AI on the job and, perhaps more importantly, what they were actually doing with it. The results offer a &lt;a href="https://www.census.gov/library/stories/2026/08/ai-use-at-work.html"&gt;detailed snapshot&lt;/a&gt; of how workers are using AI today.&lt;/p&gt;

&lt;p&gt;About 55% of U.S. workers said they had used AI for at least one of 11 work-related tasks included in the survey. The most common applications were fairly ordinary. About 37% used AI to search for information or technical help, 32% used it to write communications, documentation or instructions and another 32% had AI help them generate ideas. About 31% used AI to interpret, translate or summarize information while 27% used it for administrative tasks.&lt;/p&gt;

&lt;p&gt;In other words, much of workplace AI adoption does not seem to involve building autonomous agents or developing sophisticated machine learning models. People are using it to help with the kinds of things they already do every day.&lt;/p&gt;

&lt;p&gt;Many also said it was saving them time. Among workers who had used AI during the previous week, 31% estimated that it saved them one to two hours. Another 15% said they saved three to four hours and 15% reported saving more than four hours.&lt;/p&gt;

&lt;p&gt;AI did not save time for everyone. About 10% said it did not save them any time and 3% said using it actually required additional time to complete their work. So, the reported productivity benefits were not universal.&lt;/p&gt;

&lt;p&gt;The Census findings cover U.S. workers generally, not government employees specifically. But they raise an interesting question for agencies trying to expand their own use of AI: As employees become more comfortable with the technology, what does practical adoption look like inside government?&lt;/p&gt;

&lt;p&gt;I recently &lt;a href="https://www.fedinsider.com/portfolio-items/ai-in-action-the-right-use-cases-for-every-stage-of-government-ai-adoption/"&gt;moderated a discussion&lt;/a&gt; about government AI adoption with government and industry officials that included Pamela McKnight, chief AI officer for Louisville Metro Government in Kentucky. Louisville has taken exactly that kind of approach, combining centralized governance with efforts to get AI capabilities into the hands of employees throughout the organization.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;There has to be an understanding that business will be done differently now,&amp;rdquo; McKnight said. &amp;ldquo;It&amp;rsquo;s not just about educating people about how to use an AI tool, but also identifying a use case within their area and then actually implementing that AI tool into their workstream.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Rather than expecting a central AI team to discover every possible use case, Louisville has worked to identify employees who are interested in the technology, give them access to training and tools, and encourage those with both interest and aptitude to become AI leaders within their own areas of government.&lt;/p&gt;

&lt;p&gt;Louisville&amp;#39;s experience offers a government example to place alongside the broader workplace patterns Census measured. Its approach is to let employees identify potential use cases within their own areas, then pair that operational knowledge with access to AI tools, training and support. In Louisville, however, giving employees room to experiment does not mean creating an AI free-for-all, or deploying AI simply because the technology is available.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;You have to have guardrails in place, and we worked very closely with our cyber teams on those, so that is number one,&amp;rdquo; McKnight said. &amp;ldquo;And then our office is an enabler. We come along beside them and support and enable them as partners &amp;hellip; we train them, we educate them and we show them how to specifically use those different AI tools.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Another implementation question is which AI tool best fits a particular government task. At &lt;a href="https://www.fedinsider.com/portfolio-items/bringing-cybersecurity-up-to-speed-in-the-age-of-agentic-ai/"&gt;another discussion&lt;/a&gt; I recently moderated, state and local government officials warned that different AI systems have different strengths and weaknesses.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Make sure you have the right AI as they are not all created equal and will be better at different things,&amp;rdquo; said Domain Information Security Officer for the State of Tennessee Brendan Taylor. &amp;ldquo;And even if you have OpenAI or Mythos, Gemini or whatever, make sure you are using their right product for what you are trying to do. Some are better at security or coding or productivity tasks like making reports. Make sure you are matching with the right solution.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;And while government technology leaders are working through those practical questions, the Census Bureau will continue doing what it does best: measuring what is actually happening.&lt;/p&gt;

&lt;p&gt;The Household Trends and &lt;a href="https://www.census.gov/programs-surveys/household-pulse-survey/technical-documentation/source-accuracy.html"&gt;Outlook Pulse Survey&lt;/a&gt; is conducted every two months to provide timely information about changing social and economic conditions. In this case, it captured a workforce already experimenting with AI in very practical ways. Among workers who had used AI for at least one of the tasks Census measured, 24% said they used it every day during the previous week while another 46% had used it on at least one day.&lt;/p&gt;

&lt;p&gt;The survey does not say whether employers should encourage more AI use or what tools they should deploy. But it does provide a useful snapshot of where things stand today: what workers are using AI for, how often they are turning to it and, in many cases, how much time they believe it is saving them.&lt;/p&gt;

&lt;p&gt;And for government agencies trying to understand how AI is finding its way into everyday work, that may be one more Census count worth watching.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;John Breeden II is an award-winning journalist and reviewer with over 20 years of experience covering technology. He is the CEO of the &lt;/em&gt;&lt;a href="https://techwritersbureau.com/"&gt;&lt;em&gt;Tech Writers Bureau&lt;/em&gt;&lt;/a&gt;&lt;em&gt;, a group that creates technological thought leadership content for organizations of all sizes. Twitter: @LabGuys&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/19/GettyImages_2217849566/large.jpg" width="618" height="284"><media:credit>J Studios/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/19/GettyImages_2217849566/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>The watchdog gets watched: GAO’s hiring process length faces scrutiny </title><link>https://www.nextgov.com/policy/2026/08/watchdog-gets-watched-gaos-hiring-process-length-faces-scrutiny/415523/</link><description>In a new report by the inspector general for the Government Accountability Office, investigators also found that in fiscal 2024 the agency excluded certain data from time-to-hire calculations and was inconsistent about when the hiring process started.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Sean Michael Newhouse</dc:creator><pubDate>Wed, 19 Aug 2026 16:24:00 -0400</pubDate><guid>https://www.nextgov.com/policy/2026/08/watchdog-gets-watched-gaos-hiring-process-length-faces-scrutiny/415523/</guid><category>Policy</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Government Accountability Office is an independent legislative branch agency that reviews the effectiveness and efficiency of federal programs. For example, in recent weeks, GAO has issued reports finding that the &lt;a href="https://www.govexec.com/oversight/2026/08/states-overseas-housing-rules-gao/415396/?oref=ge-featured-river-top"&gt;State Department could be overspending&lt;/a&gt; on residences for overseas employees because certain housing standards haven&amp;rsquo;t been updated in more than three decades and that the &lt;a href="https://www.govexec.com/oversight/2026/08/fema-slashed-staff-effects-future-disaster-response-watchdog/415210/"&gt;Federal Emergency Management Agency cut staff&lt;/a&gt; without considering the impacts on disaster operations.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;GAO&amp;rsquo;s own watchdog, however, determined in &lt;a href="https://www.gao.gov/products/oig-26-1"&gt;a report&lt;/a&gt; published on Monday that the oversight agency is taking longer to hire than other federal agencies and that there are issues with how it measures certain hiring data, which could impede efforts to shorten the time that it takes to recruit.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The length of GAO&amp;rsquo;s hiring process increases the agency&amp;rsquo;s risk of not meeting its stated goal of hiring well-qualified candidates because prospective employees may accept other job opportunities while waiting for GAO to complete its hiring process,&amp;rdquo; the inspector general for the GAO wrote.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In fiscal 2024, the IG reported that GAO took an average of about 103 days to hire employees into roles that have been deemed mission critical occupations across government (e.g. information technology management). To compare, the agency&amp;rsquo;s internal hiring target is 98 to 101 days, and the Office of Personnel Management&amp;rsquo;s hiring goal for executive branch agencies is 80 days.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;For instance, it took executive branch agencies that are part of an OPM dashboard an average of 72.1 days to hire for contracting roles in fiscal 2024 compared with 110.1 days for GAO to recruit for identical positions.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;GAO&amp;rsquo;s chief human capital officer defended the hiring length in a letter attached to the report, noting that the agency &amp;ldquo;relies heavily on multiple rounds of interviews as an important part of our assessment process.&amp;rdquo; The official also said that GAO allows potential hires to negotiate their salaries, unlike other agencies, &amp;ldquo;but which may simultaneously add time to the process and may increase our ability to attract a broader applicant pool.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The IG also reported that the agency inadvertently excluded 20, about 30%, of its fiscal 2024 mission-critical hires from time-to-hire data and that there&amp;rsquo;s a discrepancy between whether the hiring process starts when human capital staff consult with a hiring manager about a vacancy or when such consultation is complete.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;By using the consultation completion dates, [Human Capital Office]&amp;rsquo;s calculations would have undercounted the days spent on some hiring actions,&amp;rdquo; investigators wrote. &amp;ldquo;Further, HCO staff indicated that consultations often took longer than the allotted two days. However, because HCO did not record the start date for consultations, it cannot determine how long consultations took or accurately assess the length of its hiring process.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;GAO agreed with two of its IG&amp;rsquo;s recommendations: to periodically review hiring timelines and address inefficiencies and to update all internal documents to reflect the established target hiring time frames.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;With respect to a recommendation to ensure all hiring actions are included in time-to-hire calculations, GAO countered that certain actions, such as annual promotions for analysts, shouldn&amp;rsquo;t be included. And regarding a recommendation about accurately documenting hiring dates, GAO suggested performing separate tracking of early actions in the hiring process (e.g. consultation with hiring manager).&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Regardless, GAO officials said they would implement all of the recommendations by April 1, 2027.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The IG also noted that GAO in fiscal 2025 hired fewer than 10 entry-level employees and experienced a net loss of around 100 staffers because it didn&amp;rsquo;t backfill positions due to &amp;ldquo;budget constraints.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The Office of Management and Budget has previously &lt;a href="https://www.govexec.com/oversight/2026/06/fema-omb-noms-grilled-alleged-political-sway-government-assistance/414248/?oref=ge-featured-river-top"&gt;criticized GAO&lt;/a&gt; after the agency on several occasions determined that the administration violated rules around impoundments, which is when the executive branch delays or withholds congressionally approved spending.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;For fiscal 2026, House Republicans proposed halving GAO&amp;rsquo;s spending level, but the final appropriations bill &lt;a href="https://www.govexec.com/management/2025/11/major-takeaways-federal-agencies-funding-deal-reopen-government/409446/"&gt;kept the agency&amp;rsquo;s funding flat&lt;/a&gt;.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/19/081926_Getty_GovExec_GAO-1/large.jpg" width="618" height="284"><media:description>GAO in fiscal 2024 took an average of around 103 days to hire employees into mission critical positions. </media:description><media:credit>John M. Chase / Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/19/081926_Getty_GovExec_GAO-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Report calls for deterrence mechanisms, government participation in AI-biology security</title><link>https://www.nextgov.com/artificial-intelligence/2026/08/report-calls-deterrence-mechanisms-government-participation-ai-biology-security/415517/</link><description>“The federal government just does not have enough experts left to handle this threat or even be able to coordinate among outside groups without significant immediate investment,” one federal official said of the report’s findings.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alexandra Kelley</dc:creator><pubDate>Wed, 19 Aug 2026 14:15:00 -0400</pubDate><guid>https://www.nextgov.com/artificial-intelligence/2026/08/report-calls-deterrence-mechanisms-government-participation-ai-biology-security/415517/</guid><category>Artificial Intelligence</category><content:encoded>&lt;![CDATA[&lt;p&gt;Safely managing the use of artificial intelligence technologies in biological research demands advanced threat actor detection.&amp;nbsp;One federal official says there is a need for earlier, additional public investments in these cybersecurity mechanisms.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.rand.org/pubs/research_reports/RRA4999-1.html"&gt;A new report&lt;/a&gt; from the research nonprofit RAND addresses how the increased application of AI tools in biological research fields poses serious threats to global health and national security, particularly &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/08/openai-agents-rebuilt-internal-message-board-lead-hugging-face-breach/415240/"&gt;as model capabilities rapidly advance&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The study&amp;nbsp;calls&amp;nbsp;the development of a novel pathogen that is then released as a biological weapon the ultimate risk scenario in AI-enabled biotechnology, and it focuses on how to mitigate a hypothetical &amp;ldquo;high-consequence&amp;rdquo; biological incident.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Referencing the biological risk chain &amp;mdash; a framework that labels the parts of a biological research field, such as genome synthesis, that are susceptible to an attack &amp;mdash; the report&amp;#39;s&amp;nbsp;authors suggest layering risk mitigation techniques at several points within the chain to monitor and stop threats: model-layer safeguards, access and deployment controls, upstream governance and select physical chokepoint interventions.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Optimal detection systems should be able to identify suspicious activity within nodes of any given network handling sensitive biological data.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;By layering mitigations at multiple points along this chain, it is possible to extend the time required for malicious activity, deter potential nefarious activity or intentions, increase the operational effort necessary to proceed, and raise the likelihood that suspicious behavior is detected and disrupted before release,&amp;rdquo; the report says.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The authors assert that government support is &amp;ldquo;central&amp;rdquo; to the strategy&amp;rsquo;s effectiveness. While initial voluntary action from academic and industry entities has implemented secure access measures, the report notes that standardization of AI-enabled biological networks is still uneven.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The government should establish minimum requirements for access controls, user verification, and audit logging that are applicable to AI models and [biological tools]&amp;nbsp;that are above defined risk thresholds, and the government should do so while providing clear guidance on what constitutes adequate credentialing and monitoring for different capability levels,&amp;rdquo; the report reads.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;A senior government AI official told &lt;em&gt;Nextgov/FCW &lt;/em&gt;they agreed with this perspective, emphasizing the importance of investing early in risk mitigation strategies, especially in light of &lt;a href="https://www.nextgov.com/cybersecurity/2026/04/anthropics-glasswing-initiative-raises-questions-us-cyber-operations/412721/"&gt;the debut&lt;/a&gt; and &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/anthropic-confirms-its-ai-breached-3-organizations-during-testing/415138/"&gt;subsequent hacking activity&lt;/a&gt; of Anthropic&amp;rsquo;s advanced Mythos model.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Implementing this strategy&amp;rsquo;s mitigations will require investments in new research, institutional adaptation, legal clarification and international coordination,&amp;rdquo; the senior official said. &amp;ldquo;We cannot wait for a &amp;lsquo;BioMythos&amp;rsquo; moment.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The senior official added that allocating more resources will be necessary for a robust risk prevention strategy, including additions to the federal workforce.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The federal government just does not have enough experts left to handle this threat or even be able to coordinate among outside groups without significant immediate investment across multiple departments, including hiring, dedicated authorities and budget increases,&amp;rdquo; they said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Security concerns surrounding AI in applied biological sciences and research have spiked following the independent actions of AI models from &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/anthropic-confirms-its-ai-breached-3-organizations-during-testing/415138/"&gt;Anthropic&lt;/a&gt; and &lt;a href="https://www.nextgov.com/cybersecurity/2026/08/hugging-face-ai-breach-most-consequential-hack-morris-worm-former-nsa-cyber-chief-says/415230/"&gt;OpenAI&lt;/a&gt; in contained environments, resulting in breaches and harm to external online entities.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The Department of Homeland Security issued a &lt;a href="http://www.nextgov.com/artificial-intelligence/2024/06/dhs-report-details-ais-potential-amplify-biological-chemical-threats/397607/"&gt;report in 2024&lt;/a&gt;&amp;nbsp;documenting the threat potential of AI-enabled chemical and biological weapons, recommending, among other items, the need for specific federal guidance to govern how models tailored for biological applications are used.&amp;nbsp;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/19/081926AIbiologyNG/large.jpg" width="618" height="284"><media:credit>Just_Super/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/19/081926AIbiologyNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>DOJ charges 17 Iranians in cybertheft campaign</title><link>https://www.nextgov.com/cybersecurity/2026/08/doj-charges-17-iranians-cybertheft-campaign/415511/</link><description>Prosecutors say the Mabna Institute — which conducted intrusions for Iran’s Islamic Revolutionary Guard Corps, among other campaigns — stole 31.5 terabytes of academic data and breached email accounts at U.S. agencies and companies.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 19 Aug 2026 12:13:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/doj-charges-17-iranians-cybertheft-campaign/415511/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;Federal prosecutors have charged 17 Iranians affiliated with the Tehran-based Mabna Institute over an alleged hacking-for-hire operation that stole research and intellectual property from hundreds of universities and compromised email accounts belonging to U.S. government agencies and companies.&lt;/p&gt;

&lt;p&gt;The&amp;nbsp;&lt;a href="https://www.justice.gov/opa/pr/17-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic-revolutionary"&gt;14-count superseding indictment&lt;/a&gt;, unsealed Tuesday, adds eight defendants to a case brought against nine other members of the firm in 2018. Prosecutors said the expanded charges expose a broader network that conducted cyber intrusions for Iran&amp;rsquo;s Islamic Revolutionary Guard Corps and other Iranian government and university clients.&lt;/p&gt;

&lt;p&gt;The Mabna Institute targeted systems belonging to 144 U.S. universities, 178 universities abroad, at least 42 U.S. companies, 11 foreign companies and at least five federal and state government agencies since around 2013, according to the Justice Department.&lt;/p&gt;

&lt;p&gt;The victims included the Labor Department, Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations and UNICEF. The hackers also allegedly targeted HBO and unnamed technology firms and defense contractors.&lt;/p&gt;

&lt;p&gt;Prosecutors said the university campaign targeted more than 100,000 professors&amp;rsquo; accounts worldwide and successfully compromised approximately 8,000. The hackers used stolen credentials to access journals, dissertations, electronic books and other research spanning fields ranging from medicine and engineering to the social sciences.&lt;/p&gt;

&lt;p&gt;All told, the group allegedly stole at least 31.5 terabytes of academic data and intellectual property. U.S. universities had spent more than $3.4 billion to procure or obtain access to the targeted materials, although prosecutors did not characterize that entire amount as a financial loss from the theft.&lt;/p&gt;

&lt;p&gt;Some of the stolen material was later sold to customers in Iran through two websites. One offered academic resources taken from universities, while the other allowed customers to use compromised professors&amp;rsquo; accounts to enter university library systems directly, according to the indictment.&lt;/p&gt;

&lt;p&gt;Prosecutors said Mabna&amp;rsquo;s founders established the firm to help Iranian universities and research organizations obtain scientific resources from abroad. It employed or contracted with hackers who carried out phishing attacks, searched for vulnerable systems and traded credentials for compromised accounts.&lt;/p&gt;

&lt;p&gt;The defendants face charges that include conspiracy to commit computer intrusions, wire fraud and aggravated identity theft. Some of the offenses carry maximum prison sentences of 20 years. The State Department is separately offering a reward of up to $10 million for information leading to the location of five of the defendants.&lt;/p&gt;

&lt;p&gt;The charges come amid concerns about Iran&amp;rsquo;s use of cyber operations during the ongoing war.&lt;/p&gt;

&lt;p&gt;Since U.S. and Israeli strikes began in February, suspected Iran-aligned groups have been linked to a&lt;a href="https://www.nextgov.com/cybersecurity/2026/03/suspected-pro-iran-hacker-group-tied-stryker-cyberattack/412050/"&gt; &lt;/a&gt;disruptive attack against &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/suspected-pro-iran-hacker-group-tied-stryker-cyberattack/412050/"&gt;medical technology company Stryker&lt;/a&gt;, the&amp;nbsp;&lt;a href="https://www.nextgov.com/cybersecurity/2026/03/pro-iran-hackers-claim-breach-fbi-directors-email/412440/"&gt;compromise&lt;/a&gt; of FBI Director Kash Patel&amp;rsquo;s personal email and attacks against&amp;nbsp;&lt;a href="https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/"&gt;industrial-control systems across several U.S. sectors&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;More than 30 Minnesota water systems and water infrastructure in several other states have been &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/cisa-urges-water-utilities-take-exposed-systems-down-after-minnesota-hacks/415142/"&gt;targeted in the last month&lt;/a&gt; in activity some officials suspect may be tied to Iran. U.S. officials previously&amp;nbsp;&lt;a href="https://www.nextgov.com/cybersecurity/2026/06/us-officials-see-iran-cyber-threat-persisting-despite-preliminary-deal/414243/"&gt;told &lt;em&gt;Nextgov/FCW&lt;/em&gt;&lt;/a&gt; that they expected Iranian and Iran-aligned cyber operations to continue regardless of whether fighting subsided.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/19/081926IranNG/large.jpg" width="618" height="284"><media:credit>Mojito_mak/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/19/081926IranNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Social Security expands electronic health record sharing to speed up disability claims adjudication</title><link>https://www.nextgov.com/digital-government/2026/08/social-security-expands-electronic-health-record-sharing-speed-disability-claims-adjudication/415496/</link><description>A health data sharing superhighway “allows SSA to access complete, structured medical records within seconds or minutes for claimants, helping to significantly reduce disability claim processing times,” an agency official told Nextgov/FCW.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christian Robles</dc:creator><pubDate>Tue, 18 Aug 2026 16:00:00 -0400</pubDate><guid>https://www.nextgov.com/digital-government/2026/08/social-security-expands-electronic-health-record-sharing-speed-disability-claims-adjudication/415496/</guid><category>Digital Government</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Social Security Administration is looking to speed up disability claims adjudication by allowing Americans to consent to their medical providers sending the agency digital copies of their health records through a data sharing superhighway.&lt;/p&gt;

&lt;p&gt;In April, Epic &amp;mdash; the largest electronic health record vendor for U.S. hospitals &amp;mdash; &lt;a href="https://www.epic.com/epic/post/health-systems-on-epic-are-first-to-connect-with-the-social-security-administration-through-tefca/"&gt;announced&lt;/a&gt; that its health system customers are connected to SSA through the Trusted Exchange Framework and Common Agreement, or TEFCA. Through that superhighway, dozens of hospitals and clinics can send digital medical records to SSA, eliminating the need to fax documents to the agency and slashing disability claims processing times by &lt;a href="https://www.ssa.gov/news/en/advocates/2026-02-17.html"&gt;up to 50%.&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Jacksonville, Florida-based Baptist Health is among the first Epic customers to start sharing electronic health records with SSA through TEFCA.&lt;/p&gt;

&lt;p&gt;Baptist Health has sent SSA several thousand electronic medical records since it started sharing data with the agency through TEFCA at the end of July, Aaron Miri, the health system&amp;rsquo;s chief digital and information officer, told &lt;em&gt;Nextgov/FCW&lt;/em&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Because of TEFCA, Baptist Health has reduced the number of staff dedicated to processing medical records for SSA to essentially half a person, Miri said in an interview. Before TEFCA, three staffers were manually sending SSA medical records through fax machines and checking that the agency actually received the information, he said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We&amp;rsquo;re seeing time saved, we&amp;#39;re seeing accuracy [of medical records] go up, we&amp;#39;re seeing happy patients,&amp;rdquo; Miri said. &amp;ldquo;It&amp;#39;s just positive, positive, positive.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Dozens of Epic customers in California, Oklahoma, Washington, Arizona and other states have also connected to SSA through TEFCA.&lt;/p&gt;

&lt;p&gt;Epic expects more than 550 hospitals and nearly 20,000 clinics will use TEFCA to exchange data with SSA by the end of the month, and all of its customers to eventually migrate to TEFCA, a company spokesperson told &lt;em&gt;Nextgov/FCW&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;SSA has connected to 84 health care entities and made 60,595 data requests through TEFCA as of August 13, according to an agency official familiar with its health information technology strategy.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;SSA obtaining electronic medical records for disability claims adjudication is not new. The agency has received health information from medical providers through Carequality and eHealth Exchange&amp;nbsp;&amp;mdash;&amp;nbsp;two other health data sharing superhighways&amp;nbsp;&amp;mdash;&amp;nbsp;for years. But TEFCA has several advantages compared to those pathways.&lt;/p&gt;

&lt;p&gt;Medical providers can use their existing connection to the TEFCA rather than starting new legal agreements to connect with the SSA, the Epic spokesperson said. They also no longer have to constantly provide SSA with an updated list of their facilities because TEFCA has a directory SSA can use to identify facilities, they added.&lt;/p&gt;

&lt;p&gt;Over 65% of Epic customers are currently sharing records with SSA across TEFCA, Carequality and eHealth Exchange, they said.&lt;/p&gt;

&lt;p&gt;But SSA is agnostic whether medical providers use TEFCA or another pathway to share data, so long as patient consent is part of the equation and they share adequate information for disability claims adjudication, the agency official said.&lt;/p&gt;

&lt;p&gt;SSA is working with TEFCA Qualified Health Information Networks, or QHINs, besides Epic, which would give more medical providers the ability to send the agency digital health records, according to the agency official.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;eClinicalWorks and NetSmart are actively in various stages of development and testing with SSA today,&amp;rdquo; they clarified. SSA has a seat on the TEFCA governing council,&lt;em&gt;Nextgov/FCW &lt;/em&gt;&lt;a href="https://www.nextgov.com/digital-government/2026/08/federal-agencies-quietly-joined-health-data-superhighway-governing-council/415324/"&gt;previously reported&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The Epic spokesperson said the company wants all medical providers &amp;mdash; regardless of whether they use Epic software &amp;mdash; to electronically send medical records to SSA. But that could prove difficult to achieve.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Many behavioral health, specialty and rural providers do not use electronic health records, meaning they continue to rely on manual record request processing, noted Jennifer Burdick, a divisional supervising attorney at Community Legal Services of Philadelphia. Department of Health and Human Services data backs up that assessment: thousands of substance use and mental health treatment facilities &lt;a href="https://healthit.gov/data/data-briefs/electronic-health-record-adoption-and-exchange-capabilities-among-substance-use-and-mental-health-treatment-facilities-2024/"&gt;continue to use paper charts&lt;/a&gt; instead of software to maintain patient records.&lt;/p&gt;

&lt;p&gt;Even though TEFCA promises to speed up claims adjudication for thousands of Americans, disability advocates have warned Americans are finding it &lt;a href="https://www.nextgov.com/digital-government/2026/03/accessing-social-security-disability-benefits-became-harder-2025-researchers-find/411887/"&gt;hard to access SSA disability benefits.&lt;/a&gt; That&amp;rsquo;s in part because SSA is pushing online servicing and has introduced AI onto its phone lines, according to a Disability Rights Education &amp;amp; Defense Fund report published in March. SSA contested claims that disability benefits are becoming harder to access and touted a decline in its initial pending backlog in a previous statement to &lt;em&gt;Nextgov/FCW&lt;/em&gt;.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/18/081826SSANG/large.jpg" width="618" height="284"><media:credit>Wesley Lapointe for The Washington Post via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/18/081826SSANG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>The Russian hurdle in Trump’s new offensive cyber program</title><link>https://www.nextgov.com/cybersecurity/2026/08/russian-hurdle-trumps-new-offensive-cyber-program/415493/</link><description>The White House wants private companies to help take down cybercriminals overseas. But in Russia, the line between criminal hackers and the government is difficult to draw.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Tue, 18 Aug 2026 15:26:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/russian-hurdle-trumps-new-offensive-cyber-program/415493/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;President Donald Trump&amp;rsquo;s new plan to enlist private companies to help disrupt cybercriminals abroad may face a fundamental problem when it comes to Russia: distinguishing criminal hackers and state-backed operatives.&lt;/p&gt;

&lt;p&gt;Russian intelligence services have long tolerated, protected or intermittently recruited financially-motivated hackers without exercising full control over them. That dynamic gives Moscow easier access to hacking talent, and it complicates a major carveout in Trump&amp;rsquo;s new directive that excludes groups part of or directed by a foreign government, experts and former U.S. officials say.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The line between government control, government-affiliated and government-acknowledged is certainly blurry in Russia,&amp;rdquo; said Michael Daniel, president and CEO of the Cyber Threat Alliance and a former White House cybersecurity coordinator under President Barack Obama. &amp;ldquo;Determining the exact relationship between malicious actors and the Russian government has long been a challenge and is often impossible.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;A White House &lt;a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/"&gt;memorandum&lt;/a&gt; signed last week paves the way for vetted U.S. companies to conduct cyber surveillance and operations that manipulate, disrupt and destroy systems used by foreign criminal groups. Companies would work under contracts with the Justice Department and Department of Homeland Security, and every operation would require written approval.&lt;/p&gt;

&lt;p&gt;The memo says eligible targets cannot be &amp;ldquo;an institutional part of a foreign government&amp;rdquo; or &amp;ldquo;wholly operated under a foreign government&amp;rsquo;s direction.&amp;rdquo; It then instructs officials to assume a group is not part of, or wholly controlled by, a foreign government unless &amp;ldquo;clear intelligence&amp;rdquo; establishes that connection.&lt;/p&gt;

&lt;p&gt;Such intelligence collection from spy agencies like the National Security Agency and CIA can help firms determine targeting criteria, though it may not be enough for Russia&amp;rsquo;s ever-evolving cyber landscape.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Russia&amp;rsquo;s cyber web is opaque and always shifting, blurring lines between government and cybercriminal, with no single rule for understanding each and every relationship,&amp;rdquo; said Justin Sherman, CEO of Global Cyber Strategies, a Washington, D.C.-based research and advisory firm.&lt;/p&gt;

&lt;p&gt;Some of that ambiguity is intentional and allows the Kremlin to expand the pool of hackers it can covertly draw upon, Sherman said. It also reflects broader and pervasive corruption conditions inside Russia.&lt;/p&gt;

&lt;p&gt;U.S. companies may have insights about those groups but lack the broader intelligence available to the government. Federal agencies, meanwhile, can only share or declassify so much, he said. &amp;ldquo;Private companies have critical insights in some ways and limited in others,&amp;rdquo; Sherman said. With an incomplete picture, &amp;ldquo;you&amp;rsquo;re bound to get it wrong some of the time.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Simple indicators don&amp;rsquo;t necessarily settle attribution questions, he added. Ties with the FSB &amp;mdash; Russia&amp;rsquo;s Federal Security Service that succeeded the Soviet Union&amp;rsquo;s KGB &amp;mdash; do not by themselves prove that a criminal group is state-directed, nor does a Russian intelligence service&amp;rsquo;s use of tools developed by criminals establish continuous government control.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Simple, bumper sticker ideas for deciding if a Russian cybercriminal is a state actor or not will often collapse in practice,&amp;rdquo; said Sherman.&lt;/p&gt;

&lt;p&gt;Past cases illustrate how those relationships can work. In 2017, the &lt;a href="https://www.justice.gov/archives/opa/pr/us-charges-russian-fsb-officers-and-their-criminal-conspirators-hacking-yahoo-and-millions"&gt;DOJ charged&lt;/a&gt; two FSB officers with directing and protecting criminal hackers involved in the breach of Yahoo. Prosecutors said one of the hackers also conducted separate intrusions for personal profit. The Treasury Department has similarly said Maksim Yakubets, the alleged leader of the Evil Corp cybercrime organization, &lt;a href="https://home.treasury.gov/news/press-releases/sm845"&gt;worked for the FSB&lt;/a&gt; and was tasked with projects on behalf of the Russian state while his organization carried out financially motivated attacks.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The Russians haven&amp;rsquo;t been strangers to using private sector proxies to get what they want, as long as they&amp;rsquo;re not attacking them,&amp;rdquo; said Chris Painter, a former State Department cyber coordinator and White House cyber official. He questioned how a company could determine where a particular group falls along that continuum when the answer is often not immediately apparent, even for well-resourced governments.&lt;/p&gt;

&lt;p&gt;The new policy is the latest step in an offensive cyber posture the administration has been building for the last year. Trump&amp;rsquo;s &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/trumps-new-cyber-strategy-details-more-offensive-response-cyber-threats/411963/"&gt;national cybersecurity strategy&lt;/a&gt;, released in March, called for &amp;ldquo;unprecedented coordination&amp;rdquo; between government and industry on offensive and defensive missions. It pledged to &amp;ldquo;unleash the private sector&amp;rdquo; by creating incentives for companies to identify and disrupt adversary networks.&lt;/p&gt;

&lt;p&gt;But that set-up remained unclear for months. National Cyber Director Sean Cairncross&lt;a href="https://www.nextgov.com/cybersecurity/2026/03/national-cyber-director-doesnt-envision-industry-doing-offensive-hacking/412176/"&gt; said shortly after&lt;/a&gt; the strategy&amp;rsquo;s release that he was &amp;ldquo;not talking about private sector, industry or companies engaged in a cyber offensive campaign.&amp;rdquo; Instead, he described companies sharing information and capabilities that would enable the government to respond.&lt;/p&gt;

&lt;p&gt;Some industry executives interviewed by &lt;em&gt;Nextgov/FCW&lt;/em&gt; in April nevertheless &lt;a href="https://www.nextgov.com/cybersecurity/2026/04/us-push-counter-hackers-draws-industry-deeper-offensive-cyber-debate/412770/"&gt;predicted that the government would eventually contract with companies&lt;/a&gt; to support cyber operations. They also raised unresolved questions about legal authorities and how experts would define the fine line between creating obstacles for adversaries and hacking them offensively.&lt;/p&gt;

&lt;p&gt;The administration moved further in May when its &lt;a href="https://www.nextgov.com/cybersecurity/2026/05/us-lists-offensive-cyberattacks-counterterrorism-strategy/413374/"&gt;counterterrorism strategy&lt;/a&gt; explicitly identified offensive cyber operations as one of the tools Washington could use against threatening groups and the states that support them. That document offered scant details about how such operations would work.&lt;/p&gt;

&lt;p&gt;Sherman argued that the U.S. shouldn&amp;rsquo;t let uncertainty about Russia&amp;rsquo;s cyber links stop it from taking action. The United States is overdue to reconsider assumptions about restraint and do more to counter Russia&amp;rsquo;s offensive cyber activity, he said, but a more aggressive posture does not make the underlying attribution decisions any easier.&lt;/p&gt;

&lt;p&gt;Daniel said that ambiguity could give Washington leverage. Moscow could either let an operation against known criminals go unanswered or object and risk exposing its ties to them.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The U.S. could use this formulation to call the Russians&amp;rsquo; bluff &amp;mdash; either acknowledge a relationship or let the group take the damage,&amp;rdquo; he said. But maintaining that bind would require the United States to choose its targets carefully. If a company inadvertently struck clandestine personnel from Moscow&amp;rsquo;s intelligence and security agencies, he added, the operation could create substantially greater consequences.&lt;/p&gt;

&lt;p&gt;Cybercriminals routinely operate through hijacked servers and systems belonging to &lt;a href="https://www.nextgov.com/cybersecurity/2026/06/hidden-market-turning-home-internet-connections-cover-hackers/414413/"&gt;unwitting third parties&lt;/a&gt;, meaning companies carrying out hacks may have to distinguish targeted criminals from the infrastructure they have compromised.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;A lot is left to be determined on how the oversight is going to work, how the targeting is going to work,&amp;rdquo; Painter said. &amp;ldquo;That&amp;rsquo;s all supposed to be decided in 60 days,&amp;rdquo; he said,&amp;nbsp;referring to the timeline the new policy must be developed by.&lt;/p&gt;

&lt;p&gt;Painter said the best version of the program would be a tightly controlled process in which the government uses intelligence provided by companies and its own agencies to select legitimate targets. Companies would likely want written assurances that the government had approved a target and that their actions were covered by the program, he said.&lt;/p&gt;

&lt;p&gt;The public directive does not explain how responsibility would be divided if a contractor followed an approved plan and the underlying intelligence proved wrong. Much of the operational process will also be governed by a classified annex.&lt;/p&gt;

&lt;p&gt;Coordinating government decisions and private-sector activity in something approaching real time will itself be difficult, Daniel said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I don&amp;rsquo;t know of any analogous precedent,&amp;rdquo; he added.&lt;/p&gt;

&lt;p&gt;A DHS spokesperson did not respond to questions about how the administration would distinguish Russian cybercrime groups from state-linked actors or who would bear responsibility if a target were misidentified.&lt;/p&gt;

&lt;p&gt;The department &amp;ldquo;looks forward to implementing President Trump&amp;rsquo;s directive to combat cyber-enabled transnational crime threatening Americans and our businesses,&amp;rdquo; the spokesperson said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Last year alone, cyber-enabled Transnational Criminal Organizations stole more than $20 billion directly from Americans through rampant fraud, ransomware, and extortion schemes,&amp;rdquo; White House spokesperson Lauren Bis said when asked the same line of questions. &amp;ldquo;The Trump administration is mounting an aggressive campaign to disrupt these illicit syndicates and dismantle them at the source.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The Justice and State departments did not provide comments. Russia&amp;rsquo;s embassy in Washington was also contacted.&lt;/p&gt;

&lt;p&gt;The prospect of operations against pro-Russia cybercriminals carries a possible diplomatic dimension. Trump has continued direct engagement with Russian President Vladimir Putin and has sought to broker an end to the war in Ukraine. The two leaders agreed in July to &lt;a href="https://www.reuters.com/world/europe/kremlin-says-putin-trump-agreed-during-weekend-call-talk-again-near-future-2026-07-06/"&gt;maintain contact and speak again&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The administration has previously adjusted its cyber posture during negotiations with Moscow. Rep. Don Bacon, R-Neb., who chairs the House Armed Services Committee&amp;rsquo;s cyber panel, &lt;a href="https://bacon.house.gov/news/documentsingle.aspx?DocumentID=2694"&gt;confirmed&lt;/a&gt; last year that Defense Secretary Pete Hegseth&lt;a href="https://www.nextgov.com/cybersecurity/2025/03/hegseth-orders-suspension-cyber-information-operations-planning-against-russia/403415/"&gt; ordered&lt;/a&gt; a brief pause in U.S. Cyber Command operations against Russia as the administration pursued Ukraine talks.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The memorandum requires coordination with the State Department, suggesting diplomatic consequences will be considered before an operation is approved. It does not say publicly how officials would weigh disrupting a Russian cybercrime group against other negotiations with the Kremlin.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If there&amp;rsquo;s a decision made that says we&amp;rsquo;re being careful with Russia now because we&amp;rsquo;re in some sensitive talks, that will play into it,&amp;rdquo; Painter said. Companies could also &amp;ldquo;paint the target on themselves&amp;rdquo; and face Russian retaliation if their involvement became public, he added. Even if a company is required to keep its role secret, it wouldn&amp;rsquo;t prevent an adversary or another party from exposing it.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I understand what they&amp;rsquo;re trying to do, and if it has really robust oversight, and including targeting and review and oversight of what they&amp;rsquo;re doing, it might work fine,&amp;rdquo; Painter said. &amp;ldquo;But there&amp;rsquo;s so much of a chance of that going wrong.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/18/081826TrumpPutinNG/large.jpg" width="618" height="284"><media:description>U.S. President Donald Trump (R) and Russian President Vladimir Putin arrive for a press conference at Joint Base Elmendorf-Richardson on August 15, 2025 in Anchorage, Alaska. </media:description><media:credit>Andrew Harnik/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/18/081826TrumpPutinNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>CISA contemplates whether to hire security software buying help</title><link>https://www.nextgov.com/cybersecurity/2026/08/cisa-contemplates-whether-hire-security-software-buying-help/415486/</link><description>The Cybersecurity and Infrastructure Security Agency issued a sources sought notice that describes its desire to bring in a company that can help manage enterprise license and materials purchases.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ross Wilkers</dc:creator><pubDate>Tue, 18 Aug 2026 12:56:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/cisa-contemplates-whether-hire-security-software-buying-help/415486/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Cybersecurity and Infrastructure&amp;nbsp;Security Agency is contemplating whether to hire a contractor to help manage its purchases of cybersecurity software and related tools via a single mechanism.&lt;/p&gt;

&lt;p&gt;CISA currently acquires the tools through the &lt;a href="https://www.washingtontechnology.com/contracts/2024/04/dhs-extends-civilian-network-cyber-contracts/395983/"&gt;Continuous Diagnostics and Mitigation program&lt;/a&gt; for protecting civilian government networks and Capacity Building, an arm of the agency that leads federal enterprise cyber governance efforts.&lt;/p&gt;

&lt;p&gt;By launching &lt;a href="https://sam.gov/workspace/contract/opp/a12bcbd9bfbc4e3ea64a0f8db379df70/view"&gt;this sources sought notice on Aug. 12&lt;/a&gt;, CISA is signaling the start of its evaluation of acquisition approaches that would support roughly $600 million in cyber software purchases per year.&lt;/p&gt;

&lt;p&gt;The agency eventually wants that figure to grow to $6 billion per year over the entire contract&amp;rsquo;s lifecycle, should a contract be created.&lt;/p&gt;

&lt;p&gt;CISA is working with the General Services Administration&amp;rsquo;s Assisted Acquisition Services team to evaluate the market research collected via the request for information. GSA AAS works with other agencies on planning, awarding and managing complex contracts.&lt;/p&gt;

&lt;p&gt;In the new notice, CISA describes its desire to bring in a contractor that can aid the agency in managing its enterprise license and materials purchases. The contractor would also work with CISA&amp;rsquo;s CB team to implement a singular software buying management process and procurement support platforms.&lt;/p&gt;

&lt;p&gt;CISA is undertaking this effort as part of its plans to transition away from the CDM program&amp;rsquo;s current approved product list to a new Cyber Product List and Technical Capability Catalog. The agency describes the latter two initiatives as its baselines for future enterprise cyber software procurements.&lt;/p&gt;

&lt;p&gt;The RFI describes the scope of work as covering strategic buying advisory services, acquisition and procurement support, enterprise license management, software asset management, category management, vendor management and procurement analytics. These services would be provided in addition to the cyber tools themselves.&lt;/p&gt;

&lt;p&gt;Other requirements include market analysis, historical spend analysis, pricing analysis, procurement strategy development, software category management, enterprise licensing recommendations, and development of cost savings metrics.&lt;/p&gt;

&lt;p&gt;Responses to the RFI are due by 5 p.m. ET&amp;nbsp;on Sept. 1.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/18/digital_code/large.jpg" width="618" height="284"><media:credit>Gettyimages.com / Fotograzia</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/18/digital_code/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Labor looks to AI to tackle accommodation requests from disabled employees</title><link>https://www.nextgov.com/artificial-intelligence/2026/08/labor-department-seeks-ai-triage-accommodation-requests-disabled-employees/415484/</link><description>Employees say they’ve waited months or longer for decisions, as the Labor Department considers using AI to sort requests and flag missing documentation.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jory Heckman</dc:creator><pubDate>Tue, 18 Aug 2026 11:26:00 -0400</pubDate><guid>https://www.nextgov.com/artificial-intelligence/2026/08/labor-department-seeks-ai-triage-accommodation-requests-disabled-employees/415484/</guid><category>Artificial Intelligence</category><content:encoded>&lt;![CDATA[&lt;p&gt;Faced with a backlog of accommodation requests from employees with disabilities and medical conditions, the Labor Department plans to use artificial intelligence to triage the workload.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;An internal email obtained by &lt;em&gt;Government Executive &lt;/em&gt;states that staff at the Civil Rights Center, which processes reasonable accommodation requests, currently must &amp;ldquo;engage substantively with every request regardless of completeness or likely outcome, limiting capacity and delaying determinations.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The process requires case-by-case judgment, but cases vary significantly in complexity and documentation quality: some are well-supported and straightforward, some require additional documentation, and some are not well-supported by the documentation provided,&amp;rdquo; the email states.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Labor Department employees told &lt;em&gt;Government Executive &lt;/em&gt;that the department is facing a backlog of hundreds of RA requests. Several reported waiting months or, in some cases, a year or longer for for reviews, delays they say have hampered&amp;nbsp;productivity at a department charged with protecting the workplace rights of workers with disabilities.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;One DOL employee told &lt;em&gt;Government Executive &lt;/em&gt;that he submitted a reasonable accommodation request in March 2025, supported by documentation from his primary care and a mental health providers, yet his case remains pending.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;It&amp;rsquo;s just kind of ironic to me that the Labor Department is violating policies that they set,&amp;rdquo; he said. &amp;ldquo;That&amp;rsquo;s the most frustrating part, to be honest, is that they can&amp;rsquo;t even abide by their own rules.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Labor officials wrote in the internal memo that AI will &amp;ldquo;streamline&amp;rdquo; this work, citing four AI applications under review &amp;ldquo;to improve this process.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The memo stresses these AI tools will play a supporting role in processing reasonable accommodations, and that Civil Rights Center employees &amp;ldquo;will continue to make decisions on necessary actions (including how and what is requested).&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The department expects that AI &amp;ldquo;could triage incoming requests by likely complexity and documentation sufficiency, allowing staff to prioritize effectively.&amp;rdquo; It adds that &amp;ldquo;AI-assisted document analysis&amp;rdquo; could flag incomplete or inconsistent medical documentation earlier in the process, &amp;ldquo;reducing back-and-forth and shortening timelines.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The memo also states that &amp;ldquo;Al-enabled communication capability could engage requestors by providing updates, prompting requestors for additional information, and initiate follow-up to keep requests progressing without staff intervention.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;DOL also wrote that &amp;ldquo;Al could assess whether the accommodation requested is effective for the documented functional limitation,&amp;rdquo; or suggest &amp;ldquo;if other equally effective options exist.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The Labor Department did not respond to a request for comment.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Jodi Hershey, a former reasonable accommodation specialist at the Federal Emergency Management Agency and the founder of the workplace accommodation firm EASE, LLC, said &amp;ldquo;the problem DOL is trying to solve is real&amp;rdquo; &amp;ndash; many federal agencies don&amp;rsquo;t have the staff needed to keep up with the volume of incoming accommodation requests.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I&amp;#39;ve seen employees wait a year or more for a decision on something they needed on day one &amp;mdash; sometimes going without the very accommodation that lets them do their job. So I don&amp;#39;t dismiss the impulse to find a faster path. The status quo is already failing disabled employees,&amp;rdquo; she said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Hershey said AI &amp;ldquo;could genuinely help employees&amp;rdquo; navigate the reasonable accommodation process. &amp;ldquo;But that&amp;#39;s very different from an agency using AI to take the human judgment out of the decision, and that&amp;#39;s where this plan worries me,&amp;rdquo; she said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;&amp;lsquo;A human still makes the final call&amp;rsquo; sounds reassuring, but if the AI has already sorted the case, flagged the documents, and suggested an answer, the human is grading the algorithm&amp;#39;s homework. Real oversight means a person can actually reach a different conclusion &amp;mdash; and that the employee knows a machine was ever involved,&amp;rdquo; she said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Michael Fallings, managing partner at Tully Rinckey PLLC, a firm specializing in federal employment law, said he&amp;rsquo;s represented clients who have waited a year or longer for their agencies to process their reasonable accommodation requests.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;While agencies may be tempted to use AI to speed up the work, Fallings warned that processing confidential medical records through AI tools may raise some legal risks.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I&amp;rsquo;m sure the government&amp;rsquo;s thought process is &amp;hellip; &amp;lsquo;We may not have the number of staff to handle it,&amp;rsquo; but that does then create privacy issues for employees when you&amp;rsquo;re not using people, you&amp;rsquo;re using technology,&amp;rdquo; Fallings said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Hershey said she was most concerned by the Labor Department&amp;rsquo;s plans to triage requests by &amp;ldquo;likely outcome&amp;rdquo; using AI.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The employees with the thinnest documentation are often the ones with the least access to good healthcare, or to anyone who can help them navigate the paperwork. If the system quietly moves those cases to the back of the line, you&amp;#39;ve built a process that works best for the people who needed the least help to begin with,&amp;rdquo; she said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&amp;quot;Hundreds of stories like this&lt;/strong&gt;&amp;quot;&lt;/p&gt;

&lt;p&gt;Aliyah Levin, president of the American Federation of Government Employees Local 2391, said the Labor Department is dealing with a backlog of &amp;ldquo;almost a thousand people that haven&amp;rsquo;t been accommodated.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Many employees, she added, were hired for fully remote positions, or only had to report to the office twice per two-week pay period. President Donald Trump&amp;rsquo;s first-day memo required most federal employees to work onsite &amp;mdash; but&lt;a href="https://www.govexec.com/workforce/2026/01/trumps-return-office-mandate-exempted-feds-disabilities-many-are-being-ordered-work-person-anyway/410524/"&gt; exempted employees with disabilities.&amp;nbsp;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;This administration came in on day one and eliminated all of our workplace flexibilities &amp;mdash; all of them &amp;mdash; and said, &amp;lsquo;No matter what, regardless of who you are, whatever deal you&amp;rsquo;ve got, however you were hired, you now have to have your butt in the seat in an office that you&amp;rsquo;ve never reported to,&amp;rsquo;&amp;rdquo; Levin said.&lt;/p&gt;

&lt;p&gt;Levin said one bargaining unit member, an Occupational Safety and Health Administration employee with a blood-pressure condition and vertigo, was hired as a remote worker, but later was told to start reporting to the office.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Levin said the department granted the OSHA employee a remote work accommodation last month, but &amp;ldquo;there&amp;rsquo;s hundreds and hundreds of stories like this&amp;rdquo; where employees are still waiting to hear back.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;It has a disparate impact on veterans, which have varying degrees of disability. It&amp;rsquo;s affecting them the most,&amp;rdquo; she said.&amp;nbsp; &amp;ldquo;We have people who, for whatever reason, they have issues driving. They rarely drive, never drive, and they live in LA. Now they have to drive to get to work.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Levin said &amp;ldquo;productivity has plummeted, in terms of implementing the mission.&amp;rdquo; Among their duties, DOL employees carry out wage theft investigations, workplace safety enforcement, benefits administration, labor statistics, mine safety inspections and veterans&amp;#39; employment programs.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Omar Algeciras, AFGE Local 2391 vice president and a wage and hour investigator, said that when DOL employees &amp;ldquo;cannot receive the accommodations they need, the public eventually feels the effects.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;quot;The Department of Labor enforces workplace laws across the country. Employees believe the Department should meet the same standard of fairness, accessibility, and accountability expected of every employer,&amp;rdquo; Algeciras said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&amp;quot;Employees are not being protected&amp;quot;&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Another Labor Department employee said she&amp;rsquo;s been waiting nine months for her reasonable accommodation request to be processed. She said she received an interim accommodation while her paperwork is under review, but it&amp;#39;s&amp;nbsp;scheduled to run out soon.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I started reaching out three or four weeks ago, before the expiration, asking for an update &amp;ndash; asking about the interactive process being started, and none of that has happened. I haven&amp;rsquo;t gotten an update,&amp;rdquo; she said.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The Labor Department, she added, is &amp;ldquo;supposed to be protecting American workers, and their employees are not being protected.&amp;rdquo;&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;A third employee requested a reasonable accommodation to work from home about half of the time in August 2025. The request was granted in February 2026, but he is still waiting for an ergonomic chair and standing desk.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I am finally seeing some progress, but I just don&amp;rsquo;t know why a basic chair took so long to get,&amp;rdquo; he said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The third Labor Department employee said the department saw a surge in reasonable accommodation requests following the Trump administration&amp;rsquo;s return-to-office mandate, but a shrinking human resources workforce has been unable to keep up.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;They&amp;rsquo;re just so backed up because a lot of people took the Fork [in the Road]. They really haven&amp;rsquo;t filled these positions to be able to process these reasonable accommodations,&amp;rdquo; the employee said. &amp;ldquo;People need them.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The third employee said the HR worker assigned to process his reasonable accommodation request has changed three times so far.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;A fourth employee, a combat veteran, said he requested a reasonable accommodation in January to manage his depression and anxiety, but is still waiting to hear back.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We enforce workers&amp;rsquo; protections, but then here I am, dealing with my own dilemma,&amp;rdquo; he said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;A fifth employee, a disabled veteran who was hired to a fully remote position in 2024, said she requested a reasonable accommodation in April 2025 after being asked to report to the office full-time.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;After adjusting to remote work and the benefits of how it positively impacted my mental health, it really set me in an anxiety spiral, where I was just like&amp;rsquo; &amp;lsquo;This is uncomfortable,&amp;rsquo;&amp;rdquo; she said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The employee said the department ultimately shelved her RA request, allowing her to continue working remotely because her husband is a 100% disabled veteran. The Trump administration has&lt;a href="https://www.war.gov/News/News-Stories/Article/Article/4069473/military-spouses-exempted-from-return-to-work-mandate/"&gt; exempted spouses&lt;/a&gt; of 100% disabled veterans from its return-to-office mandate.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;That accommodation may be short-lived. The employee said she received an offer for a new Labor Department job, but was told her military spouse RTO exemption would not apply. To avoid having to relocate across the country, the employee was advised to submit a new reasonable accommodation request, but was warned there are no guarantees it will be accepted.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;They&amp;rsquo;re telling me maybe if I reapplied for a reasonable accommodation under the new job &amp;hellip; then it might be accepted. &amp;ldquo;I have to accept the new job and then apply for the reasonable accommodation,&amp;rdquo; the employee said. &amp;ldquo;But that&amp;rsquo;s really terrifying, because I am not in a position to move. My spouse has a well-established care team and everything in place. We can&amp;rsquo;t just pick that up and move.&amp;rdquo;&lt;/p&gt;

&lt;div class="related-articles-placeholder"&gt;[[Related Posts]]&lt;/div&gt;

&lt;p&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/18/DOL/large.png" width="618" height="284"><media:description>Labor Department employees told Government Executive that the department is facing a backlog of hundreds of reasonable accommodation requests.</media:description><media:credit>Kevin Carter/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/18/DOL/thumb.png" width="138" height="83"></media:thumbnail></media:content></item><item><title>White House S&amp;T strategy calls for new approaches to safeguard US research</title><link>https://www.nextgov.com/policy/2026/08/white-house-st-strategy-calls-new-approaches-safeguard-us-research/415477/</link><description>The new guidance says the U.S. "will further strengthen its workforce by attracting and retaining top-tier global talent in critical national security S&amp;T fields” — a departure from last year’s National Security Strategy that said global talent “undercuts American workers.”</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Edward Graham</dc:creator><pubDate>Mon, 17 Aug 2026 18:20:00 -0400</pubDate><guid>https://www.nextgov.com/policy/2026/08/white-house-st-strategy-calls-new-approaches-safeguard-us-research/415477/</guid><category>Policy</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Trump administration says the nation&amp;rsquo;s science and technology research ecosystem needs to embrace &amp;ldquo;novel security solutions&amp;rdquo; to ensure the U.S. maintains its global edge, according to a new document publicly released on Monday.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The &lt;a href="https://www.whitehouse.gov/wp-content/uploads/2026/08/NSSTS-082026.pdf"&gt;National Security Science and Technology Strategy&lt;/a&gt; published by the White House Office of Science and Technology Policy outlines how the U.S. innovation sector should be leveraged and guarded to defend the country. The new document builds off last year&amp;rsquo;s &lt;a href="https://www.nextgov.com/cybersecurity/2025/12/trumps-national-security-strategy-wants-spy-agencies-watch-world-supply-chains/409971/"&gt;National Security Strategy&lt;/a&gt;, which called, in part, for &amp;ldquo;protecting the competitiveness of the U.S. economy and bolstering the resilience of the American technology sector.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;To help safeguard the nation&amp;rsquo;s innovation sector from threats &amp;ldquo;that could impair U.S. economic and military strength and competitiveness,&amp;rdquo; the strategy calls for &amp;ldquo;approaches that protect without inhibiting the productivity and agility of the national security S&amp;amp;T enterprise.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;President Donald Trump previously moved to curtail illicit foreign interference in the nation&amp;rsquo;s research institutions, most notably through a &lt;a href="https://trumpwhitehouse.archives.gov/presidential-actions/presidential-memorandum-united-states-government-supported-research-development-national-security-policy/"&gt;January 2021 memo&lt;/a&gt; that sought to keep adversarial governments from exploiting U.S. science and technology research.&lt;/p&gt;

&lt;p&gt;Lawmakers from both parties have also pushed legislation to limit Chinese involvement in federally-funded research projects, and the Pentagon similarly &lt;a href="https://www.war.gov/News/Releases/Release/Article/4575019/department-of-war-orders-research-security-audits-at-30-academic-institutions/"&gt;announced&lt;/a&gt; on Monday that it called for 30 U.S. academic institutions to review their ties with foreign entities.&lt;/p&gt;

&lt;p&gt;But the strategy says research institutions need to take further steps to enhance their threat awareness, including conducting &amp;ldquo;automated research security vetting&amp;rdquo; of agency-funded research proposals and performing continuous monitoring of federally-supported projects.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;It also calls for &amp;ldquo;bolstering counter-intelligence support to governmental and non-governmental research centers&amp;rdquo; &amp;mdash; which would give researchers more immediate and timely insights into potential threats &amp;mdash; and creating &amp;ldquo;risk-based review criteria and a repository of sharable information to enhance the efficiency of information collection and sharing among agencies.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;It noted, for instance, that the FBI-led &lt;a href="https://www.nextgov.com/emerging-tech/2026/06/white-house-expected-direct-intelligence-agencies-protect-quantum-research-foreign-threats/414308/"&gt;Quantum Information Science and Technology Counterintelligence Protection Team&lt;/a&gt; &amp;ldquo;brings an interagency team of quantum experts and security professionals to fine-tune technology protection and security outreach activities for the quickly evolving quantum R&amp;amp;D community.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Another section calls for &amp;ldquo;establishing cybersecurity guidelines for researchers and research institutions,&amp;rdquo; although it is sparse on the details of what this would look like. The National Science Foundation, for its part, has a &lt;a href="https://www.nsf.gov/research-security"&gt;research security policy framework&lt;/a&gt; that includes some cyber-specific guidance as part of its broader blueprint.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Given the evolving nature of research security threats, security experts should embrace comprehensive, new, and novel security solutions, particularly where they can be crafted to address unique or nuanced requirements of specific technology fields,&amp;rdquo; the document said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The strategy&amp;rsquo;s implementation section highlights the need to enhance K-12 and higher education training opportunities and bring more skilled talent into the federal workforce &amp;mdash; an effort the Trump administration &lt;a href="https://www.nextgov.com/people/2026/04/opm-cuts-degree-requirements-government-tech-jobs-new-standards/412884/"&gt;has been undertaking&lt;/a&gt;, in part, by prioritizing skills-based hiring over degree requirements.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Notably, however, the strategy references the need to attract more nonimmigrant tech workers to the U.S., which differs from the Trump administration&amp;rsquo;s prior stance that called for a more restrictive approach.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The United States will further strengthen its workforce by attracting and retaining top-tier global talent in critical national security S&amp;amp;T fields,&amp;rdquo; the strategy says. &amp;ldquo;Agencies will collaborate on using existing authorities to recruit the exquisite talent necessary to ensure the national security S&amp;amp;T Enterprise leads the world in developing and applying these technologies.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;OSTP did not immediately respond to a request for comment about the strategy&amp;rsquo;s inclusion of the need to attract and retain global talent.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Last year&amp;rsquo;s National Security Strategy &lt;a href="https://www.whitehouse.gov/wp-content/uploads/2025/12/2025-National-Security-Strategy.pdf"&gt;said, in part&lt;/a&gt;, that the U.S. &amp;ldquo;cannot allow meritocracy to be used as a justification to open America&amp;rsquo;s labor market to the world in the name of finding &amp;lsquo;global talent&amp;rsquo; that undercuts American workers.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Trump issued a &lt;a href="https://www.whitehouse.gov/presidential-actions/2025/09/restriction-on-entry-of-certain-nonimmigrant-workers/"&gt;proclamation&lt;/a&gt; in September 2025 that moved to restrict the number of H-1B visas, saying that the program has harmed American workers. The visas allow U.S. firms to temporarily hire foreign workers, with the tech industry notably using the program to attract nonimmigrant talent. The proclamation attempted to institute a $100,000 H-1B visa fee, although a district court has &lt;a href="https://news.bloomberglaw.com/daily-labor-report/first-circuit-denies-trump-bid-to-pause-order-tossing-h-1b-fee"&gt;overturned&lt;/a&gt; that mandate.&lt;/p&gt;

&lt;p&gt;In addition to calling for the nation&amp;rsquo;s innovation sector to embrace new security solutions, the strategy said the U.S. needs to speed up its pace of innovation, build up its domestic &amp;ldquo;technological resilience&amp;rdquo; and focus its science and technology ecosystem on &amp;ldquo;maintaining battlefield advantage, countering strategic threats to the homeland, and shaping the competition toward areas of U.S. strength.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Nextgov/FCW Cyber Reporter David DiMolfetta contributed to this story.&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/17/GettyImages_2289747070/large.jpg" width="618" height="284"><media:credit>Kevin Carter/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/17/GettyImages_2289747070/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>National crisis and support hotline operations remained consistent despite staffing cuts, watchdog found</title><link>https://www.nextgov.com/people/2026/08/national-crisis-and-support-hotline-operations-remained-consistent-despite-staffing-cuts-watchdog-found/415469/</link><description>Some staff operating mental health support hotlines at the departments of Health and Human Services and Veterans Affairs were subject to reductions in force last year and have not yet been replaced.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christian Robles</dc:creator><pubDate>Mon, 17 Aug 2026 15:55:00 -0400</pubDate><guid>https://www.nextgov.com/people/2026/08/national-crisis-and-support-hotline-operations-remained-consistent-despite-staffing-cuts-watchdog-found/415469/</guid><category>People</category><content:encoded>&lt;![CDATA[&lt;p&gt;Three hotlines offering Americans mental health crisis support saw the quality of their services remain consistent and their communications increase, even as the federal agencies managing them saw a slight decline in staff, according to a &lt;a href="https://www.gao.gov/assets/gao-26-109046.pdf"&gt;Government Accountability Office report&lt;/a&gt; published on Aug. 6.&lt;/p&gt;

&lt;p&gt;The 988 Suicide &amp;amp; Crisis Lifeline, Veterans Crisis Line and National Maternal Mental Health Hotline generally saw calls, texts and chats increase in fiscal 2025 compared to fiscal 2024, the watchdog found.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Performance metrics remained largely consistent across the three hotlines amid the spike in communications, according to the report.&lt;/p&gt;

&lt;p&gt;The 988 Lifeline saw answer rates &amp;mdash; the percentage of contacts routed to crisis contact centers and answered by crisis counselors &amp;mdash; hold steady for calls and texts throughout fiscal 2025 at levels comparable to past fiscal years, GAO found. The hotline also saw the average response times for calls remain steady throughout fiscal 2025 but did see large variations in the average response times for texts and chats.&lt;/p&gt;

&lt;p&gt;The Veterans Crisis Line saw monthly answer rates for texts, chats and calls remain &amp;ldquo;high throughout [fiscal] 2025&amp;rdquo; &amp;mdash; 89% to 99% &amp;mdash; and &amp;ldquo;consistent with previous years,&amp;rdquo; according to GAO. The average response time for answered calls and texts in fiscal 2025 were 8.6 and 27.1 seconds, respectively, which are comparable to the averages from fiscal 2021 through 2024, the watchdog concluded.&lt;/p&gt;

&lt;p&gt;The National Maternal Mental Health Hotline saw &amp;ldquo;high&amp;rdquo; monthly answer rates for calls and texts of 92% to 95% throughout fiscal 2025, the report found. Throughout the fiscal year, 89% to 94% of hotline contacts had wait times of less than 30 seconds, it added.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Staffing changes&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The findings suggest that the performance of all three mental health support hotlines was largely insulated from the operational challenges other federal agencies faced following sweeping 2025 reductions in force.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The departments of Health and Human Services and Veterans Affairs lost some employees working on the hotlines under 2025 reductions in force, GAO found.&lt;/p&gt;

&lt;p&gt;The 988 Lifeline coordinating office, for example, saw its headcount drop from 24 to 18 during fiscal 2025, according to GAO. The Substance Abuse and Mental Health Services Administration, which oversees the office, had not backfilled those positions as of February 2026.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;But the watchdog cautioned that overall workforce changes for the 988 Lifeline are unknown because the number&amp;rsquo;s crisis responders are employed by over 200 local crisis contact centers. GAO did not tabulate workforce changes for these local facilities.&lt;/p&gt;

&lt;p&gt;A &lt;a href="https://jamanetwork.com/journals/jamanetworkopen/fullarticle/2848613?utm_campaign=articlePDF&amp;amp;utm_medium=articlePDFlink&amp;amp;utm_source=articlePDF&amp;amp;utm_content=jamanetworkopen.2026.10789"&gt;May 2026 survey&lt;/a&gt; in&amp;nbsp;JAMA, however, found that 71% of 988 Lifeline center leaders say their center is understaffed and almost 90% of them reported difficulty acquiring resources to hire staff.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;This study suggests that 988 Lifeline center staffing shortages could be associated with operational demands, underscoring the importance of increased investments to bolster the 988 Lifeline workforce,&amp;rdquo; the medical journal&amp;#39;s&amp;nbsp;survey concluded.&lt;/p&gt;

&lt;p&gt;The Veterans Crisis Line saw its workforce remain largely steady, dropping to 1,149 in April 2026 from 1,162 in October 2024, according to the GAO report. Additionally, the hotline&amp;rsquo;s responder turnover rate hit 18% in fiscal 2025, which is on par with the 17% it saw in fiscal 2024, the report added.&lt;/p&gt;

&lt;p&gt;HHS lost four of the six full-time employees dedicated to providing oversight of National Maternal Mental Health Hotline operations under an April 2025 reduction in force, the Health Resources and Services Administration told GAO. Those four positions have not been filled and staff from other programs have been fulfilling oversight responsibilities as of March 2026, the agency told GAO.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The watchdog did not assess whether the contractor that operates and staffs the hotline, Postpartum Support International, saw a change in staffing levels.&lt;/p&gt;

&lt;p&gt;A spokesperson for Sen. Maggie Hassan, D-N.H., who requested the GAO report, did not return a request for comment by the time of publication.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/17/GettyImages_1393097396/large.jpg" width="618" height="284"><media:credit>A stockphoto/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/17/GettyImages_1393097396/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>CMMC Works. Now let’s sharpen it.</title><link>https://www.nextgov.com/ideas/2026/08/cmmc-works-now-lets-sharpen-it/415465/</link><description>COMMENTARY | This is not the moment to loosen the standard. The Defense Federal Acquisition Regulation Supplement requirements behind CMMC should not change.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Katie Arrington</dc:creator><pubDate>Mon, 17 Aug 2026 15:19:00 -0400</pubDate><guid>https://www.nextgov.com/ideas/2026/08/cmmc-works-now-lets-sharpen-it/415465/</guid><category>Ideas</category><content:encoded>&lt;![CDATA[&lt;p&gt;I built the&lt;a href="https://dodcio.defense.gov/cmmc/About/"&gt; Cybersecurity Maturity Model Certification&lt;/a&gt; because self-attestation was failing our war industrial base. Contractors could simply promise they were following basic cybersecurity practices, with no verification behind that promise. Our adversaries noticed that gap long before Washington did &amp;mdash; and they have not eased up since. If anything, the opposite is true.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Nation-state actors and the ransomware crews they tolerate or direct are more aggressive, better funded, and faster than they were five years ago. This is not the moment to loosen the standard. The Defense Federal Acquisition Regulation Supplement requirements behind CMMC should not change, and I would not support it if they did.&lt;/p&gt;

&lt;p&gt;But defending a program doesn&amp;#39;t mean pretending it&amp;#39;s perfectly aimed. Now that CMMC is a final rule moving into real contracts, it&amp;#39;s the right time to ask: are we targeting it precisely enough? I don&amp;#39;t think we are yet &amp;mdash; and artificial intelligence, used correctly, can help fix that without touching the cybersecurity bar itself.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The problem is targeting, not the standard&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;CMMC&amp;#39;s requirements hinge on controlled unclassified information. But CUI determinations across the war industrial base are inconsistent: Two subcontractors doing nearly identical work can end up with completely different assessments because the call still depends on manual judgment with incomplete visibility into how data actually flows down. Some small businesses get pushed into heavy assessment burdens for data that isn&amp;#39;t really CUI. Others handling real, sensitive data slip through with a lighter requirement. Neither outcome helps national security; the first wastes compliance dollars, the second leaves real exposure unaddressed.&lt;/p&gt;

&lt;p&gt;AI can do the first-pass sorting here &amp;mdash; flagging likely CUI from contract language and statements of work and catching mismatches between what a prime contract designates and what actually flows down to subcontractors &amp;mdash; far more consistently than today&amp;#39;s patchwork of manual reviews. In this scenario, a human with contracting authority still makes the final call. But that human should be working from a much better starting point than we give them now.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Small business is the economy, not just the supply chain&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Small businesses&lt;a href="https://advocacy.sba.gov/2026/02/03/frequently-asked-questions-about-small-business-2026/"&gt; are 99.9%&lt;/a&gt; of American companies and employ nearly half the private workforce. And right now, they face threats most aren&amp;#39;t equipped to handle: ransomware that can shut down operations overnight; AI-enabled fraud that&amp;#39;s harder to spot every year, and a coming reckoning when quantum computing breaks today&amp;#39;s standard encryption. The quantum threat is already real, since data harvested now can simply be decrypted later.&lt;/p&gt;

&lt;p&gt;I&amp;#39;m glad the Small Business Administration is leaning into this.&lt;a href="https://www.congress.gov/crs-product/IF12732"&gt; Its Cybersecurity for Small Business Pilot Program&lt;/a&gt; has done real work funding training through state partners. But training grants aren&amp;#39;t capital, and no amount of counseling gets a small manufacturer through a ransomware recovery or a quantum-resistant encryption upgrade. Small businesses can&amp;#39;t get favorable financing for cybersecurity the way they can for equipment because most lenders don&amp;#39;t know how to underwrite it.&lt;/p&gt;

&lt;p&gt;We need a dedicated SBA loan program for cybersecurity investment &amp;mdash; open to every small business, not just those working with the Department of War &amp;mdash; to fund things like multi-factor authentication rollouts, endpoint detection, incident response, and early migration toward quantum-resistant encryption, before it&amp;#39;s an emergency instead of a plan.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Same mission, two fronts&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Inside the war industrial base, use AI to make sure CUI calls and flow-down match reality. Outside it, give the broader small business economy the capital to defend itself against adversaries who are only getting more aggressive. I still believe unverified promises are not a security strategy. But precision and support aren&amp;#39;t the enemies of security &amp;mdash; they&amp;#39;re what make it sustainable.&lt;/p&gt;

&lt;p&gt;Sharpen how we target CMMC, and open the door for every small business to invest in its own war footing. That&amp;#39;s not lowering the bar. That&amp;#39;s making sure the bar is doing its job.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Katie Arrington is a former South Carolina state legislator and cybersecurity executive who served as DoD CISO for Acquisition and Sustainment starting in 2019, and later returned as DoD CISO/PTDO DoD CIO under the second Trump administration. She spearheaded the Pentagon&amp;rsquo;s initial efforts to create the CMMC program for defense contractors beginning in 2019, driven by a conviction that contractors needed to actually prove &amp;mdash; not just self-attest to &amp;mdash; their cybersecurity compliance in order to protect sensitive defense data from adversaries. Her commitment to the program has been described as stemming from a deeply personal mission to secure the Defense Industrial Base from cyber threats that jeopardize national security.&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/17/GettyImages_2287542899/large.jpg" width="618" height="284"><media:credit>Kevin Carter/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/17/GettyImages_2287542899/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>L3Harris promotes Mehta to CEO in abrupt leadership change</title><link>https://www.nextgov.com/people/2026/08/l3harris-promotes-mehta-ceo-abrupt-leadership-change/415462/</link><description>Chris Kubasik, L3Harris’ CEO since June 2021, has left the company following a code of conduct investigation.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ross Wilkers</dc:creator><pubDate>Mon, 17 Aug 2026 09:31:47 -0400</pubDate><guid>https://www.nextgov.com/people/2026/08/l3harris-promotes-mehta-ceo-abrupt-leadership-change/415462/</guid><category>People</category><content:encoded>&lt;![CDATA[&lt;p&gt;L3Harris Technologies&amp;rsquo; board of directors has promoted Sam Mehta to chief executive from his former role as president of space and mission systems in an abrupt leadership change announced Monday.&lt;/p&gt;

&lt;p&gt;Chris Kubasik, &lt;a href="https://www.washingtontechnology.com/2021/08/l3harris-declares-its-post-merger-divestiture-push-as-nearly-done/355416/"&gt;L3Harris&amp;rsquo; CEO since June 2021&lt;/a&gt;, stepped down from that position and his other roles as chairman and member of the board of directors effective immediately.&lt;/p&gt;

&lt;p&gt;L3Harris said the board determined to enter into a separation agreement with Kubasik after an investigation found conduct by him that was &amp;ldquo;not consistent with the values of the company as outlined in its code of conduct.&amp;rdquo;&amp;nbsp;The company added the alleged conduct was not related to its financial reporting, controls, customer relationships or operational performance.&lt;/p&gt;

&lt;p&gt;Mehta &lt;a href="https://www.washingtontechnology.com/companies/2023/01/l3harris-hires-new-communications-segment-leader/381398/"&gt;joined L3Harris in 2023&lt;/a&gt; as president of the communications segment, then added the additional title of president of the space and mission systems segment &lt;a href="https://www.washingtontechnology.com/companies/2026/03/karmans-incoming-ceo-and-more-leadership-moves-across-market/412105/"&gt;at the start of this year&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;This transition at the very top of L3Harris is taking place in a year where the company announced its &lt;a href="https://www.washingtontechnology.com/companies/2026/01/l3harris-spin-its-rocket-motor-business-pentagon-anchor-investor/410644/"&gt;intentions to take the missile solutions segment public&lt;/a&gt; following a $1 billion investment from the Defense Department.&lt;/p&gt;

&lt;p&gt;L3Harris originally eyed the second half of this year for the initial public offering, but Kubasik &lt;a href="https://www.washingtontechnology.com/companies/2026/07/l3harris-presses-pause-missile-solutions-ipo-plan/415121/"&gt;told investors in July that the IPO&lt;/a&gt; is being delayed until at least mid-2027 because of market conditions the company sees as not reflecting the value of Mission Solutions.&lt;/p&gt;

&lt;p&gt;Kubasik&amp;rsquo;s tenure as CEO started with the completion of the integration of L3 Technologies and Harris Corp. &lt;a href="https://www.washingtontechnology.com/2019/07/with-deal-done-l3-harris-combo-takes-initial-shape/326567/"&gt;following their merger in 2019&lt;/a&gt;, and includes the $4.7 billion &lt;a href="https://www.washingtontechnology.com/companies/2023/10/l3harris-gets-new-lens-capacity-aerojet-its-fold/391577/"&gt;acquisition of Aerojet Rocketdyne in 2023&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The pending Missile Solutions IPO is not the only move L3Harris has undertaken with respect to its space business. L3Harris closed the sale of a &lt;a href="https://www.washingtontechnology.com/companies/2026/08/rocketdyne-returns-market/415202/"&gt;60% stake in the space propulsion and power systems business this month&lt;/a&gt; to AE Industrial Partners, while retaining a 40% stake.&lt;/p&gt;

&lt;p&gt;In addition to Mehta&amp;rsquo;s promotion, Lauren Barnes has moved up to be president of the space and mission systems segment from her prior role as president of spectrum superiority. Christopher Aebli, formerly president of mission critical communications, was elevated to president of the communications and spectrum dominance.&lt;/p&gt;

&lt;p&gt;Lewis Hay III, a member of the L3Harris and a predecessor board since 2002, was elected chairman after previously holding the title of lead independent director.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/17/L3Harris_logo-2/large.jpg" width="618" height="284"><media:description>L3Harris Technologies signage at Special Operations Forces Week in May in Tampa, Florida.</media:description><media:credit>Photo by Luke Sharrett / Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/17/L3Harris_logo-2/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>As warfare becomes engineering, the era of the digital mercenary dawns</title><link>https://www.nextgov.com/cybersecurity/2026/08/warfare-becomes-engineering-era-digital-mercenary-dawns/415442/</link><description>The White House revives “privateering for the digital age” by authorizing cyber firms to strike foreign targets.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Patrick Tucker</dc:creator><pubDate>Fri, 14 Aug 2026 20:28:52 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/warfare-becomes-engineering-era-digital-mercenary-dawns/415442/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;Private cyber firms will be allowed to take action against foreign threats under a new White House policy, another step into a future where tech developers are ever more closely entwined with military operations, which now evolve faster than governments can keep up.&lt;/p&gt;

&lt;p&gt;Under the policy, &lt;a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/"&gt;announced&lt;/a&gt; Wednesday, the U.S. government will pay private cybersecurity companies to &amp;ldquo;manipulate,&amp;rdquo; &amp;ldquo;degrade,&amp;rdquo; &amp;ldquo;disrupt,&amp;rdquo; and &amp;ldquo;destroy&amp;rdquo; foreign adversary computer networks. The U.S. government historically reserves the right to take those sorts of actions, although they increasingly do so with help from front-line private workers.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The companies will undergo vetting, be supervised by the departments of Justice and Homeland Security, and be forbidden to take actions that could &amp;ldquo;result in the loss of life or serious injury,&amp;rdquo; according to the presidential memo.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The United States just revived privateering for the digital age,&amp;rdquo; &lt;a href="https://controlsystemssecurity.com/posts/cyberteering-return-letter-marque-cyberspace.html"&gt;wrote&lt;/a&gt; Jeff Gray, who led training for DHS&amp;rsquo;s emergency response team and currently leads incident response training with the Cybersecurity and Infrastructure Security Agency.&lt;/p&gt;

&lt;p&gt;The phrase recalls the 17th and 18th centuries, when governments issued letters of marque that allowed swashbuckling sea captains to attack foreign merchant ships. That official authorization is what distinguished men like Captain Kidd and Henry Morgan as &amp;ldquo;privateers,&amp;rdquo; not pirates. But when they lost that marque, many, like Kidd, went on to be pirates anyway.&lt;/p&gt;

&lt;p&gt;Gray acknowledges that the term isn&amp;rsquo;t a perfect fit; for one thing, letters of marque are &lt;a href="https://constitution.congress.gov/browse/essay/artI-S8-C11-3-4/ALDE_00000196/"&gt;granted&lt;/a&gt; by Congress, not the president. Nevertheless, he says, &amp;ldquo;The government is authorizing private actors to conduct offensive cyber operations on its behalf, under its control. That&amp;#39;s privateering.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The memo says hiring private hackers is only logical:&amp;nbsp; &amp;ldquo;American businesses&amp;rsquo; innovative capabilities have historically been underutilized&amp;rdquo; to &amp;ldquo;secure a critical offensive cyber advantage for the United States.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Russia has been &lt;a href="https://www.defenseone.com/technology/2021/10/russian-corruption-makes-it-harder-crack-down-ransomware/186252/"&gt;doing&lt;/a&gt; this sort of thing for years: enlisting, or &lt;a href="https://therecord.media/a-conversation-with-alisa-esage-a-russian-hacker-who-had-her-company-sanctioned-after-the-2016-election"&gt;coercing&lt;/a&gt;, private companies and groups to carry out cyberattacks against Western targets.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;One cybersecurity exec said the policy makes sense, especially as AI gives adversaries more tools.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;There will be more cyberattacks for sure, so I do think you want to expand the takedown activity as well,&amp;rdquo; said the executive, a founder of a prominent U.S. cybersecurity firm that works with the U.S. government.&lt;/p&gt;

&lt;p&gt;AI-assisted cyberattacks rose 89 percent in 2025, according to a February&lt;a href="https://go.crowdstrike.com/rs/281-OBQ-266/images/CrowdStrike-2026-Global-Threat-Report.pdf"&gt; report f&lt;/a&gt;rom cybersecurity company CrowdStrike.&lt;/p&gt;

&lt;p&gt;Gray also described the strategy as &amp;ldquo;strategically sound.&amp;rdquo; But he expects it to provoke a short-term increase in attacks, and over a longer timeframe, to cause adversaries to shift tactics, accelerate operations, and gain additional &amp;ldquo;cover&amp;rdquo; to hide their operations.&lt;/p&gt;

&lt;p&gt;Finally, Gray noted that law-enforcement agencies have long &lt;a href="https://www.justice.gov/usao-ak/pr/authorities-disrupt-worlds-largest-iot-ddos-botnets-responsible-record-breaking-attacks"&gt;hired&lt;/a&gt; private firms for this sort of work, particularly taking down &lt;a href="https://www.justice.gov/archives/opa/pr/justice-department-announces-court-authorized-disruption-botnet-controlled-russian-federation#:~:text=%E2%80%9CBy%20working%20closely%20with%20WatchGuard%20and%20other,public%2Dprivate%20partnership%20brings%20to%20our%20country's%20cybersecurity."&gt;botnets&lt;/a&gt;. &amp;ldquo;The work is still the same. But the environment just got more complicated,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;The cyber exec agreed. &amp;ldquo;Instead of a law-enforcement person pushing the button, it will be a private-sector person,&amp;rdquo; said the company founder. &amp;ldquo;I expect every Israeli cyber startup to jump at the chance.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Cyberops and physical war&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The policy is the latest indication that software weapons are &lt;a href="https://www.defenseone.com/business/2025/06/pentagon-pushes-us-dronemakers-innovate-quickly-ukraine-does/405739/"&gt;evolving&lt;/a&gt; to be as crucial as hardware on the modern battlefield&amp;mdash;and that is putting private coders and weapon designers &lt;a href="https://www.defenseone.com/technology/2024/10/us-made-jam-resistant-drones-are-helping-ukrainians-cut-through-russia-ew/400735/"&gt;closer&lt;/a&gt;&lt;strong&gt; &lt;/strong&gt;to real-world operations. In Ukraine, for example, engineers with drone maker Shield AI and other contractors work closely with soldiers, sometimes under fire, to modify weapons based on digital attacks.&lt;/p&gt;

&lt;p&gt;The job of fighting is, more and more, becoming a job of engineering, said one former senior defense official we spoke to in 2025, just after Donald Trump returned to office. The official said that the Pentagon&amp;rsquo;s new leaders were considering a plan to let drone makers and other tech companies conduct operations under company-owned, company-operated agreements.&lt;/p&gt;

&lt;p&gt;The idea was not without precedent. SpaceX operates the Starlink satellites that connect U.S. troops, rather than allowing U.S. personnel to do so. And under the first Trump administration, the Pentagon &lt;a href="https://www.anduril.com/news/special-operations-command-selects-anduril-industries-as-systems-integration-partner"&gt;paid&lt;/a&gt; Anduril to maintain and update drones in the field, deploying along with special operations forces.&lt;/p&gt;

&lt;p&gt;The official said putting engineers in the field is essential to getting new capabilities to the front lines faster.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;A lot of these technologies,&amp;rdquo; they said, are&amp;nbsp; &amp;ldquo;super exquisite, they&amp;#39;re fragile, they&amp;#39;re very technical. The people that built them are the ones that know how they work.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Having the weapons&amp;rsquo; makers observe and even operate their products in the field reduced red tape in getting new designs approved, changed, or deployed.&lt;/p&gt;

&lt;p&gt;The official last year acknowledged that most defense firms don&amp;rsquo;t operate that way, and federal law outlines boundaries on what defense contractors can and can&amp;rsquo;t do (engaging in combat is in the &amp;quot;can&amp;rsquo;t do&amp;quot; column). But ultimately, they said, &amp;ldquo;If you want capability in 2027 the only way you&amp;#39;re going to get is if this happens.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;In April, CENTCOM &lt;a href="https://shield.ai/shield-ai-selected-by-u-s-navy-to-compete-for-800m-in-isr-services-with-v-bat/"&gt;hired&lt;/a&gt; Shield AI to provide intelligence, surveillance, and reconnaissance to U.S. forces with its V-BAT drone, under a contractor-owned, contractor-operated arrangement.&lt;/p&gt;

&lt;p&gt;Brandon Tseng, Shield AI&amp;rsquo;s co-founder, said of the agreement: &amp;ldquo;We aren&amp;rsquo;t just bringing the V-BAT product and service to the Navy; we&amp;rsquo;re bringing a world-class team with a wealth of operational experience and the ability to produce undeniable outcomes for our warfighters.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/14/GettyImages_2197446878_1/large.jpg" width="618" height="284"><media:description>A 10th Mountain Division soldier operates a simulation of the Low Altitude Stalking and Strike Ordnance (LASSO) loitering munition during the Combined Resolve 25-1 exercise at the Hohenfels Training Area near Hohenfels, Germany, on February 3, 2025.</media:description><media:credit>Sean Gallup/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/14/GettyImages_2197446878_1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Tech Bills of the Week: Leveraging AI for environmental evaluations; crafting a report on China’s AI ecosystem; and more</title><link>https://www.nextgov.com/policy/2026/08/tech-bills-week-leveraging-ai-environmental-evaluations-crafting-new-report-chinas-ai-stack-ecosystem-and-limiting-adversarial-access-national-labs/415441/</link><description>Recently proposals look, in part, to deploy artificial intelligence solutions to prevent natural disasters from impeding U.S. military operations and evaluate China’s AI chip manufacturing sector.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alexandra Kelley and Edward Graham</dc:creator><pubDate>Fri, 14 Aug 2026 18:31:00 -0400</pubDate><guid>https://www.nextgov.com/policy/2026/08/tech-bills-week-leveraging-ai-environmental-evaluations-crafting-new-report-chinas-ai-stack-ecosystem-and-limiting-adversarial-access-national-labs/415441/</guid><category>Policy</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;strong&gt;Using AI for environmental evaluations near military sites&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A bill introduced on Aug. 6 aims to fortify the U.S. military by improving the management of natural resources near military installations with the help of AI technology.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.congress.gov/bill/119th-congress/house-bill/10069/text?s=2&amp;amp;r=3&amp;amp;hl=artificial+intelligence"&gt;The Military Readiness Through Resilient Lands Act&lt;/a&gt; &amp;mdash; introduced by Reps. George Whitesides, D-Calif., Chrissy Houlahan, D-Pa., and Mike Haridopolos, R-Fla. &amp;mdash; seeks to amend the Sikes Act of 1960 to modernize the Pentagon&amp;rsquo;s conservation efforts for natural resources located on military bases.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The bill would support the conservation provisions stipulated in the Sikes Act by mandating the Department of Defense to assess and, as deemed appropriate, apply AI and other technologies to help develop and maintain site-specific conservation goals and metrics. AI would be used to support the &amp;ldquo;assessment of natural resources and ecosystem services as relevant to mission readiness, climate resilience, or community safety on military installations.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;In applying advanced technologies like AI to evaluate the status of the environment and natural resources near military bases, Defense can then forecast and prevent natural disasters from impeding national security operations.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;As our nation&amp;rsquo;s military continues to protect our country, it is imperative that our bases and installations are prepared for potential threats, including natural disasters,&amp;rdquo; said Whitesides in &lt;a href="https://whitesides.house.gov/2026/08/07/reps-whitesides-houlahan-haridopolos-introduce-bipartisan-bill-to-bolster-military-readiness-for-natural-disasters/"&gt;a press release&lt;/a&gt;. &amp;ldquo;If a wildfire strikes a military installation, like we saw in Camp Pendleton earlier this year, it could shut down its operations, putting all of us at risk. Through the use of advanced technology and cutting-edge monitoring systems, our military can better understand the natural resources that exist on their installations, and take preventative actions to protect the installation from threats like natural disasters.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Monitoring AI in China&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Sen. Jon Husted, R-Ohio, introduced a measure on Aug. 7 that seeks to provide a closer look at China&amp;rsquo;s AI stack manufacturing sector via an annual review.&lt;/p&gt;

&lt;p&gt;The bill, &lt;a href="https://www.congress.gov/bill/119th-congress/senate-bill/5382/text?s=2&amp;amp;r=2&amp;amp;hl=artificial+intelligence"&gt;the China AI Power Report Act&lt;/a&gt;, tasks the secretaries of the departments of Commerce and State with spearheading an annual report on what China&amp;rsquo;s government is doing to further advance its AI stack, specifically focusing on its supply chain operations.&lt;/p&gt;

&lt;p&gt;The state of semiconductor chips being manufactured and employed in China is the starring topic of the report. The report would assess details like the processing power and efficiency of AI computing chips, corresponding software, chip manufacturing costs, and other chip design and sector details.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;America must continue to compete and win in the technology race, but we know that communist China&amp;rsquo;s strategy has never been to compete, but to steal and exploit. This bipartisan package would strengthen our understanding of China&amp;rsquo;s action, improve enforcement and protect American companies, workers and innovations from Chinese espionage,&amp;rdquo; Husted &lt;a href="https://www.husted.senate.gov/media/press-releases/husted-warner-lead-bipartisan-package-of-bills-to-strengthen-u-s-national-security-and-hold-china-accountable/"&gt;said in a press release&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The inaugural report would be due 180 days following the bill&amp;rsquo;s ratification, and then annually for three years. Select congressional committees would receive the report at an unclassified level.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Limiting adversaries&amp;rsquo; access to national labs&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Rep. Pat Harrigan, R-N.C., &lt;a href="https://harrigan.house.gov/media/press-releases/congressman-pat-harrigan-introduces-gate-act-protect-us-national-laboratories"&gt;introduced&lt;/a&gt; a proposal on Friday that seeks to restrict foreign nationals&amp;rsquo; access to U.S. national laboratories if the individuals are from China, Russia, Iran, North Korea or Cuba.&lt;/p&gt;

&lt;p&gt;The bill would prohibit covered foreign nationals from accessing national lab &amp;ldquo;facilities, information, or technology as visitors or long-term assignees.&amp;rdquo; The Energy Department would also be given the authority to grant waivers after consulting with agency intelligence officials and FBI counterintelligence officials in instances &amp;ldquo;when the benefits to the United States outweigh the national security and economic risks.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The measure, the Guarding American Technology from Exploitation &amp;mdash; or GATE &amp;mdash; Act, is a House companion to a bill &lt;a href="https://www.cotton.senate.gov/news/press-releases/cotton-colleagues-get-spies-out-of-our-national-labs"&gt;introduced&lt;/a&gt; by Sen. Tom Cotton, R-Ark., in March.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;China, Russia, Iran, and North Korea have spent years targeting American innovation to close the technological gap with the United States,&amp;rdquo; Harrigan said in a statement. &amp;ldquo;The GATE Act puts a clear safeguard around critical American research while preserving access when our own counterintelligence professionals determine it serves the national interest.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Shoring up the cybersecurity of U.S. water infrastructure&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Sens. Adam Schiff, D-Calif., and Amy Klobuchar, D-Minn., &lt;a href="https://www.schiff.senate.gov/news/press-releases/news-sens-schiff-klobuchar-release-comprehensive-cybersecurity-bill-in-wake-of-recent-cyberattacks-on-water-infrastructure/"&gt;rolled out a measure&lt;/a&gt; on Monday that looks to enhance the cyber defenses of critical U.S. water infrastructure services by empowering the Environmental Protection Agency to conduct cybersecurity assessments of public water systems, and then require corrective steps when significant vulnerabilities are identified in the services.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The EPA would also &amp;ldquo;establish tiered cybersecurity standards&amp;rdquo; in consultation with the Cybersecurity and Infrastructure Security Agency, the National Institute of Standards and Technology and other state and local partners and stakeholders.&lt;/p&gt;

&lt;p&gt;Large drinking water and wastewater systems would be directed to evaluate cyber risks as part of their current risk and reliance planning measures, and an additional $300 million would be added annually to the Drinking Water and Clean Water State Revolving Funds dedicated to cyber enhancements within critical wastewater services.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Every American depends on safe, reliable drinking water, yet recent events have exposed just how vulnerable our water systems remain to cyberattacks by foreign adversaries and criminal entities,&amp;rdquo; Schiff said in a statement. &amp;ldquo;These threats are not hypothetical&amp;mdash;they are happening right now. This legislation gives EPA the tools it needs to protect this critical infrastructure while providing the resources that local water and wastewater systems need to strengthen their cybersecurity without passing the cost on to ratepayers.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The proposal&amp;rsquo;s unveiling comes after a wave of cyberattacks linked to Iranian hackers &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/cyber-industry-coalition-urges-federal-action-after-suspected-iran-linked-water-hacks/415156/"&gt;affected&lt;/a&gt; more than 30 water utilities in Minnesota last month.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/14/860x394/large.jpg" width="618" height="284"><media:credit>Jarmo Piironen/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/14/860x394/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Gartner has confirmed the battle for authority is happening right now. Is your agency ready for the aftermath?</title><link>https://www.nextgov.com/ideas/2026/08/gartner-has-confirmed-battle-authority-happening-right-now-your-agency-ready-aftermath/415435/</link><description>COMMENTARY | If agencies don't act, the consequences won't be abstract.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Brian Chidester</dc:creator><pubDate>Fri, 14 Aug 2026 15:40:00 -0400</pubDate><guid>https://www.nextgov.com/ideas/2026/08/gartner-has-confirmed-battle-authority-happening-right-now-your-agency-ready-aftermath/415435/</guid><category>Ideas</category><content:encoded>&lt;![CDATA[&lt;p&gt;For decades, government agencies have measured digital success by a familiar yardstick: rank on Google, drive clicks to the .gov site&amp;nbsp;and let citizens navigate from there. That yardstick is breaking. Citizens are no longer starting their search for information with a list of blue links;&amp;nbsp;they&amp;#39;re starting it with a single AI-generated answer, and in a growing number of cases, they never click through to a source at all.&lt;/p&gt;

&lt;p&gt;Gartner has now put numbers behind what many of us have felt building for the past two years. The firm predicts that by 2028, an organization&amp;rsquo;s organic search traffic will fall by 50% or more as individuals embrace generative AI-powered search, and separately forecasts a 25% decline in traditional search engine volume by the end of this year as AI chatbots and virtual agents take over as answer engines. That&amp;#39;s not just a trend. For government, it&amp;#39;s a governance problem.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The authority vacuum&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;When a citizen asks ChatGPT, Gemini&amp;nbsp;or Perplexity how to replace a lost SNAP card or appeal a benefits denial, the AI model doesn&amp;#39;t necessarily reach for the agency&amp;#39;s website first. It reaches for whatever content it has learned to trust as authoritative. If the agency hasn&amp;#39;t structured its content to be clearly sourced, current and machine-readable, the model may pull from a third-party aggregator monetizing confusion or a source from the wrong jurisdiction entirely.&lt;/p&gt;

&lt;p&gt;This is the &amp;quot;battle for authority.&amp;quot; It isn&amp;#39;t a battle for rankings anymore. It&amp;#39;s&amp;nbsp;a battle over who gets to be the voice an AI system trusts enough to cite. Right now, most government agencies aren&amp;#39;t even aware they&amp;#39;re in it.&lt;/p&gt;

&lt;p&gt;Recent research on AI-augmented search behavior found that roughly 60% of internet searches now end without a click, because users are satisfied with the AI-generated summary and feel no need to visit the source. For a private brand, that&amp;#39;s a conversion problem. For a government agency, it&amp;#39;s a legitimacy problem &amp;mdash; because if an AI system is quietly becoming the primary interface between citizens and their government, and the agency has no visibility into what that system is telling people, the agency has effectively lost control of its own message.&lt;/p&gt;

&lt;p&gt;Three forces are compounding the problem for public sector organizations specifically:&lt;/p&gt;

&lt;ol&gt;
	&lt;li aria-level="1"&gt;&lt;strong&gt;The information ecosystem citizens rely on is already under strain.&lt;/strong&gt; Gartner&amp;#39;s broader research on citizen trust found that a majority of people believe the quality of online information sources has degraded in recent years, driven by misinformation, low-quality content and bot-generated noise. Citizens are being pushed toward AI assistants as a shortcut past that noise &amp;mdash; which only raises the stakes for making sure those assistants are pulling from the right government source when they answer.&lt;/li&gt;
	&lt;li aria-level="1"&gt;&lt;strong&gt;AI models reward structure, not just accuracy.&lt;/strong&gt; Being factually correct is no longer sufficient. Generative engines favor content that is written in plain, question-and-answer language, organized with clear headings and short paragraphs, dated and refreshed regularly&amp;nbsp;and backed by verifiable citations and consistent cross-references. A perfectly accurate policy page buried in a dense PDF with no update date is far less likely to be surfaced than a clearly structured FAQ &amp;mdash; even if the FAQ is hosted by a third party with a looser relationship to the truth.&lt;/li&gt;
	&lt;li aria-level="1"&gt;&lt;strong&gt;Small visibility gaps compound into large trust gaps.&lt;/strong&gt; Emerging data suggests that even modest improvements in AI citation share can translate into disproportionate downstream effects &amp;mdash; a meaningful increase in how often an agency is cited by generative engines has been associated with a substantially larger lift in actual service enrollment. The inverse is just as true: agencies that lose citation share don&amp;#39;t just lose traffic, but they also lose the ability to correct misinformation before it reaches citizens who need accurate, time-sensitive guidance on benefits, health alerts&amp;nbsp;or public safety.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;What the aftermath looks like&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;If agencies don&amp;#39;t act, the consequences won&amp;#39;t be abstract. They&amp;#39;ll show up as citizens receiving incorrect eligibility guidance synthesized from outdated or out-of-jurisdiction sources; a widening trust gap as AI-cited misinformation goes unanswered because no one at the agency is monitoring what AI platforms are actually saying; wasted resources as digital teams keep optimizing for a search paradigm that&amp;#39;s shrinking, while ignoring the one that&amp;#39;s growing; and, over time, a slow transfer of &amp;quot;official voice&amp;quot; status from the agency itself to whichever aggregator, advocacy group&amp;nbsp;or commercial site the AI models learn to trust instead.&lt;/p&gt;

&lt;p&gt;None of this is hypothetical anxiety about the future. It&amp;#39;s a description of where the traffic and trust data already point.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Building authority before the vacuum fills itself&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The good news is that authority in the GEO era is buildable. It&amp;#39;s an evidence architecture, not a mystery. Agencies that want to remain the trusted source need to treat AI visibility as seriously as they&amp;#39;ve historically treated public affairs and constituent communications, which means monitoring what AI platforms are saying about their programs and policies, not just what&amp;#39;s ranking on Google; restructuring core content &amp;mdash; FAQs, benefit explainers and&amp;nbsp;safety notices &amp;mdash; into the answer-first, clearly dated, plainly written format that generative engines are built to extract and cite; and closing the loop between visibility and outcomes, connecting AI citation data to actual service utilization so digital teams can prioritize the highest-impact pages first.&lt;/p&gt;

&lt;p&gt;This is precisely the gap we are trying to close for government digital teams &amp;mdash; giving agencies visibility into how they&amp;#39;re represented across AI platforms, insight into how AI bots are actually using their content and prescriptive, actionable recommendations for closing the authority gap before a citizen encounters bad information instead of good.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The mandate is already here&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Mandates like the 21st Century IDEA and a growing body of state and local digital service regulations already require agencies to deliver clear, accessible information to the public. Those requirements didn&amp;#39;t anticipate a world where the primary access point to that information is a generative AI model rather than a webpage &amp;mdash; but the underlying obligation hasn&amp;#39;t changed. Accessibility and accuracy now have to be engineered for machines that summarize on the public&amp;#39;s behalf, not just for the humans who used to click through.&lt;/p&gt;

&lt;p&gt;The battle for authority Gartner is describing isn&amp;#39;t coming; it&amp;#39;s underway. Agencies that recognize this now &amp;mdash; and start building the structured, monitored, machine-readable authority that AI platforms are built to trust&amp;nbsp;&amp;mdash;&amp;nbsp;will be the ones citizens can still find, and still believe, when they ask an AI assistant instead of a search engine. The ones that wait will find out the hard way what happens when someone else becomes the voice of their agency instead.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Brian Chidester is the Head of Industry Strategy for the Public Sector at Adobe.&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/14/GettyImages_2220362900/large.jpg" width="618" height="284"><media:credit>Suriya Phosri/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/14/GettyImages_2220362900/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Blue states seek to stop DHS from accessing commercial driver's license database</title><link>https://www.nextgov.com/digital-government/2026/08/blue-states-seek-stop-dhs-accessing-commercial-drivers-license-database/415429/</link><description>In a court filing, a coalition of Democrat-led states says the Department of Homeland Security’s demand for trucker data is part of a broader effort to create a “nationwide surveillance system.”</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christian Robles</dc:creator><pubDate>Fri, 14 Aug 2026 14:41:00 -0400</pubDate><guid>https://www.nextgov.com/digital-government/2026/08/blue-states-seek-stop-dhs-accessing-commercial-drivers-license-database/415429/</guid><category>Digital Government</category><content:encoded>&lt;![CDATA[&lt;p&gt;A group of 22 states is asking a federal court to invalidate a subpoena that would give the Department of Homeland Security access to about 17 million commercial driver&amp;#39;s&amp;nbsp;license records.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The coalition argues DHS has no legal authority to demand the truck drivers&amp;rsquo; license records and would jeopardize drivers&amp;rsquo; privacy if they receive them, according to a &lt;a href="https://ag.ny.gov/sites/default/files/court-filings/illinois-et-al-v-united-states-department-of-homeland-security-brief-iso-2026.pdf"&gt;lawsuit filed&lt;/a&gt; Thursday. The group also alleges the demand is part of a pattern of DHS seeking personally identifiable records to build a &amp;ldquo;nationwide surveillance system.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Once again, the Trump administration is trying to unlawfully seize Marylanders&amp;#39; personal data with no legitimate purpose, no safeguards to protect it, and no warning to the public or consultation with the states,&amp;rdquo; said Maryland Attorney General Anthony Brown in a &lt;a href="https://oag.maryland.gov/News/pages/Attorney-General-Brown-Sues-Trump-Administration-for-Unlawfully-Demanding-Personal-Information-of-CDL-Drivers-.aspx"&gt;press release&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The administration previously sought to turn over Medicaid, Supplemental Nutrition Assistance Program and other state data to immigration enforcement authorities.&lt;/p&gt;

&lt;p&gt;The federal government is seeking data going back five years from the Commercial Drivers&amp;rsquo; License Information System, or CDLIS &amp;mdash; including names, dates of birth, license numbers and Social Security numbers &amp;mdash; according to the lawsuit filed in the District Court for the Eastern District of Virginia.&lt;/p&gt;

&lt;p&gt;The Federal Motor Carrier Safety Administration, or FMCSA, first asked the American Association of Motor Vehicle Administrators, or AAMVA, for the commercial drivers&amp;rsquo; data on June 25, the lawsuit says. The AAMVA raised concerns with the request in a June 30 letter, noting that the FMCSA is not entitled to CDLIS records and it must adhere to U.S. privacy laws.&lt;/p&gt;

&lt;p&gt;At an in-person July 23 meeting, FMCSA allegedly threatened to withhold all of AAMVA&amp;rsquo;s federal grants and contracts and file litigation if it did not inform the Department of Transportation by the next day whether it would hand over CDLIS records, the lawsuit says. The next day, the association told FMCSA it would disclose requested information by or around August 17, the filing continued.&lt;/p&gt;

&lt;p&gt;But several days later, DHS served a subpoena asking for the same CDLIS records as FMCSA. That subpoena was withdrawn, but a new one was issued on Tuesday and gave AAMVA until this Monday to respond, according to a &lt;a href="https://drive.google.com/file/d/1SdmvV7DeeTO4TDZ_NyyV6jp6LWYcV1NH/view?usp=sharing"&gt;court filing&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;On Friday, a federal judge ordered an &lt;a href="https://drive.google.com/file/d/17v1zJ-seKKhXExAHNZyVMqWmuZuGdEUU/view?usp=sharing"&gt;administrative stay&lt;/a&gt;, punting the deadline for AAMVA to respond to DHS&amp;rsquo; demand to an unknown date. The judge also scheduled a hearing on whether to invalidate the subpoena for this coming Thursday.&lt;/p&gt;

&lt;p&gt;The latest subpoena implies DHS is seeking CDLIS data to investigate &amp;ldquo;illegal practices in commercial driver&amp;rsquo;s license schools&amp;rdquo; and conduct immigration enforcement.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;It is incredibly dangerous for illegal aliens, who often don&amp;rsquo;t know our traffic laws or even English, to be operating vehicles on America&amp;rsquo;s roads,&amp;quot; DHS said in a statement. &amp;quot;These sanctuary politicians must stop giving illegal aliens driver&amp;rsquo;s licenses before another American gets killed.&amp;quot;&lt;/p&gt;

&lt;p&gt;AAMVA did not return a request for comment&amp;nbsp;by publication.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Editor&amp;#39;s note: This article has been updated to include a statement from DHS.&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/14/GettyImages_2261511064/large.jpg" width="618" height="284"><media:credit>Alex Wong/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/14/GettyImages_2261511064/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item></channel></rss>