From AI Adoption to AI Accountability in Federal Agencies

July 22, 2026

Federal agencies have an AI control problem. One that matters more now than it did a month ago.

Earlier this month the White House issued an Executive Order (check out our blog) directing federal agencies to begin deploying AI enabled cyber defenses within 30 days, and mandating that CISA issue new AI security guidance for the federal enterprise. For agencies still relying on periodic review and passive monitoring to govern AI, the clock is already ticking.

 

AI risk doesn’t follow traditional security models

Unlike traditional enterprise software, AI systems don’t remain static between review cycles.  They adapt constantly based on inputs, users, and data flowing across environments, and that breaks a core assumption most federal security programs were built on: that systems can be assessed, approved, and periodically revalidated on a fixed schedule. 

With AI, risk can change in real time. A model update, a new user behavior, or a carefully crafted prompt can alter system behavior in ways that introduce new exposure before a security team has any opportunity to respond. Last September, Anthropic publicly disclosed what it called the first documented AI orchestrated cyberattack at scale. A Chinese state-sponsored group jailbroke an AI coding tool by feeding it small, seemingly innocent tasks that obscured the full scope of the operation, then used it to target roughly 30 organizations, including government agencies and financial institutions, automating 80-90% of the campaign with minimal human involvement. The attack didn’t require novel malware or zero-days. It just needed to target an AI system with no inline enforcement layer watching what it was actually being directed to do. In this environment, point-in-time controls and periodic reviews are no longer sufficient. If security isn’t operating inline with AI systems, it’s already behind on risk.

 

The federal mandate to govern AI at scale

This challenge is reflected directly in frameworks agencies are now expected to execute against. OMB M-24-10 mandates risk management and ongoing monitoring for AI systems. The NIST AI Risk Management Framework requires continuous evaluation of AI behavior across the full system lifecycle. The June AI Executive Order builds on both, directing agencies to harden defenses and enforce against AI driven threats. Taken together, these mandates are no longer asking agencies to inventory AI, they’re asking agencies to control it. 

Execution is where the gap emerges. Most agencies have made progress on AI visibility. Far fewer can enforce what happens inside those interactions in real time. That’s the gap where AI governance stays informational rather than operational.

 

From AI visibility to AI accountability

Closing the gap requires agencies to move from observing AI activity to actively controlling and validating it as it happens. That means being able to control how AI systems access and process sensitive data, enforce policy on prompts and responses in real time, continuously test systems for jailbreaks, prompt injection, and misuse, and validate that AI systems operate within mission and security boundaries, not at the end of a review cycle, but as an ongoing practice.

 

Where Netskope fits

Netskope One AI Security provides a single solution to govern an agency’s full AI ecosystem and protect the data flowing through it. Two capabilities within that portfolio are now available on Netskopes FedRAMP High authorized NewEdge Government platform. Netskope One AI Guardrails and Netskope One AI Red Teaming are available now, with additional capabilities coming soon. Together, they address the two sides of the accountability problem, enforcement and validation. 

AI Guardrails operates as an active enforcement layer that blocks AI specific threats like prompt injection and jailbreaking, while automatically moderating human interactions to enforce ongoing policy compliance and data integrity. Rather than relying on static filters or post-event review it inspects every prompt and response in real-time to detect adversarial intent, prevent data exposure and block attempts to override system behavior. It enforces consistent policy controls across managed and unmanaged AI tools, integrates with Netskope One DLP to protect CUI and other regulated data from leakage through prompts and generated outputs, and aligns AI security operations to MITRE ATLAS and OWASP Top 10 for LLMs. For agencies required to demonstrate continuous monitoring under FISMA and OMB M-24-10, this is enforcement embedded directly into the workflow, not layered on after the fact.

AI Red Teaming addresses the validation side of the equation. AI Red Teaming automates adversarial stress testing of private large language models (LLMs) using a library of over 18,000 scenarios, and simulating real-world attacks such as prompt injection, jailbreak attempts, and multi-turn manipulation techniques to surface weaknesses before they can be exploited. It evaluates AI systems against mission workflows, edge cases and user behaviors to identify failure points, and integrate into CI/CD pipelines so that new risks introduced through model updates or code changes are assessed continuously rather than at the next scheduled review.

 

Securing AI at mission scale

Together, AI Guardrails and AI Red Teaming give agencies real-time enforcement paired with continuous validation. That gives agencies something they can demonstrate to auditors and oversight bodies: AI governance that’s operational, not just documented.

The agencies that get this right aren’t necessarily the ones that move fastest on AI adoption. They’re the ones building security into how AI operates, with enforcement at the point of every interaction and validation built into every release cycle. These capabilities are available now on a FedRAMP High authorized platform. 

To learn more, read our solutions overview: Netskope One AI for Federal Agencies. To see these capabilities in action, join us at our Federal AI in the Fast Lane roadshow in Washington, DC on July 21, 2026 for expert insight and live demos. Register now!

author image

Lindsay Schwartz

Lindsay Schwartz is a public sector cybersecurity marketing leader with 15+ years’ experience at Tenable, Cisco, and Sourcefire. She focuses on helping public sector agencies secure data, modernize access and adopt AI to reduce risk and support mission outcomes.
Lindsay Schwartz is a public sector cybersecurity marketing leader with 15+ years’ experience at Tenable, Cisco, and Sourcefire. She focuses on helping public sector agencies secure data, modernize access and adopt AI to reduce risk and support mission outcomes.
Keep a close eye on The Lens