Government AI Use Cases Have Passed 3,600. Security Must Catch Up

September 21, 2026
Government's AI Use Cases Just Passed 3600

With encouragement from the highest levels of government, federal agencies are creating thousands of AI use cases. As these use cases come online, agency leaders must ensure that the appropriate cybersecurity protections are in place to prevent AI tools from inadvertently exposing government data and infrastructure to malicious actors.

The Office of Management and Budget (OMB) 2025 Federal Agency Artificial Intelligence Use Case Inventory last year documented 3,611 individual use cases across 56 submitting agencies. Several civilian agencies have since reported more than 300 AI use cases, and we should anticipate these numbers growing at pace in the future.

This activity is reminiscent of the rush to the cloud a decade ago with the federal government’s Cloud First initiative that resulted in an ill-prepared security architecture that left gaps exposed and made it difficult to realize expectations for returns on investment. Despite the recent White House executive order calling for voluntary pre-release access of AI models for the government, agencies deploying them will need to do so cautiously to avoid a repeat of something similar to the Cloud First backlash.

While AI is improving operations and service delivery, agencies must manage its use. Agencies are tasked with achieving “compliant acceleration”, deploying these use cases rapidly while meeting strict requirements for security, transparency, and risk management outlined in the NIST AI Risk Management Framework, OMB M-25-21, along with guidance issued by the Cybersecurity and Infrastructure Security Agency.

This is easier said than done. The core challenge is that traditional enterprise security strategies often break when faced with AI. Legacy tools lack visibility into AI usage, cannot inspect prompts or model interactions, and are fundamentally not designed to govern AI behaviors or enforce policies across AI-driven workflows. This creates dangerous blind spots across the lifecycle of every federal AI use case.

Agencies are using AI to work with sensitive data without human intervention. They must determine exactly what AI is doing with this data, how it is doing it and make sure it’s working in the appropriate way. They must be able to run automated tests against known attack types on LLMs they’re deploying. And they should bake in red teaming early in the deployment process.

A four-step approach can help agencies to secure AI deployment:

1. Start with a discovery process

Agencies cannot secure use cases they don’t know about. It is critical to discover AI tools and traffic from AI agents, embedded AI within SaaS platforms, and unmanaged AI usage across the enterprise. They need to understand what’s in use within their environments and what the use cases are. From there, they can start building a process for ingesting that before it gets out of hand. This has to be continuous, not a periodic survey; shadow AI shows up between inventory cycles, not on a schedule.

2. Classify risk

Once discovered, these applications must be classified by risk, data sensitivity and mission impact. When users attempt to interact with unapproved AI tools, agencies should use real-time “coach and pivot” alerts to safely guide them toward approved, managed federal AI usage.

3. Establish agent visibility

As federal use cases evolve from simple chatbots to autonomous AI agents capable of taking action across systems, risk extends to non-human behavior. The danger is immediate. Red Team exercises by the National Institute of Standards and Technology in 2025 found that novel attacks against AI agents succeeded 81% of the time.

Agency teams must understand what agents reside in the enterprise and what assets are tied to each. Subscription services are often the number one threat, because they can be bought without going through a larger procurement process. Agency teams also need to determine how employees are using those assets. Is there an upload? Are they logging into them? What are the request-response interactions?

4. Install gateways and safeguards

Agencies must be able to control interactions with AI and make sure they are secure and don’t involve sensitive data. This involves doubling down on coaching users, understanding how the new attack landscape looks, and being able to build that into the agency’s cyber ops plan. Inline enforcement, not logging after the fact, is what makes this step work. For self-hosted federal AI use cases, agencies should validate model resilience through continuous red teaming, simulating adversarial scenarios against thousands of automated test cases before and after deployment to catch degradation or new attack paths early.

 

AI is already embedded in how agencies deliver on their mission. Agencies that get ahead of it now, with discovery, risk classification, agent visibility, and inline enforcement, will be positioned to scale AI safely.

For more information on how Netskope can help federal agencies secure AI review AI Security for Federal Agencies.

 

author image

Mark Mitchell

Mark Mitchell is an Enterprise Security Architect who has worked in both the public and private sectors. He has built zero trust-based architectures since 2014 including a full cloud-based policy enforcement point architecture in 2017 for a federal agency he worked with at the time. Since joining Netskope, Mark has focused on evangelizing the adoption of SASE architecture within the federal government and the benefits that it brings; increased security, performance and compliance while reducing complexity especially in multi-cloud environments.
Mark Mitchell is an Enterprise Security Architect who has worked in both the public and private sectors. He has built zero trust-based architectures since 2014 including a full cloud-based policy enforcement point architecture in 2017 for a federal agency he worked with at the time. Since joining Netskope, Mark has…
Keep a close eye on The Lens