<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:nb="https://www.newsbreak.com/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Nextgov/FCW - All Content</title><link>https://www.nextgov.com/</link><description>Federal technology and cybersecurity news and best practices.</description><atom:link href="https://www.nextgov.com/rss/all/" rel="self"></atom:link><language>en-us</language><lastBuildDate>Tue, 11 Aug 2026 18:45:00 -0400</lastBuildDate><item><title>Oversight and program management gaps slowing VA’s benefits processing system modernization, OIG says</title><link>https://www.nextgov.com/modernization/2026/08/oversight-and-program-management-gaps-slowing-vas-benefits-processing-system-modernization-oig-says/415356/</link><description>The watchdog said cost estimate and project planning issues are among the top factors afflicting VA’s overhaul of its legacy Benefits Enterprise Platform.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Edward Graham</dc:creator><pubDate>Tue, 11 Aug 2026 18:45:00 -0400</pubDate><guid>https://www.nextgov.com/modernization/2026/08/oversight-and-program-management-gaps-slowing-vas-benefits-processing-system-modernization-oig-says/415356/</guid><category>Modernization</category><content:encoded>&lt;![CDATA[&lt;p&gt;Efforts to modernize a Department of Veterans Affairs system that supports the processing of veterans&amp;rsquo; benefits claims have been hampered by &amp;ldquo;insufficient oversight and weak program management,&amp;rdquo; according to the agency&amp;rsquo;s Office of Inspector General.&lt;/p&gt;

&lt;p&gt;The watchdog warned in an audit &lt;a href="https://www.vaoig.gov/sites/default/files/reports/2026-08/vaoig_-_25-01098-103_final.pdf"&gt;released&lt;/a&gt; on Tuesday that VA&amp;rsquo;s Office of Information and Technology has not taken all of the necessary steps to keep the revamp of the agency&amp;rsquo;s Benefits Enterprise Platform on track, which could potentially affect the processing of veterans&amp;rsquo; benefits and other modernization efforts.&lt;/p&gt;

&lt;p&gt;The BEP platform &amp;mdash; &lt;a href="https://www.govinfo.gov/content/pkg/CMR-VA1-00187554/pdf/CMR-VA1-00187554.pdf"&gt;one of 85 legacy systems&lt;/a&gt; that VA has identified as needing to be modernized or decommissioned to &amp;ldquo;improve overall efficiency of claims processing&amp;rdquo; &amp;mdash; helps facilitate the sharing of information between the Veterans Benefits Administration and other &amp;ldquo;business line systems&amp;rdquo; that include pension, vocational rehabilitation and employment benefits.&lt;/p&gt;

&lt;p&gt;VA &lt;a href="https://fedscoop.com/department-of-veterans-affairs-awards-booz-allen-1-1b-benefits-processing-contract/"&gt;awarded&lt;/a&gt; Booz Allen Hamilton a $1.1 billion contract in May 2021 to integrate its benefits systems into a new cloud-based Benefits Integration Platform, with the plan calling for the legacy BEP system to be migrated to this new service and then subsequently decommissioned. Although the contract was supposed to be completed this month, OIG noted that the latest timetable from VA said the BEP modernization effort is now slated to be completed in the second quarter of fiscal year 2034.&lt;/p&gt;

&lt;p&gt;&amp;quot;Because BEP supports a significant number of systems, there is increased risk that other systems relying on it may experience negative consequences from potential delays in the modernization effort,&amp;rdquo; the report said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The audit said the Office of Information and Technology failed to develop &amp;ldquo;a high-quality, reliable program schedule as recommended by the Government Accountability Office&amp;rsquo;s Schedule Assessment Guide&amp;rdquo; for the project and has instead relied on an agile project management tool for the effort &amp;mdash; a tool that &amp;ldquo;does not contain roadmaps or detailed plans for the entire scope of the project.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;OIG also found that the office lacked a reliable lifecycle cost estimate for the modernization initiative, which has resulted in inconsistent funding information being included in various BEP plans and has &amp;ldquo;limit[ed] VA&amp;rsquo;s ability to make informed decisions.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Lack of proper oversight, the watchdog reported, also may have jeopardized the security of veterans&amp;rsquo; sensitive personal data when the office &amp;ldquo;hosted minor applications without conducting required security assessments.&amp;rdquo; After OIG notified VA officials about documented vulnerabilities &amp;mdash; some of which dated as far back as 2021 &amp;mdash; the watchdog said VA took the necessary steps to assess the security of its applications and remediate any identified issues.&lt;/p&gt;

&lt;p&gt;OIG&amp;rsquo;s audit recommended that VA take steps to enhance its BEP modernization efforts, including by developing and maintaining a program schedule that aligns with best practices, ensuring that staff are following proper procedures when it comes to storing scheduling information, developing a &amp;ldquo;reliable, validated life cycle cost estimate&amp;rdquo; for the project and tracking all relevant project costs. VA officials said they concurred with the watchdog&amp;rsquo;s recommendations.&lt;/p&gt;

&lt;p&gt;The BEP project is just the latest VA modernization initiative to be singled out for criticism by OIG for resulting in significant delays, cost overruns and oversight gaps.&lt;/p&gt;

&lt;p&gt;VA is still in the process of developing a new digital GI Bill system, which the watchdog noted in an August 2024 report has seen its cost more than double as a result of &amp;ldquo;&lt;a href="https://www.nextgov.com/modernization/2026/02/digital-gi-bill-delays-are-reflection-vas-it-management-problem-lawmakers-say/411208/"&gt;insufficient planning&lt;/a&gt;.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The agency&amp;rsquo;s large-scale electronic health record modernization project has also been plagued by cost overruns, delays and oversight issues since the deployment effort began in earnest in 2020. The Trump administration has prioritized righting that effort, however, and VA Secretary Doug Collins said earlier this year that an EHR rollout resumption push has been &amp;ldquo;&lt;a href="https://www.nextgov.com/modernization/2026/05/ehr-restart-was-phenomenal-despite-persistent-challenges-initial-sites-va-secretary-says/413712/"&gt;phenomenal&lt;/a&gt;&amp;rdquo; so far.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/11/GettyImages_1167511743/large.jpg" width="618" height="284"><media:credit>P_Wei/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/11/GettyImages_1167511743/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Trump admin delays TANF data sharing plan opposed by blue states</title><link>https://www.nextgov.com/digital-government/2026/08/trump-admin-delays-tanf-data-sharing-plan-opposed-blue-states/415353/</link><description>Democrat-led states are concerned the administration will share cash assistance recipients’ sensitive information with immigration enforcement and other federal agencies.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christian Robles</dc:creator><pubDate>Tue, 11 Aug 2026 17:43:00 -0400</pubDate><guid>https://www.nextgov.com/digital-government/2026/08/trump-admin-delays-tanf-data-sharing-plan-opposed-blue-states/415353/</guid><category>Digital Government</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Trump administration pushed the effective date for a proposal allowing the Administration for Children and Families to share Temporary Assistance for Needy Families &amp;mdash; or TANF &amp;mdash; recipients&amp;rsquo; information with other federal agencies to Sept. 1, according to a Federal Register &lt;a href="https://www.federalregister.gov/documents/2026/08/07/2026-16176/privacy-act-of-1974-system-of-records#addresses"&gt;listing posted last week&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Without the extension, the policy shift was set to kick in Tuesday, according to another &lt;a href="https://www.federalregister.gov/documents/2026/07/20/2026-14587/privacy-act-of-1974-system-of-records"&gt;Federal Register notice&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The delay comes as a coalition of Democratic attorneys general is requesting a federal district court vacate ACF&amp;rsquo;s proposal and declare it unlawful, according to an &lt;a href="https://storage.courtlistener.com/recap/gov.uscourts.dcd.295159/gov.uscourts.dcd.295159.1.0.pdf"&gt;Aug. 3 filing&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The coalition alleged ACF could illegally share millions of TANF recipients&amp;rsquo; Social Security numbers, marital status, income and other sensitive information with the Department of Homeland Security and other agencies if the Trump administration has its way.&lt;/p&gt;

&lt;p&gt;That data sharing &amp;ldquo;will erode the trust that State agencies have developed with TANF recipients and will deter qualified beneficiaries from applying for TANF benefits, forcing Plaintiff States to spend more of their own money to ensure that families are housed and children do not go hungry,&amp;rdquo; the coalition said in the lawsuit filed in the U.S. District Court for the District of Columbia.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If ACF can proceed with sharing TANF data with DHS, without clearly defined purposes and limits required by federal law, then community fears that DHS will use that data for other purposes will impede that public trust and chill participation in State TANF programs by citizens and qualified non-citizens alike,&amp;rdquo; the coalition added.&lt;/p&gt;

&lt;p&gt;The group of attorneys general alleged that the administration&amp;rsquo;s data sharing plan is &amp;ldquo;arbitrary and capricious&amp;rdquo; under the Administrative Procedure Act. The coalition also claimed it violates the Constitution&amp;rsquo;s Spending Clause because states &amp;ldquo;could not have foreseen these potential uses and disclosures years ago when they collected and shared this data with ACF.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;An ACF spokesperson did not return a request for comment by the time of publication. The administration wrote in the Federal Register that its TANF data-sharing policies are designed to curtail fraud and ensure compliance with TANF requirements, such as verifying recipients&amp;rsquo; immigration status.&lt;/p&gt;

&lt;p&gt;A &lt;a href="https://www.regulations.gov/document/ACF-2026-0727-0001"&gt;public comment period &lt;/a&gt;for the TANF proposal closes Tuesday. The federal government gave states and the District of Columbia &lt;a href="https://www.congress.gov/crs-product/R48413"&gt;nearly $16.5 billion&lt;/a&gt; in TANF block grants in fiscal 2024, according to the Congressional Research Service.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/11/GettyImages_2288520850/large.jpg" width="618" height="284"><media:description> Construction workers install rebar and other materials at the new helipad on the South Lawn of the White House after President Donald Trump ordered changes to the project on August 6, 2026 in Washington, DC.</media:description><media:credit>Kevin Carter/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/11/GettyImages_2288520850/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>How OneGov is changing CACI's contractor role</title><link>https://www.nextgov.com/acquisition/2026/08/how-caci-looks-governments-software-license-buying-shift/415346/</link><description>CEO John Mengucci tells investors the government's direct licensing push means less revenue but more profit for integrators.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ross Wilkers</dc:creator><pubDate>Tue, 11 Aug 2026 17:00:00 -0400</pubDate><guid>https://www.nextgov.com/acquisition/2026/08/how-caci-looks-governments-software-license-buying-shift/415346/</guid><category>Acquisition</category><content:encoded>&lt;![CDATA[&lt;p&gt;CACI International counts as business partners many of the same brand name technology companies that the U.S. government wants to have more direct relationships with, especially licenses for enterprise software platforms.&lt;/p&gt;

&lt;p&gt;During CACI&amp;rsquo;s fiscal fourth quarter and year-end earnings call with investors Thursday, chief executive John Mengucci described that shift as having a &amp;ldquo;small revenue impact&amp;rdquo; and one resulting in &amp;ldquo;more positive margins.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The General Services Administration&amp;rsquo;s OneGov initiative for unified technology procurements is the highest-profile example of how the government is seeking more direct relationships with commercial providers, &lt;a href="https://www.washingtontechnology.com/contracts/2026/08/gsas-agenda-resellers-focuses-service-pricing-transparency/415249/"&gt;including contracts for the product itself and associated licenses&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;GSA is looking to obtain savings through volume discounts of tech products it believes can essentially be purchased in bulk and in a more consolidated manner and wants to do so on behalf of other agencies.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Customers traditionally repurpose those savings right back to CACI, that gives us an ability to deliver additional capabilities,&amp;rdquo; Mengucci said.&lt;/p&gt;

&lt;p&gt;Mengucci said that under the traditional model of integrators like CACI as primes, revenue was often reduced by the value of the licenses from the enterprise software providers. That revenue often provided CACI with &amp;ldquo;little-to-no margin,&amp;rdquo; he added.&lt;/p&gt;

&lt;p&gt;CACI is experiencing the shift of who the prime contractor is firsthand in Federal HR 2.0 &amp;ndash; the Office of Personnel Management&amp;rsquo;s effort to overhaul the government&amp;rsquo;s human resource systems by consolidating them into a single platform.&lt;/p&gt;

&lt;p&gt;Oracle &lt;a href="https://www.washingtontechnology.com/contracts/2026/07/opms-hr-systems-award-clears-protest-window/414598/"&gt;won the 10-year, $395.8 million contract over the summer&lt;/a&gt; and has enlisted CACI as a key teammate for the program alongside Baker Tilly and Deloitte. The core implementation will be based off of Oracle Fusion Cloud HCM.&lt;/p&gt;

&lt;p&gt;In talking with analysts, Mengucci described the partial role-reversal of who the prime is as one of merely changing the order of things.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;What the OEMs (original equipment manufacturers) don&amp;#39;t want, and generally aren&amp;#39;t able to deliver, is the full implementation,&amp;rdquo; Mengucci said. &amp;ldquo;The government is going to them for the licensing first and then we are partnering with those folks.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We&amp;#39;ve been in partnerships with them over the last eight-to-10 for a lot of those large enterprise tech jobs that we&amp;#39;ve put out there,&amp;rdquo; Mengucci added.&lt;/p&gt;

&lt;p&gt;Fourth quarter revenue of $2.7 billion was 17% higher than the prior year period with an organic growth rate of 11%, while profit of $353.1 million showed a 33% year-over-year increase in EBITDA (earnings before interest, taxes, depreciation and amortization).&lt;/p&gt;

&lt;p&gt;Full fiscal year 2026 revenue of $9.6 billion was 10.9% higher than the prior year period with an organic growth rate of 7.2%, while EBITDA of $1.2 billion showed a 21% year-over-year increase from FY 2025. CACI ended fiscal 2026 with an EBITDA margin of 12.3%, up from the prior year&amp;rsquo;s 11.2%.&lt;/p&gt;

&lt;p&gt;CACI&amp;rsquo;s initial guidance for its 2027 fiscal year, which started July 1, pegs revenue in the range of $10.65 billion-to-$10.85 billion on an EBITDA margin in the high-12% range.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/11/John_Mengucci_CACI_photo-1/large.jpg" width="618" height="284"><media:description>CACI International's chief executive John Mengucci.</media:description><media:credit>CACI photo.</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/11/John_Mengucci_CACI_photo-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>DHS wraps up Oracle's Cumulus cloud contract</title><link>https://www.nextgov.com/acquisition/2026/08/dhs-wraps-oracles-cumulus-cloud-contract/415344/</link><description>The Department of Homeland Security has two more hyperscaler awards to finalize before it can move ahead on a separate competition for this enterprise cloud program.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ross Wilkers</dc:creator><pubDate>Tue, 11 Aug 2026 15:32:00 -0400</pubDate><guid>https://www.nextgov.com/acquisition/2026/08/dhs-wraps-oracles-cumulus-cloud-contract/415344/</guid><category>Acquisition</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Homeland Security Department has entered into the second out of four planned awards under Cumulus, a centralized mechanism for acquiring commercial cloud computing services across the entire organization.&lt;/p&gt;

&lt;p&gt;Oracle&amp;rsquo;s portion of the potential five-year contract has a ceiling value of $567.9 million, DHS &lt;a href="https://sam.gov/workspace/contract/opp/683d563fc9fb4b4ca208535f0c20950f/view"&gt;said in a Friday notice to Sam.gov&lt;/a&gt;. This follows DHS&amp;rsquo; finalization in June of the award to Amazon Web Services, which is eligible for up to $2.5 billion under Cumulus.&lt;/p&gt;

&lt;p&gt;DHS first laid out its intended timeline for wrapping up each Cumulus contract with all four of the hyperscalers, with awards to Google Cloud and Microsoft still in-the-works. The department originally pegged the end of the calendar year&amp;rsquo;s second quarter as its deadline for finalizing each contract.&lt;/p&gt;

&lt;p&gt;Each award under Cumulus will cover a one-year base period and up to four option years.&lt;/p&gt;

&lt;p&gt;Cumulus is designed to have a blend of competitive and non-competitive awards across all aspects of commercial cloud including infrastructure-as-a-service, platform-as-a-service and software-as-a-service.&lt;/p&gt;

&lt;p&gt;After DHS finalizes each hyperscaler contract, the department will then work on creating a separate multiple-award competition to support the Cumulus effort.&lt;/p&gt;

&lt;div class="related-articles-placeholder"&gt;[[Related Posts]]&lt;/div&gt;

&lt;p&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/11/cloud-1/large.jpg" width="618" height="284"><media:credit>Gettyimages.com / Just Super</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/11/cloud-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>The government wants your help solving today’s biggest challenges</title><link>https://www.nextgov.com/digital-government/2026/08/government-wants-your-help-solving-todays-biggest-challenges/415339/</link><description>NIH is offering $1 million for practical ideas that could help long-acting HIV prevention and treatment reach more people, and applicants do not need a traditional research background to participate.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Breeden II</dc:creator><pubDate>Tue, 11 Aug 2026 14:36:00 -0400</pubDate><guid>https://www.nextgov.com/digital-government/2026/08/government-wants-your-help-solving-todays-biggest-challenges/415339/</guid><category>Digital Government</category><content:encoded>&lt;![CDATA[&lt;p&gt;A few years ago, I tried to help a team of astronauts survive a Martian dust storm.&lt;/p&gt;

&lt;p&gt;Fortunately, nobody was actually in danger. I was participating in the second &lt;a href="https://www.nextgov.com/emerging-tech/2023/03/nasa-asks-public-help-second-marsxr-challenge/383764/"&gt;NASA MarsXR Challenge&lt;/a&gt;, a government-sponsored competition hosted on the HeroX open-innovation platform. NASA wanted members of the public to design virtual reality scenarios that could someday help train astronauts for missions on Mars.&lt;/p&gt;

&lt;p&gt;The first phase focused on storyboarding, so participants did not need to know how to program a VR simulation. They needed to imagine a realistic challenge, explain how astronauts would respond and take advantage of the immersive capabilities offered by virtual reality. My team designed a scenario in which astronauts left their rover behind while collecting rock samples in terrain too rough for a vehicle. When a surprise dust storm swept into the area and visibility began to collapse, they had to navigate back to the rover using digital waypoints and beacons they had placed along their route.&lt;/p&gt;

&lt;p&gt;It seemed like a plausible worst-case scenario and, admittedly, a pretty exciting video game mission. The design required astronauts to think ahead, use the available technology and remain calm when conditions suddenly changed. Our entry earned an honorable mention in the first phase. We did not advance to the programming round, where winning concepts could be developed into functioning &lt;a href="https://www.nextgov.com/emerging-tech/2023/11/nasa-celebrates-winners-second-marsxr-virtual-reality-astronaut-training-competition/391742/"&gt;VR training missions&lt;/a&gt;, but the experience gave me a firsthand look at how seriously NASA approaches open-innovation competitions.&lt;/p&gt;

&lt;p&gt;NASA has used HeroX and the NASA Tournament Lab to solicit outside ideas for everything from virtual reality astronaut training to building better &lt;a href="https://www.nextgov.com/emerging-tech/2025/11/nasa-wants-you-help-kick-some-tires-moon/409383/"&gt;lunar rover wheels&lt;/a&gt;. Some of the most visible government-sponsored challenges over the past several years have naturally focused on space exploration.&lt;/p&gt;

&lt;p&gt;But one of the most consequential challenges open in 2026 is aimed at a problem that is far more Earth-bound and deeply human. The National Institutes of Health&amp;rsquo;s Office of AIDS Research is offering $1 million in prizes for ideas that could help more people gain access to long-acting HIV prevention and treatment. The competition, called the NIH ARISE-HIV LAUNCH Challenge, is &lt;a href="https://www.herox.com/NIHARISE-HIVLAUNCH"&gt;open for first-round submissions&lt;/a&gt; through Aug. 6.&lt;/p&gt;

&lt;p&gt;Federal government involvement goes well beyond an agency endorsement for the HIV Challenge. The &lt;a href="https://oar.nih.gov/"&gt;Office of AIDS Research&lt;/a&gt; is the official sponsor and is providing the $1 million prize purse. The NIH Office of the Director is conducting the challenge under the federal prize authority established by the &lt;a href="https://www.congress.gov/111/plaws/publ358/PLAW-111publ358.pdf"&gt;America COMPETES&lt;/a&gt; Reauthorization Act.&lt;/p&gt;

&lt;p&gt;The challenge is also part of a broader program called Advancing Research in Implementation Science to End HIV, or ARISE-HIV. That effort involves all NIH institutes, centers and offices that award HIV funding or support related prevention, care and treatment research. HeroX provides the public competition platform, and the challenge appears through the NASA Tournament Lab&amp;rsquo;s wider open-innovation network.&lt;/p&gt;

&lt;p&gt;To be clear, the current contest is not asking participants to invent a new HIV medication. Scientists have already developed long-acting products that can prevent or treat HIV without requiring patients to take a pill every day. Some are administered every two months, while others can provide protection for as long as six months. The challenge is getting those advances to the people who need them and making sure they remain connected to care.&lt;/p&gt;

&lt;p&gt;In an August 2025 post reflecting on her appearance with NIH Director Jay Bhattacharya on The Director&amp;rsquo;s Desk podcast, Office of AIDS Research Director Geri R. Donenberg described the gap the new challenge is trying to address.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We have effective, lifesaving interventions, but people are not benefiting equally,&amp;rdquo; she wrote.&lt;/p&gt;

&lt;p&gt;Donenberg &lt;a href="https://www.oar.nih.gov/about/directors-blog/five-takeaways-ending-hiv-epidemic-insights-my-conversation-nih-director"&gt;explained that&lt;/a&gt; implementation science can help determine how, where and by whom effective treatments should be delivered to reach different populations. An approach that works well for patients in one community may prove impractical in another because of transportation, cost, staffing, stigma, scheduling or limited access to health care.&lt;/p&gt;

&lt;p&gt;That is where the LAUNCH Challenge comes in. NIH is &lt;a href="https://www.herox.com/NIHARISE-HIVLAUNCH"&gt;asking participants&lt;/a&gt; to develop actionable ideas in at least one of four areas: access, delivery, engagement or retention.&lt;/p&gt;

&lt;p&gt;An access proposal might explore how mobile clinics, home-based services, street medicine or pharmacists could bring long-acting products to people who are not well served by traditional health care systems. A delivery proposal could address the staffing or coordination needed to administer injections safely and reliably. That might include evening appointments, transportation assistance, child care support or better integration with mental health and substance-use services.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Engagement proposals could focus on building awareness, understanding and trust among patients and their families. Finally, retention ideas might help patients remain on schedule and connected to care during the months between appointments. But those are just a few suggestions. By all means, if you have better ideas, feel free to participate in this new challenge and earn a share of the prize money.&lt;/p&gt;

&lt;p&gt;NIH is deliberately casting a wide net looking for precipitants. Individuals, informal teams, community organizations, health professionals, researchers, universities and companies can all participate. People and organizations that do not currently receive NIH funding are specifically encouraged to enter as the agency is looking for fresh and new ideas.&lt;/p&gt;

&lt;p&gt;The first-round submission for the ARISE-HIV Challenge is pretty approachable. Participants need to complete an online concept submission totaling about three pages. Participants must also provide a short public abstract and identify whether their proposal addresses access, delivery, engagement, retention or some combination of those areas.&lt;/p&gt;

&lt;p&gt;Judges will place the greatest weight on public health significance and impact, which accounts for 40% of the score. Innovation and novelty make up 35%, while the remaining 25% focuses on whether the idea is pragmatic enough to work outside a controlled research environment. HeroX and government officials explained the judging process and the importance of the challenge in a recent YouTube video.&lt;/p&gt;

&lt;div class="embed-wrapper big"&gt;
&lt;div class="embed-container embed-youtube"&gt;&lt;iframe allowfullscreen="" class="embedded" data-embed-src="https://www.youtube.com/embed/r49UEHVLGWw?wmode=transparent" frameborder="0" src="https://www.youtube.com/embed/r49UEHVLGWw?wmode=transparent"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;/div&gt;

&lt;p&gt;Completed Phase 1 entries must be submitted through HeroX by 5 p.m. Eastern on Aug. 6. NIH expects to award as many as 35 first-round prizes of $10,000 each. Those winners will be invited into Phase 2, where they will develop more detailed implementation and evaluation plans. Up to 13 second-round winners could receive approximately $50,000 each.&lt;/p&gt;

&lt;p&gt;And this is a busy time for government sponsored and federally focused challenges as the HIV event is not the only one being opened to outside solvers. The Department of Energy&amp;rsquo;s Office of Electricity recently launched the $500,000 Storage Design Strategies to Ease Production Prize, known as the &lt;a href="https://www.herox.com/storagedesignSTEP-prize"&gt;Storage Design STEP Prize&lt;/a&gt;. It asks developers of emerging grid-scale storage technologies to identify manufacturing, material-sourcing and supply-chain obstacles before those problems prevent promising designs from reaching commercial production. Phase 1 entries are due Oct. 8.&lt;/p&gt;

&lt;p&gt;Another active competition, the privately organized GoAERO Prize, is supported by NASA, RTX, Boeing, Honeywell, Iridium and other partners. Teams for that challenge are actually building compact, portable aircraft that could autonomously carry a person or emergency supplies into areas where conventional rescue vehicles cannot easily reach. Its final fly-off will take place at NASA&amp;rsquo;s Ames Research Center in April 2027. The best overall performer can earn $1 million, with additional prizes for missions involving rapid deployment, difficult conditions and precise maneuvering around obstacles.&lt;/p&gt;

&lt;div class="embed-wrapper big"&gt;
&lt;div class="embed-container embed-youtube"&gt;&lt;iframe allowfullscreen="" class="embedded" data-embed-src="https://www.youtube.com/embed/9iMLv05O3QY?wmode=transparent" frameborder="0" src="https://www.youtube.com/embed/9iMLv05O3QY?wmode=transparent"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;/div&gt;

&lt;p&gt;The live challenges are radically different, but they share the same underlying idea. Agencies and other sponsors describe a difficult problem, establish rules and rewards, then open the door to people who may never have encountered the issue through a conventional grant, contract or government job.&lt;/p&gt;

&lt;p&gt;My Mars scenario never became a functioning astronaut-training mission. But earning an honorable mention showed that someone outside NASA could still contribute an idea the agency considered useful. The next valuable idea may come from a community health worker who understands why patients miss appointments, an engineer trying to manufacture a new kind of battery or an aviation team that knows how to reach people stranded after a disaster.&lt;/p&gt;

&lt;p&gt;For readers with a useful perspective, technical skill or firsthand understanding of one of these problems, the invitation is real: take a look, join a team or submit an idea. You may not win the top prize, but you could still contribute something that advances a technology, helps an agency or improves someone&amp;rsquo;s life.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;John Breeden II is an award-winning journalist and reviewer with over 20 years of experience covering technology. He is the CEO of the &lt;/em&gt;&lt;a href="https://techwritersbureau.com/"&gt;&lt;em&gt;Tech Writers Bureau&lt;/em&gt;&lt;/a&gt;&lt;em&gt;, a group that creates technological thought leadership content for organizations of all sizes. Twitter: @LabGuys&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/11/GettyImages_1276547627/large.jpg" width="618" height="284"><media:description>View of the main historical building (Building 1) of the National Institutes of Health (NIH) inside Bethesda campus. U.S. Public Health Service seal is seen on top of it.</media:description><media:credit>Grandbrothers / Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/11/GettyImages_1276547627/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Federal agencies quietly joined health data superhighway governing council</title><link>https://www.nextgov.com/digital-government/2026/08/federal-agencies-quietly-joined-health-data-superhighway-governing-council/415324/</link><description>The rapidly growing superhighway — known as TEFCA — will help federal agencies digitally obtain health records from thousands of hospitals, clinics and other medical providers.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christian Robles</dc:creator><pubDate>Mon, 10 Aug 2026 17:37:00 -0400</pubDate><guid>https://www.nextgov.com/digital-government/2026/08/federal-agencies-quietly-joined-health-data-superhighway-governing-council/415324/</guid><category>Digital Government</category><content:encoded>&lt;![CDATA[&lt;p&gt;Officials with the Consumer Product Safety Commission, Social Security Administration and Indian Health Service were added to the governing council for a federal initiative designed to facilitate the exchange of health data in June, &lt;em&gt;Nextgov/FCW&lt;/em&gt; has learned.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The council&amp;rsquo;s recent additions highlight how agencies are increasingly eyeing participation in the initiative &amp;mdash; known as the Trusted Exchange Framework and Common Agreement, or TEFCA &amp;mdash; to obtain digital health records that would help quickly process disability claims, track consumer safety issues and improve medical care.&lt;/p&gt;

&lt;p&gt;The new federal representatives on the TEFCA governing council are:&lt;/p&gt;

&lt;ul&gt;
	&lt;li aria-level="1"&gt;Brien Lorenze, executive director of CPSC&lt;/li&gt;
	&lt;li aria-level="1"&gt;Sean Fry, executive advisor of health information technology and electronic records in SSA&amp;rsquo;s office of disability policy&lt;/li&gt;
	&lt;li aria-level="1"&gt;Bobby Villines, acting director of the division of information technology within IHS&amp;rsquo; office of information technology&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The &lt;a href="https://rce.sequoiaproject.org/tefca-governing-council/"&gt;TEFCA website&lt;/a&gt; was updated Monday afternoon to list the governing council members, including federal representatives, after &lt;em&gt;Nextgov/FCW&lt;/em&gt; inquired about new representatives. The governing council saw the federal members added in June, according to a spokesperson for the Department of Health and Human Services&amp;rsquo; Office of the National Coordinator for Health Information Technology.&lt;/p&gt;

&lt;p&gt;The governing council is tasked with monitoring health data exchanges, reviewing potential updates to the superhighway and helping resolve contentious cases of health information sharing, according to &lt;a href="https://rce.sequoiaproject.org/wp-content/uploads/2025/01/TEFCA-Governance-SOP-2024-1.10.25-final-508.pdf"&gt;TEFCA rules&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The rules state that up to five individuals affiliated with a federal agency can sit on the governing council. The governing council can be expanded to include more federal representatives.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The ability for members to vote on the governing council depends on whether their agency is &amp;ldquo;actively involved in or enabling TEFCA exchange,&amp;rdquo; according to the rules. CPSC&amp;rsquo;s representative is a nonvoting member on the governing council.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How the agencies are leveraging TEFCA&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The three agencies with new representatives on the TEFCA governing council are actively eyeing the health data sharing initiative to support agency procedures. Some are already receiving data through TEFCA.&lt;/p&gt;

&lt;p&gt;In February, SSA announced it joined TEFCA to &lt;a href="https://www.ssa.gov/blog/en/posts/2026-02-11.html"&gt;speed up&lt;/a&gt; disability benefits processing by more than 50% in some cases. Health systems using Epic electronic health records &lt;a href="https://www.epic.com/epic/post/health-systems-on-epic-are-first-to-connect-with-the-social-security-administration-through-tefca/"&gt;have already begun&lt;/a&gt; to digitally send SSA health information through TEFCA.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;SSA has long pulled medical records through other health data superhighways known as Carequality and eHealth Exchange, but TEFCA has enabled additional hospitals and clinics using Epic electronic health records to send health information to the federal government, according to Epic. SSA specifically chose eHealth Exchange as its Qualified Health Information Network, or QHIN, which is essentially an onramp to the broader TEFCA superhighway.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;An SSA spokesperson did not return a request for comment on the agency&amp;rsquo;s participation in the governing council.&lt;/p&gt;

&lt;p&gt;In July, CPSC announced it will leverage a QHIN, &lt;a href="https://www.cpsc.gov/Newsroom/News-Releases/2026/CPSC-Modernizes-Decades-Old-Injury-Surveillance-System-to-Protect-More-Americans-Faster"&gt;Konza Health&lt;/a&gt;, to update its National Electronic Injury Surveillance System, or NEISS, a tracking system for consumer product-related injuries. The new system would allow hospitals in all 50 states to share vital medical information with CPSC and speed up the detection of hazardous consumer products, the agency said in a press release.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;As CPSC modernizes [NEISS to] NEISS-R, interoperability with the nation&amp;#39;s health information infrastructure has become increasingly important. TEFCA provides a common framework for trusted health information exchange that can support authorized public health activities while promoting privacy, security, and standardized data exchange,&amp;rdquo; a CPSC spokesperson told &lt;em&gt;Nextgov/FCW&lt;/em&gt;. &amp;ldquo;CPSC&amp;#39;s participation reflects the mutual recognition that TEFCA and NEISS-R have complementary public health objectives and that collaboration benefits both efforts.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;CPSC&amp;rsquo;s partnership with Konza Health has garnered controversy from the likes of &lt;a href="https://www.youtube.com/watch?v=h7vJVid4Y8w"&gt;Rachel Maddow&lt;/a&gt; and &lt;a href="https://advocacy.consumerreports.org/press_release/consumer-reports-product-injury-data-should-be-modernized-but-the-cpsc-doesnt-need-patients-personal-medical-records-to-do-it/"&gt;consumer advocacy groups&lt;/a&gt; because it may sweep up personally identifiable information, such as names, addresses and birthdates, according to a &lt;a href="https://kffhealthnews.org/health-industry/cpsc-consumer-product-safety-commission-trump-er-injury-data-grab-neiss-konza/"&gt;&lt;em&gt;KFF Health&lt;/em&gt; report&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Hospital technologists are also wary about the initiative because Konza Health officials have described medical record sharing as mandatory or else hospitals could be charged with violating federal information blocking rules, the report says.&lt;/p&gt;

&lt;p&gt;The HHS office overseeing TEFCA invited CPSC to recommend a federal representative on the governing council in April.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;IHS became &lt;a href="https://ehealthexchange.org/first-federal-health-agency-joins-tefca-selecting-ehealth-exchange/"&gt;the first federal agency&lt;/a&gt; to join TEFCA in December 2024 with eHealth Exchange serving as its QHIN onramp. As a health care provider to federally recognized tribes, IHS is using TEFCA to improve care coordination between agency and nonagency medical providers.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The patients we serve are commonly shared with private sector, academic, or other federal healthcare providers. As such, the IHS has a clear interest in modernization and optimization of interoperability and coordination of care, and having a seat and a voice on the TEFCA Governing Council supports that interest,&amp;rdquo; an IHS spokesperson told &lt;em&gt;Nextgov/FCW&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;In addition to federal representatives, the TEFCA governing council has added several health IT industry bigwigs, including Alex Mugge and Hans Buitendijk of Oracle and Matt Becker of Kno2, &lt;em&gt;Nextgov/FCW&lt;/em&gt; has learned.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/10/GettyImages_2228735046/large.jpg" width="618" height="284"><media:credit>Thanadon Naksanee / Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/10/GettyImages_2228735046/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Senate’s short-term funding bill provides temporary extensions for TMF, cyber data-sharing law</title><link>https://www.nextgov.com/policy/2026/08/senates-short-term-funding-bill-provides-temporary-extensions-tmf-cyber-data-sharing-law/415322/</link><description>The continuing resolution that overwhelmingly passed the upper chamber this weekend would push the federal government’s funding deadline until Dec. 11.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Edward Graham</dc:creator><pubDate>Mon, 10 Aug 2026 17:25:00 -0400</pubDate><guid>https://www.nextgov.com/policy/2026/08/senates-short-term-funding-bill-provides-temporary-extensions-tmf-cyber-data-sharing-law/415322/</guid><category>Policy</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Senate approved a temporary funding measure this weekend that would provide a short-term extension for both the Technology Modernization Fund and a key cybersecurity law, although the proposal faces an uncertain future in the House.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The continuing resolution, which overwhelmingly passed the upper chamber in a 90-6 vote on Saturday morning, would punt funding for the federal government until Dec. 11. In lieu of further action and President Donald Trump signing such legislation, the government faces the likelihood of another shutdown beginning on Oct. 1.&lt;/p&gt;

&lt;p&gt;The Senate-passed legislation, in part, extends the Technology Modernization Fund, a federal program that provides financial assistance to government technology projects. TMF was established in 2017 and helps support longer-term IT modernization initiatives while also having agencies pay back the investments that they received.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;A Government Accountability Office report &lt;a href="https://www.nextgov.com/modernization/2026/07/technology-modernization-fund-has-saved-little-big-savings-are-expected-later-gao-finds/414968/"&gt;released&lt;/a&gt; last month found that TMF-funded projects have only resulted in about $13.5 million in savings through June 2025, although the watchdog estimated that 24 reviewed projects that received program funds between fiscal years 2018 and 2025 will result in roughly $1.06 billion in savings alone.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Saturday&amp;rsquo;s funding measure also provided a short-term extension for the Cybersecurity Information Sharing Act of 2015, a cornerstone cyber data-sharing measure that lets companies disseminate cyber threat intelligence with federal partners and one another while maintaining key legal exemptions. The law temporarily expired during the 43-day government shutdown late last year, although Congress passed a funding package in February that extended the statute through Sept. 30.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Trump administration officials have expressed a desire for lawmakers to extend the law for a prolonged period of time to enhance cyber information sharing.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;National Cyber Director Sean Cairncross said &lt;a href="https://www.nextgov.com/cybersecurity/2026/05/trump-admin-will-push-long-term-reauthorization-key-cyber-data-sharing-law/413395/"&gt;during an event&lt;/a&gt; in May that the White House was &amp;ldquo;pushing for a long-term reauthorization&amp;rdquo; of the law, noting that the administration&amp;rsquo;s &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/trumps-new-cyber-strategy-details-more-offensive-response-cyber-threats/411963/"&gt;national cybersecurity strategy&lt;/a&gt; includes a focus on enhancing information sharing between the government and the private sector.&lt;/p&gt;

&lt;p&gt;Lawmakers have &lt;a href="https://www.govexec.com/management/2026/08/what-history-tells-us-about-potential-government-shutdown/415259/?oref=ge-home-top-story"&gt;moved to push the next federal funding fight&lt;/a&gt; until after the November midterm elections, although both chambers still need to come together to support one measure.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Saturday&amp;rsquo;s bill passed before senators departed for the August recess. The House, which is also slated to be out until Aug. 31, passed its own temporary funding measure on July 21. Senate Democrats, however, have called that bill a non-starter.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/10/GettyImages_2289550622/large.jpg" width="618" height="284"><media:description>U.S. Senate Majority Leader John Thune (R-SD) speaks to the press in the U.S. Capitol on August 08, 2026 in Washington, DC. Senators worked through the night to pass a short-term funding extension. </media:description><media:credit>Finn Gomez/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/10/GettyImages_2289550622/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Senate Finance panel’s top Dem proposes excise tax on new data centers</title><link>https://www.nextgov.com/artificial-intelligence/2026/08/senate-finance-panels-top-dem-proposes-excise-tax-new-data-centers/415321/</link><description>Oregon Sen. Ron Wyden’s draft white paper calls for a new tax on hyperscalers and data center operators.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alexandra Kelley</dc:creator><pubDate>Mon, 10 Aug 2026 17:12:00 -0400</pubDate><guid>https://www.nextgov.com/artificial-intelligence/2026/08/senate-finance-panels-top-dem-proposes-excise-tax-new-data-centers/415321/</guid><category>Artificial Intelligence</category><content:encoded>&lt;![CDATA[&lt;p&gt;A new draft white paper from a top Senate Democrat proposes tax code updates that would shift incentives for data center construction.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.finance.senate.gov/imo/media/doc/080626_wyden_data_center_tax_white_paper.pdf"&gt;The paper&lt;/a&gt;, released on Aug. 6 by Sen. Ron Wyden, D-Ore.&amp;nbsp;&amp;mdash; ranking member of the Senate Finance Committee &amp;mdash; proposes changing the incentives that could spur more data center construction amid the national boom in a bid to offset consumer burdens associated with more data centers.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Wyden&amp;rsquo;s framework hinges on two changes to existing tax code: removing the current tax incentives that apply to data center construction and applying a new excise tax on data centers whose workloads primarily handle AI compute.&lt;/p&gt;

&lt;p&gt;With the removal of the tax incentive and the creation of an excise tax on data center operations, the new revenue would help address the myriad concerns with increased data center costs, including higher energy prices, workforce turmoil and a drain on broader resources.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;American communities are rightfully questioning whether the rapid buildout of data centers across the nation will benefit them, as local disruptions rise and Americans grow concerned about the long-term career prospects of millions of workers,&amp;rdquo; Wyden said in &lt;a href="https://www.finance.senate.gov/ranking-members-news/wyden-unveils-proposal-to-ensure-data-centers-pay-for-disruptions-caused-to-communities"&gt;a press release&lt;/a&gt;. &amp;ldquo;These proposals are a first step towards safeguarding taxpayer dollars and ensuring there are resources to support American workers displaced by the coming disruptions to the economy.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Wyden includes several caveats to his tax proposal. The new excise tax would function as a gross receipts tax that charges a fee the total revenue or sales of a business.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Two types of data centers will be subject to the tax: those owned, operated or rented by massive data center operators, and those being used by major data center payors, which include major hyperscalers Amazon and Meta. The paper stipulates that the tax would target the large AI hyperscalers and other entities that are primarily &amp;ldquo;causing the data center boom and most able to pay.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Wyden&amp;rsquo;s proposal offers selective exemptions, which apply to data center assets constructed before 2024. It states that &amp;ldquo;for all but the largest actors,&amp;rdquo; the share of data center assets built before 2024 won&amp;rsquo;t be subject to the new tax.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;These proposals will not end data center development or put at risk the U.S. maintaining its&lt;/p&gt;

&lt;p&gt;status as the global leader in AI and other innovative technologies,&amp;rdquo; the paper reads. &amp;ldquo;Rather, they will ensure we have the resources to help the communities and workers most impacted as data center construction continues.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The proposal also says that the tax would apply to data centers in space. The draft paper stipulates that if a space-based data center attempts to avoid the tax by being labeled as a non-U.S. asset, a withholding tax will apply to payments made by U.S. taxpayers to use the data center. Space-focused tech firms, including Blue Origin and SpaceX, have &lt;a href="https://www.theguardian.com/science/2026/jul/23/space-datacenters-bezos-blue-origin"&gt;proposed&lt;/a&gt; building millions of orbital data centers.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Wyden also solicited feedback on his proposal, calling for the public to provide the Senate Finance Committee&amp;rsquo;s minority staff with comments by Aug. 31. The paper said that discussion draft language is expected to arrive in the coming fall.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Data center construction and the question of who bears the burden of increased electricity rates and other potential hazards has become a major political talking point. Democrats, in particular, have been &lt;a href="https://www.pbs.org/newshour/nation/democrats-seize-on-ai-data-center-backlash-thats-dividing-rural-republicans-in-places-like-texas"&gt;looking to leverage&lt;/a&gt; growing opposition to further data center construction as a political issue ahead of the 2026 midterm elections.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In March, President Donal Trump unveiled &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/03/7-tech-companies-commit-protect-consumers-rising-electricity-prices/411883/"&gt;the Ratepayer Protection Pledge&lt;/a&gt; that brought companies Amazon, xAI, Oracle, Microsoft, Meta, Google and OpenAI to agree to absorb utility costs stemming from data centers handling their technology&amp;rsquo;s compute loads.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Other lawmakers have also turned their attention to issues brought about by the data center boom. Sen. Bernie Sanders, I-Vt., previously called for a moratorium on new construction until more information can be garnered about both data center impacts and AI itself.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We cannot sit back and allow a handful of billionaire Big Tech oligarchs to make decisions that will reshape our economy, our democracy and the future of humanity,&amp;rdquo; &lt;a href="https://www.sanders.senate.gov/press-releases/news-sanders-yes-we-need-a-moratorium-on-data-center-construction/"&gt;Sanders wrote in February&lt;/a&gt;. &amp;ldquo;We need serious public debate and democratic oversight over this enormously consequential issue.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/10/GettyImages_2281570436/large.jpg" width="618" height="284"><media:description>Sen. Ron Wyden, D-Ore., is seen during votes in the U.S. Capitol on Wednesday, June 17, 2026. </media:description><media:credit>Tom Williams/CQ-Roll Call, Inc via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/10/GettyImages_2281570436/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Federal systems increasingly likely to face accidental AI breach after Hugging Face, experts say</title><link>https://www.nextgov.com/cybersecurity/2026/08/federal-systems-increasingly-likely-face-accidental-ai-breach-after-hugging-face-experts-say/415307/</link><description>Former officials and security experts say aged systems, contractors and agency AI adoption could open similar paths into government networks.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Mon, 10 Aug 2026 11:19:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/federal-systems-increasingly-likely-face-accidental-ai-breach-after-hugging-face-experts-say/415307/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; An OpenAI agent tasked with finding software flaws escaped its testing environment, hacked into Hugging Face and spent days moving through the company&amp;rsquo;s systems in search of answers to an evaluation. It had not been sent to attack the company, yet it did so anyway &amp;mdash; and a smattering of other accidental AI intrusions in separate environments have &lt;a href="https://www.theguardian.com/technology/2026/aug/05/openai-anthropic-models-went-rogue-cybersecurity-test-ai-security-institute"&gt;since followed&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;If the same chain of events began again, former officials and cybersecurity experts told &lt;em&gt;Nextgov/FCW&lt;/em&gt; there is little reason to assume a federal agency would be spared. In interviews during Black Hat and DEF CON this past week, they said aging networks, systems that are not properly separated and the government&amp;rsquo;s heavy reliance on contractors could present weaknesses that would let an unauthorized AI agent move from one environment into another before defenders realize.&lt;/p&gt;

&lt;p&gt;One former federal chief information officer likened the risk to turning loose a hunting dog: &amp;ldquo;If you&amp;rsquo;re going to put your dog in the yard and instruct it to hunt, probably best to ensure the back gate is closed.&amp;rdquo; The former official spoke on condition of anonymity to discuss their views more candidly.&lt;/p&gt;

&lt;p&gt;The&lt;a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/"&gt; July intrusion&lt;/a&gt; began during an internal OpenAI test designed to measure how effectively advanced models could find and exploit vulnerabilities. OpenAI said the agent &amp;mdash; powered by GPT-5.6 Sol and a more capable internal research prototype &amp;mdash; was operating with some security safeguards intentionally reduced.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The agent exploited a previously unknown flaw in an internal package-management service, reached the public internet and commandeered a third-party code sandbox as a staging point. From there, it exploited two flaws in Hugging Face&amp;rsquo;s dataset-processing systems, obtained credentials, executed commands and moved through parts of the company&amp;rsquo;s infrastructure.&lt;/p&gt;

&lt;p&gt;In the leadup to the intrusion, OpenAI models created an internal message board, used it to trade hacking methods and found a way to bring it back even after humans shut it down, company engineers &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/08/openai-agents-rebuilt-internal-message-board-lead-hugging-face-breach/415240/"&gt;said in a presentation&lt;/a&gt; at the cyber conferences this past week.&lt;/p&gt;

&lt;p&gt;The agent deliberately exploited Hugging Face&amp;rsquo;s systems in pursuit of its assigned goal, but OpenAI had not instructed it to attack the company. Bob Costello, who served as chief information officer at the Cybersecurity and Infrastructure Security Agency before becoming chief digital and information officer at Merlin Group, said a similar federal incident could begin with authorized security testing.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;As we start using really advanced AI to operate our systems or penetration-test our systems or blue-red-purple team our systems,&amp;rdquo; he said, &amp;ldquo;maybe one of those kind of goes sideways, [and] takes a lateral system to the side.&amp;rdquo; The color-coding he described refers to red teams that simulate hackers, blue teams that defend systems and purple teams that combine both approaches to find digital weaknesses.&lt;/p&gt;

&lt;p&gt;That possibility is becoming more relevant as agencies begin experimenting with AI agents that can retrieve information and take actions. The General Services Administration is preparing a&lt;a href="https://www.gsa.gov/artificial-intelligence/ai-community-of-practice/events-and-training/2026-ai-hackathon"&gt; governmentwide hackathon&lt;/a&gt; in which federal, state and local employees will build connections between AI systems and agency data and public services, including prototypes that would let AI route data directly to an agency.&amp;nbsp;The work is slated to be conducted exclusively in sandboxed environments and will not involve any access to restricted data or production systems.&lt;/p&gt;

&lt;p&gt;Contractors may keep their federal and commercial systems separate, said Leslie Nielsen, the executive vice president and CISO at Mimecast, but the same employees may still access both: &amp;ldquo;There&amp;rsquo;s lots of people using it from both sides, and getting in through one could eventually lead to the other.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The chances of it happening again, I would say it&amp;rsquo;s going to,&amp;rdquo; he added. &amp;ldquo;Some of these [federal] infrastructures are just so big and, candidly, so old, that there are little nooks and crannies in them, they&amp;rsquo;re going to get teased out.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Asked to assess the likelihood of a comparable federal incident, Ellen Boehm, senior vice president of internet-of-things strategy and operations at Keyfactor, called it &amp;ldquo;pretty likely&amp;rdquo; and placed the odds at &amp;ldquo;seven out of 10.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Michael Leland, vice president and field chief technology officer at enterprise browser provider Island, said some civilian agencies are exposed because &amp;ldquo;they don&amp;rsquo;t have the infrastructure, they don&amp;rsquo;t have the talent, and they haven&amp;rsquo;t spent years building those guardrails or that containment because they didn&amp;rsquo;t have to.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;It shouldn&amp;rsquo;t be different for AI because AI doesn&amp;rsquo;t care where it is,&amp;rdquo; Leland said. &amp;ldquo;It is opportunistic.&amp;rdquo; Agencies that don&amp;rsquo;t do national security work that have lower cyberdefense standards are &amp;ldquo;very much at risk,&amp;rdquo; he added.&lt;/p&gt;

&lt;p&gt;Bob Ackerman, co-founder and managing partner at cyber venture capital firm DataTribe, also said many organizations have embraced powerful AI systems before learning how to reliably control them.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We fundamentally are kidding ourselves that we&amp;rsquo;ve got this under control,&amp;rdquo; Ackerman said. &amp;ldquo;We&amp;rsquo;ve got a really, really powerful tool, but we don&amp;rsquo;t know how to control it yet.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;But people interviewed for this story largely rejected the idea that autonomous agents have rendered the government&amp;rsquo;s existing security playbook obsolete. The Hugging Face campaign relied on recognizable techniques like finding exposed systems, stealing credentials, escalating privileges and moving between connected environments, all of which are problems agencies have faced for years.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;It&amp;rsquo;s really not gonna play out all that differently than if it was a hands-on keyboard actor &amp;hellip; or someone who&amp;rsquo;s writing a script and letting a programmatic algorithm go and do its thing,&amp;rdquo; said Ben Bernstein, who manages the cybersecurity advisors team at Huntress.&lt;/p&gt;

&lt;p&gt;The difference, ultimately, is tempo and scale. An AI hacker can probe potential routes, link digital weaknesses and iterate its maneuvers without the delays of human intervention. Such tools maintain a relentless fixation on specific targets, persisting with an objective well beyond the point where a human operative might question the value of taking their selected intrusion path. On top of it all, they don&amp;rsquo;t need to eat, sleep or take restroom breaks.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;An agent&amp;rsquo;s just a fast hacker at the end of the day, right?&amp;rdquo; Nielsen said. &amp;ldquo;But the one thing the agent doesn&amp;rsquo;t have is a moral or ethical compass. They&amp;rsquo;re given a task and they have focus, and they&amp;rsquo;re going to go do what you&amp;rsquo;ve told them to do.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;David Weston, Microsoft&amp;rsquo;s corporate vice president of agentic security, similarly cautioned against treating the federal government as a fundamentally different kind of target. The approach demonstrated in the Hugging Face breach &amp;ldquo;is going to be a challenge for most folks,&amp;rdquo; he said, but the response still comes down to basic security practices.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Regardless of the target, everyone needs to follow those fundamentals,&amp;rdquo; Weston added.&lt;/p&gt;

&lt;p&gt;Duncan Greatwood, CEO of Xage Security, also said agencies should not rely on simply telling an agent not to perform certain actions because those instructions can be bypassed. Instead, they should use separate security controls that technically prevent the agent from reaching systems or changing data it&amp;rsquo;s not authorized to touch. He described the approach as &amp;ldquo;bounded autonomy.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;You allow the agent to do stuff, but you&amp;rsquo;re not going to allow it to go crazy. You&amp;rsquo;re going to put hard bounds around it,&amp;rdquo; Greatwood said.&lt;/p&gt;

&lt;p&gt;Retired Gen. Paul Nakasone, the former director of U.S. Cyber Command and the NSA who now leads Vanderbilt University&amp;rsquo;s Institute of National Security and sits on OpenAI&amp;rsquo;s board, called the Hugging Face episode &amp;ldquo;an inflection point in terms of AI-generated autonomous cyber attack.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;My question is, how do we ensure that the defense starts to catch up, right?&amp;rdquo; Nakasone said. &amp;ldquo;How do we make sure that artificial intelligence is able to bring together a capable defense that allows us to do vulnerability detection, to do patching, to do incident response, and to do mitigation?&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Editor&amp;#39;s note: This article has been updated to clarify the participants in GSA&amp;#39;s upcoming hackathon and where the work will&amp;nbsp;occur.&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/10/GettyImages_2288181917/large.jpg" width="618" height="284"><media:description> Sam Altman, CEO of OpenAI, leaves a meeting at the U.S. Capitol on July 29, 2026 in Washington, DC. </media:description><media:credit>Kevin Dietsch / Staff  Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/10/GettyImages_2288181917/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Cloudflare to seek DOD IL4 authorization after new FedRAMP, GovRAMP designations</title><link>https://www.nextgov.com/acquisition/2026/08/cloudflare-seek-dod-il4-authorization-after-new-fedramp-govramp-designations/415299/</link><description>The connectivity cloud giant recently achieved FedRAMP High certification and GovRAMP Moderate authorization.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christian Robles</dc:creator><pubDate>Mon, 10 Aug 2026 09:00:00 -0400</pubDate><guid>https://www.nextgov.com/acquisition/2026/08/cloudflare-seek-dod-il4-authorization-after-new-fedramp-govramp-designations/415299/</guid><category>Acquisition</category><content:encoded>&lt;![CDATA[&lt;p&gt;Cloudflare announced Monday it plans to seek Department of Defense Impact Level 4 authorization to bring a platform that can store and process controlled unclassified information to defense agencies.&lt;/p&gt;

&lt;p&gt;The connectivity cloud company also achieved &lt;a href="https://www.fedramp.gov/marketplace/products/FR2000863987A/"&gt;FedRAMP High certification&lt;/a&gt;, which covers civilian federal agencies, Thursday and &lt;a href="https://govramp.org/program-participants#apl"&gt;GovRAMP Moderate authorization&lt;/a&gt;, which covers state and local governments, in April.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;With the FedRAMP High certification, agencies can use Cloudflare for Government to process sensitive information related to national security, critical infrastructure and financial systems, according to a press release. The certification comes shortly after the FedRAMP director &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/after-hugging-face-breach-fedramp-chief-tells-slow-patch-vendors-stay-out-government/414972/?oref=ng-homepage-river"&gt;warned vendors&lt;/a&gt; they should not be allowed to sell products to agencies if they are too slow in patching vulnerabilities.&lt;/p&gt;

&lt;p&gt;With the GovRAMP Moderate authorization, state and local governments can similarly use Cloudflare for Government to protect sensitive information and meet state-specific data privacy mandates, the release said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;FedRAMP High, GovRAMP Moderate, and our intent to pursue DoD IL4 let us bring a platform to federal, state, local, and defense teams to advance their missions, retire legacy technologies, and accelerate their shifts to a more secure, efficient, and innovative future,&amp;rdquo; David Mihalchik, vice president of U.S. public sector at Cloudflare, said in the release.&lt;/p&gt;

&lt;p&gt;The departments of Energy, Health and Human Services, Commerce, Homeland Security, Interior, Justice and State, in addition to other agencies, already use Cloudflare technologies.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/07/080726cloudflareNG/large.jpg" width="618" height="284"><media:credit>Stanislav Kogiku/SOPA Images/LightRocket via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/07/080726cloudflareNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Voting machine researchers say federal work abruptly ended after Trump ally pushed back on their findings</title><link>https://www.nextgov.com/cybersecurity/2026/08/voting-machine-researchers-say-federal-work-abruptly-ended-after-trump-ally-pushed-back-their-findings/415300/</link><description>Mojave Research executives said at DEF CON that the government had been preparing to expand the company’s election security work, and linked Trump adviser Kurt Olsen to pressure they faced after finding election system vulnerabilities but no evidence votes were altered.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Sun, 09 Aug 2026 06:00:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/voting-machine-researchers-say-federal-work-abruptly-ended-after-trump-ally-pushed-back-their-findings/415300/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; After spending roughly six weeks analyzing Dominion voting systems used in Puerto Rico&amp;rsquo;s 2024 elections, Mojave Research came back to the Trump administration with findings that startled its researchers.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The systems contained at least a dozen high- or critical-severity software vulnerabilities. Passwords were reused, firewalls were disabled and basic cryptographic protections were poorly implemented. And in Puerto Rico, active cellular hardware modems opened additional pathways into underlying software that was thought to be isolated.&lt;/p&gt;

&lt;p&gt;But the small cybersecurity firm found no evidence that any of those weaknesses had actually been exploited, or that votes had been changed. The company still wanted more time to be certain.&lt;/p&gt;

&lt;p&gt;Federal officials initially seemed willing to give them considerably more of it. The company was asked to grow the team working on the effort from roughly 10 people to about 60, according to CEO Jason Wareham.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Chief Technology Officer Manbir Gulati also said Mojave received an authorization to proceed with a follow-on effort, hired personnel and was given funding to acquire equipment for examining additional voting systems ahead of the November midterms. A contracting officer had even been brought in to finalize the new agreement, Gulati said.&lt;/p&gt;

&lt;p&gt;Then, as Mojave prepared to move ahead, the work was abruptly shut down.&lt;/p&gt;

&lt;p&gt;Wareham and Gulati recounted the episode on Friday at DEF CON hacker convention&amp;rsquo;s Voting Village, where they publicly unpacked their technical findings before sitting down with a small group of reporters and onlookers afterward.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Their account fills in new details about a federal effort that grew out of the Trump administration&amp;rsquo;s broader focus on voting machines and election interference, and the political pressures that emerged when Mojave&amp;rsquo;s findings did not support claims of election manipulation.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The ODNI request&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Mojave never set out to become an election security provider. Its involvement began last year through the Office of the Director of National Intelligence under then-director Tulsi Gabbard, where it was already performing unrelated technical work for the agency when officials approached the company about examining voting machines and data obtained from Puerto Rico.&lt;/p&gt;

&lt;p&gt;Reuters &lt;a href="https://www.reuters.com/world/americas/us-spy-chiefs-office-investigated-voting-machines-puerto-rico-2026-02-04/"&gt;reported&lt;/a&gt; in February that the May 2025 operation was tied to an effort involving ODNI and the FBI to investigate allegations that Venezuela had hacked Puerto Rico&amp;rsquo;s voting systems, though Gabbard&amp;rsquo;s office denied that Venezuela drove its work and said the examination was focused on technical vulnerabilities. The probe produced no clear evidence of Venezuelan interference.&lt;/p&gt;

&lt;p&gt;Wareham said at DEF CON that ODNI asked whether his team of reverse engineers and forensic specialists could travel to Puerto Rico and capture an image of a voting system that had actually been used in an election, without the vendor overseeing the process. He agreed, thinking it would be a relatively small addition to Mojave&amp;rsquo;s existing contract.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The assignment instead dropped Mojave into a much larger skirmish over American elections. &amp;ldquo;Ultimately, I made the worst decision of my life in a business context,&amp;rdquo; Wareham said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;President Donald Trump has spent years falsely maintaining that his 2020 loss was stolen and the product of widespread fraud and foreign interference, claims that have been rejected by courts and officials in his own administration. A 2021 intelligence community &lt;a href="https://www.intel.gov/assets/documents/702-documents/declassified/ICA-declass-16MAR21.pdf"&gt;assessment&lt;/a&gt; found no indication that a foreign actor attempted to alter ballots, vote tabulations or any other technical aspect of the election.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Since returning to office, Trump and allies have revived investigations into the 2020 contest and pushed election security back to the center of his administration&amp;rsquo;s agenda. Gabbard&amp;rsquo;s ODNI was &lt;a href="https://www.nextgov.com/people/2026/02/gabbards-expanded-role-election-security-draws-scrutiny/411295/"&gt;one part of that effort&lt;/a&gt;, hauling off and analyzing voting systems from Puerto Rico and later becoming involved in a federal investigation of 2020 election records in Georgia.&lt;/p&gt;

&lt;p&gt;Wareham said the ODNI officials directly overseeing the company&amp;rsquo;s technical work wanted the research to continue. Both he and Gulati described the ODNI staff they worked with as professionals who wanted to protect the security of election systems.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The resistance, Wareham said, came from a separate White House collective that was repeatedly dissatisfied Mojave had not produced evidence supporting claims that the 2020 election had been manipulated.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;There was a separate group &amp;mdash; let&amp;rsquo;s call them White House-adjacent &amp;mdash; who was dissatisfied,&amp;rdquo; he said. &amp;ldquo;They were dissatisfied overall that I was not willing to name and shame at that moment&amp;rdquo; and declare that Trump had actually won the 2020 election.&lt;/p&gt;

&lt;p&gt;Asked whether he believed Mojave&amp;rsquo;s government work was axed because it failed to find the &amp;ldquo;smoking gun&amp;rdquo; some officials wanted, Wareham said: &amp;ldquo;I believe that was part of the termination, yes.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Reuters reported in April that Kurt Olsen, a prominent 2020 election-denier and Trump adviser involved in efforts to investigate the election, &lt;a href="https://www.reuters.com/world/us/trump-aides-chase-vote-rigging-claims-even-after-latest-probe-finds-nothing-2026-04-23/"&gt;pressed Mojave&lt;/a&gt; to broaden its work in search of evidence that could support those claims.&lt;/p&gt;

&lt;p&gt;Olsen, who now works at the Justice Department, turned against the company when its research failed to uncover evidence that the Puerto Rico machines had been hacked. He advocated terminating its work and accused Mojave of secretly receiving money from billionaire George Soros, a frequent target of right-wing conspiracy theories, the news agency reported. ODNI has said Mojave&amp;rsquo;s contract ended because the company completed its voting-machine analysis.&lt;/p&gt;

&lt;p&gt;Wareham said an ODNI official informed him while Mojave was preparing to expand its work that the company had been accused of receiving Soros funding. The allegation prompted him to compile a detailed accounting of the young company&amp;rsquo;s funding sources within three days and send it up the government chain. Asked who he was told had made the accusation, he said an ODNI official reported to him that it was Olsen.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;One, I&amp;rsquo;m not funded by George Soros,&amp;rdquo; Wareham said. &amp;ldquo;Two, it would be great to be funded by George Soros because I would probably not be here, I&amp;rsquo;d be on a yacht.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The company kept moving forward. Wareham said Mojave briefed the White House on some of its findings around September. The firm believed it was heading toward a broader effort to remediate vulnerabilities before the midterms and conduct a deeper analysis for signs that the weaknesses it discovered had ever been actually abused.&lt;/p&gt;

&lt;p&gt;Then came the record-long &lt;a href="https://www.govexec.com/management/2025/11/government-reopen-after-house-votes-end-longest-ever-shutdown/409477/?oref=ge-topic-lander-river"&gt;government shutdown&lt;/a&gt;. Wareham said that on the day he expected an expanded contract to move ahead, Mojave instead received a stop-work order and no additional funding.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I think the government shutdown was all that was required, really, to have some folks that I didn&amp;rsquo;t know were still in the game, again, White-House adjacent, to take their shot,&amp;rdquo; he said. Wareham stopped short of saying he had direct proof that White House officials ordered Mojave removed because of its findings, but said &amp;ldquo;it was reported to me it was Kurt Olsen&amp;rdquo; who led the efforts.&lt;/p&gt;

&lt;p&gt;The White House, ODNI and Olsen did not return requests for comment.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Identified vulnerabilities&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Mojave had found many issues with the machines it examined. Gulati described the Puerto Rico system during the Voting Village presentation as &amp;ldquo;deeply insecure,&amp;rdquo; saying it did not meet the security bar he would expect from &amp;ldquo;an average low-risk application, let alone critical infrastructure.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Researchers identified at least 12 major vulnerabilities in commercial software installed on the system, Gulati said. Mojave successfully executed five of them. None were newly discovered flaws, and fixes were already available &amp;mdash; in some cases well before the system was used in the election.&lt;/p&gt;

&lt;p&gt;Other weaknesses were rooted more deeply in how the system was built and deployed. Some passwords could be easily cracked and others were embedded directly into software. Firewalls were turned off on critical systems and ports were left open. Gulati was particularly critical of the system&amp;rsquo;s cryptography, which he described as being &amp;ldquo;in shambles.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The company does not believe every problem it found necessarily stopped at Puerto Rico, as its formal review covered only one system from one manufacturer in one jurisdiction. Gulati suspects the issues could extend beyond a single voting machine company, though Mojave has not examined enough systems from other manufacturers to establish that.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I don&amp;rsquo;t expect that the problems are unique to them,&amp;rdquo; he said. &amp;ldquo;I think many manufacturers probably exhibit the same problems.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Mojave produced an approximately 100-page document of the Puerto Rico findings. Gulati said Mojave has been in discussions with Liberty Vote &amp;mdash; which acquired Dominion&amp;rsquo;s election business last year &amp;mdash; and that Liberty told the researchers it does not plan to make changes before November.&lt;/p&gt;

&lt;p&gt;Liberty said it has not received Mojave&amp;rsquo;s report.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Liberty Vote is not in receipt of any such report so, therefore, we cannot provide any comment,&amp;rdquo; a spokesperson said. &amp;ldquo;As always, Liberty Vote is committed to advancing the future of secure American elections.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;No evidence of vote tampering&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Looking at the systems headed into the midterms, Gulati said, &amp;ldquo;I do know that as of now, the state that we have described is going to be pretty similar to what will be deployed in November.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Despite the extensive findings, Gulati repeatedly returned to what the researchers did not establish: &amp;ldquo;We found extensive and largely unacceptable weaknesses,&amp;rdquo; he said in the presentation. &amp;ldquo;But we did not find evidence that those weaknesses were actively exploited or that votes were altered.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;That distinction has drawn renewed attention as Trump and his allies again focus on election matters.&lt;/p&gt;

&lt;p&gt;Last month, the president used a prime-time White House address to release newly declassified intelligence he said showed China interfered in the 2020 election. Among several disclosures, Trump pointed to intelligence showing Beijing had acquired personal information on roughly 220 million American voters. But the documents &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/trump-stretches-declassified-china-intelligence-broader-2020-election-claims/414837/"&gt;did not show&lt;/a&gt; China altered votes or gained the ability to manipulate voting systems.&lt;/p&gt;

&lt;p&gt;Gulati echoed those conclusions Friday when asked about the declassification.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The China thing isn&amp;rsquo;t really much of anything,&amp;rdquo; he said, arguing that a large amount of the voter information at issue could be obtained commercially and should not be confused with access to election systems in ways that can manipulate votes.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;There is no evidence that I know of that says China successfully or any other country has successfully infiltrated our systems and manipulated votes in any way,&amp;rdquo; he added.&lt;/p&gt;

&lt;p&gt;Wareham called the 100-page document a preliminary report and said the firm had wanted another six months to a year to dig deeper into the underlying data.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Gulati said the company&amp;rsquo;s interactions with the ODNI employees overseeing that work were markedly different from the political pressure the researchers later encountered. &amp;ldquo;We were never pressured to put anything in our reports that was untrue or politically leaning in a certain way,&amp;rdquo; he said of those officials.&lt;/p&gt;

&lt;p&gt;Wareham said Friday that Mojave itself has pushed for its report to be made public for roughly a year and has recently been told it could soon emerge through a Freedom of Information Act request. &lt;em&gt;Nextgov/FCW&lt;/em&gt; could not immediately determine the origin of the FOIA requester. As of publishing time, ODNI&amp;rsquo;s FOIA logs are &lt;a href="https://archive.dni.gov/index.php/foia#:~:text=ODNI%20FOIA%20Logs,January%202025"&gt;available up until January 2025&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I&amp;rsquo;m a little annoyed that we are very close to midterms and we had a whole year to freaking figure this out,&amp;rdquo; Wareham said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;With their government work scrapped, he announced at the Voting Village that he had filed paperwork to create the &lt;a href="https://vote.machineassurance.org/"&gt;Machine Assurance Institute&lt;/a&gt;, seeking to bring together cybersecurity researchers and election technology companies to examine and independently verify voting infrastructure.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We wanted to be the national security answer, and put to bed, finally, discussions about prior elections and/or accusations of voter fraud,&amp;rdquo; said Wareham. &amp;ldquo;Because, believe it or not, I find it fairly national security-destabilizing to constantly accuse each other of cheating.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/09/GettyImages_1289778741/large.jpg" width="618" height="284"><media:credit>eyecrave productions / Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/09/GettyImages_1289778741/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Senate confirms Adam Cassady to run State Department cyberspace bureau</title><link>https://www.nextgov.com/people/2026/08/senate-confirms-adam-cassady-run-state-department-cyberspace-bureau/415292/</link><description>The confirmation comes as the tech diplomacy shop he would traditionally lead in his new role has seen significant reorganizations in the last year.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Fri, 07 Aug 2026 15:24:00 -0400</pubDate><guid>https://www.nextgov.com/people/2026/08/senate-confirms-adam-cassady-run-state-department-cyberspace-bureau/415292/</guid><category>People</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Senate on Friday confirmed Adam Cassady as the new U.S. ambassador for cyber and digital policy, filling a high-profile role that had been vacant since the start of the second Trump administration.&lt;/p&gt;

&lt;p&gt;Cassady, currently a senior official at the National Telecommunications and Information Administration, was approved in a 51-47 vote as part of a package of some 70 nominees.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The Bureau of Cyberspace and Digital Policy, which traditionally is led by the person named to the position he was just confirmed for, has undergone significant workforce changes. A &lt;a href="https://www.nextgov.com/policy/2025/04/state-department-moves-cyber-and-intelligence-bureaus-under-agencywide-reorg/404753/"&gt;reorganization&lt;/a&gt; last year saw the bureau divided into three separate entities, including a new Bureau of Emerging Threats, and a reduction in overall staff.&lt;/p&gt;

&lt;p&gt;The cyber bureau has mainly focused on international diplomacy for U.S. cyberspace, telecommunications and emerging technologies, and has sought to counter authoritarian tech practices. It was formally launched in 2022 under then-president Joe Biden. Cassady&amp;rsquo;s purview is not entirely clear under the new organizational structure imposed over the last year.&lt;/p&gt;

&lt;p&gt;Under the Biden administration, the unit was headed by retired U.S. Marine Corps officer and technology executive Nate Fick, who used his position to take &lt;a href="https://www.nextgov.com/cybersecurity/2024/05/us-diplomats-told-china-stop-volt-typhoon-campaign-its-becoming-more-advanced-intelligence-officials-say/396361/"&gt;firm stances&lt;/a&gt; against Chinese officials when addressing Beijing-backed cyber intrusions into U.S. critical infrastructure.&lt;/p&gt;

&lt;p&gt;During his April confirmation hearing, Cassady emphasized a need for international collaboration on secure and resilient digital systems. He also sidestepped giving a definitive stance on the export of &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/04/experts-call-halt-ai-chip-exports-china-after-white-house-distillation-warning/413132/"&gt;advanced semiconductor chips&lt;/a&gt; to China, saying he would &amp;ldquo;very, very quickly develop&amp;rdquo; a position on the issue.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;As NTIA&amp;rsquo;s Deputy Administrator, Adam was critical to many of the agency&amp;#39;s most significant achievements in advancing America&amp;rsquo;s technology leadership and protecting our interests abroad,&amp;rdquo; NTIA head Arielle Roth said in a statement. &amp;ldquo;His experience makes him exceptionally well-suited to represent America&amp;rsquo;s strength on the world stage.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/07/080726StateNG/large.jpg" width="618" height="284"><media:credit>Li Rui/Xinhua via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/07/080726StateNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>New ‘Water Watch Center’ launched to help small utilities stop cyberattacks</title><link>https://www.nextgov.com/cybersecurity/2026/08/new-water-watch-center-launched-help-small-utilities-stop-cyberattacks/415288/</link><description>The initiative comes as multiple states grapple with intrusions into their water systems that some officials suspect could be tied to Iran.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Fri, 07 Aug 2026 14:19:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/new-water-watch-center-launched-help-small-utilities-stop-cyberattacks/415288/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; A new program is seeking to assist water providers around the country as multiple states grapple with possible Iran-linked cyber intrusions against water infrastructure.&lt;/p&gt;

&lt;p&gt;The Water Watch Center provides direct cyber mitigation support to utilities serving fewer than 10,000 people, which represents most of the nation&amp;rsquo;s community water systems. Launched at this year&amp;rsquo;s DEF CON hacker convention, the initiative is a joint effort between the National Rural Water Association and DEF CON Franklin, a project of the Cyber Policy Initiative at the University of Chicago Harris School of Public Policy.&lt;/p&gt;

&lt;p&gt;More than 30 community water systems in Minnesota were targeted late last month, according to state officials. Around 12 states have reported similar activity in recent days, though state officials said they continued operating safely and experienced no known effects on public health. The FBI and Cybersecurity and Infrastructure Security Agency are working on &lt;a href="https://www.nextgov.com/cybersecurity/2026/08/cisa-still-finds-water-system-controls-exposed-online-amid-multistate-hacks/415266/"&gt;incident response&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;An initial group of five cybersecurity firms will help deliver services to water utilities as part of the initiative.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;These leading cyber firms and NRWA are architecting a scalable cyber delivery model that has eluded water industry and national security officials to date,&amp;rdquo; Jake Braun, the co-founder of DEF CON Franklin and a former White House acting principal deputy national cyber director, said in a statement.&lt;/p&gt;

&lt;p&gt;Retired Gen. Paul Nakasone, who led U.S. Cyber Command and the NSA from 2018 to 2024, said at DEF CON this year that water utilities around the country are highly exposed, and he pushed for higher defense standards in the sector.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;These [programmable logic controllers] should not be exposed to the internet,&amp;rdquo; he told reporters in a briefing on Friday, referring to the small computers used to operate pumps, valves and other equipment inside water facilities.&lt;/p&gt;

&lt;p&gt;Some U.S. officials believe Iran may be responsible, though there has been no definitive public confirmation.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I think [the government] is taking a very measured approach to make sure that they have the right actor that&amp;rsquo;s doing this,&amp;rdquo; Nakasone said when asked about why Iran hasn&amp;rsquo;t publicly been linked to the hacks&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I look at intent. I look at capability. I look at history. I&amp;rsquo;m not the person that&amp;rsquo;s making the call on the attribution, but I see an actor here that has certainly shown a history of being able to do this,&amp;rdquo; he said. &amp;ldquo;They certainly have the capability, and I think there&amp;rsquo;s an intent right now &amp;mdash; we&amp;rsquo;re in conflict with Iran.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/07/080726waterNG/large.jpg" width="618" height="284"><media:credit>Seth McConnell/The Denver Post via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/07/080726waterNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Tech Bills of the Week: Deterring AI distillation; Taxing AI developers; and more</title><link>https://www.nextgov.com/policy/2026/08/tech-bills-week-deterring-ai-distillation-taxing-ai-developers-and-more/415287/</link><description>This week’s bills addressed how to fortify the U.S. AI ecosystem through penalizing adversaries for model distillation, taxing large developers for AI-driven layoffs, and more.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alexandra Kelley</dc:creator><pubDate>Fri, 07 Aug 2026 14:03:00 -0400</pubDate><guid>https://www.nextgov.com/policy/2026/08/tech-bills-week-deterring-ai-distillation-taxing-ai-developers-and-more/415287/</guid><category>Policy</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;strong&gt;Deterring AI distillation&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Lawmakers are looking to address the threat of AI model distillation by adversaries, with a new bill introduced by Sen. Bill Hagerty, R-Texas targeting illicit intellectual property infringement by Chinese actors.&lt;/p&gt;

&lt;p&gt;The Blocking Large-Scale Adversarial Distillation Efforts &amp;mdash; or BLADE &amp;mdash; Act of 2026 was introduced on Wednesday, just weeks after &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/07/white-house-accuses-chinese-ai-developer-ip-theft/414948/"&gt;the White House voiced concern&lt;/a&gt; over Chinese AI developers training their models on American AI systems in a process called distillation. The BLADE Act mandates that the Executive Branch identify and consolidate the specific foreign entities driving illegal distillation operations.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;As the United States must remain at the forefront of competitiveness in artificial intelligence, we cannot allow our adversaries to steal the intellectual property of America&amp;rsquo;s top AI companies and thereby threaten U.S. national security and economic security,&amp;rdquo; said Hagerty in a press release. &amp;ldquo;The BLADE Act will expose and punish foreign entities that conduct hostile distillation campaigns against our frontier AI companies. Our nation must counter malign actors who seek to subvert our nation&amp;rsquo;s leadership and innovation in artificial intelligence.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;After composing and publicly releasing the list of entities engaging in AI model distillation, the Department of Commerce and Department of Treasury would be tasked with imposing export controls and financial sanctions, respectively, on the listed entities.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The BLADE Act boasts bipartisan support, with Sens. Tim Scott, R-S.C., Andy Kim, D-N.J., and Catherine Cortez Mastro, D-Nev., joining Hagerty in introducing the bill.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Taxing AI-driven unemployment&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A group of House Democrats introduced a new bill on Thursday designed to fight predicted mass layoffs spurred by the rapid advancement and widespread deployment of artificial intelligence.&lt;/p&gt;

&lt;p&gt;Reps. Greg Casar, D-Texas, Valerie Foushee, D-N.C., and Sara Jacobs, D-Calif., introduced the AI Tax and Work Protection Act to prevent mass unemployment through a new oversight office created by taxes levied on AI developers.&lt;/p&gt;

&lt;p&gt;In a press call, Casar described the pending economic situation as an &amp;ldquo;emergency&amp;rdquo; that demands federal intervention.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Right now, no one in Washington has a plan to deal with the threat that AI could pose to the workforce, and no one really knows what Democrats&amp;#39; policy position is on AI and job loss,&amp;rdquo; Casar said on Thursday. &amp;ldquo;We are not going to let millions of Americans go without work just so a few billionaires can become trillionaires, and we&amp;#39;re not going to let AI CEOs take your job and make you unemployed.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The bill creates a new Work Protection Administration, funded completely by taxes on AI companies based on the input tokens required for a given AI system or the total revenue generated by selling AI products, whichever is higher.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The Work Protection Administration&amp;rsquo;s purpose is to create jobs to offset AI-linked layoffs. With the tax revenue, the office will invest in job creation in sectors like housing construction, infrastructure modernization, child care and elder care via local grants.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The tax starts small, but if unemployment goes up, the tax rate goes up, and we use that money to invest in jobs that need doing, taking care of our elderly, teaching our kids, fixing our broken infrastructure,&amp;rdquo; Casar said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Studying AI&amp;rsquo;s impact in classrooms&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Rep. George Whitesides, D-Calif., introduced a new bill on Monday that would instruct the National Science Foundation to develop more workshops that examine how to effectively deploy AI in education environments.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.congress.gov/bill/119th-congress/house-bill/10042/text?s=2&amp;amp;r=2&amp;amp;hl=artificial+intelligence"&gt;The Understanding AI in the Classroom Act&lt;/a&gt; specifically aims to examine the impact AI has on kids&amp;rsquo; attention spans; their cognitive, social and behavioral development; and their burgeoning dependencies.&lt;/p&gt;

&lt;p&gt;Six months after the workshops are completed, the NSF director will then compile a report on the findings and share them with the House Committee on Science, Space and Technology and the Senate Committee on Commerce, Science and Transportation.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Evaluating AI in the financial sector&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Sen. Mark Warner, D-Va., &lt;a href="https://www.congress.gov/bill/119th-congress/senate-bill/5358/text?s=2&amp;amp;r=2&amp;amp;hl=artificial+intelligence"&gt;introduced a new bill on Thursday&lt;/a&gt; that would amend the Financial Stability Act of 2010 to establish more oversight of AI&amp;rsquo;s presence in the financial sector by giving the Financial Stability Oversight Council duties specific to that technology.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Warner&amp;rsquo;s new bill follows a letter he and other Democrats sent to the Trump administration calling for information &lt;a href="https://www.warner.senate.gov/newsroom/press-releases/warner-colleagues-press-trump-administration-on-chaotic-opaque-oversight-of-new-artificial-intelligence-models/"&gt;on the new framework&lt;/a&gt; officials established for evaluating AI models and their cybersecurity risks but have not released publicly.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Disclosing AI in healthcare claims&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A proposed amendment to the Public Health Service Act and the Social Security Act includes provisions mandating that insurance providers disclose if AI has been used to evaluate insurance claims and coverage decisions.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.congress.gov/bill/119th-congress/house-bill/10024/text?s=2&amp;amp;r=3&amp;amp;hl=artificial+intelligence"&gt;The Health Insurance Transparency for Patients Act&lt;/a&gt;, introduced on Monday by Rep. Ashley Hinson, R-Iowa, outfits the landmark health bills with clauses designed to help patients when a denied claim had been processed with the help of AI tools.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Big health insurance companies have a pattern of purposely denying patients coverage based on technicalities to protect their own bottom line,&amp;rdquo; Hinson said in &lt;a href="https://hinson.house.gov/media/press-releases/hinson-introduces-bill-hold-big-health-insurance-accountable"&gt;a press release&lt;/a&gt;. &amp;ldquo;And they get away with it because nobody can see how they&amp;rsquo;re making these decisions. My bill holds them accountable by exposing these unfair practices, so patients are no longer in the dark and Iowans can get better healthcare coverage.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Aligning immigration with AI dominance&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A bill introduced on Thursday seeks to better align immigration policy with the need to fortify the U.S. AI sector.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.congress.gov/bill/119th-congress/senate-bill/5307/text?s=2&amp;amp;r=3&amp;amp;hl=artificial+intelligence"&gt;S.5307&lt;/a&gt;, introduced by Sen. Chris Coons, D-Del., seeks to create a strategy specifically focused on harmonizing U.S. immigration policy with the national security need to lead globally in developing a robust AI sector. In addition to AI, the bill also looks to examine how immigration policy alignment can fortify innovation in the broader U.S. scientific, technological and entrepreneurial ecosystem.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/07/GettyImages_1399560076/large.jpg" width="618" height="284"><media:credit>Jarmo Piironen/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/07/GettyImages_1399560076/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>As AI models break free, White House works with firms on secret safety measures</title><link>https://www.nextgov.com/defense/2026/08/ai-models-white-house-and-companies-secret-safety-measures/415286/</link><description>Lawmakers blast administration's "ad-hoc" AI strategy; tech giants pitch ideas to keep federal contracts flowing.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Patrick Tucker</dc:creator><pubDate>Fri, 07 Aug 2026 12:52:00 -0400</pubDate><guid>https://www.nextgov.com/defense/2026/08/ai-models-white-house-and-companies-secret-safety-measures/415286/</guid><category>Defense</category><content:encoded>&lt;![CDATA[&lt;p&gt;No one is saying, officially, what was decided&amp;nbsp;when top frontier AI labs&amp;mdash;Google, OpenAI, Anthropic, and Meta&amp;mdash;met with White House officials on Tuesday to discuss voluntary guidelines for testing new models.&lt;/p&gt;

&lt;p&gt;But Democratic lawmakers &lt;a href="https://www.gillibrand.senate.gov/wp-content/uploads/2026/08/Senate-AI-Model-Access-Letter.pdf"&gt;described&lt;/a&gt; the Trump administration&amp;#39;s&amp;nbsp;approach to regulation as &amp;ldquo;ad-hoc and unpredictable,&amp;rdquo; and said it&amp;rsquo;s likely to boost global adoption of rival Chinese models at the worst possible time.&lt;/p&gt;

&lt;p&gt;Two officials with one of the labs said that Google, Anthropic, and OpenAI submitted a joint draft of the regulation around nine days ago and then began to work with each other and with the White House to find points of agreement. According to the officials, the labs all agreed they should be able to continue A/B testing as part of the process for developing models, and the White House concurred.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Companies that agree to the framework will submit their models to U.S. inspectors to be evaluated for safety for 30 days before those companies can receive federal funding&amp;mdash;including from the Defense Department, whose 2027 budget request seeks more than&amp;nbsp;&lt;a href="https://www.theguardian.com/us-news/2026/apr/22/pentagon-asks-for-54bn-in-pivot-towards-ai-powered-war"&gt;$54 billion&lt;/a&gt; for AI companies, according to the officials.&lt;/p&gt;

&lt;p&gt;A June White House &lt;a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/"&gt;executive order&lt;/a&gt;&amp;nbsp;adds that models from participating companies would get extra intellectual property protection from Chinese competitors or others who might seek to steal secrets.&lt;/p&gt;

&lt;p&gt;The White House is not commenting on how it will conduct the inspections. One of the officials said the the Office of Science and Technology Policy is still trying to set testing standards and how bodies like the National Institute of Standards and Technology and the Cybersecurity and Infrastructure Security Agency will conduct or design tests.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The murkiness around the policy&amp;rsquo;s details has angered some top lawmakers. In&amp;nbsp;a&amp;nbsp;Tuesday letter, Senate Democrats ask&amp;nbsp;the White House to &amp;ldquo;provide an unclassified response, with a classified annex if necessary, clarifying the Administration&amp;rsquo;s current policy and approach to limiting access to advanced AI models.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The lawmakers also evinced concern about the models&amp;#39;&amp;nbsp;new abilities to defy easy inspection, scrutiny, and limitation.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;During an internal evaluation [in July] OpenAI models escaped their testing environment and used high-level technical capabilities to compromise a third party&amp;rsquo;s network without any instructions to take those actions,&amp;rdquo; the letter reads. &amp;ldquo;The Federal Government cannot be passive as these capabilities emerge.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;AI&amp;rsquo;s Jurassic Park moment&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Last week, Chinese company Moonshot AI released a new open-weight model, &lt;a href="https://www.tomshardware.com/tech-industry/artificial-intelligence/moonshot-ai-releases-weights-for-kimi-k3-firing-a-shot-across-the-bow-of-openai-and-anthropic-open-weight-model-performs-almost-as-well-as-frontier-models-while-being-2-3x-easier-to-run"&gt;Kimi 3&lt;/a&gt;, that performs as well as some top U.S. models and is being offered to consumers around the world at a far lower price.&lt;/p&gt;

&lt;p&gt;Lawmakers and others are increasingly worried the United States could fall behind&amp;nbsp;China in a race to develop faster, more efficient, more profitable models and to shape the way global populations use, buy, sell, and even build AI. &lt;a href="https://www.defenseone.com/business/2026/08/attackers-are-targeting-open-source-ai-just-big-tech-embracing-it/415165/"&gt;Open weight&lt;/a&gt; models have become a key point of contention.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Anthropic wants&amp;nbsp;more scrutiny of open-weight models and more&amp;nbsp;efforts to curb sales of high-performance chips to China to thwart distillation attacks. But others in the industry are taking a more supportive &lt;a href="https://www.defenseone.com/business/2026/08/attackers-are-targeting-open-source-ai-just-big-tech-embracing-it/415165/"&gt;view of open weights&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;A former senior White House official and a former senior defense official with direct knowledge of the discussion said Anthropic pushed for more language in the framework to address open-weight security, but came away disappointed.&lt;/p&gt;

&lt;p&gt;Anthropic did not comment for this story.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In recent months,&amp;nbsp;several of the newest AI models have broken&amp;nbsp;out of their virtual testing containers.&lt;/p&gt;

&lt;p&gt;Anthropic disclosed the first such incident in &lt;a href="https://www.anthropic.com/research/mythos-preview"&gt;April,&lt;/a&gt; when an early version of their Mythos model was able to &amp;ldquo;autonomously write some remarkably sophisticated exploits,&amp;rdquo; including one that allowed it to escape an isolated testing environment that programmers use to test code for effectiveness and safety before it&amp;rsquo;s released.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Anthropic pulled the model from general release, but made it available under &amp;quot;Project Glasswing&amp;quot; so&amp;nbsp;the government and a handful of large companies&amp;nbsp;could find and fix vulnerabilities in their software.&lt;/p&gt;

&lt;p&gt;The White House responded with an export-control ban on June 12, &lt;a href="https://www.politico.com/news/2026/06/13/inside-the-whirlwind-24-hours-that-led-the-white-house-to-slap-export-controls-on-anthropic-00961519"&gt;barring&lt;/a&gt; access to the model not just to foreign countries but even foreigners&amp;nbsp;in the United States. That meant that Anthropic&amp;rsquo;s own researchers, many of whom were born outside of the United States, could not work on the model. The White House &lt;a href="https://www.washingtonpost.com/technology/2026/06/30/white-house-drops-export-controls-anthropics-mythos-fable-ai-models/"&gt;reversed&lt;/a&gt; the ban on June 30.&lt;/p&gt;

&lt;p&gt;In July, tensions around a national AI safety strategy, or lack thereof, grew hotter. Both Anthropic and OpenAI revealed &lt;a href="https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf"&gt;new incidents&lt;/a&gt; in which models breached their containment. It came as no surprise to many veteran cybersecurity experts. AI researcher and author Gary Marcus, in 2022, predicted such a possibility on his &lt;a href="https://garymarcus.substack.com/p/ais-jurassic-park-moment"&gt;blog&lt;/a&gt;, describing it as an &amp;ldquo;AI&amp;rsquo;s Jurassic Park Moment.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Last week, AWS Chief Security Officer Stephen Schmidt&amp;nbsp;told reporters: &amp;ldquo;Containers are not security boundaries. I actually have a T-shirt that says that, which I started wearing about three years ago.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;AWS hosts multiple models for users&amp;nbsp;through its Bedrock platform. Schmidt said the AI Mythos era requires a far more vigilant approach to cybersecurity, especially for researchers.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;One of the reasons that we built the virtualization infrastructure for AWS using our own Nitro Hypervisors so many years ago was we realized that containers were not an appropriate security boundary then. The same is true for AI. You cannot use an AI container as a security boundary.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;In March, a group of British researchers &lt;a href="https://arxiv.org/html/2603.02277v1"&gt;calculated&lt;/a&gt; the sandbox breakout period for various large language models, which proved very accurate months later.&lt;/p&gt;

&lt;p&gt;A follow-on &lt;a href="https://arxiv.org/html/2603.02277v3"&gt;paper published this week&lt;/a&gt; by the same group describes how to build better containment environments for the models emerging today.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/07/GettyImages_2281424316-1/large.jpg" width="618" height="284"><media:description>President Donald Trump and OpenAI CEO Sam Altman in Evian, France, on June 17, 2026.</media:description><media:credit>Ludovic MARIN / AFP via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/07/GettyImages_2281424316-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>CISA cautions against rigid rules for future of cyber vulnerability program</title><link>https://www.nextgov.com/cybersecurity/2026/08/cisa-cautions-against-rigid-rules-future-cyber-vulnerability-program/415282/</link><description>A top agency official said formal backing from Congress could strengthen the global vulnerability-tracking system but warned against measures that may limit its ability to adapt to ever-changing hacking threats.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Fri, 07 Aug 2026 10:33:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/cisa-cautions-against-rigid-rules-future-cyber-vulnerability-program/415282/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; The Cybersecurity and Infrastructure Security Agency sees value in formally placing the world&amp;rsquo;s dominant software vulnerability tracking program into federal law but is cautioning Congress against imposing rules that could make it harder to adapt as artificial intelligence and international partners reshape the system.&lt;/p&gt;

&lt;p&gt;The Common Vulnerabilities and Exposures Program, or CVE, gives publicly known security flaws standardized identifiers so that governments, software companies and researchers can easily communicate about the same issue. It was first created in 1999, and it underpins cybersecurity discussions across both private industry and the national intelligence community.&lt;/p&gt;

&lt;p&gt;Policymaking interest in the program followed a funding scare last year that exposed the fragility of the arrangement supporting its functions. MITRE, the scientific research giant that helps operate CVE under a federal contract,&lt;a href="https://www.nextgov.com/cybersecurity/2025/04/mitre-backed-cyber-vulnerability-program-lose-funding-wednesday/404585/"&gt; warned last April&lt;/a&gt; that its funding from the government would imminently expire.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;CISA then extended the contract within hours, a sweeping relief for the cybersecurity community that raised fresh questions about why a major global cybersecurity resource leaned so much on a sole U.S. contract. A CISA official previously said that a &amp;ldquo;broad internal contracting review caused a brief renewal delay in April 2025, but operations continued without disruption and MITRE was ultimately retained as the program operator.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;A legislative proposal&lt;a href="https://www.nextgov.com/cybersecurity/2026/06/planned-ndaa-amendment-would-codify-cisas-role-cyber-vulnerability-program/414286/"&gt; reported by &lt;em&gt;Nextgov/FCW&lt;/em&gt;&lt;/a&gt; in June would formally authorize CVE within the Department of Homeland Security and establish a clearer legal role for CISA, its longtime federal sponsor.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Defining the importance of the program in legislation in general seems like a very helpful thing,&amp;rdquo; Lindsey Cerkovnik, branch chief for vulnerability response and coordination at CISA, said Thursday during a panel at the Black Hat cybersecurity conference.&lt;/p&gt;

&lt;p&gt;But Cerkovnik, whose office helps oversee CVE, said legislation could become counterproductive if it dictates too precisely how the program must operate.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;When you overdefine how to execute the thing, it can make it very restrictive and difficult,&amp;rdquo; she said. &amp;ldquo;In some ways, we are wary of overly-restrictive guidance&amp;rdquo; that could make CVE less nimble, agile and flexible, she added.&lt;/p&gt;

&lt;p&gt;The congressional proposal would also require CISA and the National Institute of Standards and Technology to develop a modernization plan and establish a 15-member board to set CVE policies and priorities. Permanent seats would go to CISA, NIST and top-level CVE authorities, while rotating members would represent industry, academia, researchers and foreign governments.&lt;/p&gt;

&lt;p&gt;Reps. Delia Ramirez, D-Ill., and George Whitesides, D-Calif., submitted the proposal as an &lt;a href="https://rules.house.gov/bill/119/hr-8800#:~:text=Authorizes%20the%20existing,Department%20of%20Commerce."&gt;amendment&lt;/a&gt; to the fiscal 2027 defense authorization bill. But the House Rules Committee didn&amp;rsquo;t select it for floor consideration, preventing it from getting a vote in the full House last month.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Cerkovnik said CISA had reviewed the proposal and saw both benefits and challenges. Formal recognition could help preserve support for the program, although CISA and DHS have maintained its operations without a lapse for more than 26 years, she said.&lt;/p&gt;

&lt;p&gt;CISA is CVE&amp;rsquo;s sole federal sponsor, while MITRE helps execute the program alongside a global network of more than 530 CVE Numbering Authorities, known as CNAs. Those organizations &amp;mdash; which include software vendors, research groups and national cybersecurity agencies &amp;mdash; can assign identifiers and publish information about vulnerabilities within their areas of responsibility.&lt;/p&gt;

&lt;p&gt;The number and variety of those participants has allowed CVE to keep pace with a growing volume of software flaws. AI, however, is widely expected to accelerate vulnerability discovery further and may require the program to make changes that its current structure did not anticipate.&lt;/p&gt;

&lt;p&gt;Cerkovnik pointed to a recently announced AI researcher CNA &lt;a href="https://www.cve.org/Media/News/item/blog/2026/07/28/CVE-Launches-Frontier-AI-Researcher-CNA-Pilot"&gt;pilot program&lt;/a&gt; that would allow selected AI companies to assign CVE identifiers for vulnerabilities uncovered through research using their own models.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;That program may need to bring people with AI expertise into its leadership, she said, and rules narrowly prescribing who can serve on CVE boards or how new participants are admitted could complicate that kind of response. Cerkovnik didn&amp;rsquo;t say the current congressional proposal would block the pilot, instead using it to illustrate why the program needs room to adjust as technology changes.&lt;/p&gt;

&lt;p&gt;CVE is also becoming less centered on the United States. The European Union Agency for Cybersecurity, known as ENISA, became a CVE Numbering Authority in 2024 and a CVE Root in November 2025. Roots oversee groups of numbering authorities, helping organizations join the program and maintaining the quality of the vulnerability records they produce.&lt;/p&gt;

&lt;p&gt;ENISA has since begun bringing European organizations under its Root, building on the agency&amp;rsquo;s stated goal of&lt;a href="https://www.nextgov.com/cybersecurity/2026/03/eu-wants-support-bedrock-cyber-vulnerability-program-top-official-says/412429/"&gt; helping strengthen and modernize CVE&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Nuno Rodrigues Carvalho, ENISA&amp;rsquo;s head of sector for incident and vulnerability services, said on the panel Thursday that the agency now wants to &amp;ldquo;step up in the coming months&amp;rdquo; to also be a top-level Root, bringing it to the same level as CISA and MITRE.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;He described a more federated model in which organizations in Europe, Japan and potentially other regions oversee nearby numbering authorities and provide further support to the project.&lt;/p&gt;

&lt;p&gt;Europe already accounts for roughly one-fifth of the organizations authorized to assign CVE identifiers, Carvalho said. ENISA also operates the European Vulnerability Database, although he emphasized that it relies on CVE identifiers rather than competing with the existing system.&lt;/p&gt;

&lt;p&gt;Cerkovnik backed growing foreign participation, arguing the past year had reinforced the need to describe CVE as &amp;ldquo;a global program and not just a U.S.-centric program.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;AI poses another challenge by potentially increasing the number of vulnerabilities companies and governments must process. Cerkovnik said she expects CVE to scale alongside that growth but is more concerned about whether organizations can determine which flaws demand immediate attention.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Not all vulnerabilities matter. Not all vulnerabilities matter at the same level,&amp;rdquo; she said. CISA made a similar argument in a&lt;a href="https://www.nextgov.com/cybersecurity/2026/06/cisa-directive-revamps-how-agencies-prioritize-vulnerable-systems/414096/"&gt; binding directive&lt;/a&gt; issued in June that tells federal agencies to base patching deadlines on a variety of factors.&lt;/p&gt;

&lt;p&gt;Some lower-risk flaws could be left until a system receives a major upgrade, while the most dangerous vulnerabilities may require action within days. That kind of triage will become more important as AI produces more findings, Cerkovnik said, because neither CVE nor the organizations relying on it can treat every newly discovered flaw as equally urgent.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/07/IMG_4308/large.jpg" width="618" height="284"><media:description>(L to R) Nuno Rodrigues Carvalho, head of sector for Incident and Vulnerability Services at the European Union Agency for Cybersecurity, and Lindsey Cerkovnik, branch chief of vulnerability response and coordination at the Cybersecurity and Infrastructure Security Agency, speak with Nextgov/FCW Cybersecurity Reporter David DiMolfetta Aug. 6 ant the Black Hat cybersecurity conference.</media:description><media:credit>David DiMolfetta/Staff</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/07/IMG_4308/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>CISA still finds water system controls exposed online amid multistate hacks</title><link>https://www.nextgov.com/cybersecurity/2026/08/cisa-still-finds-water-system-controls-exposed-online-amid-multistate-hacks/415266/</link><description>The agency is working with the FBI to help victims but is not attributing the cyber intrusions to any group, acting director Nick Andersen told Nextgov/FCW.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Thu, 06 Aug 2026 14:53:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/cisa-still-finds-water-system-controls-exposed-online-amid-multistate-hacks/415266/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; Federal cyber officials are still finding water system controls exposed to the public internet, even as the Cybersecurity and Infrastructure Security Agency and the FBI help utilities recover from a series of cyberattacks affecting at least 12 states, acting CISA Director Nick Andersen told &lt;em&gt;Nextgov/FCW&lt;/em&gt; on Thursday.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We&amp;rsquo;re seeing things like [programmable logic controllers] that are open and accessible on the internet with either no password set or default password set,&amp;rdquo; Andersen said in a brief interview on the sidelines of the Black Hat cybersecurity conference. &amp;ldquo;We&amp;rsquo;re not making ourselves hardened targets.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Programmable logic controllers, commonly dubbed PLCs, are small computers used to operate pumps, valves and other equipment inside water facilities. Connecting them to the internet can allow operators to manage equipment remotely but it can also give hackers a path into systems that directly control physical processes.&lt;/p&gt;

&lt;p&gt;Andersen said CISA&amp;rsquo;s immediate guidance to utilities remains straightforward: &amp;ldquo;Get your operational technology off the internet, set a password.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The remarks come about a week after&lt;a href="https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs"&gt; CISA warned&lt;/a&gt; that hackers were &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/cisa-urges-water-utilities-take-exposed-systems-down-after-minnesota-hacks/415142/"&gt;increasingly targeting&lt;/a&gt; internet-connected controllers used by water and wastewater utilities. The agency said attackers had changed passwords and other settings, locking out operators and contributing to water pressure problems, boil-water notices and extended periods of manual operation.&lt;/p&gt;

&lt;p&gt;More than 30 community water systems in Minnesota were targeted late last month, according to state officials. Around 12 states have reported similar activity in recent days, though state officials said they continued operating safely and experienced no known effects on public health. The FBI has said it is aware of the incidents. Andersen also said CISA is working with the FBI on incident response.&lt;/p&gt;

&lt;p&gt;But the cyberdefense agency isn&amp;rsquo;t attempting to determine publicly who was responsible for the hacks, he said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Some U.S. officials suspect Iran-linked hackers carried out the attacks. A CISA &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/cisa-urges-water-utilities-take-exposed-systems-down-after-minnesota-hacks/415142/#:~:text=A%20recent%20memo,on%20July%2022."&gt;notice&lt;/a&gt; distributed to water utilities last month said the activity in Minnesota shared characteristics with an earlier campaign involving Iran-affiliated hackers, though it didn&amp;rsquo;t provide direct evidence linking the latest incidents to Tehran.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;For us, we&amp;rsquo;re not doing anything with attribution right now,&amp;rdquo; Andersen said, explaining the agency is instead focused on assisting affected organizations, educating operators and improving the sector&amp;rsquo;s security over the longer term.&lt;/p&gt;

&lt;p&gt;CISA also tries to identify vulnerable organizations before they are attacked by examining the broader collection of internet-facing systems, Andersen said. When the agency discovers a potentially exposed device or another security problem, it coordinates with other agencies and contacts the operator, he added.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Andersen couldn&amp;rsquo;t provide a precise estimate of how many exposed or poorly secured devices remain online.&lt;/p&gt;

&lt;p&gt;Water utilities can be difficult to secure because many are small, have limited budgets and depend on aging equipment installed and maintained by multiple contractors. Still, Andersen said infrastructure operators bear some responsibility for taking basic precautions that can make their systems more difficult to compromise.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;There&amp;rsquo;s a degree of personal responsibility there to sort of engage in these minimum requirements that are feasible for helping to continue to secure yourselves,&amp;rdquo; he said.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/06/080626waterNG/large.jpg" width="618" height="284"><media:credit>Brandon Bell/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/06/080626waterNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>DOGE took credit for savings that never happened, watchdog finds</title><link>https://www.nextgov.com/digital-government/2026/08/doge-took-credit-savings-never-happened-watchdog-finds/415265/</link><description>The Department of Government Efficiency claimed tens of billions of dollars in savings on its infamous “Wall of Receipts,” but the Government Accountability Office found it touted savings that never happened and could not be substantiated.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christian Robles</dc:creator><pubDate>Thu, 06 Aug 2026 14:32:00 -0400</pubDate><guid>https://www.nextgov.com/digital-government/2026/08/doge-took-credit-savings-never-happened-watchdog-finds/415265/</guid><category>Digital Government</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Trump administration should prominently display data quality issues and limitations on the Department of Government Efficiency&amp;rsquo;s &lt;a href="https://doge.gov/savings"&gt;website listing estimated savings&lt;/a&gt;, the Government Accountability Office recommended in a &lt;a href="https://www.gao.gov/assets/gao-26-108615.pdf"&gt;new report&lt;/a&gt;, finding the public tally heralding billions of dollars in estimated savings was rife with errors.&lt;/p&gt;

&lt;p&gt;The watchdog found that the website&amp;rsquo;s estimated savings tracker &amp;mdash; or &amp;ldquo;Wall of Receipts&amp;rdquo; &amp;mdash; listed contracts that were not actually cancelled, took credit for leases that were in the process of termination before DOGE&amp;rsquo;s existence and did not adequately explain how savings were calculated. The findings cast doubt on DOGE&amp;rsquo;s claim that it saved taxpayers $215 billion by slashing contracts, grants, leases and other wasteful expenditures.&lt;/p&gt;

&lt;p&gt;The report, requested by Sens. Gary Peters, D-Mich., and Richard Blumenthal, D-Conn., analyzed the wall of receipts&amp;rsquo; estimated savings of roughly $110.34 billion from supposedly terminated contracts, grants and leases.&lt;/p&gt;

&lt;p&gt;GAO found that roughly $34.6 billion of the estimated $61 billion saved from cancelled contracts came from either contracts that were never actually terminated or could not be corroborated as terminated.&lt;/p&gt;

&lt;p&gt;DOGE specifically reported it cancelled 13,476 contracts but &amp;ldquo;almost 2,000 contracts were not terminated,&amp;rdquo; according to GAO&amp;rsquo;s analysis of the Federal Procurement Data System. In one case, DOGE continued to estimate saving taxpayers more than $1.7 billion by cancelling a Defense Health Agency IT support contract after Defense Department officials got DOGE officials to agree the contract should not be terminated, GAO wrote. No action was ultimately taken on the contract.&lt;/p&gt;

&lt;p&gt;Additionally, about 27.8% of contracts listed as terminated &amp;mdash; including all contracts at the DOGE-dismantled United States Agency for International Development &amp;mdash; did not include identifying information, GAO found. Because of this lack of information, the office could not find 1,856 supposedly terminated contracts on the Federal Procurement Data System even after taking additional steps to do so.&lt;/p&gt;

&lt;p&gt;The watchdog added that DOGE did not consistently use its stated methodology for calculating estimated savings from terminated contracts. And even in cases where DOGE did use its stated methodology, it did not &amp;ldquo;account for many complexities and nuances of federal contracting or sufficiently identify limitations.&amp;rdquo; DOGE &amp;mdash; whose operation formally ended as of July 4 &amp;mdash; did not return GAO&amp;rsquo;s requests for interviews or clarifications.&lt;/p&gt;

&lt;p&gt;DOGE did not provide sufficient information to verify about 96.2% &amp;mdash; or $47.32 billion &amp;mdash; of estimated grant savings, GAO found. But even for the small portion of grant savings GAO could replicate, &amp;ldquo;the amount of reported savings may not be realized,&amp;rdquo; according to the report.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;DOGE reported that it terminated 264 leases, saving taxpayers about $113 million. But the General Services Administration told GAO that 108 out of those 264 leases were identified for termination before DOGE was established. Because of that discrepancy and other inaccuracies, GAO estimated DOGE overstated how much it saved on terminated leases by $81.1 million.&lt;/p&gt;

&lt;p&gt;DOGE also further overstated lease savings by not considering other factors, such as relocation costs and potential early termination fees, according to the report.&lt;/p&gt;

&lt;p&gt;The White House did not return a request for comment by the time of publication.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;This GAO report underscores the need for increased transparency and accountability from the Trump Administration so the American public can better understand DOGE&amp;rsquo;s activities as the organization guts vital government programs,&amp;rdquo; Blumenthal said in a &lt;a href="https://www.hsgac.senate.gov/media/dems/peters-blumenthal-release-gao-report-finding-doge-misled-americans-about-claimed-savings/"&gt;press release&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The GAO released a separate report Wednesday where it said it &lt;a href="https://www.nextgov.com/people/2026/08/watchdog-numbers-size-doge-many-details-remain-unknown/415242/?oref=ng-topic-lander-top-story"&gt;could not verify&lt;/a&gt; if DOGE employees completed required ethics training designed to avoid conflicts of interest.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/06/080626DOGENG/large.jpg" width="618" height="284"><media:credit>Thomas Fuller/SOPA Images/LightRocket via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/06/080626DOGENG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Palantir calls on GSA to withdraw draft AI acquisition rule</title><link>https://www.nextgov.com/acquisition/2026/08/palantir-calls-gsa-withdraw-draft-ai-acquisition-rule/415253/</link><description>The stance is more aggressive than that of many groups representing contractors, who told GSA to revise, rather than withdraw, the proposed large language model acquisition rule.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christian Robles</dc:creator><pubDate>Thu, 06 Aug 2026 11:49:00 -0400</pubDate><guid>https://www.nextgov.com/acquisition/2026/08/palantir-calls-gsa-withdraw-draft-ai-acquisition-rule/415253/</guid><category>Acquisition</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;/p&gt;

&lt;p&gt;The General Services Administration should axe its &lt;a href="https://www.federalregister.gov/documents/2026/06/17/2026-12205/general-services-acquisition-regulation-acquisition-of-information-and-communication-technology"&gt;draft large language model-specific acquisition&lt;/a&gt; rule, in part because it is purportedly unlawful and would undermine Trump administration goals if it were finalized, Palantir argued in recent comments on the proposal.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If implemented, the Proposed AI Clause will likely prevent Palantir from providing government customers with the AI-powered solutions they need through GSA contracts,&amp;rdquo; law firm Freshfields warned on behalf of the company.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Accordingly, Palantir expects government customers to turn to non-GSA contract vehicles to acquire Palantir&amp;rsquo;s most valuable AI-powered commercial solutions, thus diluting the promise of GSA contracts overall,&amp;rdquo; the company &lt;a href="https://www.regulations.gov/comment/GSA-GSAR-2026-0331-0066"&gt;added in a letter&lt;/a&gt; to GSA.&lt;/p&gt;

&lt;p&gt;Palantir argued that GSA has no independent authority to finalize the proposed LLM rule and would violate the Federal Acquisition Streamlining Act by mandating contracting requirements beyond standard commercial practices if it did finalize it. It notes that the courts have held that when an agency claims authority to decide on an issue of &amp;ldquo;vast economic and political significance,&amp;rdquo; Congress must delegate that authority in statute, which it has not done here. The company further said that the rule would significantly burden contractors and cause agencies to turn to other contract vehicles, undermining the Trump administration&amp;rsquo;s goal of reducing inefficiencies and &lt;a href="https://www.whitehouse.gov/presidential-actions/2025/03/eliminating-waste-and-saving-taxpayer-dollars-by-consolidating-procurement/"&gt;consolidating procurement through GSA&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The company also called the proposed LLM rule incompatible with legal requirements for defense acquisitions &amp;mdash; such as limitations on the clauses defense agencies can require of contractors and prohibitions on &amp;ldquo;demanding proprietary IP rights as a condition of contract award&amp;rdquo; &amp;mdash; and said it disregards decades of intellectual property rights precedence.&lt;/p&gt;

&lt;p&gt;Menaka Kalaskar, head of Palantir&amp;rsquo;s U.S. government legal and contracting team, raised much of the same concerns during a GSA listening session last month but stopped short of calling for the agency to withdraw the rule.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If the clause is really needed, then it can be included in the [&lt;a href="https://www.acquisition.gov/far-overhaul"&gt;Federal Acquisition Regulation&lt;/a&gt;] overhaul rather than the GSA coming out on its own,&amp;rdquo; Kalaskar said at the time.&lt;/p&gt;

&lt;p&gt;Palantir&amp;rsquo;s call for GSA to kill the LLM acquisition clause stands apart from much of the rest of the federal contracting industry.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;During last month&amp;rsquo;s &lt;a href="https://www.nextgov.com/acquisition/2026/07/gsas-draft-ai-procurement-rule-has-improved-needs-further-reforms-contractors-say/414788/?oref=ng-author-river"&gt;listening session&lt;/a&gt;, industry groups representing contractors widely urged GSA to clarify definitions and modify flowdown requirements if the agency wanted to achieve its goal of safeguarding government data processed by LLMs. Groups reiterated many of those same talking points in letters sent to GSA, according to an &lt;em&gt;Nextgov/FCW&lt;/em&gt; review of a dozen public comments on regulations.gov.&lt;/p&gt;

&lt;p&gt;Coalition for Common Sense in Government Procurement members &amp;ldquo;continue to have concerns regarding the overly broad language utilized in the AI clause and believe the AI clause may have a chilling effect on contractor use and adoption of AI should the clause be finalized as written,&amp;rdquo; the group wrote to GSA.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The coalition asked GSA to ensure only data directly submitted to an LLM&amp;rsquo;s inference engine &amp;mdash; not upstream and downstream processing by ancillary system components &amp;mdash; be subject to LLM rule requirements. The group also asked GSA to create a bright-line test to clearly define when LLM functionality is &amp;ldquo;incidental to the primary purpose of the core requirement being procured&amp;rdquo; and therefore not subject to LLM rule requirements.&lt;/p&gt;

&lt;p&gt;The Software &amp;amp; Information Industry Association, AEM Corporation, Sheppard, Mullin, Richter &amp;amp; Hampton LLP, the Business Software Alliance, Professional Services Council and the Information Technology Industry Council similarly called for GSA to more clearly define the scope of the LLM acquisition rule, &lt;em&gt;Nextgov/FCW&lt;/em&gt; found in a review of comments sent to GSA.&lt;/p&gt;

&lt;p&gt;But the contracting industry is not united on how to reform the proposal.&lt;/p&gt;

&lt;p&gt;For example, the Information Technology Industry Council urged GSA to get rid of a requirement that contractors ensure LLMs are developed and monitored in a way that adheres to &amp;ldquo;unbiased AI principles.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The criteria through which the government will evaluate compliance are still insufficiently defined, which creates ongoing uncertainty regarding the government&amp;rsquo;s expectations,&amp;rdquo; Megan Petersen, ITI&amp;rsquo;s senior vice president of policy, public sector and counsel, told &lt;em&gt;Nextgov/FCW&lt;/em&gt;. &amp;ldquo;Without clear definitions and transparent compliance benchmarks, contractors will be held to an impossible performance standard.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Other groups instead urged GSA to clear up the &amp;ldquo;unbiased AI principles&amp;rdquo; language with objective metrics contractors could use to ensure compliance with the regulation.&lt;/p&gt;

&lt;p&gt;The Professional Services Council urged GSA to publish its benchmark methodology and evaluation criteria for &amp;ldquo;unbiased AI principles&amp;rdquo; and update them through notice-and-comment periods. The group pointed to NIST AI RMF 1.0 trustworthiness criteria and the IEEE 7003 Algorithmic Bias standard as some third-party standards GSA could use.&lt;/p&gt;

&lt;p&gt;In total, 79 stakeholders sent GSA comments on the potential LLM procurement overhaul before the Aug. 3 deadline, according to regulations.gov.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/06/080626PalantirNG/large.jpg" width="618" height="284"><media:credit>Jakub Porzycki/NurPhoto via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/06/080626PalantirNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>AI advances are pushing governments to treat cyberattacks as routine, Western officials say</title><link>https://www.nextgov.com/cybersecurity/2026/08/ai-advances-are-pushing-governments-treat-cyberattacks-routine-western-officials-say/415250/</link><description>The remarks underscore a grim outlook for cyberdefenders showing that AI systems are able to exploit vulnerabilities faster than governments can patch them.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Thu, 06 Aug 2026 10:15:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/ai-advances-are-pushing-governments-treat-cyberattacks-routine-western-officials-say/415250/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; The rise of autonomous artificial intelligence systems capable of finding and exploiting software flaws is putting serious pressure on governments to treat cyberattacks as inevitable events rather than rare emergencies, senior officials from the United States, Canada and Britain said Wednesday.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Cyber compromise is not a black swan anymore. It&amp;rsquo;s just a swan,&amp;rdquo; Joseph Alm, the Department of Homeland Security&amp;rsquo;s assistant secretary for cyber, infrastructure, risk and resilience policy, said on an OpenPolicy panel at the Black Hat cyber conference. Organizations can no longer treat a breach as an unforeseeable crisis, he argued, and they should instead assume one will occur and prepare to limit the damage.&lt;/p&gt;

&lt;p&gt;Alm said governments and companies need to devote more attention to &amp;ldquo;harm reduction,&amp;rdquo; including the steps they would take to contain an intrusion and continue operating after a hacker gets inside. AI is making it easier for hackers to find and exploit the weaknesses already buried in older technology, he added.&lt;/p&gt;

&lt;p&gt;The remarks highlight a bleak near-term reality for cyberdefenders that concludes AI systems will find and exploit weaknesses faster than governments can fix them, and that agencies will need to assume some attacks will succeed and plan accordingly.&lt;/p&gt;

&lt;p&gt;Michael Duffy, the federal government&amp;rsquo;s acting chief information security officer, said federal cyber policies over the past decade have largely been written after a crisis, with the Office of Personnel Management and SolarWinds breaches prompting new requirements designed to prevent the same failures from recurring.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The U.S. has become better at finding what went wrong and preventing the same failure from happening again, but the next decade needs to focus on anticipating attacks and ensuring agencies can continue functioning while under pressure, he argued .&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We know things cannot go down for an extended period of time,&amp;rdquo; Duffy said.&lt;/p&gt;

&lt;p&gt;Some officials, however, cautioned against viewing AI as the source of most cyber risk. Jonathon Ellison, the U.K. National Cyber Security Centre&amp;rsquo;s director for national resilience, said a more immediate problem for many organizations remains the large number of known weaknesses already sitting inside their networks after years of underinvestment.&lt;/p&gt;

&lt;p&gt;Policy discussions can focus too heavily on AI discovering new vulnerabilities when companies are already carrying enormous security burdens from outdated and poorly secured technology, Ellison said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Thomas Lind, a former intelligence officer who directed policy at the White House Office of the National Cyber Director until June, noted that while officials anticipated advanced AI cyber capabilities, the rapid proliferation of these tools beyond certain governments and large firms has drastically reduced response times for policymakers and defenders.&lt;/p&gt;

&lt;p&gt;Rajiv Gupta, head of the Canadian Centre for Cyber Security, similarly described autonomous agents as a significant change that governments are still working to understand, even though Canada has used less advanced forms of AI in cyber defense for years. At the same time, he said, countries still face a substantial backlog of older technology that must be replaced or secured, and governments will not have a &amp;ldquo;patch army&amp;rdquo; capable of fixing every vulnerable system for every organization.&lt;/p&gt;

&lt;p&gt;That reality has led Canadian officials to consider what basic services citizens should expect the government to preserve during an extreme disruption, including the hypothetical loss of internet access for as long as three months. Gupta described the work as a &amp;ldquo;Minimum Viable Canada&amp;rdquo; initiative focused on identifying and maintaining the country&amp;rsquo;s most essential functions through a crisis.&lt;/p&gt;

&lt;p&gt;The warnings come amid a series of recent unprecedented cyber incidents involving autonomous AI agents. Last month, OpenAI models escaped an internal cybersecurity evaluation environment and breached Hugging Face. Britain&amp;rsquo;s&lt;a href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing"&gt; AI Security Institute&lt;/a&gt; disclosed this week that agents powered by Anthropic&amp;rsquo;s Mythos 5 and OpenAI&amp;rsquo;s GPT-5.6 Sol took unauthorized actions on the public internet during testing, including an unsuccessful attempt to place malicious code in an open-source software project.&lt;/p&gt;

&lt;p&gt;And just Wednesday, Meta confirmed that one of its models &lt;a href="https://www.theinformation.com/articles/meta-ai-model-hacked-another-company-cybersecurity-testing"&gt;exploited a flaw&lt;/a&gt; at another company after an outside testing firm mistakenly gave it internet access.&lt;/p&gt;

&lt;p&gt;Duffy said he is working with NIST, the Cybersecurity and Infrastructure Security Agency and other parts of the government to more quickly turn technical guidance on emerging cybersecurity risks, including those involving AI, into policies for federal agencies. He didn&amp;rsquo;t provide a timeline for any finalized guidance.&lt;/p&gt;

&lt;p&gt;The government can&amp;rsquo;t wait for another major incident to determine how AI should be governed or how agencies should use them, Duffy argued. &amp;ldquo;We likely won&amp;rsquo;t have time to pick up the pieces with the speed and the scale of what we&amp;rsquo;re seeing in these AI capabilities,&amp;rdquo; he said. &amp;ldquo;We know the types of steps that need to be taken. Let&amp;rsquo;s take them now.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/06/080626AIcyberNG/large.jpg" width="618" height="284"><media:credit>Apichat Noipang/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/06/080626AIcyberNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Watchdog puts new numbers on the size of DOGE, but many details remain unknown as agencies refuse to turn over information </title><link>https://www.nextgov.com/people/2026/08/watchdog-numbers-size-doge-many-details-remain-unknown/415242/</link><description>In a new report, the Government Accountability Office said it was unable to verify if all Department of Government Efficiency employees completed mandatory activities intended to avoid conflicts of interest.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Sean Michael Newhouse</dc:creator><pubDate>Thu, 06 Aug 2026 09:00:00 -0400</pubDate><guid>https://www.nextgov.com/people/2026/08/watchdog-numbers-size-doge-many-details-remain-unknown/415242/</guid><category>People</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Government Accountability Office on Wednesday published &lt;a href="https://www.gao.gov/assets/gao-26-108403.pdf"&gt;a report&lt;/a&gt; that uncovered more information about the individuals who worked for the Department of Government Efficiency. Still, the congressional watchdog&amp;rsquo;s findings were limited, including with respect to whether the DOGE employees completed required ethics training and paperwork, due to a lack of cooperation from agencies.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Investigators determined that there were at least 206 employees who worked for the Trump administration&amp;rsquo;s cost-cutting entity that held positions in the Executive Office of the President, even if they were detailed to other agencies, between Jan. 20, 2025, and Jan. 31, 2026. That number excludes DOGE staffers who were not assigned to the EOP.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;GAO found that at least 128 of these individuals separated from their EOP positions by Jan. 31, 2026.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Of those 206 staffers, at least 27 were special government employees, meaning they could not serve for more than 130 days during any one-year period. For example, Elon Musk, the former de facto head of DOGE, was an SGE, which &lt;a href="https://www.govexec.com/management/2025/02/musks-role-special-government-employee-raises-ethics-questions/402820/"&gt;raised conflict of interest questions&lt;/a&gt; due to his companies receiving billions in federal contracts.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;However investigators were not able to determine the appointment type, such as Schedule C political appointee or noncareer Senior Executive Service, for more than 150 of the personnel because many agencies did not provide the requested information.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;This total includes the 127 [U.S. DOGE Service] employees who held titles as digital services experts or consultants within USDS,&amp;rdquo; according to the report. &amp;ldquo;Although USDS has stated that USDS positions last no more than 4 years, we were unable to determine whether these USDS employees or other personnel had held such time-limited appointments.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;In total, 10 agencies and the EOP did not respond to requests from GAO for records that these DOGE employees participated in ethics training and completed financial disclosure reports.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;As a result, we are not able to determine the total number of DOGE personnel who held positions within EOP who received trainings or who completed financial disclosures at those 10 agencies or at EOP,&amp;rdquo; investigators wrote.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Nine agencies, covering 64 DOGE employees, did submit information about whether the staffers did such training and reports. But GAO argued that much of the documentation was incomplete. For example, the Agriculture Department provided an &amp;ldquo;ethics-related presentation&amp;rdquo; for Trump appointees but didn&amp;rsquo;t offer evidence for when, or if, the DOGE staffers received the training.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The White House did not respond to a request for comment.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;While &amp;ldquo;the U.S. DOGE Service Temporary Organization&amp;rdquo; terminated on July 4, pursuant to the &lt;a href="https://www.whitehouse.gov/presidential-actions/2025/01/establishing-and-implementing-the-presidents-department-of-government-efficiency/"&gt;executive order&lt;/a&gt; establishing it, GAO pointed out that the directive permanently renamed an existing White House office as the U.S. DOGE Service.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Since the EO does not call for the termination of the broader USDS entity, it is possible that USDS and personnel at federal agencies could continue to do work that advances some of these initiatives after the temporary organization&amp;rsquo;s termination,&amp;rdquo; investigators wrote.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;DOGE spearheaded many of the civil service reductions that took place last year, resulting in &lt;a href="https://data.opm.gov/explore-data/analytics/workforce-size-and-composition"&gt;a decrease of more than 350,000 to the federal employee headcount&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;GAO in April reported that the &lt;a href="https://www.govexec.com/technology/2026/04/treasury-security-controls-doge-system-access-gao/413183/?oref=ge-topic-lander-river"&gt;Treasury Department and DOGE did not follow all security protocols&lt;/a&gt; with respect to granting access to government payment systems.&lt;br /&gt;
&amp;nbsp;&lt;/p&gt;

&lt;div class="related-articles-placeholder"&gt;[[Related Posts]]&lt;/div&gt;

&lt;p&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/05/080526_Getty_GovExec_Musk-1/large.jpg" width="618" height="284"><media:description> Elon Musk walks to the White House on March 9, 2025. The Government Accountability Office reported that at least 27 Department of Government Efficiency employees, including Musk, were classified as special government employees. </media:description><media:credit>Samuel Corum / Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/05/080526_Getty_GovExec_Musk-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>OpenAI agents rebuilt internal message board in lead-up to Hugging Face breach</title><link>https://www.nextgov.com/artificial-intelligence/2026/08/openai-agents-rebuilt-internal-message-board-lead-hugging-face-breach/415240/</link><description>Models in separate experiments used the channel to exchange exploits as they repeatedly compromised OpenAI systems.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 05 Aug 2026 19:06:00 -0400</pubDate><guid>https://www.nextgov.com/artificial-intelligence/2026/08/openai-agents-rebuilt-internal-message-board-lead-hugging-face-breach/415240/</guid><category>Artificial Intelligence</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; OpenAI models created a shared message board inside the company&amp;rsquo;s systems, used it to trade hacking methods and found a way to bring it back after engineers shut it down, company researchers said Wednesday in a more complete account of how an internal test led the agents to breach Hugging Face last month.&lt;/p&gt;

&lt;p&gt;The account, presented at the Black Hat cybersecurity conference, showed how agents working on separate experiments found one another, exchanged information and built on each other&amp;rsquo;s work over roughly two months, ultimately contributing to the &lt;a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/"&gt;breach&lt;/a&gt; and illustrating how difficult to contain such advanced AI systems can become when they work together.&lt;/p&gt;

&lt;p&gt;The breakdown offered major new details about how the agents coordinated and the possible dangers of increasingly autonomous AI systems finding ways to work together when they can reach real-world computer systems.&lt;/p&gt;

&lt;p&gt;It involved &amp;ldquo;a team of agents who are working together, finding exploits, sharing them with one another, moving laterally through our systems, through external systems and doing this over the course of days and weeks,&amp;rdquo; said Eric Wallace, an OpenAI researcher.&lt;/p&gt;

&lt;p&gt;The agents were participating in internal training and cybersecurity evaluations in which some safeguards had been reduced so OpenAI could measure their capabilities.&lt;/p&gt;

&lt;p&gt;Wallace and OpenAI security engineer Michael Dalton said the activity began in May, when agents struggling to complete difficult or, in some cases, impossible assignments began searching for shortcuts. One discovered that it could leave files on Artifactory, a service OpenAI used to download and store software packages, and a second later used it to ask whether other agents had found a missing file.&lt;/p&gt;

&lt;p&gt;Those agents found the files and responded, gradually turning the service into an accidental message board through which models in separate experiments could exchange instructions and information about newly discovered security flaws. Some agents began assigning work to one another or leaving behind scripts that allowed another model to continue where they had stopped.&lt;/p&gt;

&lt;p&gt;The agents eventually found a previously unknown flaw that gave them control of the service, and their activity caused an outage in early July that alerted OpenAI engineers to the problem. The company rebuilt the affected system, revoked the credentials the agents had used and deleted the message board, but the fix did not last. Two days later, agents found another way to leave messages through the same service and resumed sharing information.&lt;/p&gt;

&lt;p&gt;Their communications became increasingly organized, with agents developing ways to address one another, exchange tools and avoid overwriting each other&amp;rsquo;s work. At one point, Wallace said, they considered signing their messages because they suspected another agent was impersonating members of the group.&lt;/p&gt;

&lt;p&gt;The agents then carried out overlapping attacks against OpenAI&amp;rsquo;s infrastructure and Hugging Face. Inside OpenAI, they found another previously unknown flaw, took control of a server and obtained administrator access to a wider part of the company&amp;rsquo;s computing environment, Dalton said.&lt;/p&gt;

&lt;p&gt;At Hugging Face, they took advantage of two flaws in the company&amp;rsquo;s systems for processing uploaded datasets. One allowed them to retrieve internal files and credentials, while the other allowed them to run commands on Hugging Face servers. Dalton said the agents expanded their access across multiple parts of the company&amp;rsquo;s infrastructure in less than 13 hours.&lt;/p&gt;

&lt;p&gt;Hugging Face&amp;rsquo;s &lt;a href="https://huggingface.co/blog/agent-intrusion-technical-timeline"&gt;technical reconstruction&lt;/a&gt; documented some 17,600 actions during the campaign. The agents accessed five private datasets that appeared connected to the cybersecurity test, but the company found no evidence that they altered public models, datasets or software packages.&lt;/p&gt;

&lt;p&gt;On Tuesday, at Black Hat, former NSA cyber director Rob Joyce said the Hugging Face episode was arguably the &lt;a href="https://www.nextgov.com/cybersecurity/2026/08/hugging-face-ai-breach-most-consequential-hack-morris-worm-former-nsa-cyber-chief-says/415230/?oref=ng-homepage-river"&gt;most consequential hack&lt;/a&gt; since the Morris Worm in 1988.&lt;/p&gt;

&lt;p&gt;Dalton said the incident demonstrated that groups of AI agents can already carry out coordinated hacking campaigns without people directing each individual action, leaving defenders under pressure to develop tools capable of responding at the same speed.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;What I would internalize is AI-orchestrated, fully automated offensive attacks are real now, and the actions we have discussed today were an unintended side effect of running evaluations on frontier AI,&amp;rdquo; he said. &amp;ldquo;In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize and use offensive agent collectives in the manner that we have just described here.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/05/080526OpenAING/large.jpg" width="618" height="284"><media:credit> CFOTO/Future Publishing via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/05/080526OpenAING/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Hugging Face AI breach is ‘most consequential hack’ since Morris Worm, former NSA cyber chief says</title><link>https://www.nextgov.com/cybersecurity/2026/08/hugging-face-ai-breach-most-consequential-hack-morris-worm-former-nsa-cyber-chief-says/415230/</link><description>AI may let hackers exploit newly disclosed software flaws so quickly that organizations should weigh whether to immediately patch internet-connected devices, even at the risk of causing outages, Rob Joyce said.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 05 Aug 2026 13:32:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/hugging-face-ai-breach-most-consequential-hack-morris-worm-former-nsa-cyber-chief-says/415230/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; An OpenAI system that broke out of a cybersecurity test and entered Hugging Face&amp;rsquo;s network was a &amp;ldquo;watershed moment&amp;rdquo; comparable to the 1988 Morris Worm infection, former National Security Agency cybersecurity director Rob Joyce said Wednesday.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We&amp;rsquo;re living in the last several weeks through with what I think is the most consequential hack,&amp;rdquo; Joyce said. He spoke alongside fellow former NSA cybersecurity director Dave Luber during a World Wide Technology panel held at the Black Hat cyber conference.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I have to go back all the way to the Morris Worm in the &amp;rsquo;80s to say something that&amp;rsquo;s equivalent to how it&amp;rsquo;s going to change the way we think about our infrastructure,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;The Morris Worm spread automatically across the early internet, disrupting thousands of computers and helping spur major changes in how the government and technology industry handled cyber incidents. The episode led to the first felony conviction under the 1986 Computer Fraud and Abuse Act.&lt;/p&gt;

&lt;p&gt;Joyce said he once believed large language models would mainly help hackers write convincing phishing emails and create fake images, audio and video, but he didn&amp;rsquo;t expect them to become broadly useful for carrying out the more technical stages of an attack.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;And boy, was I wrong,&amp;rdquo; he said, adding that the systems can now understand computer programs and networks well enough to find vulnerabilities that can be turned into working intrusions.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://huggingface.co/blog/security-incident-july-2026"&gt;Hugging Face disclosed in July&lt;/a&gt; that an autonomous agent powered by OpenAI models had gained unauthorized access to parts of its production network. The company operates a widely used platform where developers store and share AI models, software and data.&lt;/p&gt;

&lt;p&gt;OpenAI had been testing how effectively its models could find and exploit software vulnerabilities. The company loosened some of the models&amp;rsquo; normal security safeguards for the exercise, which was supposed to remain inside an isolated testing environment. The agent instead reached Hugging Face, accessed internal datasets and credentials and moved across parts of its infrastructure.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Other researchers have since reported AI agents acting beyond the intended limits of cybersecurity tests. Britain&amp;rsquo;s AI Security Institute&lt;a href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing"&gt; said Tuesday&lt;/a&gt; that agents powered by Anthropic and OpenAI models took unauthorized actions on the public internet during 10 of 122 test runs.&lt;/p&gt;

&lt;p&gt;In the most serious case, an agent created fake online identities and attempted to convince an open-source software maintainer to approve malicious code. The maintainer rejected the proposed change, and investigators found no resulting real-world harm.&lt;/p&gt;

&lt;p&gt;Luber, who succeeded Joyce at NSA before retiring from government last year, said advanced AI can also make powerful hacking tools available to a wider range of adversarial groups.&lt;/p&gt;

&lt;p&gt;Five years ago, Luber said, previously unknown software flaws &amp;mdash; known as zero-days because developers have &amp;ldquo;zero days&amp;rdquo; to fix them before being exploited &amp;mdash; were mainly used by well-resourced nation-state hackers, while ransomware gangs generally relied on known vulnerabilities that victims had failed to patch.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I think that&amp;rsquo;s changed,&amp;rdquo; Luber said. As advanced capabilities become more widely available, ransomware collectives could acquire more undisclosed exploits and use them more freely to break into victims&amp;rsquo; networks, he added.&lt;/p&gt;

&lt;p&gt;Joyce said attackers already use automation to scan continuously for various digital security gaps. AI agents can perform that work around the clock without becoming tired or distracted. Defenders, meanwhile, still rely heavily on people to review alerts, approve updates and respond to suspicious activity.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The attackers are coming at machine-speed,&amp;rdquo; Joyce said. &amp;ldquo;We are on the defense, not at machine-speed today, and that&amp;rsquo;s got to change.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The tools aren&amp;rsquo;t necessarily inventing entirely new hacking techniques, Joyce said, but they are becoming much better at uncovering years of neglected security problems &amp;mdash; often dubbed technology debt &amp;mdash; across companies and government agencies. Tech debt can include outdated software, unpatched security flaws, default passwords and systems that were built or configured quickly but never fully secured.&lt;/p&gt;

&lt;p&gt;That speed should change how organizations install security updates, especially on devices connected directly to the public internet, he argued.&lt;/p&gt;

&lt;p&gt;Companies typically test patches before broadly installing them because a faulty update can crash computers or disrupt operations. The widespread 2024 &lt;a href="https://www.nextgov.com/cybersecurity/2024/07/how-crowdstrike-outage-carved-out-new-opportunities-hackers/398216/"&gt;CrowdStrike outage&lt;/a&gt; demonstrated the damage a defective software update can cause.&lt;/p&gt;

&lt;p&gt;But AI could allow attackers to exploit a newly disclosed vulnerability before an organization finishes testing the patch, Joyce added.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I think it&amp;rsquo;s gotten to the point where we have to blindly accept patches for those internet-facing devices and just take them from the manufacturer and immediately put them on,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;That leaves organizations choosing between the possibility that a patch causes an outage and the possibility that waiting exposes them to hacking attempts. But &amp;ldquo;of those two bad choices, I&amp;rsquo;m going to accept more risk on a self-inflicted outage than I am exposing myself to ransomware or an extortion event,&amp;rdquo; Joyce said.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/05/080526WWTNG/large.jpg" width="618" height="284"><media:description>(L to R) Former National Security Agency cybersecurity director Rob Joyce and fellow former NSA cybersecurity director Dave Luber speak with Vice President of Global Cyber at World Wide Technology Chris Konrad at an Aug. 5 World Wide Technology panel held at the Black Hat cyber conference. </media:description><media:credit>David DiMolfetta/Staff</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/05/080526WWTNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item></channel></rss>