<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:nb="https://www.newsbreak.com/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Nextgov/FCW - All Content</title><link>https://www.nextgov.com/</link><description>Federal technology and cybersecurity news and best practices.</description><atom:link href="https://www.nextgov.com/rss/all/" rel="self"></atom:link><language>en-us</language><lastBuildDate>Thu, 13 Aug 2026 16:25:09 -0400</lastBuildDate><item><title>OneGov savings balloon to over $1.6 B as agencies weigh future of AI in contracting</title><link>https://www.nextgov.com/acquisition/2026/08/onegov-savings-balloon-over-16-b-agencies-weigh-future-ai-contracting/415416/</link><description>The General Services Administration has already agreed to extend some OneGov deals and is working on brokering new ones, according to an official.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christian Robles</dc:creator><pubDate>Thu, 13 Aug 2026 16:25:09 -0400</pubDate><guid>https://www.nextgov.com/acquisition/2026/08/onegov-savings-balloon-over-16-b-agencies-weigh-future-ai-contracting/415416/</guid><category>Acquisition</category><content:encoded>&lt;![CDATA[&lt;p&gt;The OneGov program has saved the federal government about $1.62 billion &amp;mdash; including about $1.4 billion through limited-time discounts on artificial intelligence &amp;mdash; since its inception, a General Services Administration official said Thursday.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;That number may not capture the full impact because some agencies might have used the OneGov pricing to negotiate pricing on their own contracts outside of GSA&amp;rsquo;s [involvement],&amp;rdquo; Birgit Smeltzer, director of the agency&amp;rsquo;s Office of IT Products, said at the &lt;a href="https://govciomedia.com/federal-ai-forum/?utm_source=adwords&amp;amp;utm_medium=ppc&amp;amp;utm_campaign=23937808549&amp;amp;utm_term=federal%20ai%20forum&amp;amp;utm_term=federal%20ai%20forum&amp;amp;utm_campaign=EV-2026-08-13-Federal+AI+Forum+-+Search+(LL)&amp;amp;utm_source=adwords&amp;amp;utm_medium=ppc&amp;amp;utm_id=23937808549&amp;amp;hsa_acc=8714989174&amp;amp;hsa_cam=23937808549&amp;amp;hsa_grp=195203646417&amp;amp;hsa_ad=812538952488&amp;amp;hsa_src=g&amp;amp;hsa_tgt=kwd-2477792480339&amp;amp;hsa_kw=federal%20ai%20forum&amp;amp;hsa_mt=b&amp;amp;hsa_net=adwords&amp;amp;hsa_ver=3&amp;amp;gad_source=1&amp;amp;gad_campaignid=23937808549&amp;amp;gbraid=0AAAAADHFH73vQtFti58-s6oLjdsySjU06&amp;amp;gclid=CjwKCAjw1vXTBhB-EiwAEKr_kwSJUtmwuUsxM1xOpORerk_g4b8z_lbvQENymvS5E2wi9zk6hzqRdhoCFbwQAvD_BwE"&gt;GovCIO Federal AI Forum&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Indeed, the Centers for Medicare and Medicaid Services is &lt;a href="https://www.linkedin.com/posts/patrickinewbold_gsa-announces-onegov-agreement-with-amazon-activity-7490203140500258816-EdtU/"&gt;one example&lt;/a&gt; of an agency that has negotiated technology discounts beyond OneGov. But federal agencies only have limited time access to discounted software through the OneGov program.&lt;/p&gt;

&lt;p&gt;Smeltzer said some of the original equipment manufacturers have already agreed to extend the duration of their OneGov discounts or are working on forging new offers. She did not say which manufacturers have already promised to reup discounts or when GSA would announce them.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Some of the [original equipment manufacturers] have already agreed to extend some of the limited time offers, and some are looking at producing new offers for us,&amp;rdquo; she said.&lt;/p&gt;

&lt;p&gt;GSA officials previously said they want manufacturers to &lt;a href="https://www.nextgov.com/acquisition/2026/05/onegovs-discounted-deals-are-first-step-longer-term-contracts-officials-say/413684/"&gt;extend OneGov deals&lt;/a&gt; as they look to become direct contractors on the Multiple Award Schedule. Officials have also said they want the OneGov initiative to &lt;a href="https://www.nextgov.com/acquisition/2026/07/gsa-eyeing-onegov-savings-beyond-software-and-tech-official-says/414834/"&gt;extend beyond&lt;/a&gt; technology and software.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Smeltzer forecasted that even though OneGov prices &amp;ldquo;will eventually increase, the offers have already created significant value for agencies.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Leveraging the OneGov has been tremendous in order to really prove value,&amp;rdquo; said Geoffrey Sage, director of the enterprise services and analysis division within NASA&amp;rsquo;s Office of Procurement.&lt;/p&gt;

&lt;p&gt;OneGov is just one way agencies are thinking about AI and contracting.&lt;/p&gt;

&lt;p&gt;NASA has started to talk with industry about how it should use AI in contract evaluations, Sage also said at Thursday&amp;rsquo;s event. That specific application of AI has been a &amp;ldquo;thin red line&amp;rdquo; for the agency to date but it&amp;#39;s also a &amp;ldquo;necessity,&amp;rdquo; he added, while noting that NASA takes a risk-based approach in deciding to use AI.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We spend 85 percent of the agency&amp;#39;s budget through procurement,&amp;rdquo; Sage said. &amp;ldquo;We can&amp;#39;t afford AI to trip up and hamper our source evaluation process.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Federal use of AI to evaluate contracts has recently garnered scrutiny, with some contractors alleging agencies are misusing the technology and &lt;a href="https://www.nextgov.com/acquisition/2026/08/contractor-alleges-army-inappropriately-used-ai-make-450m-contract-award/415225/?oref=ng-skybox-hp"&gt;relying on hallucinations&lt;/a&gt; in their evaluations.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;NASA is also using AI to bring its number of contract writing systems down from three to one next year, Sage said.&lt;/p&gt;

&lt;p&gt;Federal officials should view industry as collaborators, Anil Chaudhry, senior AI advisor for the Transportation Department, also said at the event.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;As a government employee, you can no longer have a mindset that you&amp;#39;re competing with industry. You have to have that mindset that you&amp;#39;re collaborating with industry,&amp;rdquo; he added.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/13/GettyImages_2216861129/large.jpg" width="618" height="284"><media:credit>Douglas Rissing/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/13/GettyImages_2216861129/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>CISA just changed the rules. Is your vulnerability program ready?</title><link>https://www.nextgov.com/ideas/2026/08/cisa-just-changed-rules-your-vulnerability-program-ready/415413/</link><description>COMMENTARY | BOD 26-04 is a mandate about process. What it implies is a mandate about intelligence.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tim Miller</dc:creator><pubDate>Thu, 13 Aug 2026 16:08:00 -0400</pubDate><guid>https://www.nextgov.com/ideas/2026/08/cisa-just-changed-rules-your-vulnerability-program-ready/415413/</guid><category>Ideas</category><content:encoded>&lt;![CDATA[&lt;p&gt;The attacker is already inside. Not hypothetically &amp;ndash; statistically. &lt;a href="https://cloudsecurityalliance.org/press-releases/2026/06/02/over-80-of-organizations-that-miss-24-hour-patch-window-report-security-incidents-involving-known-vulnerabilities"&gt;Nearly half&lt;/a&gt; of organizations that experienced a production security incident last year were breached through a vulnerability their own team had already identified. They knew it was there. They just didn&amp;rsquo;t get to it in time.&lt;/p&gt;

&lt;p&gt;On June 10, CISA decided that &amp;ldquo;in time&amp;rdquo; now means three days. &lt;a href="https://www.cisa.gov/news-events/news/cisa-issues-new-directive-improving-how-federal-agencies-prioritize-mitigation-cyber-vulnerabilities"&gt;Binding Operational Directive 26-04: &lt;em&gt;Prioritizing Security Updates Based on Risk&lt;/em&gt;&lt;/a&gt; rewrites how federal agencies prioritize vulnerability remediation and for defense contractors watching closely, it&amp;rsquo;s a preview of what&amp;rsquo;s coming for them next.&lt;/p&gt;

&lt;p&gt;The directive does something deceptively simple. It tells agencies to stop treating every vulnerability as equally urgent. It establishes four criteria: whether an asset is publicly exposed; whether the vulnerability is actively exploited; whether exploitation can be automated; and whether exploitation yields full system control. It then ties remediation timelines to how many factors apply. A vulnerability that checks all four boxes must be patched within three days. Roughly 60% can be deferred entirely.&lt;/p&gt;

&lt;p&gt;The average organization takes 55 days to patch half its critical vulnerabilities. Three days is more than a tightening of standards. It is a different game entirely.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The gap this directive is trying to close&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;BOD 26-04 lands in a specific threat context. The mean time to exploit known vulnerabilities has dropped to an estimated seven days, and exploitation now routinely occurs before a patch is published. Threat actor alerts &lt;a href="https://resources.dataminr.com/resources/dataminr-2026-cyber-threat-landscape-report"&gt;increased 225%&lt;/a&gt; between 2024 and 2025. The fastest observed attacker breakout time from initial access to lateral movement is now &lt;a href="https://www.crowdstrike.com/en-us/global-threat-report/"&gt;27 seconds&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;What&amp;#39;s accelerating that window is AI. Most discussion about AI and cybersecurity focuses on zero-days, which are a real concern. But the more immediate problem is what AI does to known vulnerabilities that have been disclosed but remain unpatched. WannaCry arrived &lt;a href="https://red.anthropic.com/2026/n-days/"&gt;59 days&lt;/a&gt; after its patch. Citrix Bleed took two weeks. That window is collapsing. BOD 26-04&amp;#39;s deferral model is being issued into a threat environment where a vulnerability assessed as non-urgent today could have a working exploit by tomorrow.&lt;/p&gt;

&lt;p&gt;This is why the traditional model to scan, score, queue, and patch no longer works. CISA&amp;#39;s acting director Nick Andersen put it plainly: the agency has to be willing to say some systems are less important than others, and direct limited resources toward the risks that actually matter. A critical vulnerability is not always a critical risk. Without context, severity scores are noise. The right question is &amp;ldquo;which exposures matter to us right now, given what adversaries are actively doing?&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Detection is not the gap. Prioritization and speed are.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What the directive doesn&amp;rsquo;t solve&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;BOD 26-04 formally applies to federal civilian Executive Branch agencies, not contractors yet, but CISA&amp;#39;s own&lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk"&gt; Implementation Guidance&lt;/a&gt; directs agencies to ensure appropriate remediation timelines are part of service-level agreements or that service providers establish a contractual arrangement. Contracting officers will likely incorporate these requirements into Statements of Work as agencies act on that guidance. For defense industrial base contractors, CMMC sets the floor for what must be protected. BOD 26-04 is raising the ceiling on what operational readiness actually requires.&lt;/p&gt;

&lt;p&gt;There are also two structural limitations practitioners need to understand.&lt;/p&gt;

&lt;p&gt;The first is the deferral problem. Deferred is not the same as resolved. The 60% of vulnerabilities the directive allows agencies to defer don&amp;rsquo;t sit in a static threat environment; exploit timelines are compressing and actor groups pivot targeting constantly. A vulnerability assessed as low-urgency in June can be actively exploited by August. Defenders also need to account for vulnerability chaining: attackers frequently combine lower-severity vulnerabilities to gain a foothold, then escalate toward critical systems. A vulnerability that would never independently trigger the three-day clock can become a critical exposure when paired with one that opens a lateral movement path.&lt;/p&gt;

&lt;p&gt;The second is control posture drift. BOD 26-04&amp;#39;s first criterion &amp;ndash; whether a vulnerable asset is publicly exposed &amp;ndash; sounds like an inventory question. It is a continuous control validation problem. Exposure state changes constantly as firewall rules drift, cloud configurations shift, and new services are stood up. A vulnerability behind a compensating control can become a three-day priority the moment that control fails silently. Most programs won&amp;rsquo;t know until the next scan.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What compliance actually requires&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Consider the same vulnerability disclosure under two operating models.&lt;/p&gt;

&lt;p&gt;A defense agency cyber team receives intelligence that a known adversary group is discussing exploitation of a newly disclosed flaw in a widely used remote access tool. Under a traditional model, the alert joins a queue: CVSS score assigned, patch cycle pending. Under a continuous exposure model, the alert is correlated immediately with vulnerability footprint, current control effectiveness, and mission dependency. The team understands what the adversary can actually do given the controls in place right now, rather than the controls documented in the last assessment. Remediation begins before the KEV catalog is updated.&lt;/p&gt;

&lt;p&gt;A CMMC Level 2 subcontractor faces the same disclosure. A lean team, under a traditional model, lacks the context to know whether it&amp;#39;s relevant. Under a continuous exposure model, questions about whether this is in our environment, whether we are a target profile&amp;nbsp;and if adversaries are actively exploiting similar organizations have answers before anyone asks.&lt;/p&gt;

&lt;p&gt;The difference between a managed risk and a contract-jeopardizing incident is the time between alert and a contextualized picture of what it means.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The real ask&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;BOD 26-04 is a mandate about process. What it implies is a mandate about intelligence.&lt;/p&gt;

&lt;p&gt;CISA is right that prioritization is the real lever. The directive creates a risk-based framework where none existed and will force conversations that have been deferred for years. But it only holds if the intelligence running underneath it is continuous. The three-day clock requires knowing which systems match the exposure profile. The deferral model requires watching deferred vulnerabilities as the threat environment evolves. The control posture criteria require visibility that reflects what&amp;rsquo;s actually enforced now, rather than last quarter&amp;rsquo;s scan.&lt;/p&gt;

&lt;p&gt;That is the real ask of federal agencies today, and the defense industrial base shortly. CISA just put a deadline on it.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Tim Miller, Dataminr&amp;rsquo;s Global Field CTO and Chief Cybersecurity Strategist, has nearly two decades of experience helping public sector organizations adopt and leverage emerging technologies.&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/13/GettyImages_2229245475/large.jpg" width="618" height="284"><media:credit>Sarayut Thaneerat / Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/13/GettyImages_2229245475/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>GAO official suggests addressing AI risks through existing legislation</title><link>https://www.nextgov.com/policy/2026/08/gao-official-suggests-addressing-ai-risks-through-existing-legislation/415410/</link><description>Nick Marinos, the managing director of IT and cybersecurity issues at GAO, said leveraging existing avenues for cybersecurity information sharing can expedite getting AI safety policies into law.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alexandra Kelley</dc:creator><pubDate>Thu, 13 Aug 2026 15:09:00 -0400</pubDate><guid>https://www.nextgov.com/policy/2026/08/gao-official-suggests-addressing-ai-risks-through-existing-legislation/415410/</guid><category>Policy</category><content:encoded>&lt;![CDATA[&lt;p&gt;As Congress continues to wade through legislation focused on the various aspects of artificial intelligence, an official at the congressional watchdog &amp;mdash;&amp;nbsp;the Government Accountability Office &amp;mdash;&amp;nbsp;said lawmakers are going about AI safety the wrong way.&lt;/p&gt;

&lt;p&gt;Nick Marinos, GAO&amp;rsquo;s managing director of IT and cybersecurity issues, said the legislative approach to addressing newfound cybersecurity and other risks presented by advancing AI models is too reactive.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Speaking during a &lt;a href="https://govciomedia.com/federal-ai-forum/?utm_source=adwords&amp;amp;utm_medium=ppc&amp;amp;utm_campaign=23937808549&amp;amp;utm_term=federal%20ai%20forum&amp;amp;utm_term=federal%20ai%20forum&amp;amp;utm_campaign=EV-2026-08-13-Federal+AI+Forum+-+Search+(LL)&amp;amp;utm_source=adwords&amp;amp;utm_medium=ppc&amp;amp;utm_id=23937808549&amp;amp;hsa_acc=8714989174&amp;amp;hsa_cam=23937808549&amp;amp;hsa_grp=195203646417&amp;amp;hsa_ad=812538952488&amp;amp;hsa_src=g&amp;amp;hsa_tgt=kwd-2477792480339&amp;amp;hsa_kw=federal%20ai%20forum&amp;amp;hsa_mt=b&amp;amp;hsa_net=adwords&amp;amp;hsa_ver=3&amp;amp;gad_source=1&amp;amp;gad_campaignid=23937808549&amp;amp;gbraid=0AAAAADHFH73vQtFti58-s6oLjdsySjU06&amp;amp;gclid=CjwKCAjw1vXTBhB-EiwAEKr_kwSJUtmwuUsxM1xOpORerk_g4b8z_lbvQENymvS5E2wi9zk6hzqRdhoCFbwQAvD_BwE"&gt;GovCIO AI event&lt;/a&gt; on Thursday, Marinos said lawmakers need to go beyond thinking about cybersecurity risk mitigation policies and focus on eradicating them altogether.&lt;/p&gt;

&lt;p&gt;While he acknowledged that positive strides have been made in catching up with new technologies at the government level &amp;mdash; such as the creation of the Cybersecurity and Infrastructure Security Agency and the Office of the National Cyber Director &amp;mdash; Marinos said the government remains &amp;ldquo;behind the eight ball&amp;rdquo; in regulating AI-related threats.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If you look at a lot of the AI safety bills, think about the need for us to update key legislation,&amp;rdquo; Marinos said. &amp;ldquo;It&amp;#39;s really more about stepping away from thinking that we&amp;#39;re going to address all the vulnerabilities, but more so thinking about &amp;lsquo;how can we close the door as much as possible,&amp;rsquo; and then &amp;lsquo;how can we be very quick to respond and react when there is an incident&amp;rsquo; as well.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Some of the key legislation Marinos referred to included&amp;nbsp;the Cybersecurity Information Sharing Act of 2015. The law created a voluntary attack sharing mechanism between the government and private sector, provisions that are set to expire this coming September.&lt;/p&gt;

&lt;p&gt;The Senate &lt;a href="https://www.nextgov.com/policy/2026/08/senates-short-term-funding-bill-provides-temporary-extensions-tmf-cyber-data-sharing-law/415322/?oref=ng-author-river"&gt;approved&lt;/a&gt; a short-term funding measure on Aug. 8 that would extend the Cybersecurity Information Sharing Act until Dec. 11. The law temporarily expired during the 43-day government shutdown late last year, although Congress passed a funding package in February that extended the statute through Sept. 30.&lt;/p&gt;

&lt;p&gt;The original text of the Cybersecurity Information Sharing Act does not address AI. Marinos said that one starting point to more proactive AI safety legislation could look like an extension to the existing law that includes information sharing AI-specific attack data.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If it&amp;#39;s a given that a vulnerability is going to be found, how are we monitoring activity to prevent the most catastrophic consequence to it?&amp;rdquo; he said. &amp;ldquo;It&amp;#39;s going to take a full collaboration.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;GAO initially considered information security a &amp;ldquo;high-risk&amp;rdquo; area about 30 years ago, Marinos said, noting that even at the time the pace of technological innovation was moving at an exponentially faster rate than government guidance and action.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We&amp;#39;ve seen too often that if one part of critical infrastructure is being affected by something, it probably is being affected in other places,&amp;rdquo; he said. &amp;ldquo;If they&amp;#39;re not talking, or if the government isn&amp;#39;t trying to facilitate that communication, then as a nation, we&amp;#39;re not going to be well prepared to protect.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Industry experts agree with Marinos&amp;rsquo;s point. Cyber Threat Alliance CEO Michael Daniel said that AI-related cyber threats could be mitigated with updates to statues in a landmark bill like CISA 2015.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;While one could make an argument that existing CISA 2015 protections cover that type of information, Congress should update the definitions in the Act to clearly cover information about threats to AI systems,&amp;rdquo; Daniel told &lt;em&gt;Nextgov/FCW&lt;/em&gt;. &amp;ldquo;A single piece of legislation does not have to address every cybersecurity problem related to AI to be useful.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/13/GettyImages_1262381535/large.jpg" width="618" height="284"><media:credit>The Bold Bureau/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/13/GettyImages_1262381535/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Trump admin empowers private US firms to go after transnational cybercriminals</title><link>https://www.nextgov.com/cybersecurity/2026/08/trump-admin-gives-private-us-firms-ability-go-after-transnational-cybercriminals/415398/</link><description>“By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter [transnational criminal organizations’] threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” the memo said.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christian Robles</dc:creator><pubDate>Thu, 13 Aug 2026 12:40:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/trump-admin-gives-private-us-firms-ability-go-after-transnational-cybercriminals/415398/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The National Coordination Center will create a program allowing authorized U.S. companies to conduct cyber operations against transnational criminal organizations at the direction of the federal government, according to a &lt;a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/"&gt;memorandum&lt;/a&gt; signed by President Donald Trump on Wednesday.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Program executive directors from the departments of Homeland Security and Justice will have the authority to greenlight companies&amp;rsquo; cyber operations unless the authorization would result in a loss of life, serious injury or &amp;ldquo;rise to the level of use of forced or armed attack under international law.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The federal government would vet and conduct oversight of authorized companies, which would need to enter into contractual agreements with either DHS or Justice.&lt;/p&gt;

&lt;p&gt;The specific standards the government will use to screen the companies will be drafted by the program executive directors &amp;mdash; in coordination with the Homeland Security Council &amp;mdash; within 60 days of the memo&amp;rsquo;s signing. They will include technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence and reliability, according to the document.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The group will ensure that program participation criteria enable&amp;nbsp;involvement from large and small companies, and that operations target only transnational criminal organizations.&lt;/p&gt;

&lt;p&gt;The memo also allows participating companies to enter into commercial agreements with other private sector entities, federal agencies and state entities. The program executive directors will produce a report on the initiative&amp;rsquo;s status and submit it to the National Cyber Director and Assistant to the President and Deputy Chief of Staff for Policy and Homeland Security Advisor.&lt;/p&gt;

&lt;p&gt;The cybersecurity program seeks to build on a &lt;a href="https://www.whitehouse.gov/presidential-actions/2026/03/combating-cybercrime-fraud-and-predatory-schemes-against-american-citizens/"&gt;March executive order&lt;/a&gt; laying out steps to combat cybercrime. That order was released alongside a &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/trumps-new-cyber-strategy-details-more-offensive-response-cyber-threats/411963/"&gt;national security strategy&lt;/a&gt; that called for the government to more directly respond to adversarial threats and secure critical U.S. technologies.&lt;/p&gt;

&lt;p&gt;In a statement, Mike Centrella &amp;mdash; the head of public policy at SecurityScorecard &amp;mdash; said the document &amp;ldquo;represents an important shift in how the United States approaches cyber threats originating overseas.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Strengthening defenses remains critical, but the memorandum recognizes that addressing cybercrime also requires identifying and disrupting the infrastructure and networks that allow criminal organizations to operate,&amp;rdquo; he said, adding that the guidance &amp;ldquo;signals an evolution in public-private cybersecurity collaboration &amp;mdash; from primarily sharing information about threats toward combining government authorities with private-sector intelligence and capabilities to more actively disrupt them.&amp;quot;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/13/GettyImages_2289620789/large.jpg" width="618" height="284"><media:description>US President Donald Trump gives a thumbs up before boarding Air Force One en route back to Washington, DC, at Cleveland Hopkins International Airport in Cleveland, Ohio on August 11, 2026. </media:description><media:credit>Jim WATSON / AFP via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/13/GettyImages_2289620789/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>DARPA funds advancements in quantum networking</title><link>https://www.nextgov.com/emerging-tech/2026/08/darpa-funds-advancements-quantum-networking/415372/</link><description>The Defense Advanced Research Projects Agency entered into a contract with quantum networking company Qunnect to bolster technology to preserve quantum data in transit.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alexandra Kelley</dc:creator><pubDate>Thu, 13 Aug 2026 09:00:00 -0400</pubDate><guid>https://www.nextgov.com/emerging-tech/2026/08/darpa-funds-advancements-quantum-networking/415372/</guid><category>Emerging Tech</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Defense Advanced Research Projects Agency is exploring how to scale the reliable transmission of quantum data and pave the way for a viable quantum internet by giving networking networking company Qunnect an award to further deploy networks designed to handle qubit traffic.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Pursuant to the contract, Qunnect is granted new funding to further deploy its Carina quantum networking solution, the company announced on Thursday.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Qubits are naturally more fragile than classical bits, and transmitting them from one node to another has been a persistent problem in scaling a viable quantum network. Carina addresses several outstanding problems in safely transmitting quantum data by operating at room temperature, stabilizing environmental noise, maintaining entanglement during transmission and other engineering challenges.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Qunnect will specifically focus on refining Carina&amp;rsquo;s polarization compensation nodule, its internal system that helps reduce distortions in data transmission.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Quantum networking has mostly stayed in the lab for decades because entanglement can be lost as a result of environmental factors like heat, wind and other everyday fiber movement,&amp;rdquo; Noel Goddard, CEO of Qunnect, told &lt;em&gt;Nextgov/FCW&lt;/em&gt;. &amp;ldquo;Carina is the only commercial product built to cancel that noise out in real time, like noise-cancelling headphones for both buried and aerial fiber. This is one of the keys to Carina distributing entanglement over existing infrastructure instead of requiring purpose-built fiber or being limited to pristine lab environments.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;DARPA declined to comment on the award. Qunnect declined to disclose the exact amount of funding in the contract.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We made an early commitment to designing instruments that operate on the same infrastructure the world already uses,&amp;rdquo; Goddard said. &amp;ldquo;For the past five years, we focused on making quantum networking practical, and we&amp;rsquo;ve validated it through deployments in cities, and through partnerships with private industry and growing support from government agencies. We know that reliability is what will separate proof-of-concept demonstrations from useful networks that enable tomorrow&amp;rsquo;s applications.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Quantum networking has received more attention at the federal level recently as the quantum computing industry looks to reach new levels of maturity and successfully share data between fault-tolerant machines. In 2025, &lt;a href="https://www.nextgov.com/emerging-tech/2025/08/darpa-aims-interoperability-between-classic-and-quantum-communication/407520/"&gt;DARPA unveiled its QuANET initiative&lt;/a&gt;, which aims to marry components of classical and quantum systems together in a functioning hybrid network.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Goddard said that Qunnect&amp;rsquo;s award is a standalone Small Business Innovation Research award.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;President Donald Trump &lt;a href="https://www.nextgov.com/emerging-tech/2026/02/draft-quantum-order-tasks-many-agencies-reinvigorating-techs-development/411152/"&gt;released an executive order&lt;/a&gt; earlier this year focused on advancing quantum information sciences and technology research that specifically focuses on spurring the development of a distributed quantum computing network, tasking agencies including the Department of Energy, Department of Commerce, the National Science Foundation and NASAn to craft and submit five-year roadmaps documenting their efforts to expand quantum networking.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/12/GettyImages_2212663489/large.jpg" width="618" height="284"><media:credit>Eugene Mymrin/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/12/GettyImages_2212663489/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>OpenAI Foundation gives $100 million fund state AI implementation for public health</title><link>https://www.nextgov.com/emerging-tech/2026/08/openai-foundation-gives-100-million-fund-state-ai-implementation-public-health/415382/</link><description>The organization announced the launch of the Breakthroughs to Follow-Through Initiative, which will implement artificial intelligence tools in public health research work.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alexandra Kelley</dc:creator><pubDate>Thu, 13 Aug 2026 05:00:00 -0400</pubDate><guid>https://www.nextgov.com/emerging-tech/2026/08/openai-foundation-gives-100-million-fund-state-ai-implementation-public-health/415382/</guid><category>Emerging Tech</category><content:encoded>&lt;![CDATA[&lt;p&gt;OpenAI Foundation, the overarching nonprofit that governs OpenAI, has announced a new public health partnership with the Common Health Coalition to bring artificial intelligence tools to developing scientific breakthroughs for medical research across the country.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;OpenAI Foundation on Thursday announced its commitment of $100 million to the Breakthroughs to Follow-Through Initiative, a program where states and other local jurisdictions can accelerate medical treatment research deliveries for serious health conditions. Participating jurisdictions will be able to determine what types of AI tools, including generative AI, are needed for their individual projects.&lt;/p&gt;

&lt;p&gt;The B2F&amp;rsquo;s research funding will initially focus on hepatitis C treatment development. Local organizations and non-profits will be in charge of dispersing grant money &amp;mdash; first in states including Alabama, Illinois, Louisiana and Massachusetts. More state participants will be unveiled in the coming six months.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The organizations closest to society&amp;rsquo;s greatest challenges have the deepest understanding of what communities need, but not always the resources or technical expertise to harness the latest advances in AI,&amp;rdquo; Anna Makanju, Head of AI for Civil Society and Philanthropy at OpenAI Foundation, said in a press release. &amp;ldquo;We believe this initiative is a model for how AI can strengthen public and community health work and deliver tangible benefits to communities.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Makanju told &lt;em&gt;Nextgov/FCW&lt;/em&gt; that the foundation&amp;rsquo;s grants aren&amp;rsquo;t tied to one AI platform or system provider, granting participants flexibility in the tools they choose.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We want our partners to have the agency to decide which tools to use &amp;mdash; or what not to use &amp;mdash; and to choose what best fits their needs and the communities they serve,&amp;rdquo; she said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Dave Chokshi, the chair of the Common Health Coalition, echoed Makanju&amp;rsquo;s sentiment.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Jurisdictions will determine which tools are needed to help ensure existing medical breakthroughs actually reach the people who need them,&amp;rdquo; Chokshi told &lt;em&gt;Nextgov/FCW&lt;/em&gt;. &amp;ldquo;These tools range from identifying people overdue for screening or treatment, to outreach platforms for re-engaging patients, AI copilots that free up clinicians&amp;#39; time, navigation tools that keep patients on track through cure, and beyond, and are intended to support the human relationships at the center of care.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;In addition to offering access to advanced AI tools, Chokshi said that B2F will provide the infrastructure needed to facilitate the implementation and usage of AI tools, such as technical support to help shift from the pilot stage into deployment.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The current focus of B2F is to foster collaborative state-level partnerships, but Chokshi said they are open to participation from the federal government.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We remain very open to partnership and collaboration with the federal government as this work develops,&amp;rdquo; said Chokshi.&lt;/p&gt;

&lt;p&gt;A similar initiative was previously floated in congressional legislation. Rep. Michael McCaul, R-Texas, &lt;a href="https://www.nextgov.com/policy/2026/07/tech-bills-week-leveraging-ai-cancer-research-securing-chatbots-underage-users-and-more/414714/"&gt;introduced his bill&lt;/a&gt; on July 9, &amp;mdash; the Accelerating Innovation for Kids with Cancer Act &amp;mdash; to allocate more federal attention to leveraging AI to aid pediatric cancer research efforts.&amp;nbsp;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/12/GettyImages_2288600936/large.jpg" width="618" height="284"><media:credit>Thomas Fuller/SOPA Images/LightRocket via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/12/GettyImages_2288600936/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Pilotless Air Taxis Are Here. Your Daily Commute? Still Stuck on the Ground.</title><link>https://www.nextgov.com/emerging-tech/2026/08/pilotless-air-taxis-are-here-your-daily-commute-still-stuck-ground/415383/</link><description>If you actually want to buy a ticket on a pilotless flying taxi, China is the only place anyone claims you can.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Camille Tuutti</dc:creator><pubDate>Wed, 12 Aug 2026 18:06:00 -0400</pubDate><guid>https://www.nextgov.com/emerging-tech/2026/08/pilotless-air-taxis-are-here-your-daily-commute-still-stuck-ground/415383/</guid><category>Emerging Tech</category><content:encoded>&lt;![CDATA[&lt;p&gt;I&amp;#39;ve never had a driver&amp;#39;s license. I&amp;#39;ve been waiting for the flying car since I watched &amp;quot;The Jetsons&amp;quot; as a kid. Forty years later, pilotless air taxis are finally showing up, just not quite how the cartoon promised.&lt;/p&gt;

&lt;p&gt;A pilotless air taxi route between Shenzhen and Hong Kong has been announced: 20 minutes, about 800 yuan ($110) a seat, nobody in the cockpit, the flight path preprogrammed and monitored from a ground command center.&lt;/p&gt;

&lt;p&gt;At a low-altitude economy expo in Guangzhou in December 2025, EHang said its EH216-S autonomous air taxi would begin cross-border service that January. Coverage of the announcement repeated the same numbers: 20 minutes, 800 yuan and a shortcut between two cities about 25 miles apart in the Greater Bay Area, Beijing&amp;#39;s name for the Hong Kong-Shenzhen-Guangzhou megaregion.&lt;/p&gt;

&lt;p&gt;This is about as close as anyone has come to a real flying-car service, so I went looking for someone who could tell me more. Emails to EHang went unanswered. I blame the summer vacation season. Here&amp;#39;s what I found instead:&lt;/p&gt;

&lt;p&gt;The aircraft exists and it&amp;#39;s certified. The EH216-S seats two, uses 16 propellers, tops out around 130 km/h (80 mph) and has a maximum range of roughly 30 km, or about 19 miles. China&amp;#39;s civil aviation regulator has issued a type certificate, a standard airworthiness certificate, a production certificate and, through its operators, the first air operator certificates for civil pilotless, human-carrying eVTOL flights.&lt;/p&gt;

&lt;p&gt;So far, those approvals have covered sightseeing loops, tightly controlled test routes and early ticketed services rather than open-ended city-wide transport. In EHang&amp;#39;s own descriptions, the initial phase focuses on tours and flight experiences, often taking off and landing at the same vertiport, with broader regular scheduled service presented as a later step.&lt;/p&gt;

&lt;p&gt;EHang and the trade press now describe the Shenzhen-Hong Kong route as live and bookable, with multiple daily autonomous flights at around 800 yuan a seat, which EHang bills as the world&amp;#39;s first cross-border, fully autonomous passenger eVTOL service.&lt;/p&gt;

&lt;p&gt;Nearly everything I can find on how often these flights run, and how reliably, traces back to EHang, its partners or the eVTOL trade press; the big global outlets haven&amp;#39;t covered it. That&amp;#39;s not enough to call this a daily commuter corridor.&lt;/p&gt;

&lt;p&gt;There&amp;#39;s a reason announcements come early. Shenzhen pays subsidies for new cross-border routes to Hong Kong, plus bonuses tied to flight activity, and Guangdong province runs its own program for eVTOL operators. You can get paid for announcing a route and paid again for flying it, even while the service itself stays small and expensive.&lt;/p&gt;

&lt;p&gt;EHang is working on longer-range aircraft, and Hong Kong has opened a regulatory sandbox for advanced air mobility. Joby, Volocopter and Lilium are running piloted eVTOL demos in the U.S. and Europe under similar programs. Add it all up and you get a handful of tightly controlled test routes and a few ticketed corridors, far from a city-wide network.&lt;/p&gt;

&lt;p&gt;Right now, if you actually want to buy a ticket on a pilotless flying taxi, China is the only place anyone claims you can, and EHang is the company running those flights. Everyone else is still in demos, sandboxes or working through certification.&lt;/p&gt;

&lt;p&gt;Four decades after &amp;quot;The Jetsons&amp;quot; aired, someone did build the aircraft. It&amp;#39;s certified and it flies. I&amp;#39;d just like one that goes somewhere I actually need to be.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/12/GettyImages_2286782591-1/large.jpg" width="618" height="284"><media:description>An AutoFlight 'Prosperity' electric vertical take-off and landing (eVTOL) aircraft is demonstrated during a flight presentation organized by Alatau Advanced Air Group (AAAG) in cooperation with China's AutoFlight at the Kazanat Hippodrome in Astana, Kazakhstan, on July 24, 2026. Kazakhstan is preparing to become the first country in Central Asia to integrate electric vertical take-off and landing (eVTOL) air taxis into its transportation system. </media:description><media:credit>Meiramgul Kussainova/Anadolu via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/12/GettyImages_2286782591-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>VA seeks to extend its Oracle health record contract through 2031</title><link>https://www.nextgov.com/modernization/2026/08/va-seeks-extend-its-oracle-health-record-contract-through-2031/415380/</link><description>“This action is necessary to continue [electronic health record modernization] deployment activities and associated support services until all VA Medical Centers (VAMCs) and related facilities have fully transitioned to the EHR system,” the department said in a Sam.gov solicitation notice.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Edward Graham</dc:creator><pubDate>Wed, 12 Aug 2026 17:43:00 -0400</pubDate><guid>https://www.nextgov.com/modernization/2026/08/va-seeks-extend-its-oracle-health-record-contract-through-2031/415380/</guid><category>Modernization</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Department of Veterans Affairs is looking to extend its contract with Oracle for an additional three years to finalize its electronic health record modernization project, according to &lt;a href="https://sam.gov/workspace/contract/opp/85bba2cc888d42d8bbe8e6a48058c1cc/view"&gt;a SAM.gov notice&lt;/a&gt; that was published Tuesday.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;VA initially &lt;a href="https://www.nextgov.com/modernization/2018/05/va-signs-10b-deal-with-cerner/196276/"&gt;contracted with Cerner in 2018&lt;/a&gt; to modernize its legacy health record system. Oracle subsequently &lt;a href="https://www.washingtontechnology.com/opinion/2021/12/federal-leg-oracles-planned-28b-cerner-acquisition/360001/"&gt;acquired Cerner in 2022&lt;/a&gt; and rebranded the new unit as Oracle Health.&lt;/p&gt;

&lt;p&gt;The EHR modernization project is part of a broader government effort to implement a single, interoperable federal EHR across several agencies like the Defense Department, Coast Guard and National Oceanic and Atmospheric Administration.&lt;/p&gt;

&lt;p&gt;While the other agencies have largely completed deployments of the new software, VA has faced numerous challenges since it first went live with the new EHR system at the Mann-Grandstaff VA Medical Center in Spokane, Washington, in 2020.&lt;/p&gt;

&lt;p&gt;Issues with the software and clinician use of the system &amp;mdash; which included adverse patient safety outcomes &amp;mdash; ultimately led VA &lt;a href="https://www.nextgov.com/acquisition/2024/06/va-extends-ehr-contract-oracle-cerner-11-months/397372/"&gt;to renegotiate&lt;/a&gt; its contract with Oracle in May 2023. The revised contract includes&amp;nbsp;additional accountability measures and changes the terms of the deal from an additional five-year term to five one-year terms.&lt;/p&gt;

&lt;p&gt;Under the proposed extension, the current agreement between VA and Oracle would be modified to consist of an additional three one-year optional ordering periods.&lt;/p&gt;

&lt;p&gt;That would potentially extend the contract through May 16, 2031. The current deal is set to expire in May 2028. Agency officials have said they are hoping to complete deployments of the new EHR software at every VA medical facility &lt;a href="https://www.nextgov.com/modernization/2025/06/va-official-touts-progress-ehr-modernization-project/406113/"&gt;by 2031&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Specifically, this modification will increase the overall contract ceiling and extend the Period of Performance,&amp;rdquo; the notice says. &amp;ldquo;This action is necessary to continue [electronic health record modernization] deployment activities and associated support services until all VA Medical Centers (VAMCs) and related facilities have fully transitioned to the EHR system.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The notice adds that &amp;ldquo;the intended sole source for this firm fixed price modification is Oracle Health Government Services, Inc.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Although accompanying documents attached to the notice say &amp;ldquo;this modification will increase the total contract ceiling value from $9,996,557,385.06,&amp;rdquo; both the proposed increase and new total contract ceiling are redacted.&lt;/p&gt;

&lt;p&gt;The announcement comes as VA, under the leadership of Secretary Doug Collins, has prioritized completing the large-scale EHR modernization project after it was slowed for years by safety and usability challenges.&lt;/p&gt;

&lt;p&gt;VA paused most new deployments of the EHR system in April 2023 to address the host of issues plaguing its implementation across VA&amp;rsquo;s network of 164 medical facilities. At the time the agency initiated its &amp;ldquo;reset period,&amp;rdquo; the software had only been deployed at five sites.&lt;/p&gt;

&lt;p&gt;At the end of the Biden administration in December 2024, VA announced plans to resume rollouts of the system at four Michigan-based medical sites in mid-2026. Collins subsequently moved to scale up the number of go-lives in 2026 by adding nine medical facilities to VA&amp;rsquo;s 2026 &lt;a href="https://digital.va.gov/ehr-modernization/ehr-deployment-schedule/"&gt;deployment schedule&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;VA has successfully deployed the new software at eight medical facilities so far this year, with plans to go live at three more sites on Aug. 22 and then two more on Oct. 24.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Collins told lawmakers in May that, under his leadership, the EHR rollout resumption push has been &amp;ldquo;&lt;a href="https://www.nextgov.com/modernization/2026/05/ehr-restart-was-phenomenal-despite-persistent-challenges-initial-sites-va-secretary-says/413712/"&gt;phenomenal&lt;/a&gt;.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/12/GettyImages_1152538330-1/large.jpg" width="618" height="284"><media:credit>Westy72/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/12/GettyImages_1152538330-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Palantir’s no-bid pipeline just got bigger</title><link>https://www.nextgov.com/acquisition/2026/08/palantirs-no-bid-pipeline-just-got-bigger/415379/</link><description>A new $244M Pentagon memo skips the Federal Acquisition Regulation's process for sole-source justifications and urges agencies to find ways to work with the company.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nick Wakeman</dc:creator><pubDate>Wed, 12 Aug 2026 16:11:41 -0400</pubDate><guid>https://www.nextgov.com/acquisition/2026/08/palantirs-no-bid-pipeline-just-got-bigger/415379/</guid><category>Acquisition</category><content:encoded>&lt;![CDATA[&lt;p&gt;Palantir has secured another lucrative commitment from the Defense Department, with a pledge of up to $243.9 million in funding for the company&amp;rsquo;s software between now and March 31, 2027.&lt;/p&gt;

&lt;p&gt;Deputy Secretary of Defense Steve Feinberg has also directed DOD departments to identify options for more spending on Palantir products&amp;nbsp;from April 1, 2027 and Dec. 28, 2028.&lt;/p&gt;

&lt;p&gt;In a memo viewed by WT, Feinberg says Palantir&amp;#39;s&amp;nbsp;software is &amp;quot;providing valuable support to improve efficiencies with the defense industrial base.&amp;quot;&amp;nbsp;Feinberg highlighted DOD&amp;#39;s use of the software&amp;nbsp;to flag delays in munitions and delivery-vehicle production and maintenance.&lt;/p&gt;

&lt;p&gt;Feinberg made no mention of specific contracts or vehicles.&lt;/p&gt;

&lt;p&gt;The action follows a &lt;a href="https://www.washingtontechnology.com/contracts/2025/08/palantir-signs-10b-enterprise-agreement-army/407153/?oref=wt-topic-lander-river"&gt;July award of a 10-year, $10 billion Army agreement&lt;/a&gt;&amp;nbsp;that consolidated many of Palantir&amp;rsquo;s existing contracts into a single pact.&lt;/p&gt;

&lt;p&gt;The Feinberg memo appears to be part of a trend in federal contracting, where no-compete contracts are growing as a &lt;a href="https://www.washingtontechnology.com/contracts/2026/07/sole-source-awards-are-down-their-share-pie-not/415123/?oref=ng-author-river"&gt;percentage of all awards.&lt;/a&gt; No compete contracts accounted for 14.8% of all awards in the first half of 2026, compared to 12.6% for the same period in 2025.&lt;/p&gt;

&lt;p&gt;Federal News Radio reported that DOD said it has issued similar memos involving other companies.&lt;/p&gt;

&lt;p&gt;No compete contracts are allowed in the Federal Acquisition Regulation, which gives agencies the process for&amp;nbsp;documenting why a sole-source contract is the best use of federal funds. Reasons for a no-compete contract can include urgency, only one responsible source, critical follow-on work and national security.&lt;/p&gt;

&lt;p&gt;Feinberg&amp;#39;s memo mentions none of those reasons for directing the spending to Palantir.&lt;/p&gt;

&lt;p&gt;Palantir&amp;#39;s portfolio of&amp;nbsp;no-compete contracts includes an&amp;nbsp;Agriculture Department award for the &lt;a href="https://sam.gov/workspace/contract/opp/eb30baf84ef6427a86c05fd0cee5499a/view"&gt;One Farmer, One File program&lt;/a&gt;. Agriculture also turned to Palantir&amp;#39;s software for the department&amp;#39;s&amp;nbsp;&lt;a href="https://sam.gov/workspace/contract/opp/db05487769fe442f97fe64147f513028/view"&gt;return-to-the-office initiative&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;According to GovTribe data, the company has received $3.2 billion in contract obligations since 2024 and roughly half of those dollars came through no compete contracts.&lt;/p&gt;

&lt;p&gt;In Palantir&amp;#39;s second quarter earnings release on&amp;nbsp;Aug. 3, the company reported 93% in the second quarter compared to the same quarter a year ago. Total revenue reached $1.9 billion.&lt;/p&gt;

&lt;p&gt;U.S. government revenue grew 90% year-over-year to $809 million.&lt;/p&gt;

&lt;p&gt;Palantir also is ranked No. 40 on &lt;a href="https://www.washingtontechnology.com/rankings/top-100/2026/"&gt;the 2026 Washington Technology Top 100&lt;/a&gt;, up 22 spots from the 2025 rankings.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/12/PalantirWT20260812-1/large.jpg" width="618" height="284"><media:credit>Gettyimages.com/NurPhoto / Contributor</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/12/PalantirWT20260812-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>NIST wants to outfit the National Vulnerability Database with AI</title><link>https://www.nextgov.com/cybersecurity/2026/08/nist-wants-outfit-national-vulnerability-database-ai/415371/</link><description>The National Institute of Standards and Technology is angling to modernize how it reports and responds to cyber vulnerabilities with the help of artificial intelligence.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alexandra Kelley</dc:creator><pubDate>Wed, 12 Aug 2026 14:22:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/nist-wants-outfit-national-vulnerability-database-ai/415371/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The National Institute of Standards and Technology is looking to augment its central repository of digital vulnerabilities with help from artificial intelligence.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In a new Request for Information &lt;a href="https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of"&gt;published&lt;/a&gt; in the Federal Register on Wednesday, NIST said it is seeking input surrounding how to best modernize its National Vulnerability Database by leveraging AI to enhance how the agency documents and responds to identified cybersecurity weaknesses.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://nvd.nist.gov/"&gt;The NVD&lt;/a&gt; documents digital vulnerabilities, cataloguing their severity, impacted products and other relevant data. Some of the challenges to modernization the RFI seeks to address include growth in both the number and complexity of newly disclosed vulnerabilities, a diverse range in data quality, a reliance on automation and machine-readable security data and the emergence of AI-assisted vulnerability discovery.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The advancement of AI presents an opportunity to transform the vulnerability management ecosystem,&amp;rdquo; &lt;a href="https://public-inspection.federalregister.gov/2026-16371.pdf"&gt;the document reads&lt;/a&gt;. &amp;ldquo;This requires input from across the community to ensure this ecosystem is effective, scalable, and resilient in the face of emerging threats.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The RFI seeks feedback to better understand how AI tools can improve the broad vulnerability management lifecycle and ecosystem, enhance risk&amp;nbsp;assessment efforts and better remediate vulnerabilities.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;NIST is also looking to learn more about what, if any, changes need to be made to existing organizational structures and standards to improve both the data quality and procedural handling of vulnerabilities.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Rapid advancements in AI technology and its impact &amp;ndash;&amp;ndash; both as an asset and adversary &amp;ndash;&amp;ndash; on cybersecurity has been a paramount tech policy issue, reaching a climax after models from both &lt;a href="https://www.nextgov.com/cybersecurity/2026/08/federal-systems-increasingly-likely-face-accidental-ai-breach-after-hugging-face-experts-say/415307/"&gt;OpenAI and Anthropic escaping containment environments&lt;/a&gt;. Prior to these incidents, the White House had turned its attention to addressing the cybersecurity impacts of AI, including multiple cybersecurity action items in &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/06/trump-signs-ai-executive-order-after-postponement-last-month/413912/"&gt;a June executive order&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;As part of the EO, the Trump administration created an AI-supported vulnerability clearinghouse within &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/white-house-announces-gold-eagle-ai-clearinghouse-cyber-vulnerabilities/414768/"&gt;the new Gold Eagle initiative&lt;/a&gt;. Gold Eagle is primarily a coordinated vulnerability sharing effort. A NIST spokesperson told &lt;em&gt;Nextgov/FCW &lt;/em&gt;that its effort to modernize the NVD is not related to any recent executive action.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Our RFI is not in response to any specific executive orders or to the Gold Eagle Initiative,&amp;rdquo; the spokesperson said. &amp;ldquo;However, we expect that tools like the NVD will continue to play an important role in the broader vulnerability management and coordination ecosystem.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/12/860x394-1/large.jpg" width="618" height="284"><media:credit>R. Wilson/NIST</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/12/860x394-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>DISA sets release date for follow-on cloud solicitation</title><link>https://www.nextgov.com/acquisition/2026/08/disa-sets-release-date-follow-cloud-solicitation/415370/</link><description>The Defense Information Systems Agency is pushing to expand its $9 billion cloud vehicle beyond the big four hyperscalers.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nick Wakeman</dc:creator><pubDate>Wed, 12 Aug 2026 13:36:00 -0400</pubDate><guid>https://www.nextgov.com/acquisition/2026/08/disa-sets-release-date-follow-cloud-solicitation/415370/</guid><category>Acquisition</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Defense Information Systems Agency&amp;#39;s newest acquisition schedule pegs an expected final solicitation release date of Aug. 24 for the next iteration of the military&amp;#39;s main cloud computing contract.&lt;/p&gt;

&lt;p&gt;The Joint Warfighter Cloud Capability contract is the&amp;nbsp;Defense Department&amp;rsquo;s vehicle for buying cloud services from the main hyperscalers &amp;ndash; Amazon Web Services, Google, Microsoft Azure and Oracle.&lt;/p&gt;

&lt;p&gt;DISA&amp;#39;s expected release date was part of the agency&amp;#39;s August &lt;a href="https://www.disa.mil/partners/contract-opportunities"&gt;acquisition decisions posting on its website&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The new version will be called JWCC Unified Cloud Marketplace and expands what DOD can buy through the vehicle.&lt;/p&gt;

&lt;p&gt;Tier 1 will be for the hyperscalers. Tier 2 covers &amp;ldquo;everything-as-a-service&amp;rdquo; including&amp;nbsp;software, platform, and non-hyperscale infrastructure.&lt;/p&gt;

&lt;p&gt;Tier 3 is reserved for what DISA is calling &amp;ldquo;Commercial innovators and small businesses.&amp;rdquo; This tier will be populated by emerging companies and small businesses.&lt;/p&gt;

&lt;p&gt;DISA has not posted an estimated value for JWCC Unified Cloud Marketplace. The current JWCC vehicle had a $9 billion ceiling.&lt;/p&gt;

&lt;p&gt;Deltek data indicates AWS has received $526.5 million in task order obligations, followed by Microsoft at $221 million.&amp;nbsp;Oracle is next at&amp;nbsp;$76.9 million&amp;nbsp;and Google stands at $35.9 million.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/12/JWCCwt20260811/large.jpg" width="618" height="284"><media:credit>Gettyimages.com/sefa ozel</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/12/JWCCwt20260811/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Amazon Web Services’ Dave Levy departs for Google</title><link>https://www.nextgov.com/people/2026/08/amazon-web-services-dave-levy-departs-google/415364/</link><description>The senior executive worked at AWS since 2017.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Frank Konkel</dc:creator><pubDate>Wed, 12 Aug 2026 10:52:00 -0400</pubDate><guid>https://www.nextgov.com/people/2026/08/amazon-web-services-dave-levy-departs-google/415364/</guid><category>People</category><content:encoded>&lt;![CDATA[&lt;p&gt;Dave Levy, vice president of AWS Worldwide Public Sector, has left the cloud computing and AI giant for a role with one of its primary competitors: Google.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Levy&amp;rsquo;s last day was Friday, July 31, an AWS spokesperson confirmed to &lt;em&gt;Nextgov/FCW&lt;/em&gt;. A Google spokesperson declined to comment on Levy&amp;rsquo;s hiring.&lt;/p&gt;

&lt;p&gt;Levy joined AWS in 2017 after a 12-year run as Apple&amp;rsquo;s head of U.S. government sales &amp;mdash; first as vice president of U.S. government, nonprofit and healthcare, and ultimately leading AWS&amp;rsquo; worldwide public sector business from 2023 onward.&lt;/p&gt;

&lt;p&gt;David Appel, who formerly oversaw AWS&amp;rsquo; national security and defense portfolio, has stepped into Levy&amp;rsquo;s former role in acting capacity, according to an AWS spokesperson.&lt;/p&gt;

&lt;p&gt;Levy&amp;rsquo;s departure from AWS comes as the company nears the 15th anniversary of its&lt;a href="https://aws.amazon.com/govcloud-us/"&gt; GovCloud&lt;/a&gt;, which debuted in 2011 as the first cloud infrastructure accredited and designed for government customers. In the years since, AWS inked a series of major defense customers to multibillion-dollar cloud contracts, including the&lt;a href="https://www.theatlantic.com/technology/archive/2014/07/the-details-about-the-cias-deal-with-amazon/374632/"&gt; Central Intelligence Agency,&lt;/a&gt; the&lt;a href="https://www.nextgov.com/digital-government/2022/12/amazon-google-microsoft-oracle-awarded-9b-pentagon-cloud-contract/380596/"&gt; Pentagon&lt;/a&gt;, the&lt;a href="https://www.nextgov.com/emerging-tech/2022/04/nsa-re-awards-secret-10-billion-contract-amazon/366184/"&gt; National Security Agency&lt;/a&gt; and all&lt;a href="https://www.nextgov.com/modernization/2020/11/exclusive-cia-awards-secret-multibillion-dollar-cloud-contract/170227/"&gt; 18 U.S. intelligence agencies&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;A first-mover in the cloud computing market &amp;mdash; Amazon Elastic Cloud Compute, or EC2, debuted 20 years ago &amp;mdash; AWS&lt;a href="https://www.crn.com/news/cloud/2026/cloud-market-share-q2-2026-google-gains-share-as-aws-falls"&gt; remains&lt;/a&gt; the dominant market leader in the worldwide cloud computing market with nearly 28% of global market share.&lt;/p&gt;

&lt;p&gt;Google&amp;rsquo;s business continues to grow, too. Google Cloud, the company&amp;rsquo;s suite of cloud computing services, is steadily&lt;a href="https://www.crn.com/news/cloud/2026/cloud-market-share-q1-2026-aws-microsoft-google-battling-in-ai-era"&gt; gaining&lt;/a&gt; market share from competitors AWS and Microsoft, while the company&amp;rsquo;s AI technology, including its Gemini models, is fueling further growth as private and public sector customers clamor for AI offerings.&lt;/p&gt;

&lt;p&gt;After a public falling out with the Pentagon in 2017 over&lt;a href="https://www.war.gov/News/News-Stories/Article/Article/1254719/project-maven-to-deploy-computer-algorithms-to-war-zone-by-years-end/"&gt; Project Maven&lt;/a&gt;, Google launched a business unit in 2022 called Google Public Sector specifically designed to deliver cloud computing, AI and collaboration tools popular with its private sector customers directly to the public sector and Pentagon.&lt;a href="https://www.nextgov.com/digital-government/2022/09/googles-government-arm-names-new-chief/377503/"&gt; Helmed&lt;/a&gt; by Google Public Sector Chief Executive Officer Karen Dahut, the bullish maneuver has paid off with Google&amp;rsquo;s software running in nearly every major federal agency, its latest Gemini models&lt;a href="https://www.defenseone.com/defense-systems/2026/04/pentagon-adds-googles-latest-model-genaimil-usage-soars/413126/"&gt; powering&lt;/a&gt; the Pentagon&amp;rsquo;s GenAI.mil platform and poaching away some&lt;a href="https://www.nextgov.com/modernization/2025/12/inside-transportation-departments-technology-transformation/410400/"&gt; longtime&lt;/a&gt; Microsoft 365 customers through its Workspace collaboration suite.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/12/GettyImages_2174206135/large.jpg" width="618" height="284"><media:description>Dave Levy Vice President of Amazon Web Services speaks onstage during the 2024 Concordia Annual Summit at Sheraton New York Times Square on September 24, 2024 in New York City.</media:description><media:credit>Leigh Vogel/Getty Images for Concordia Summit</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/12/GettyImages_2174206135/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Oversight and program management gaps slowing VA’s benefits processing system modernization, OIG says</title><link>https://www.nextgov.com/modernization/2026/08/oversight-and-program-management-gaps-slowing-vas-benefits-processing-system-modernization-oig-says/415356/</link><description>The watchdog said cost estimate and project planning issues are among the top factors afflicting VA’s overhaul of its legacy Benefits Enterprise Platform.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Edward Graham</dc:creator><pubDate>Tue, 11 Aug 2026 18:45:00 -0400</pubDate><guid>https://www.nextgov.com/modernization/2026/08/oversight-and-program-management-gaps-slowing-vas-benefits-processing-system-modernization-oig-says/415356/</guid><category>Modernization</category><content:encoded>&lt;![CDATA[&lt;p&gt;Efforts to modernize a Department of Veterans Affairs system that supports the processing of veterans&amp;rsquo; benefits claims have been hampered by &amp;ldquo;insufficient oversight and weak program management,&amp;rdquo; according to the agency&amp;rsquo;s Office of Inspector General.&lt;/p&gt;

&lt;p&gt;The watchdog warned in an audit &lt;a href="https://www.vaoig.gov/sites/default/files/reports/2026-08/vaoig_-_25-01098-103_final.pdf"&gt;released&lt;/a&gt; on Tuesday that VA&amp;rsquo;s Office of Information and Technology has not taken all of the necessary steps to keep the revamp of the agency&amp;rsquo;s Benefits Enterprise Platform on track, which could potentially affect the processing of veterans&amp;rsquo; benefits and other modernization efforts.&lt;/p&gt;

&lt;p&gt;The BEP platform &amp;mdash; &lt;a href="https://www.govinfo.gov/content/pkg/CMR-VA1-00187554/pdf/CMR-VA1-00187554.pdf"&gt;one of 85 legacy systems&lt;/a&gt; that VA has identified as needing to be modernized or decommissioned to &amp;ldquo;improve overall efficiency of claims processing&amp;rdquo; &amp;mdash; helps facilitate the sharing of information between the Veterans Benefits Administration and other &amp;ldquo;business line systems&amp;rdquo; that include pension, vocational rehabilitation and employment benefits.&lt;/p&gt;

&lt;p&gt;VA &lt;a href="https://fedscoop.com/department-of-veterans-affairs-awards-booz-allen-1-1b-benefits-processing-contract/"&gt;awarded&lt;/a&gt; Booz Allen Hamilton a $1.1 billion contract in May 2021 to integrate its benefits systems into a new cloud-based Benefits Integration Platform, with the plan calling for the legacy BEP system to be migrated to this new service and then subsequently decommissioned. Although the contract was supposed to be completed this month, OIG noted that the latest timetable from VA said the BEP modernization effort is now slated to be completed in the second quarter of fiscal year 2034.&lt;/p&gt;

&lt;p&gt;&amp;quot;Because BEP supports a significant number of systems, there is increased risk that other systems relying on it may experience negative consequences from potential delays in the modernization effort,&amp;rdquo; the report said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The audit said the Office of Information and Technology failed to develop &amp;ldquo;a high-quality, reliable program schedule as recommended by the Government Accountability Office&amp;rsquo;s Schedule Assessment Guide&amp;rdquo; for the project and has instead relied on an agile project management tool for the effort &amp;mdash; a tool that &amp;ldquo;does not contain roadmaps or detailed plans for the entire scope of the project.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;OIG also found that the office lacked a reliable lifecycle cost estimate for the modernization initiative, which has resulted in inconsistent funding information being included in various BEP plans and has &amp;ldquo;limit[ed] VA&amp;rsquo;s ability to make informed decisions.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Lack of proper oversight, the watchdog reported, also may have jeopardized the security of veterans&amp;rsquo; sensitive personal data when the office &amp;ldquo;hosted minor applications without conducting required security assessments.&amp;rdquo; After OIG notified VA officials about documented vulnerabilities &amp;mdash; some of which dated as far back as 2021 &amp;mdash; the watchdog said VA took the necessary steps to assess the security of its applications and remediate any identified issues.&lt;/p&gt;

&lt;p&gt;OIG&amp;rsquo;s audit recommended that VA take steps to enhance its BEP modernization efforts, including by developing and maintaining a program schedule that aligns with best practices, ensuring that staff are following proper procedures when it comes to storing scheduling information, developing a &amp;ldquo;reliable, validated life cycle cost estimate&amp;rdquo; for the project and tracking all relevant project costs. VA officials said they concurred with the watchdog&amp;rsquo;s recommendations.&lt;/p&gt;

&lt;p&gt;The BEP project is just the latest VA modernization initiative to be singled out for criticism by OIG for resulting in significant delays, cost overruns and oversight gaps.&lt;/p&gt;

&lt;p&gt;VA is still in the process of developing a new digital GI Bill system, which the watchdog noted in an August 2024 report has seen its cost more than double as a result of &amp;ldquo;&lt;a href="https://www.nextgov.com/modernization/2026/02/digital-gi-bill-delays-are-reflection-vas-it-management-problem-lawmakers-say/411208/"&gt;insufficient planning&lt;/a&gt;.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The agency&amp;rsquo;s large-scale electronic health record modernization project has also been plagued by cost overruns, delays and oversight issues since the deployment effort began in earnest in 2020. The Trump administration has prioritized righting that effort, however, and VA Secretary Doug Collins said earlier this year that an EHR rollout resumption push has been &amp;ldquo;&lt;a href="https://www.nextgov.com/modernization/2026/05/ehr-restart-was-phenomenal-despite-persistent-challenges-initial-sites-va-secretary-says/413712/"&gt;phenomenal&lt;/a&gt;&amp;rdquo; so far.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/11/GettyImages_1167511743/large.jpg" width="618" height="284"><media:credit>P_Wei/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/11/GettyImages_1167511743/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Trump admin delays TANF data sharing plan opposed by blue states</title><link>https://www.nextgov.com/digital-government/2026/08/trump-admin-delays-tanf-data-sharing-plan-opposed-blue-states/415353/</link><description>Democrat-led states are concerned the administration will share cash assistance recipients’ sensitive information with immigration enforcement and other federal agencies.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christian Robles</dc:creator><pubDate>Tue, 11 Aug 2026 17:43:00 -0400</pubDate><guid>https://www.nextgov.com/digital-government/2026/08/trump-admin-delays-tanf-data-sharing-plan-opposed-blue-states/415353/</guid><category>Digital Government</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Trump administration pushed the effective date for a proposal allowing the Administration for Children and Families to share Temporary Assistance for Needy Families &amp;mdash; or TANF &amp;mdash; recipients&amp;rsquo; information with other federal agencies to Sept. 1, according to a Federal Register &lt;a href="https://www.federalregister.gov/documents/2026/08/07/2026-16176/privacy-act-of-1974-system-of-records#addresses"&gt;listing posted last week&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Without the extension, the policy shift was set to kick in Tuesday, according to another &lt;a href="https://www.federalregister.gov/documents/2026/07/20/2026-14587/privacy-act-of-1974-system-of-records"&gt;Federal Register notice&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The delay comes as a coalition of Democratic attorneys general is requesting a federal district court vacate ACF&amp;rsquo;s proposal and declare it unlawful, according to an &lt;a href="https://storage.courtlistener.com/recap/gov.uscourts.dcd.295159/gov.uscourts.dcd.295159.1.0.pdf"&gt;Aug. 3 filing&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The coalition alleged ACF could illegally share millions of TANF recipients&amp;rsquo; Social Security numbers, marital status, income and other sensitive information with the Department of Homeland Security and other agencies if the Trump administration has its way.&lt;/p&gt;

&lt;p&gt;That data sharing &amp;ldquo;will erode the trust that State agencies have developed with TANF recipients and will deter qualified beneficiaries from applying for TANF benefits, forcing Plaintiff States to spend more of their own money to ensure that families are housed and children do not go hungry,&amp;rdquo; the coalition said in the lawsuit filed in the U.S. District Court for the District of Columbia.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If ACF can proceed with sharing TANF data with DHS, without clearly defined purposes and limits required by federal law, then community fears that DHS will use that data for other purposes will impede that public trust and chill participation in State TANF programs by citizens and qualified non-citizens alike,&amp;rdquo; the coalition added.&lt;/p&gt;

&lt;p&gt;The group of attorneys general alleged that the administration&amp;rsquo;s data sharing plan is &amp;ldquo;arbitrary and capricious&amp;rdquo; under the Administrative Procedure Act. The coalition also claimed it violates the Constitution&amp;rsquo;s Spending Clause because states &amp;ldquo;could not have foreseen these potential uses and disclosures years ago when they collected and shared this data with ACF.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;An ACF spokesperson did not return a request for comment by the time of publication. The administration wrote in the Federal Register that its TANF data-sharing policies are designed to curtail fraud and ensure compliance with TANF requirements, such as verifying recipients&amp;rsquo; immigration status.&lt;/p&gt;

&lt;p&gt;A &lt;a href="https://www.regulations.gov/document/ACF-2026-0727-0001"&gt;public comment period &lt;/a&gt;for the TANF proposal closes Tuesday. The federal government gave states and the District of Columbia &lt;a href="https://www.congress.gov/crs-product/R48413"&gt;nearly $16.5 billion&lt;/a&gt; in TANF block grants in fiscal 2024, according to the Congressional Research Service.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/11/GettyImages_2288520850/large.jpg" width="618" height="284"><media:description> Construction workers install rebar and other materials at the new helipad on the South Lawn of the White House after President Donald Trump ordered changes to the project on August 6, 2026 in Washington, DC.</media:description><media:credit>Kevin Carter/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/11/GettyImages_2288520850/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>How OneGov is changing CACI's contractor role</title><link>https://www.nextgov.com/acquisition/2026/08/how-caci-looks-governments-software-license-buying-shift/415346/</link><description>CEO John Mengucci tells investors the government's direct licensing push means less revenue but more profit for integrators.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ross Wilkers</dc:creator><pubDate>Tue, 11 Aug 2026 17:00:00 -0400</pubDate><guid>https://www.nextgov.com/acquisition/2026/08/how-caci-looks-governments-software-license-buying-shift/415346/</guid><category>Acquisition</category><content:encoded>&lt;![CDATA[&lt;p&gt;CACI International counts as business partners many of the same brand name technology companies that the U.S. government wants to have more direct relationships with, especially licenses for enterprise software platforms.&lt;/p&gt;

&lt;p&gt;During CACI&amp;rsquo;s fiscal fourth quarter and year-end earnings call with investors Thursday, chief executive John Mengucci described that shift as having a &amp;ldquo;small revenue impact&amp;rdquo; and one resulting in &amp;ldquo;more positive margins.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The General Services Administration&amp;rsquo;s OneGov initiative for unified technology procurements is the highest-profile example of how the government is seeking more direct relationships with commercial providers, &lt;a href="https://www.washingtontechnology.com/contracts/2026/08/gsas-agenda-resellers-focuses-service-pricing-transparency/415249/"&gt;including contracts for the product itself and associated licenses&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;GSA is looking to obtain savings through volume discounts of tech products it believes can essentially be purchased in bulk and in a more consolidated manner and wants to do so on behalf of other agencies.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Customers traditionally repurpose those savings right back to CACI, that gives us an ability to deliver additional capabilities,&amp;rdquo; Mengucci said.&lt;/p&gt;

&lt;p&gt;Mengucci said that under the traditional model of integrators like CACI as primes, revenue was often reduced by the value of the licenses from the enterprise software providers. That revenue often provided CACI with &amp;ldquo;little-to-no margin,&amp;rdquo; he added.&lt;/p&gt;

&lt;p&gt;CACI is experiencing the shift of who the prime contractor is firsthand in Federal HR 2.0 &amp;ndash; the Office of Personnel Management&amp;rsquo;s effort to overhaul the government&amp;rsquo;s human resource systems by consolidating them into a single platform.&lt;/p&gt;

&lt;p&gt;Oracle &lt;a href="https://www.washingtontechnology.com/contracts/2026/07/opms-hr-systems-award-clears-protest-window/414598/"&gt;won the 10-year, $395.8 million contract over the summer&lt;/a&gt; and has enlisted CACI as a key teammate for the program alongside Baker Tilly and Deloitte. The core implementation will be based off of Oracle Fusion Cloud HCM.&lt;/p&gt;

&lt;p&gt;In talking with analysts, Mengucci described the partial role-reversal of who the prime is as one of merely changing the order of things.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;What the OEMs (original equipment manufacturers) don&amp;#39;t want, and generally aren&amp;#39;t able to deliver, is the full implementation,&amp;rdquo; Mengucci said. &amp;ldquo;The government is going to them for the licensing first and then we are partnering with those folks.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We&amp;#39;ve been in partnerships with them over the last eight-to-10 for a lot of those large enterprise tech jobs that we&amp;#39;ve put out there,&amp;rdquo; Mengucci added.&lt;/p&gt;

&lt;p&gt;Fourth quarter revenue of $2.7 billion was 17% higher than the prior year period with an organic growth rate of 11%, while profit of $353.1 million showed a 33% year-over-year increase in EBITDA (earnings before interest, taxes, depreciation and amortization).&lt;/p&gt;

&lt;p&gt;Full fiscal year 2026 revenue of $9.6 billion was 10.9% higher than the prior year period with an organic growth rate of 7.2%, while EBITDA of $1.2 billion showed a 21% year-over-year increase from FY 2025. CACI ended fiscal 2026 with an EBITDA margin of 12.3%, up from the prior year&amp;rsquo;s 11.2%.&lt;/p&gt;

&lt;p&gt;CACI&amp;rsquo;s initial guidance for its 2027 fiscal year, which started July 1, pegs revenue in the range of $10.65 billion-to-$10.85 billion on an EBITDA margin in the high-12% range.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/11/John_Mengucci_CACI_photo-1/large.jpg" width="618" height="284"><media:description>CACI International's chief executive John Mengucci.</media:description><media:credit>CACI photo.</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/11/John_Mengucci_CACI_photo-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>DHS wraps up Oracle's Cumulus cloud contract</title><link>https://www.nextgov.com/acquisition/2026/08/dhs-wraps-oracles-cumulus-cloud-contract/415344/</link><description>The Department of Homeland Security has two more hyperscaler awards to finalize before it can move ahead on a separate competition for this enterprise cloud program.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ross Wilkers</dc:creator><pubDate>Tue, 11 Aug 2026 15:32:00 -0400</pubDate><guid>https://www.nextgov.com/acquisition/2026/08/dhs-wraps-oracles-cumulus-cloud-contract/415344/</guid><category>Acquisition</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Homeland Security Department has entered into the second out of four planned awards under Cumulus, a centralized mechanism for acquiring commercial cloud computing services across the entire organization.&lt;/p&gt;

&lt;p&gt;Oracle&amp;rsquo;s portion of the potential five-year contract has a ceiling value of $567.9 million, DHS &lt;a href="https://sam.gov/workspace/contract/opp/683d563fc9fb4b4ca208535f0c20950f/view"&gt;said in a Friday notice to Sam.gov&lt;/a&gt;. This follows DHS&amp;rsquo; finalization in June of the award to Amazon Web Services, which is eligible for up to $2.5 billion under Cumulus.&lt;/p&gt;

&lt;p&gt;DHS first laid out its intended timeline for wrapping up each Cumulus contract with all four of the hyperscalers, with awards to Google Cloud and Microsoft still in-the-works. The department originally pegged the end of the calendar year&amp;rsquo;s second quarter as its deadline for finalizing each contract.&lt;/p&gt;

&lt;p&gt;Each award under Cumulus will cover a one-year base period and up to four option years.&lt;/p&gt;

&lt;p&gt;Cumulus is designed to have a blend of competitive and non-competitive awards across all aspects of commercial cloud including infrastructure-as-a-service, platform-as-a-service and software-as-a-service.&lt;/p&gt;

&lt;p&gt;After DHS finalizes each hyperscaler contract, the department will then work on creating a separate multiple-award competition to support the Cumulus effort.&lt;/p&gt;

&lt;div class="related-articles-placeholder"&gt;[[Related Posts]]&lt;/div&gt;

&lt;p&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/11/cloud-1/large.jpg" width="618" height="284"><media:credit>Gettyimages.com / Just Super</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/11/cloud-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>The government wants your help solving today’s biggest challenges</title><link>https://www.nextgov.com/digital-government/2026/08/government-wants-your-help-solving-todays-biggest-challenges/415339/</link><description>NIH is offering $1 million for practical ideas that could help long-acting HIV prevention and treatment reach more people, and applicants do not need a traditional research background to participate.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Breeden II</dc:creator><pubDate>Tue, 11 Aug 2026 14:36:00 -0400</pubDate><guid>https://www.nextgov.com/digital-government/2026/08/government-wants-your-help-solving-todays-biggest-challenges/415339/</guid><category>Digital Government</category><content:encoded>&lt;![CDATA[&lt;p&gt;A few years ago, I tried to help a team of astronauts survive a Martian dust storm.&lt;/p&gt;

&lt;p&gt;Fortunately, nobody was actually in danger. I was participating in the second &lt;a href="https://www.nextgov.com/emerging-tech/2023/03/nasa-asks-public-help-second-marsxr-challenge/383764/"&gt;NASA MarsXR Challenge&lt;/a&gt;, a government-sponsored competition hosted on the HeroX open-innovation platform. NASA wanted members of the public to design virtual reality scenarios that could someday help train astronauts for missions on Mars.&lt;/p&gt;

&lt;p&gt;The first phase focused on storyboarding, so participants did not need to know how to program a VR simulation. They needed to imagine a realistic challenge, explain how astronauts would respond and take advantage of the immersive capabilities offered by virtual reality. My team designed a scenario in which astronauts left their rover behind while collecting rock samples in terrain too rough for a vehicle. When a surprise dust storm swept into the area and visibility began to collapse, they had to navigate back to the rover using digital waypoints and beacons they had placed along their route.&lt;/p&gt;

&lt;p&gt;It seemed like a plausible worst-case scenario and, admittedly, a pretty exciting video game mission. The design required astronauts to think ahead, use the available technology and remain calm when conditions suddenly changed. Our entry earned an honorable mention in the first phase. We did not advance to the programming round, where winning concepts could be developed into functioning &lt;a href="https://www.nextgov.com/emerging-tech/2023/11/nasa-celebrates-winners-second-marsxr-virtual-reality-astronaut-training-competition/391742/"&gt;VR training missions&lt;/a&gt;, but the experience gave me a firsthand look at how seriously NASA approaches open-innovation competitions.&lt;/p&gt;

&lt;p&gt;NASA has used HeroX and the NASA Tournament Lab to solicit outside ideas for everything from virtual reality astronaut training to building better &lt;a href="https://www.nextgov.com/emerging-tech/2025/11/nasa-wants-you-help-kick-some-tires-moon/409383/"&gt;lunar rover wheels&lt;/a&gt;. Some of the most visible government-sponsored challenges over the past several years have naturally focused on space exploration.&lt;/p&gt;

&lt;p&gt;But one of the most consequential challenges open in 2026 is aimed at a problem that is far more Earth-bound and deeply human. The National Institutes of Health&amp;rsquo;s Office of AIDS Research is offering $1 million in prizes for ideas that could help more people gain access to long-acting HIV prevention and treatment. The competition, called the NIH ARISE-HIV LAUNCH Challenge, is &lt;a href="https://www.herox.com/NIHARISE-HIVLAUNCH"&gt;open for first-round submissions&lt;/a&gt; through Aug. 6.&lt;/p&gt;

&lt;p&gt;Federal government involvement goes well beyond an agency endorsement for the HIV Challenge. The &lt;a href="https://oar.nih.gov/"&gt;Office of AIDS Research&lt;/a&gt; is the official sponsor and is providing the $1 million prize purse. The NIH Office of the Director is conducting the challenge under the federal prize authority established by the &lt;a href="https://www.congress.gov/111/plaws/publ358/PLAW-111publ358.pdf"&gt;America COMPETES&lt;/a&gt; Reauthorization Act.&lt;/p&gt;

&lt;p&gt;The challenge is also part of a broader program called Advancing Research in Implementation Science to End HIV, or ARISE-HIV. That effort involves all NIH institutes, centers and offices that award HIV funding or support related prevention, care and treatment research. HeroX provides the public competition platform, and the challenge appears through the NASA Tournament Lab&amp;rsquo;s wider open-innovation network.&lt;/p&gt;

&lt;p&gt;To be clear, the current contest is not asking participants to invent a new HIV medication. Scientists have already developed long-acting products that can prevent or treat HIV without requiring patients to take a pill every day. Some are administered every two months, while others can provide protection for as long as six months. The challenge is getting those advances to the people who need them and making sure they remain connected to care.&lt;/p&gt;

&lt;p&gt;In an August 2025 post reflecting on her appearance with NIH Director Jay Bhattacharya on The Director&amp;rsquo;s Desk podcast, Office of AIDS Research Director Geri R. Donenberg described the gap the new challenge is trying to address.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We have effective, lifesaving interventions, but people are not benefiting equally,&amp;rdquo; she wrote.&lt;/p&gt;

&lt;p&gt;Donenberg &lt;a href="https://www.oar.nih.gov/about/directors-blog/five-takeaways-ending-hiv-epidemic-insights-my-conversation-nih-director"&gt;explained that&lt;/a&gt; implementation science can help determine how, where and by whom effective treatments should be delivered to reach different populations. An approach that works well for patients in one community may prove impractical in another because of transportation, cost, staffing, stigma, scheduling or limited access to health care.&lt;/p&gt;

&lt;p&gt;That is where the LAUNCH Challenge comes in. NIH is &lt;a href="https://www.herox.com/NIHARISE-HIVLAUNCH"&gt;asking participants&lt;/a&gt; to develop actionable ideas in at least one of four areas: access, delivery, engagement or retention.&lt;/p&gt;

&lt;p&gt;An access proposal might explore how mobile clinics, home-based services, street medicine or pharmacists could bring long-acting products to people who are not well served by traditional health care systems. A delivery proposal could address the staffing or coordination needed to administer injections safely and reliably. That might include evening appointments, transportation assistance, child care support or better integration with mental health and substance-use services.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Engagement proposals could focus on building awareness, understanding and trust among patients and their families. Finally, retention ideas might help patients remain on schedule and connected to care during the months between appointments. But those are just a few suggestions. By all means, if you have better ideas, feel free to participate in this new challenge and earn a share of the prize money.&lt;/p&gt;

&lt;p&gt;NIH is deliberately casting a wide net looking for precipitants. Individuals, informal teams, community organizations, health professionals, researchers, universities and companies can all participate. People and organizations that do not currently receive NIH funding are specifically encouraged to enter as the agency is looking for fresh and new ideas.&lt;/p&gt;

&lt;p&gt;The first-round submission for the ARISE-HIV Challenge is pretty approachable. Participants need to complete an online concept submission totaling about three pages. Participants must also provide a short public abstract and identify whether their proposal addresses access, delivery, engagement, retention or some combination of those areas.&lt;/p&gt;

&lt;p&gt;Judges will place the greatest weight on public health significance and impact, which accounts for 40% of the score. Innovation and novelty make up 35%, while the remaining 25% focuses on whether the idea is pragmatic enough to work outside a controlled research environment. HeroX and government officials explained the judging process and the importance of the challenge in a recent YouTube video.&lt;/p&gt;

&lt;div class="embed-wrapper big"&gt;
&lt;div class="embed-container embed-youtube"&gt;&lt;iframe allowfullscreen="" class="embedded" data-embed-src="https://www.youtube.com/embed/r49UEHVLGWw?wmode=transparent" frameborder="0" src="https://www.youtube.com/embed/r49UEHVLGWw?wmode=transparent"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;/div&gt;

&lt;p&gt;Completed Phase 1 entries must be submitted through HeroX by 5 p.m. Eastern on Aug. 6. NIH expects to award as many as 35 first-round prizes of $10,000 each. Those winners will be invited into Phase 2, where they will develop more detailed implementation and evaluation plans. Up to 13 second-round winners could receive approximately $50,000 each.&lt;/p&gt;

&lt;p&gt;And this is a busy time for government sponsored and federally focused challenges as the HIV event is not the only one being opened to outside solvers. The Department of Energy&amp;rsquo;s Office of Electricity recently launched the $500,000 Storage Design Strategies to Ease Production Prize, known as the &lt;a href="https://www.herox.com/storagedesignSTEP-prize"&gt;Storage Design STEP Prize&lt;/a&gt;. It asks developers of emerging grid-scale storage technologies to identify manufacturing, material-sourcing and supply-chain obstacles before those problems prevent promising designs from reaching commercial production. Phase 1 entries are due Oct. 8.&lt;/p&gt;

&lt;p&gt;Another active competition, the privately organized GoAERO Prize, is supported by NASA, RTX, Boeing, Honeywell, Iridium and other partners. Teams for that challenge are actually building compact, portable aircraft that could autonomously carry a person or emergency supplies into areas where conventional rescue vehicles cannot easily reach. Its final fly-off will take place at NASA&amp;rsquo;s Ames Research Center in April 2027. The best overall performer can earn $1 million, with additional prizes for missions involving rapid deployment, difficult conditions and precise maneuvering around obstacles.&lt;/p&gt;

&lt;div class="embed-wrapper big"&gt;
&lt;div class="embed-container embed-youtube"&gt;&lt;iframe allowfullscreen="" class="embedded" data-embed-src="https://www.youtube.com/embed/9iMLv05O3QY?wmode=transparent" frameborder="0" src="https://www.youtube.com/embed/9iMLv05O3QY?wmode=transparent"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;/div&gt;

&lt;p&gt;The live challenges are radically different, but they share the same underlying idea. Agencies and other sponsors describe a difficult problem, establish rules and rewards, then open the door to people who may never have encountered the issue through a conventional grant, contract or government job.&lt;/p&gt;

&lt;p&gt;My Mars scenario never became a functioning astronaut-training mission. But earning an honorable mention showed that someone outside NASA could still contribute an idea the agency considered useful. The next valuable idea may come from a community health worker who understands why patients miss appointments, an engineer trying to manufacture a new kind of battery or an aviation team that knows how to reach people stranded after a disaster.&lt;/p&gt;

&lt;p&gt;For readers with a useful perspective, technical skill or firsthand understanding of one of these problems, the invitation is real: take a look, join a team or submit an idea. You may not win the top prize, but you could still contribute something that advances a technology, helps an agency or improves someone&amp;rsquo;s life.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;John Breeden II is an award-winning journalist and reviewer with over 20 years of experience covering technology. He is the CEO of the &lt;/em&gt;&lt;a href="https://techwritersbureau.com/"&gt;&lt;em&gt;Tech Writers Bureau&lt;/em&gt;&lt;/a&gt;&lt;em&gt;, a group that creates technological thought leadership content for organizations of all sizes. Twitter: @LabGuys&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/11/GettyImages_1276547627/large.jpg" width="618" height="284"><media:description>View of the main historical building (Building 1) of the National Institutes of Health (NIH) inside Bethesda campus. U.S. Public Health Service seal is seen on top of it.</media:description><media:credit>Grandbrothers / Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/11/GettyImages_1276547627/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Federal agencies quietly joined health data superhighway governing council</title><link>https://www.nextgov.com/digital-government/2026/08/federal-agencies-quietly-joined-health-data-superhighway-governing-council/415324/</link><description>The rapidly growing superhighway — known as TEFCA — will help federal agencies digitally obtain health records from thousands of hospitals, clinics and other medical providers.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christian Robles</dc:creator><pubDate>Mon, 10 Aug 2026 17:37:00 -0400</pubDate><guid>https://www.nextgov.com/digital-government/2026/08/federal-agencies-quietly-joined-health-data-superhighway-governing-council/415324/</guid><category>Digital Government</category><content:encoded>&lt;![CDATA[&lt;p&gt;Officials with the Consumer Product Safety Commission, Social Security Administration and Indian Health Service were added to the governing council for a federal initiative designed to facilitate the exchange of health data in June, &lt;em&gt;Nextgov/FCW&lt;/em&gt; has learned.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The council&amp;rsquo;s recent additions highlight how agencies are increasingly eyeing participation in the initiative &amp;mdash; known as the Trusted Exchange Framework and Common Agreement, or TEFCA &amp;mdash; to obtain digital health records that would help quickly process disability claims, track consumer safety issues and improve medical care.&lt;/p&gt;

&lt;p&gt;The new federal representatives on the TEFCA governing council are:&lt;/p&gt;

&lt;ul&gt;
	&lt;li aria-level="1"&gt;Brien Lorenze, executive director of CPSC&lt;/li&gt;
	&lt;li aria-level="1"&gt;Sean Fry, executive advisor of health information technology and electronic records in SSA&amp;rsquo;s office of disability policy&lt;/li&gt;
	&lt;li aria-level="1"&gt;Bobby Villines, acting director of the division of information technology within IHS&amp;rsquo; office of information technology&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The &lt;a href="https://rce.sequoiaproject.org/tefca-governing-council/"&gt;TEFCA website&lt;/a&gt; was updated Monday afternoon to list the governing council members, including federal representatives, after &lt;em&gt;Nextgov/FCW&lt;/em&gt; inquired about new representatives. The governing council saw the federal members added in June, according to a spokesperson for the Department of Health and Human Services&amp;rsquo; Office of the National Coordinator for Health Information Technology.&lt;/p&gt;

&lt;p&gt;The governing council is tasked with monitoring health data exchanges, reviewing potential updates to the superhighway and helping resolve contentious cases of health information sharing, according to &lt;a href="https://rce.sequoiaproject.org/wp-content/uploads/2025/01/TEFCA-Governance-SOP-2024-1.10.25-final-508.pdf"&gt;TEFCA rules&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The rules state that up to five individuals affiliated with a federal agency can sit on the governing council. The governing council can be expanded to include more federal representatives.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The ability for members to vote on the governing council depends on whether their agency is &amp;ldquo;actively involved in or enabling TEFCA exchange,&amp;rdquo; according to the rules. CPSC&amp;rsquo;s representative is a nonvoting member on the governing council.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How the agencies are leveraging TEFCA&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The three agencies with new representatives on the TEFCA governing council are actively eyeing the health data sharing initiative to support agency procedures. Some are already receiving data through TEFCA.&lt;/p&gt;

&lt;p&gt;In February, SSA announced it joined TEFCA to &lt;a href="https://www.ssa.gov/blog/en/posts/2026-02-11.html"&gt;speed up&lt;/a&gt; disability benefits processing by more than 50% in some cases. Health systems using Epic electronic health records &lt;a href="https://www.epic.com/epic/post/health-systems-on-epic-are-first-to-connect-with-the-social-security-administration-through-tefca/"&gt;have already begun&lt;/a&gt; to digitally send SSA health information through TEFCA.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;SSA has long pulled medical records through other health data superhighways known as Carequality and eHealth Exchange, but TEFCA has enabled additional hospitals and clinics using Epic electronic health records to send health information to the federal government, according to Epic. SSA specifically chose eHealth Exchange as its Qualified Health Information Network, or QHIN, which is essentially an onramp to the broader TEFCA superhighway.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;An SSA spokesperson did not return a request for comment on the agency&amp;rsquo;s participation in the governing council.&lt;/p&gt;

&lt;p&gt;In July, CPSC announced it will leverage a QHIN, &lt;a href="https://www.cpsc.gov/Newsroom/News-Releases/2026/CPSC-Modernizes-Decades-Old-Injury-Surveillance-System-to-Protect-More-Americans-Faster"&gt;Konza Health&lt;/a&gt;, to update its National Electronic Injury Surveillance System, or NEISS, a tracking system for consumer product-related injuries. The new system would allow hospitals in all 50 states to share vital medical information with CPSC and speed up the detection of hazardous consumer products, the agency said in a press release.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;As CPSC modernizes [NEISS to] NEISS-R, interoperability with the nation&amp;#39;s health information infrastructure has become increasingly important. TEFCA provides a common framework for trusted health information exchange that can support authorized public health activities while promoting privacy, security, and standardized data exchange,&amp;rdquo; a CPSC spokesperson told &lt;em&gt;Nextgov/FCW&lt;/em&gt;. &amp;ldquo;CPSC&amp;#39;s participation reflects the mutual recognition that TEFCA and NEISS-R have complementary public health objectives and that collaboration benefits both efforts.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;CPSC&amp;rsquo;s partnership with Konza Health has garnered controversy from the likes of &lt;a href="https://www.youtube.com/watch?v=h7vJVid4Y8w"&gt;Rachel Maddow&lt;/a&gt; and &lt;a href="https://advocacy.consumerreports.org/press_release/consumer-reports-product-injury-data-should-be-modernized-but-the-cpsc-doesnt-need-patients-personal-medical-records-to-do-it/"&gt;consumer advocacy groups&lt;/a&gt; because it may sweep up personally identifiable information, such as names, addresses and birthdates, according to a &lt;a href="https://kffhealthnews.org/health-industry/cpsc-consumer-product-safety-commission-trump-er-injury-data-grab-neiss-konza/"&gt;&lt;em&gt;KFF Health&lt;/em&gt; report&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Hospital technologists are also wary about the initiative because Konza Health officials have described medical record sharing as mandatory or else hospitals could be charged with violating federal information blocking rules, the report says.&lt;/p&gt;

&lt;p&gt;The HHS office overseeing TEFCA invited CPSC to recommend a federal representative on the governing council in April.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;IHS became &lt;a href="https://ehealthexchange.org/first-federal-health-agency-joins-tefca-selecting-ehealth-exchange/"&gt;the first federal agency&lt;/a&gt; to join TEFCA in December 2024 with eHealth Exchange serving as its QHIN onramp. As a health care provider to federally recognized tribes, IHS is using TEFCA to improve care coordination between agency and nonagency medical providers.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The patients we serve are commonly shared with private sector, academic, or other federal healthcare providers. As such, the IHS has a clear interest in modernization and optimization of interoperability and coordination of care, and having a seat and a voice on the TEFCA Governing Council supports that interest,&amp;rdquo; an IHS spokesperson told &lt;em&gt;Nextgov/FCW&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;In addition to federal representatives, the TEFCA governing council has added several health IT industry bigwigs, including Alex Mugge and Hans Buitendijk of Oracle and Matt Becker of Kno2, &lt;em&gt;Nextgov/FCW&lt;/em&gt; has learned.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/10/GettyImages_2228735046/large.jpg" width="618" height="284"><media:credit>Thanadon Naksanee / Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/10/GettyImages_2228735046/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Senate’s short-term funding bill provides temporary extensions for TMF, cyber data-sharing law</title><link>https://www.nextgov.com/policy/2026/08/senates-short-term-funding-bill-provides-temporary-extensions-tmf-cyber-data-sharing-law/415322/</link><description>The continuing resolution that overwhelmingly passed the upper chamber this weekend would push the federal government’s funding deadline until Dec. 11.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Edward Graham</dc:creator><pubDate>Mon, 10 Aug 2026 17:25:00 -0400</pubDate><guid>https://www.nextgov.com/policy/2026/08/senates-short-term-funding-bill-provides-temporary-extensions-tmf-cyber-data-sharing-law/415322/</guid><category>Policy</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Senate approved a temporary funding measure this weekend that would provide a short-term extension for both the Technology Modernization Fund and a key cybersecurity law, although the proposal faces an uncertain future in the House.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The continuing resolution, which overwhelmingly passed the upper chamber in a 90-6 vote on Saturday morning, would punt funding for the federal government until Dec. 11. In lieu of further action and President Donald Trump signing such legislation, the government faces the likelihood of another shutdown beginning on Oct. 1.&lt;/p&gt;

&lt;p&gt;The Senate-passed legislation, in part, extends the Technology Modernization Fund, a federal program that provides financial assistance to government technology projects. TMF was established in 2017 and helps support longer-term IT modernization initiatives while also having agencies pay back the investments that they received.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;A Government Accountability Office report &lt;a href="https://www.nextgov.com/modernization/2026/07/technology-modernization-fund-has-saved-little-big-savings-are-expected-later-gao-finds/414968/"&gt;released&lt;/a&gt; last month found that TMF-funded projects have only resulted in about $13.5 million in savings through June 2025, although the watchdog estimated that 24 reviewed projects that received program funds between fiscal years 2018 and 2025 will result in roughly $1.06 billion in savings alone.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Saturday&amp;rsquo;s funding measure also provided a short-term extension for the Cybersecurity Information Sharing Act of 2015, a cornerstone cyber data-sharing measure that lets companies disseminate cyber threat intelligence with federal partners and one another while maintaining key legal exemptions. The law temporarily expired during the 43-day government shutdown late last year, although Congress passed a funding package in February that extended the statute through Sept. 30.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Trump administration officials have expressed a desire for lawmakers to extend the law for a prolonged period of time to enhance cyber information sharing.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;National Cyber Director Sean Cairncross said &lt;a href="https://www.nextgov.com/cybersecurity/2026/05/trump-admin-will-push-long-term-reauthorization-key-cyber-data-sharing-law/413395/"&gt;during an event&lt;/a&gt; in May that the White House was &amp;ldquo;pushing for a long-term reauthorization&amp;rdquo; of the law, noting that the administration&amp;rsquo;s &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/trumps-new-cyber-strategy-details-more-offensive-response-cyber-threats/411963/"&gt;national cybersecurity strategy&lt;/a&gt; includes a focus on enhancing information sharing between the government and the private sector.&lt;/p&gt;

&lt;p&gt;Lawmakers have &lt;a href="https://www.govexec.com/management/2026/08/what-history-tells-us-about-potential-government-shutdown/415259/?oref=ge-home-top-story"&gt;moved to push the next federal funding fight&lt;/a&gt; until after the November midterm elections, although both chambers still need to come together to support one measure.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Saturday&amp;rsquo;s bill passed before senators departed for the August recess. The House, which is also slated to be out until Aug. 31, passed its own temporary funding measure on July 21. Senate Democrats, however, have called that bill a non-starter.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/10/GettyImages_2289550622/large.jpg" width="618" height="284"><media:description>U.S. Senate Majority Leader John Thune (R-SD) speaks to the press in the U.S. Capitol on August 08, 2026 in Washington, DC. Senators worked through the night to pass a short-term funding extension. </media:description><media:credit>Finn Gomez/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/10/GettyImages_2289550622/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Senate Finance panel’s top Dem proposes excise tax on new data centers</title><link>https://www.nextgov.com/artificial-intelligence/2026/08/senate-finance-panels-top-dem-proposes-excise-tax-new-data-centers/415321/</link><description>Oregon Sen. Ron Wyden’s draft white paper calls for a new tax on hyperscalers and data center operators.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alexandra Kelley</dc:creator><pubDate>Mon, 10 Aug 2026 17:12:00 -0400</pubDate><guid>https://www.nextgov.com/artificial-intelligence/2026/08/senate-finance-panels-top-dem-proposes-excise-tax-new-data-centers/415321/</guid><category>Artificial Intelligence</category><content:encoded>&lt;![CDATA[&lt;p&gt;A new draft white paper from a top Senate Democrat proposes tax code updates that would shift incentives for data center construction.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.finance.senate.gov/imo/media/doc/080626_wyden_data_center_tax_white_paper.pdf"&gt;The paper&lt;/a&gt;, released on Aug. 6 by Sen. Ron Wyden, D-Ore.&amp;nbsp;&amp;mdash; ranking member of the Senate Finance Committee &amp;mdash; proposes changing the incentives that could spur more data center construction amid the national boom in a bid to offset consumer burdens associated with more data centers.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Wyden&amp;rsquo;s framework hinges on two changes to existing tax code: removing the current tax incentives that apply to data center construction and applying a new excise tax on data centers whose workloads primarily handle AI compute.&lt;/p&gt;

&lt;p&gt;With the removal of the tax incentive and the creation of an excise tax on data center operations, the new revenue would help address the myriad concerns with increased data center costs, including higher energy prices, workforce turmoil and a drain on broader resources.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;American communities are rightfully questioning whether the rapid buildout of data centers across the nation will benefit them, as local disruptions rise and Americans grow concerned about the long-term career prospects of millions of workers,&amp;rdquo; Wyden said in &lt;a href="https://www.finance.senate.gov/ranking-members-news/wyden-unveils-proposal-to-ensure-data-centers-pay-for-disruptions-caused-to-communities"&gt;a press release&lt;/a&gt;. &amp;ldquo;These proposals are a first step towards safeguarding taxpayer dollars and ensuring there are resources to support American workers displaced by the coming disruptions to the economy.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Wyden includes several caveats to his tax proposal. The new excise tax would function as a gross receipts tax that charges a fee the total revenue or sales of a business.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Two types of data centers will be subject to the tax: those owned, operated or rented by massive data center operators, and those being used by major data center payors, which include major hyperscalers Amazon and Meta. The paper stipulates that the tax would target the large AI hyperscalers and other entities that are primarily &amp;ldquo;causing the data center boom and most able to pay.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Wyden&amp;rsquo;s proposal offers selective exemptions, which apply to data center assets constructed before 2024. It states that &amp;ldquo;for all but the largest actors,&amp;rdquo; the share of data center assets built before 2024 won&amp;rsquo;t be subject to the new tax.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;These proposals will not end data center development or put at risk the U.S. maintaining its&lt;/p&gt;

&lt;p&gt;status as the global leader in AI and other innovative technologies,&amp;rdquo; the paper reads. &amp;ldquo;Rather, they will ensure we have the resources to help the communities and workers most impacted as data center construction continues.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The proposal also says that the tax would apply to data centers in space. The draft paper stipulates that if a space-based data center attempts to avoid the tax by being labeled as a non-U.S. asset, a withholding tax will apply to payments made by U.S. taxpayers to use the data center. Space-focused tech firms, including Blue Origin and SpaceX, have &lt;a href="https://www.theguardian.com/science/2026/jul/23/space-datacenters-bezos-blue-origin"&gt;proposed&lt;/a&gt; building millions of orbital data centers.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Wyden also solicited feedback on his proposal, calling for the public to provide the Senate Finance Committee&amp;rsquo;s minority staff with comments by Aug. 31. The paper said that discussion draft language is expected to arrive in the coming fall.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Data center construction and the question of who bears the burden of increased electricity rates and other potential hazards has become a major political talking point. Democrats, in particular, have been &lt;a href="https://www.pbs.org/newshour/nation/democrats-seize-on-ai-data-center-backlash-thats-dividing-rural-republicans-in-places-like-texas"&gt;looking to leverage&lt;/a&gt; growing opposition to further data center construction as a political issue ahead of the 2026 midterm elections.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In March, President Donal Trump unveiled &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/03/7-tech-companies-commit-protect-consumers-rising-electricity-prices/411883/"&gt;the Ratepayer Protection Pledge&lt;/a&gt; that brought companies Amazon, xAI, Oracle, Microsoft, Meta, Google and OpenAI to agree to absorb utility costs stemming from data centers handling their technology&amp;rsquo;s compute loads.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Other lawmakers have also turned their attention to issues brought about by the data center boom. Sen. Bernie Sanders, I-Vt., previously called for a moratorium on new construction until more information can be garnered about both data center impacts and AI itself.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We cannot sit back and allow a handful of billionaire Big Tech oligarchs to make decisions that will reshape our economy, our democracy and the future of humanity,&amp;rdquo; &lt;a href="https://www.sanders.senate.gov/press-releases/news-sanders-yes-we-need-a-moratorium-on-data-center-construction/"&gt;Sanders wrote in February&lt;/a&gt;. &amp;ldquo;We need serious public debate and democratic oversight over this enormously consequential issue.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/10/GettyImages_2281570436/large.jpg" width="618" height="284"><media:description>Sen. Ron Wyden, D-Ore., is seen during votes in the U.S. Capitol on Wednesday, June 17, 2026. </media:description><media:credit>Tom Williams/CQ-Roll Call, Inc via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/10/GettyImages_2281570436/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Federal systems increasingly likely to face accidental AI breach after Hugging Face, experts say</title><link>https://www.nextgov.com/cybersecurity/2026/08/federal-systems-increasingly-likely-face-accidental-ai-breach-after-hugging-face-experts-say/415307/</link><description>Former officials and security experts say aged systems, contractors and agency AI adoption could open similar paths into government networks.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Mon, 10 Aug 2026 11:19:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/federal-systems-increasingly-likely-face-accidental-ai-breach-after-hugging-face-experts-say/415307/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; An OpenAI agent tasked with finding software flaws escaped its testing environment, hacked into Hugging Face and spent days moving through the company&amp;rsquo;s systems in search of answers to an evaluation. It had not been sent to attack the company, yet it did so anyway &amp;mdash; and a smattering of other accidental AI intrusions in separate environments have &lt;a href="https://www.theguardian.com/technology/2026/aug/05/openai-anthropic-models-went-rogue-cybersecurity-test-ai-security-institute"&gt;since followed&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;If the same chain of events began again, former officials and cybersecurity experts told &lt;em&gt;Nextgov/FCW&lt;/em&gt; there is little reason to assume a federal agency would be spared. In interviews during Black Hat and DEF CON this past week, they said aging networks, systems that are not properly separated and the government&amp;rsquo;s heavy reliance on contractors could present weaknesses that would let an unauthorized AI agent move from one environment into another before defenders realize.&lt;/p&gt;

&lt;p&gt;One former federal chief information officer likened the risk to turning loose a hunting dog: &amp;ldquo;If you&amp;rsquo;re going to put your dog in the yard and instruct it to hunt, probably best to ensure the back gate is closed.&amp;rdquo; The former official spoke on condition of anonymity to discuss their views more candidly.&lt;/p&gt;

&lt;p&gt;The&lt;a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/"&gt; July intrusion&lt;/a&gt; began during an internal OpenAI test designed to measure how effectively advanced models could find and exploit vulnerabilities. OpenAI said the agent &amp;mdash; powered by GPT-5.6 Sol and a more capable internal research prototype &amp;mdash; was operating with some security safeguards intentionally reduced.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The agent exploited a previously unknown flaw in an internal package-management service, reached the public internet and commandeered a third-party code sandbox as a staging point. From there, it exploited two flaws in Hugging Face&amp;rsquo;s dataset-processing systems, obtained credentials, executed commands and moved through parts of the company&amp;rsquo;s infrastructure.&lt;/p&gt;

&lt;p&gt;In the leadup to the intrusion, OpenAI models created an internal message board, used it to trade hacking methods and found a way to bring it back even after humans shut it down, company engineers &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/08/openai-agents-rebuilt-internal-message-board-lead-hugging-face-breach/415240/"&gt;said in a presentation&lt;/a&gt; at the cyber conferences this past week.&lt;/p&gt;

&lt;p&gt;The agent deliberately exploited Hugging Face&amp;rsquo;s systems in pursuit of its assigned goal, but OpenAI had not instructed it to attack the company. Bob Costello, who served as chief information officer at the Cybersecurity and Infrastructure Security Agency before becoming chief digital and information officer at Merlin Group, said a similar federal incident could begin with authorized security testing.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;As we start using really advanced AI to operate our systems or penetration-test our systems or blue-red-purple team our systems,&amp;rdquo; he said, &amp;ldquo;maybe one of those kind of goes sideways, [and] takes a lateral system to the side.&amp;rdquo; The color-coding he described refers to red teams that simulate hackers, blue teams that defend systems and purple teams that combine both approaches to find digital weaknesses.&lt;/p&gt;

&lt;p&gt;That possibility is becoming more relevant as agencies begin experimenting with AI agents that can retrieve information and take actions. The General Services Administration is preparing a&lt;a href="https://www.gsa.gov/artificial-intelligence/ai-community-of-practice/events-and-training/2026-ai-hackathon"&gt; governmentwide hackathon&lt;/a&gt; in which federal, state and local employees will build connections between AI systems and agency data and public services, including prototypes that would let AI route data directly to an agency.&amp;nbsp;The work is slated to be conducted exclusively in sandboxed environments and will not involve any access to restricted data or production systems.&lt;/p&gt;

&lt;p&gt;Contractors may keep their federal and commercial systems separate, said Leslie Nielsen, the executive vice president and CISO at Mimecast, but the same employees may still access both: &amp;ldquo;There&amp;rsquo;s lots of people using it from both sides, and getting in through one could eventually lead to the other.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The chances of it happening again, I would say it&amp;rsquo;s going to,&amp;rdquo; he added. &amp;ldquo;Some of these [federal] infrastructures are just so big and, candidly, so old, that there are little nooks and crannies in them, they&amp;rsquo;re going to get teased out.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Asked to assess the likelihood of a comparable federal incident, Ellen Boehm, senior vice president of internet-of-things strategy and operations at Keyfactor, called it &amp;ldquo;pretty likely&amp;rdquo; and placed the odds at &amp;ldquo;seven out of 10.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Michael Leland, vice president and field chief technology officer at enterprise browser provider Island, said some civilian agencies are exposed because &amp;ldquo;they don&amp;rsquo;t have the infrastructure, they don&amp;rsquo;t have the talent, and they haven&amp;rsquo;t spent years building those guardrails or that containment because they didn&amp;rsquo;t have to.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;It shouldn&amp;rsquo;t be different for AI because AI doesn&amp;rsquo;t care where it is,&amp;rdquo; Leland said. &amp;ldquo;It is opportunistic.&amp;rdquo; Agencies that don&amp;rsquo;t do national security work that have lower cyberdefense standards are &amp;ldquo;very much at risk,&amp;rdquo; he added.&lt;/p&gt;

&lt;p&gt;Bob Ackerman, co-founder and managing partner at cyber venture capital firm DataTribe, also said many organizations have embraced powerful AI systems before learning how to reliably control them.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We fundamentally are kidding ourselves that we&amp;rsquo;ve got this under control,&amp;rdquo; Ackerman said. &amp;ldquo;We&amp;rsquo;ve got a really, really powerful tool, but we don&amp;rsquo;t know how to control it yet.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;But people interviewed for this story largely rejected the idea that autonomous agents have rendered the government&amp;rsquo;s existing security playbook obsolete. The Hugging Face campaign relied on recognizable techniques like finding exposed systems, stealing credentials, escalating privileges and moving between connected environments, all of which are problems agencies have faced for years.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;It&amp;rsquo;s really not gonna play out all that differently than if it was a hands-on keyboard actor &amp;hellip; or someone who&amp;rsquo;s writing a script and letting a programmatic algorithm go and do its thing,&amp;rdquo; said Ben Bernstein, who manages the cybersecurity advisors team at Huntress.&lt;/p&gt;

&lt;p&gt;The difference, ultimately, is tempo and scale. An AI hacker can probe potential routes, link digital weaknesses and iterate its maneuvers without the delays of human intervention. Such tools maintain a relentless fixation on specific targets, persisting with an objective well beyond the point where a human operative might question the value of taking their selected intrusion path. On top of it all, they don&amp;rsquo;t need to eat, sleep or take restroom breaks.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;An agent&amp;rsquo;s just a fast hacker at the end of the day, right?&amp;rdquo; Nielsen said. &amp;ldquo;But the one thing the agent doesn&amp;rsquo;t have is a moral or ethical compass. They&amp;rsquo;re given a task and they have focus, and they&amp;rsquo;re going to go do what you&amp;rsquo;ve told them to do.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;David Weston, Microsoft&amp;rsquo;s corporate vice president of agentic security, similarly cautioned against treating the federal government as a fundamentally different kind of target. The approach demonstrated in the Hugging Face breach &amp;ldquo;is going to be a challenge for most folks,&amp;rdquo; he said, but the response still comes down to basic security practices.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Regardless of the target, everyone needs to follow those fundamentals,&amp;rdquo; Weston added.&lt;/p&gt;

&lt;p&gt;Duncan Greatwood, CEO of Xage Security, also said agencies should not rely on simply telling an agent not to perform certain actions because those instructions can be bypassed. Instead, they should use separate security controls that technically prevent the agent from reaching systems or changing data it&amp;rsquo;s not authorized to touch. He described the approach as &amp;ldquo;bounded autonomy.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;You allow the agent to do stuff, but you&amp;rsquo;re not going to allow it to go crazy. You&amp;rsquo;re going to put hard bounds around it,&amp;rdquo; Greatwood said.&lt;/p&gt;

&lt;p&gt;Retired Gen. Paul Nakasone, the former director of U.S. Cyber Command and the NSA who now leads Vanderbilt University&amp;rsquo;s Institute of National Security and sits on OpenAI&amp;rsquo;s board, called the Hugging Face episode &amp;ldquo;an inflection point in terms of AI-generated autonomous cyber attack.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;My question is, how do we ensure that the defense starts to catch up, right?&amp;rdquo; Nakasone said. &amp;ldquo;How do we make sure that artificial intelligence is able to bring together a capable defense that allows us to do vulnerability detection, to do patching, to do incident response, and to do mitigation?&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Editor&amp;#39;s note: This article has been updated to clarify the participants in GSA&amp;#39;s upcoming hackathon and where the work will&amp;nbsp;occur.&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/10/GettyImages_2288181917/large.jpg" width="618" height="284"><media:description> Sam Altman, CEO of OpenAI, leaves a meeting at the U.S. Capitol on July 29, 2026 in Washington, DC. </media:description><media:credit>Kevin Dietsch / Staff  Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/10/GettyImages_2288181917/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Cloudflare to seek DOD IL4 authorization after new FedRAMP, GovRAMP designations</title><link>https://www.nextgov.com/acquisition/2026/08/cloudflare-seek-dod-il4-authorization-after-new-fedramp-govramp-designations/415299/</link><description>The connectivity cloud giant recently achieved FedRAMP High certification and GovRAMP Moderate authorization.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christian Robles</dc:creator><pubDate>Mon, 10 Aug 2026 09:00:00 -0400</pubDate><guid>https://www.nextgov.com/acquisition/2026/08/cloudflare-seek-dod-il4-authorization-after-new-fedramp-govramp-designations/415299/</guid><category>Acquisition</category><content:encoded>&lt;![CDATA[&lt;p&gt;Cloudflare announced Monday it plans to seek Department of Defense Impact Level 4 authorization to bring a platform that can store and process controlled unclassified information to defense agencies.&lt;/p&gt;

&lt;p&gt;The connectivity cloud company also achieved &lt;a href="https://www.fedramp.gov/marketplace/products/FR2000863987A/"&gt;FedRAMP High certification&lt;/a&gt;, which covers civilian federal agencies, Thursday and &lt;a href="https://govramp.org/program-participants#apl"&gt;GovRAMP Moderate authorization&lt;/a&gt;, which covers state and local governments, in April.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;With the FedRAMP High certification, agencies can use Cloudflare for Government to process sensitive information related to national security, critical infrastructure and financial systems, according to a press release. The certification comes shortly after the FedRAMP director &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/after-hugging-face-breach-fedramp-chief-tells-slow-patch-vendors-stay-out-government/414972/?oref=ng-homepage-river"&gt;warned vendors&lt;/a&gt; they should not be allowed to sell products to agencies if they are too slow in patching vulnerabilities.&lt;/p&gt;

&lt;p&gt;With the GovRAMP Moderate authorization, state and local governments can similarly use Cloudflare for Government to protect sensitive information and meet state-specific data privacy mandates, the release said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;FedRAMP High, GovRAMP Moderate, and our intent to pursue DoD IL4 let us bring a platform to federal, state, local, and defense teams to advance their missions, retire legacy technologies, and accelerate their shifts to a more secure, efficient, and innovative future,&amp;rdquo; David Mihalchik, vice president of U.S. public sector at Cloudflare, said in the release.&lt;/p&gt;

&lt;p&gt;The departments of Energy, Health and Human Services, Commerce, Homeland Security, Interior, Justice and State, in addition to other agencies, already use Cloudflare technologies.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/07/080726cloudflareNG/large.jpg" width="618" height="284"><media:credit>Stanislav Kogiku/SOPA Images/LightRocket via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/07/080726cloudflareNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Voting machine researchers say federal work abruptly ended after Trump ally pushed back on their findings</title><link>https://www.nextgov.com/cybersecurity/2026/08/voting-machine-researchers-say-federal-work-abruptly-ended-after-trump-ally-pushed-back-their-findings/415300/</link><description>Mojave Research executives said at DEF CON that the government had been preparing to expand the company’s election security work, and linked Trump adviser Kurt Olsen to pressure they faced after finding election system vulnerabilities but no evidence votes were altered.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Sun, 09 Aug 2026 06:00:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/voting-machine-researchers-say-federal-work-abruptly-ended-after-trump-ally-pushed-back-their-findings/415300/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; After spending roughly six weeks analyzing Dominion voting systems used in Puerto Rico&amp;rsquo;s 2024 elections, Mojave Research came back to the Trump administration with findings that startled its researchers.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The systems contained at least a dozen high- or critical-severity software vulnerabilities. Passwords were reused, firewalls were disabled and basic cryptographic protections were poorly implemented. And in Puerto Rico, active cellular hardware modems opened additional pathways into underlying software that was thought to be isolated.&lt;/p&gt;

&lt;p&gt;But the small cybersecurity firm found no evidence that any of those weaknesses had actually been exploited, or that votes had been changed. The company still wanted more time to be certain.&lt;/p&gt;

&lt;p&gt;Federal officials initially seemed willing to give them considerably more of it. The company was asked to grow the team working on the effort from roughly 10 people to about 60, according to CEO Jason Wareham.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Chief Technology Officer Manbir Gulati also said Mojave received an authorization to proceed with a follow-on effort, hired personnel and was given funding to acquire equipment for examining additional voting systems ahead of the November midterms. A contracting officer had even been brought in to finalize the new agreement, Gulati said.&lt;/p&gt;

&lt;p&gt;Then, as Mojave prepared to move ahead, the work was abruptly shut down.&lt;/p&gt;

&lt;p&gt;Wareham and Gulati recounted the episode on Friday at DEF CON hacker convention&amp;rsquo;s Voting Village, where they publicly unpacked their technical findings before sitting down with a small group of reporters and onlookers afterward.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Their account fills in new details about a federal effort that grew out of the Trump administration&amp;rsquo;s broader focus on voting machines and election interference, and the political pressures that emerged when Mojave&amp;rsquo;s findings did not support claims of election manipulation.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The ODNI request&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Mojave never set out to become an election security provider. Its involvement began last year through the Office of the Director of National Intelligence under then-director Tulsi Gabbard, where it was already performing unrelated technical work for the agency when officials approached the company about examining voting machines and data obtained from Puerto Rico.&lt;/p&gt;

&lt;p&gt;Reuters &lt;a href="https://www.reuters.com/world/americas/us-spy-chiefs-office-investigated-voting-machines-puerto-rico-2026-02-04/"&gt;reported&lt;/a&gt; in February that the May 2025 operation was tied to an effort involving ODNI and the FBI to investigate allegations that Venezuela had hacked Puerto Rico&amp;rsquo;s voting systems, though Gabbard&amp;rsquo;s office denied that Venezuela drove its work and said the examination was focused on technical vulnerabilities. The probe produced no clear evidence of Venezuelan interference.&lt;/p&gt;

&lt;p&gt;Wareham said at DEF CON that ODNI asked whether his team of reverse engineers and forensic specialists could travel to Puerto Rico and capture an image of a voting system that had actually been used in an election, without the vendor overseeing the process. He agreed, thinking it would be a relatively small addition to Mojave&amp;rsquo;s existing contract.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The assignment instead dropped Mojave into a much larger skirmish over American elections. &amp;ldquo;Ultimately, I made the worst decision of my life in a business context,&amp;rdquo; Wareham said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;President Donald Trump has spent years falsely maintaining that his 2020 loss was stolen and the product of widespread fraud and foreign interference, claims that have been rejected by courts and officials in his own administration. A 2021 intelligence community &lt;a href="https://www.intel.gov/assets/documents/702-documents/declassified/ICA-declass-16MAR21.pdf"&gt;assessment&lt;/a&gt; found no indication that a foreign actor attempted to alter ballots, vote tabulations or any other technical aspect of the election.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Since returning to office, Trump and allies have revived investigations into the 2020 contest and pushed election security back to the center of his administration&amp;rsquo;s agenda. Gabbard&amp;rsquo;s ODNI was &lt;a href="https://www.nextgov.com/people/2026/02/gabbards-expanded-role-election-security-draws-scrutiny/411295/"&gt;one part of that effort&lt;/a&gt;, hauling off and analyzing voting systems from Puerto Rico and later becoming involved in a federal investigation of 2020 election records in Georgia.&lt;/p&gt;

&lt;p&gt;Wareham said the ODNI officials directly overseeing the company&amp;rsquo;s technical work wanted the research to continue. Both he and Gulati described the ODNI staff they worked with as professionals who wanted to protect the security of election systems.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The resistance, Wareham said, came from a separate White House collective that was repeatedly dissatisfied Mojave had not produced evidence supporting claims that the 2020 election had been manipulated.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;There was a separate group &amp;mdash; let&amp;rsquo;s call them White House-adjacent &amp;mdash; who was dissatisfied,&amp;rdquo; he said. &amp;ldquo;They were dissatisfied overall that I was not willing to name and shame at that moment&amp;rdquo; and declare that Trump had actually won the 2020 election.&lt;/p&gt;

&lt;p&gt;Asked whether he believed Mojave&amp;rsquo;s government work was axed because it failed to find the &amp;ldquo;smoking gun&amp;rdquo; some officials wanted, Wareham said: &amp;ldquo;I believe that was part of the termination, yes.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Reuters reported in April that Kurt Olsen, a prominent 2020 election-denier and Trump adviser involved in efforts to investigate the election, &lt;a href="https://www.reuters.com/world/us/trump-aides-chase-vote-rigging-claims-even-after-latest-probe-finds-nothing-2026-04-23/"&gt;pressed Mojave&lt;/a&gt; to broaden its work in search of evidence that could support those claims.&lt;/p&gt;

&lt;p&gt;Olsen, who now works at the Justice Department, turned against the company when its research failed to uncover evidence that the Puerto Rico machines had been hacked. He advocated terminating its work and accused Mojave of secretly receiving money from billionaire George Soros, a frequent target of right-wing conspiracy theories, the news agency reported. ODNI has said Mojave&amp;rsquo;s contract ended because the company completed its voting-machine analysis.&lt;/p&gt;

&lt;p&gt;Wareham said an ODNI official informed him while Mojave was preparing to expand its work that the company had been accused of receiving Soros funding. The allegation prompted him to compile a detailed accounting of the young company&amp;rsquo;s funding sources within three days and send it up the government chain. Asked who he was told had made the accusation, he said an ODNI official reported to him that it was Olsen.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;One, I&amp;rsquo;m not funded by George Soros,&amp;rdquo; Wareham said. &amp;ldquo;Two, it would be great to be funded by George Soros because I would probably not be here, I&amp;rsquo;d be on a yacht.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The company kept moving forward. Wareham said Mojave briefed the White House on some of its findings around September. The firm believed it was heading toward a broader effort to remediate vulnerabilities before the midterms and conduct a deeper analysis for signs that the weaknesses it discovered had ever been actually abused.&lt;/p&gt;

&lt;p&gt;Then came the record-long &lt;a href="https://www.govexec.com/management/2025/11/government-reopen-after-house-votes-end-longest-ever-shutdown/409477/?oref=ge-topic-lander-river"&gt;government shutdown&lt;/a&gt;. Wareham said that on the day he expected an expanded contract to move ahead, Mojave instead received a stop-work order and no additional funding.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I think the government shutdown was all that was required, really, to have some folks that I didn&amp;rsquo;t know were still in the game, again, White-House adjacent, to take their shot,&amp;rdquo; he said. Wareham stopped short of saying he had direct proof that White House officials ordered Mojave removed because of its findings, but said &amp;ldquo;it was reported to me it was Kurt Olsen&amp;rdquo; who led the efforts.&lt;/p&gt;

&lt;p&gt;The White House, ODNI and Olsen did not return requests for comment.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Identified vulnerabilities&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Mojave had found many issues with the machines it examined. Gulati described the Puerto Rico system during the Voting Village presentation as &amp;ldquo;deeply insecure,&amp;rdquo; saying it did not meet the security bar he would expect from &amp;ldquo;an average low-risk application, let alone critical infrastructure.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Researchers identified at least 12 major vulnerabilities in commercial software installed on the system, Gulati said. Mojave successfully executed five of them. None were newly discovered flaws, and fixes were already available &amp;mdash; in some cases well before the system was used in the election.&lt;/p&gt;

&lt;p&gt;Other weaknesses were rooted more deeply in how the system was built and deployed. Some passwords could be easily cracked and others were embedded directly into software. Firewalls were turned off on critical systems and ports were left open. Gulati was particularly critical of the system&amp;rsquo;s cryptography, which he described as being &amp;ldquo;in shambles.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The company does not believe every problem it found necessarily stopped at Puerto Rico, as its formal review covered only one system from one manufacturer in one jurisdiction. Gulati suspects the issues could extend beyond a single voting machine company, though Mojave has not examined enough systems from other manufacturers to establish that.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I don&amp;rsquo;t expect that the problems are unique to them,&amp;rdquo; he said. &amp;ldquo;I think many manufacturers probably exhibit the same problems.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Mojave produced an approximately 100-page document of the Puerto Rico findings. Gulati said Mojave has been in discussions with Liberty Vote &amp;mdash; which acquired Dominion&amp;rsquo;s election business last year &amp;mdash; and that Liberty told the researchers it does not plan to make changes before November.&lt;/p&gt;

&lt;p&gt;Liberty said it has not received Mojave&amp;rsquo;s report.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Liberty Vote is not in receipt of any such report so, therefore, we cannot provide any comment,&amp;rdquo; a spokesperson said. &amp;ldquo;As always, Liberty Vote is committed to advancing the future of secure American elections.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;No evidence of vote tampering&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Looking at the systems headed into the midterms, Gulati said, &amp;ldquo;I do know that as of now, the state that we have described is going to be pretty similar to what will be deployed in November.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Despite the extensive findings, Gulati repeatedly returned to what the researchers did not establish: &amp;ldquo;We found extensive and largely unacceptable weaknesses,&amp;rdquo; he said in the presentation. &amp;ldquo;But we did not find evidence that those weaknesses were actively exploited or that votes were altered.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;That distinction has drawn renewed attention as Trump and his allies again focus on election matters.&lt;/p&gt;

&lt;p&gt;Last month, the president used a prime-time White House address to release newly declassified intelligence he said showed China interfered in the 2020 election. Among several disclosures, Trump pointed to intelligence showing Beijing had acquired personal information on roughly 220 million American voters. But the documents &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/trump-stretches-declassified-china-intelligence-broader-2020-election-claims/414837/"&gt;did not show&lt;/a&gt; China altered votes or gained the ability to manipulate voting systems.&lt;/p&gt;

&lt;p&gt;Gulati echoed those conclusions Friday when asked about the declassification.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The China thing isn&amp;rsquo;t really much of anything,&amp;rdquo; he said, arguing that a large amount of the voter information at issue could be obtained commercially and should not be confused with access to election systems in ways that can manipulate votes.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;There is no evidence that I know of that says China successfully or any other country has successfully infiltrated our systems and manipulated votes in any way,&amp;rdquo; he added.&lt;/p&gt;

&lt;p&gt;Wareham called the 100-page document a preliminary report and said the firm had wanted another six months to a year to dig deeper into the underlying data.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Gulati said the company&amp;rsquo;s interactions with the ODNI employees overseeing that work were markedly different from the political pressure the researchers later encountered. &amp;ldquo;We were never pressured to put anything in our reports that was untrue or politically leaning in a certain way,&amp;rdquo; he said of those officials.&lt;/p&gt;

&lt;p&gt;Wareham said Friday that Mojave itself has pushed for its report to be made public for roughly a year and has recently been told it could soon emerge through a Freedom of Information Act request. &lt;em&gt;Nextgov/FCW&lt;/em&gt; could not immediately determine the origin of the FOIA requester. As of publishing time, ODNI&amp;rsquo;s FOIA logs are &lt;a href="https://archive.dni.gov/index.php/foia#:~:text=ODNI%20FOIA%20Logs,January%202025"&gt;available up until January 2025&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I&amp;rsquo;m a little annoyed that we are very close to midterms and we had a whole year to freaking figure this out,&amp;rdquo; Wareham said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;With their government work scrapped, he announced at the Voting Village that he had filed paperwork to create the &lt;a href="https://vote.machineassurance.org/"&gt;Machine Assurance Institute&lt;/a&gt;, seeking to bring together cybersecurity researchers and election technology companies to examine and independently verify voting infrastructure.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We wanted to be the national security answer, and put to bed, finally, discussions about prior elections and/or accusations of voter fraud,&amp;rdquo; said Wareham. &amp;ldquo;Because, believe it or not, I find it fairly national security-destabilizing to constantly accuse each other of cheating.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/09/GettyImages_1289778741/large.jpg" width="618" height="284"><media:credit>eyecrave productions / Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/09/GettyImages_1289778741/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Senate confirms Adam Cassady to run State Department cyberspace bureau</title><link>https://www.nextgov.com/people/2026/08/senate-confirms-adam-cassady-run-state-department-cyberspace-bureau/415292/</link><description>The confirmation comes as the tech diplomacy shop he would traditionally lead in his new role has seen significant reorganizations in the last year.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Fri, 07 Aug 2026 15:24:00 -0400</pubDate><guid>https://www.nextgov.com/people/2026/08/senate-confirms-adam-cassady-run-state-department-cyberspace-bureau/415292/</guid><category>People</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Senate on Friday confirmed Adam Cassady as the new U.S. ambassador for cyber and digital policy, filling a high-profile role that had been vacant since the start of the second Trump administration.&lt;/p&gt;

&lt;p&gt;Cassady, currently a senior official at the National Telecommunications and Information Administration, was approved in a 51-47 vote as part of a package of some 70 nominees.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The Bureau of Cyberspace and Digital Policy, which traditionally is led by the person named to the position he was just confirmed for, has undergone significant workforce changes. A &lt;a href="https://www.nextgov.com/policy/2025/04/state-department-moves-cyber-and-intelligence-bureaus-under-agencywide-reorg/404753/"&gt;reorganization&lt;/a&gt; last year saw the bureau divided into three separate entities, including a new Bureau of Emerging Threats, and a reduction in overall staff.&lt;/p&gt;

&lt;p&gt;The cyber bureau has mainly focused on international diplomacy for U.S. cyberspace, telecommunications and emerging technologies, and has sought to counter authoritarian tech practices. It was formally launched in 2022 under then-president Joe Biden. Cassady&amp;rsquo;s purview is not entirely clear under the new organizational structure imposed over the last year.&lt;/p&gt;

&lt;p&gt;Under the Biden administration, the unit was headed by retired U.S. Marine Corps officer and technology executive Nate Fick, who used his position to take &lt;a href="https://www.nextgov.com/cybersecurity/2024/05/us-diplomats-told-china-stop-volt-typhoon-campaign-its-becoming-more-advanced-intelligence-officials-say/396361/"&gt;firm stances&lt;/a&gt; against Chinese officials when addressing Beijing-backed cyber intrusions into U.S. critical infrastructure.&lt;/p&gt;

&lt;p&gt;During his April confirmation hearing, Cassady emphasized a need for international collaboration on secure and resilient digital systems. He also sidestepped giving a definitive stance on the export of &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/04/experts-call-halt-ai-chip-exports-china-after-white-house-distillation-warning/413132/"&gt;advanced semiconductor chips&lt;/a&gt; to China, saying he would &amp;ldquo;very, very quickly develop&amp;rdquo; a position on the issue.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;As NTIA&amp;rsquo;s Deputy Administrator, Adam was critical to many of the agency&amp;#39;s most significant achievements in advancing America&amp;rsquo;s technology leadership and protecting our interests abroad,&amp;rdquo; NTIA head Arielle Roth said in a statement. &amp;ldquo;His experience makes him exceptionally well-suited to represent America&amp;rsquo;s strength on the world stage.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/07/080726StateNG/large.jpg" width="618" height="284"><media:credit>Li Rui/Xinhua via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/07/080726StateNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item></channel></rss>