TL;DR: Federal agencies have more than doubled AI use since 2023, with HHS, VA, DHS, and DOI representing half of reported use cases, while cloud sprawl and legacy systems keep data visibility patchy, according to Cyera. The core issue is no longer just compliance, but proving continuous control over sensitive data as AI expands access paths.
Editorial analysis by NHI Mgmt Group, based on content published by Cyera: “Trust in the Age of AI: Why Cyera Is Bringing Data Security to the Federal Frontlines”.
By the numbers:
- Federal agencies have more than doubled their use of AI since 2023.
Key questions
Q: How should state agencies govern AI tools that can reach sensitive data?
A: State agencies should inventory every AI-connected access path, assign an owner, and require a revocation path before the tool is allowed to touch internal data.
Q: Why does patchy data visibility create more risk for federal AI programmes?
A: Because AI expands the number of paths that can touch the same sensitive data, and weak visibility makes those paths hard to inventory, review, or defend.
Q: What breaks when agencies cannot prove continuous control over AI-used data?
A: Governance breaks at the point where security teams can no longer explain where data lives, who can access it, or whether the current access state matches policy.
Practitioner guidance
- Define the data access surface Map which AI workflows, services, and operator roles can reach regulated federal data, then assign a control owner for each path.
- Unify data discovery with entitlement review Correlate sensitive data discovery, cloud permissions, and legacy system entitlements so reviewers can see the same estate that AI can query.
- Separate compliance evidence from runtime control Use FedRAMP evidence to satisfy baseline assurance, then add operating controls that can explain and restrict AI access to sensitive data in real time.
Bottom line: Federal AI adoption is exposing a governance gap where data access and visibility matter more than policy statements alone.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Federal AI governance is now an access governance problem. The article is right to move the conversation away from generic compliance language and toward data reachability. When AI systems are introduced into federal workflows, the primary question becomes which identities, services, and tools can surface sensitive data at runtime. That shifts the control conversation from static policy to governed access paths, and practitioners should treat that as an IAM and data security design issue, not a model-only issue.
A few things that frame the scale:
- Business leaders plan to spend $124 million on average on AI in 2026, and 91% say data security and risk will shape their AI strategy.
A question worth separating out:
Q: Should agencies treat FedRAMP as sufficient for AI data security?
A: No. FedRAMP is a baseline for assurance, but AI-enabled data access needs runtime context about sensitivity, purpose, and exposure. Agencies should use the framework to establish minimum trust and then add continuous visibility and access governance for the actual operating environment.
👉 Read our full editorial: AI data security for federal agencies is becoming an access problem