ai-cybersecuritytrade-pressNewsThe Broadside2 min read

Data-in-Use Gap Dogs DoD's AI-First Ambitions

An AI model holding classified data in plaintext memory is a standing invitation to the insider threat, and current federal frameworks don't address the problem.


TL;DR

Marine Corps CIO Colin Crosby told AFCEA NOVA Naval IT Day that the Secretary of Defense has directed DoD to become "an AI-first warfighting force." The ambition collides with an underexamined problem: on most infrastructure, an AI model processing classified data holds it in plaintext memory, where any system administrator, or anyone with a compromised credential, can read it. Data-at-rest and data-in-transit encryption are mature; data-in-use protections aren't, and the NIST AI RMF and related federal guidance largely treat AI security as a model-performance and privacy-policy problem, not a memory-level one.

When Marine Corps CIO Colin Crosby told AFCEA NOVA Naval IT Day that the Secretary of Defense wants an "AI-first warfighting force," he was telegraphing more than ambition. He was describing a future in which AI models process classified intelligence and operational plans as a matter of routine. The cybersecurity architecture for that future, however, hasn't caught up to the ambition.

The problem sits at a layer most AI security conversations skip. Data-at-rest encryption protects stored models and training sets. Data-in-transit encryption protects network traffic. But when an AI model computes, holding classified data in memory to generate an inference or analyze a target, that data sits in plaintext. A system administrator with legitimate console access, or an attacker who compromises an admin credential, can read it directly. No firewall is breached. No malware is deployed. The access is, technically, authorized.

This isn't a theoretical worry for commercial cloud tenants. For DoD, it should be disqualifying. Air-gapped networks help but don't solve the problem: they block remote attacks, not console access. The threat is inside the perimeter.

The commentary, published by Federal News Network, argues that hardware-based confidential computing, in which technologies like AMD SEV and Intel TDX encrypt data in use at the silicon level, is the missing architectural layer. That's worth noting for what it is: an argument made by an industry participant with a commercial stake in the category. But the underlying observation stands regardless of who's making it. Current federal AI security frameworks, including the NIST AI Risk Management Framework and the guidance flowing from EO 14110, treat AI security primarily as a model-level concern: accuracy, bias, explainability, privacy policy. Memory-level data-in-use protections are largely absent from the conversation.

For the practitioner, the immediate question is whether any AI workload handling CUI or classified data is running on infrastructure that assumes administrative visibility into memory is benign. It almost certainly is. That's not a vulnerability to patch. It's an architectural assumption to revisit.


Published ·Deep Fathom

Data-in-Use Gap Dogs DoD's AI-First Ambitions — The Broadside