Federal security still guards a perimeter the data crossed long ago
CISA's AI collaboration playbook and planned info-sharing center already presuppose data flowing across agency lines, but most federal security architectures still defend a network border.
TL;DR
A NextGov commentary argues federal agencies are still defending network perimeters while their data disperses across cloud environments and AI training pipelines. The piece calls for security that travels with the data rather than waiting at the border. CISA's own AI collaboration infrastructure, from the JCDC AI playbook to the in-development AI-ISAC, already assumes data and incidents will cross organizational lines. Agency security architectures haven't caught up to that assumption.
The NextGov/FCW commentary, published July 29, argues that the perimeter security model federal agencies have relied on for years no longer matches how government actually works. Mission data now lives in cloud services and on edge devices; it feeds the AI training pipelines agencies are racing to build. None of these respect the network boundary the old model was built to guard. The piece contends that agencies need data-centric protection: detection at the storage layer, controls that travel with the data across environments, and recovery plans that span on-prem systems and multiple cloud environments.
CISA's own recent work points in the same direction. The JCDC AI Cybersecurity Collaboration Playbook, published in January 2025, provides guidance for voluntary information sharing about AI system incidents and vulnerabilities across the AI community: government, providers, developers, and adopters. The playbook was shaped by two tabletop exercises involving roughly 150 AI specialists, and CISA describes it as a living document that'll adapt as the AI security environment evolves. Meanwhile, the AI Information-Sharing and Analysis Center ordered by the White House's AI strategy remains in development. CISA's Nick Andersen told reporters in February 2026 that talks were ongoing but there was no completion timeline, and that the agency wanted to avoid duplicating existing private-sector information-sharing efforts.
The operational model CISA is building assumes data and incidents will move across agency and industry boundaries. Shared threat intelligence, cross-organizational incident response, and formal channels for AI vulnerability disclosure all presuppose information that doesn't stop at the network edge. The commentary's argument is that most federal security architectures still don't. Whether that gap narrows won't depend on another strategy document. It'll depend on whether agencies reallocate resources from border defense to protection that follows the data.
Published ·Deep Fathom