procurementtrade-pressNewsThe Broadside1 min read

GAO finds acquisition bottlenecks slow federal threat response

The speed gap isn't new, but AI-accelerated exploitation timelines mean procurement delays that were once tolerable are now a structural vulnerability.


TL;DR

A June GAO report found that 15 of 24 major federal agencies cited outdated acquisition regulations as directly slowing their ability to procure technology. The same number reported difficulty obtaining solutions they'd already identified as necessary. The finding lands as AI tools shrink the disclosure-to-exploitation window from weeks to hours, a mismatch the acquisition system, designed for predictability, was never built to absorb.

The GAO finding isn't a surprise to anyone inside a federal security team. What's shifted is the cost of the delay.

NCSC Chief Technology Officer Ollie Whitehouse warned in May that organizations must prepare for a "vulnerability patch wave" driven by AI's growing ability to identify and exploit technical debt at speed and scale. The models that can scaffold production code faster than any team by hand are increasingly capable of finding unpatched vulnerabilities just as quickly, two sides of the same advancement, moving in parallel. In internal testing, Anthropic's Claude Mythos Preview autonomously discovered a 27-year-old remote code execution vulnerability in OpenBSD that had survived five million automated security scans.

CISA has already moved. Its June 10 binding operational directive now requires federal agencies to patch the highest-risk vulnerabilities on internet-exposed devices within three days, down from the historical average of two to three weeks. Jay Gazlay, CISA's acting associate director for vulnerability management, called the shift a correction of "mistakes we made with previous BODs," refocusing agencies on where they should spend time patching "and more importantly, where they shouldn't."

But patching faster doesn't help if the tool that applies the patch still takes 18 months to buy. The Professional Services Council's Stephanie Kostro, speaking to Federal News Network in August, noted that GSA's draft AI terms-of-service clause (revised after industry pushback) illustrates how even a single contract clause can take months to get right. Multiply that across the full acquisition lifecycle, and the math doesn't close.

The officials who live this aren't slow because they're indifferent. They're operating a system that was built for predictability, in an environment where predictability is gone. That's not a funding problem. It's a time problem, and the clock is only getting faster.


Published ·Deep Fathom

GAO finds acquisition bottlenecks slow federal threat response — The Broadside