OMB says compliance bottlenecks still slow agency AI deployments
FedRAMP 20x has cut authorization time from over a year to five weeks for the pilot, but federal CIOs still can't get AI capabilities fielded at the speed they want, and the shadow IT that results is a feature of the compliance burden, not a side effect.
TL;DR
OMB federal cybersecurity branch director Nick Polk told a Digital Government Institute summit that reducing compliance bottlenecks for frontier AI model access is a "clear focus" of the federal CIO. FedRAMP 20x has accelerated (114 authorizations in FY 2025, four AI services through the 20x pilot) but Polk said no agency CIO is satisfied with time-to-ATO. CISA and Treasury are doing the operational learning, with CISA deploying Anthropic's Claude Mythos since June to scan federal open-source repos for vulnerabilities. Polk also flagged the identity-threat vector: North Korean actors are using AI capabilities to escalate federal credential attacks.
Nick Polk, OMB's branch director for federal cybersecurity, delivered a diagnosis at the Digital Government Institute's July 28 summit that will resonate with every federal CISO who's ever fought an ATO timeline: "I have not met a CIO that doesn't want to reduce the time to get an Authority to Operate."
That's despite real acceleration. GSA's FedRAMP 20x pilot hit 114 authorizations in FY 2025 (more than double the FY 2024 total) and collapsed average authorization time from over a year to roughly five weeks. Four AI services have moved through the Phase One pilot. The first three AI Prioritization FedRAMP 20x Low authorizations are expected in January 2026. But Polk's framing suggests the bottleneck isn't a backlog problem anymore; it's a structural one.
Who's doing the work
CISA received access to Anthropic's Claude Mythos in June and is using it to scan federal open-source repositories for vulnerabilities. Treasury is running parallel operational trials. Both are effectively the government's test fleet for frontier AI models in defensive cybersecurity roles. Polk said OMB is leaning on them to "spread the best practices around," which is the nice way of saying the rest of government hasn't caught up.
The White House launched Gold Eagle, its AI cybersecurity clearinghouse mandated by Trump's June 2 frontier AI executive order, on July 14, with Treasury leading in coordination with CISA and DoD. CISA issued a binding operational directive on June 10 pushing risk-based vulnerability prioritization, one of the EO's direct taskings.
The shadow IT warning
Polk made an argument that compliance teams rarely hear stated this bluntly: shadow IT isn't a discipline problem, it's a capacity signal. "If your enterprise system requires so much compliance, so much paperwork, so much time to get authorized, you are going to have shadow IT." His framing treats unauthorized tooling as a natural response to an authorization process that can't keep pace with mission demand, and he tied it directly to the AI deployment problem.
He also flagged that AI capabilities are now being used against federal identity systems, citing an ongoing North Korean campaign targeting federal credentials. The attack surface isn't theoretical.
Published ·Deep Fathom