AI has shortened the distance between discovery and exploitation considerably, and the acquisition system has not kept pace.
Federal agencies rarely struggle to identify their cyber risks. They struggle to close them in time. A June Government Accountability Office report on federal cloud procurement confirmed that of the 24 major agencies GAO reviewed, 15 said outdated federal acquisition regulations directly slowed their ability to procure technology. The same number reported difficulty obtaining solutions they had already identified as necessary. Funding existed in many cases and the awareness was there, but the path to actually buying the fix did not move fast enough to meet agency needs.
This gap matters more now for cybersecurity practitioners because artificial intelligence has changed the clock attackers operate on. Vulnerabilities that once took weeks or months to exploit can now be identified and weaponized in hours. AI tools scan for exposed systems, automate credential attacks, and adapt in real time as defenses respond. Meanwhile, the process federal agencies use to authorize and purchase a fix has not sped up to match. The result is a widening gap between how fast threats move and how fast government can respond to them.
The problem is structural, not a lack of urgency
Picture a fairly common scenario playing out inside a federal agency: A chief information security officer identifies a critical gap in vendor visibility or endpoint protection, and the team already knows exactly which tool would close it. The trouble is that the fiscal year’s funding was allocated eighteen months earlier, long before anyone knew this particular gap would exist. Moving money to cover it usually means going through formal reprogramming, a process that exists for good reason, but was never built to move quickly. Even when a contract vehicle is technically available, it may not actually cover the specific capability the team needs, which can mean the search for a faster path has to start from scratch at the worst possible moment.
Although these individual steps exist to keep spending accountable and deliberate, all together, they assume a threat environment that may no longer exist. In a perfect world, adversaries could reasonably be expected to move at a pace roughly matched to the government’s own planning cycles, but AI has quietly eroded that assumption, and the officials who watch this play out day to day are usually the ones most aware of how far behind it can leave them. The slowdown rarely comes from a failure of leadership or will. It tends to come from a system built for predictability trying to keep pace with a threat environment built for speed.
What agencies can do about it
Fixing this may not require new legislation, though regulatory modernization could certainly help. Much of the progress agencies can make starts with two things fully within their own control, well before any crisis forces the issue.
- Shrink the distance between finding a gap and having time to close it.
Most agencies still learn how serious a risk is at roughly the same moment they need to act on it, largely because assessments happen annually while the underlying risk shifts daily. That collapsed timeline is often what turns a fixable problem into a genuine emergency with little runway left.
Continuous, real-time visibility can change that math by giving agencies something the acquisition process may never manufacture on its own: lead time. With enough lead time, a budget conversation might start months before a threat becomes acute, which could make the difference between funding a fix on a normal cycle and scrambling for emergency dollars after the damage is done.
- Pre-build the path to yes, long before it is needed.
The slowest part of federal buying rarely comes from the final decision itself. It tends to come from everything that has to happen first, as teams work out which contract vehicle applies, who owns the budget line, and who needs to sign off.
Agencies that map their fastest available acquisition path ahead of time, and confirm it genuinely covers the capability they are likely to need, can remove much of that discovery process from the timeline the moment a real gap shows up. What might otherwise become a scramble can instead turn into a sequence the team has already walked through.
Alongside these two, public-private partnerships help close what internal reform alone cannot. No agency builds all of its own threat visibility from scratch, and much of the most current intelligence on emerging risk lives with industry. Agencies that treat these relationships as standing infrastructure, built well before they are needed, may find support arrives faster when it actually matters, simply because the trust already exists.
The bottom line
Government generally has the tools, the talent, and often the funding required to defend against modern cyber threats. What it may still lack is a buying process that can match the speed those threats now move at. AI has shortened the distance between discovery and exploitation considerably, and the acquisition system has not kept pace. Closing that gap will likely come down to agencies that can see risk early enough to act on it, that already know their fastest path to a yes, and that treat industry relationships as part of their defense rather than a transaction to work out later. The next GAO report on this subject should not have to say the same thing twice.
Mike Centrella is head of public policy at SecurityScorecard.
Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.
