Outpaced: AI and Policy’s Role in Transforming Cybersecurity Compliance : Center for Security and Emerging Technology , August , 2026
From the report: "American commercial industry leads the world in software development and artificial intelligence (AI). That advantage does not automatically transfer to the military. The federal cybersecurity compliance process is a major barrier between America’s most advanced technologies and the warfighters who need them. The Authorization to Operate (ATO) is the federal government’s formal mechanism for assessing and approving software systems. However, the ATO process and its governing framework—the Risk Management Framework (RMF)—are described as ineffective, slow, duplicative, and in need of reform. Bureaucratic delays can carry a devastating cost. A former intelligence officer describes just how high those stakes can be: “I firmly believed that software was the reason that a bunch of civilians had died. . . . We had critical fixes like known operational issues that were causing operational risk that were sitting on the shelf waiting to go through the ATO process.”
Prior research has documented ATO process inefficiencies within specific service contexts and cataloged security shortfalls. This paper is the first analysis to examine not only the process itself but the foundational legal authorities, competing stakeholder incentives, and governance structures that collectively produce delays. This paper also assesses why reforms have not solved these issues, despite sustained attention over more than a decade. A summary of the analysis is captured in Figure 1."
Authors - Carroll, KatherineSubjects
Authors
Publishers
Format
Related Resources