Blog Zscaler
Recevez les dernières mises à jour du blog de Zscaler dans votre boîte de réception
M-25-21 Changes the AI Conversation for Federal Civilian Agencies
This is the first post in a three-part series on AI security and governance for Federal Civilian agencies.
Bottom line up front: OMB Memorandum M-25-21 makes AI adoption an agency operating priority. But the memo also makes clear that speed without governance, security, and public trust isn't acceptable. For Federal Civilian AI leaders, the practical challenge is broader than most realize. AI risk extends well beyond employees using public GenAI tools.
AI is quickly becoming part of how Federal Civilian agencies work.
Used well, it can improve citizen services, reduce manual work, modernize legacy processes, strengthen cybersecurity operations, support research and analysis, assist with fraud detection, speed up software development, and help employees work more efficiently.
But AI adoption in government is different from AI adoption in the private sector.
Federal agencies have to account for public trust, privacy, cybersecurity, civil rights, records management, procurement integrity, transparency, data protection, and mission accountability. When AI touches citizens, benefits, grants, inspections, regulatory processes, healthcare, financial data, enforcement activity, or other sensitive workflows, the risk profile changes.
OMB Memorandum M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust, speaks directly to this tension.
The memo makes a clear point: agencies should move faster with AI, but not by setting aside governance, safeguards, or public trust. They need to innovate while making sure AI is secure, accountable, privacy-aware, risk-managed, and aligned to mission outcomes.
For AI technology executives and AI security leaders, the practical question is: How do we help the agency use AI faster while still maintaining the visibility, control, and evidence needed to govern it responsibly?
More than a compliance memo
M-25-21 signals that AI adoption is now an agency operating priority.
The memo directs agencies to promote responsible AI adoption while putting safeguards in place for privacy, civil rights, civil liberties, cybersecurity, and public trust. It also reinforces core responsibilities: designating or retaining a Chief AI Officer, convening AI governance bodies, updating internal policies, developing generative AI acceptable-use policies, maintaining AI use case inventories, implementing risk management practices for high-impact AI, and documenting governance decisions.
For Federal Civilian agencies, this means AI governance can't live only in strategy documents, governance boards, or spreadsheets.
It has to be enforceable.
Agencies need to answer basic but difficult questions. What AI tools are people using? Who's using them? Which use cases are approved, experimental, or unmanaged? What data is being shared? Which SaaS applications have embedded AI? Which developer tools are using AI? Which cloud workloads are calling models or agents? Which AI applications are connected to sensitive government data? Which systems may qualify as high-impact AI? Which systems have been tested before deployment?
These aren't just policy questions. They're operational questions.
Federal Civilian AI risk is broader than public GenAI
A lot of AI security conversations start with public GenAI tools, specifically employees pasting sensitive information into ChatGPT, Gemini, Claude, or similar services.
That risk is real. But it's only one part of the picture.
AI is now showing up across the agency technology environment: public GenAI applications, SaaS platforms with embedded AI, desktop tools, browser extensions, coding assistants, IDE (Integrated Development Environment) plugins, cloud AI services, foundation models, agency-built AI applications, RAG (Retrieval-Augmented Generation) systems, agents, MCP (Model Context Protocol) servers, API-based model integrations, and automation workflows.
AI may appear in places that aren't obvious to security, governance, or mission leaders.
An analyst might use a public AI tool to summarize a report. A grants office might rely on an AI-enabled SaaS workflow. A benefits program might experiment with an AI assistant. A developer might use an AI coding assistant to modernize a legacy application. A cloud team might deploy a model in AWS GovCloud or Azure Government. A program office might pilot an AI-powered citizen service experience. A security operations team might use AI to support triage and investigation.
Those use cases don't carry the same risk. They shouldn't all get the same controls. And they may create different governance obligations under M-25-21.
Agencies need a lifecycle approach to AI security and governance, one that connects M-25-21's policy direction to enforceable, repeatable execution. We'll lay out that operating model in the next post in this series.
To learn more about how Zscaler helps Federal Civilian agencies secure AI adoption, reach out to your Zscaler account team for a detailed overview of our AI Security capabilities.
Next in this series: A Practical Framework for Secure AI Adoption in Federal Civilian Agencies
Cet article a-t-il été utile ?
Clause de non-responsabilité : Cet article de blog a été créé par Zscaler à des fins d’information uniquement et est fourni « en l’état » sans aucune garantie d’exactitude, d’exhaustivité ou de fiabilité. Zscaler n’assume aucune responsabilité pour toute erreur ou omission ou pour toute action prise sur la base des informations fournies. Tous les sites Web ou ressources de tiers liés à cet article de blog sont fournis pour des raisons de commodité uniquement, et Zscaler n’est pas responsable de leur contenu ni de leurs pratiques. Tout le contenu peut être modifié sans préavis. En accédant à ce blog, vous acceptez ces conditions et reconnaissez qu’il est de votre responsabilité de vérifier et d’utiliser les informations en fonction de vos besoins.
Recevez les dernières mises à jour du blog de Zscaler dans votre boîte de réception
En envoyant le formulaire, vous acceptez notre politique de confidentialité.



