Subscribe to the Premier Computers blog

Get new posts on security, compliance, and business in your inbox.

← Back to all articles
Business

Can Government Actually Keep Up with AI Without Blowing a Hole in Security?

The Skeptic and the Optimist argue whether federal agencies can adopt AI at private-sector speed without trading away the security controls that took decades to build.

Our last piece looked at how banks are bolting AI onto systems that still have decades-old cracks in them. That raised an obvious follow-up: if banks, with all their money and motivation, are struggling to do this safely, what happens when you ask government agencies to keep pace? Two of our regular voices took it from there.

The Optimist: Let’s start with the basic case. Government agencies process insane amounts of paperwork, benefits claims, fraud detection, permitting. AI is genuinely good at that kind of repetitive pattern-matching work. If agencies adopt it, you could see faster services and fewer backlogs. Why wouldn’t we want that pace?

The Skeptic: Because “pace” is exactly the problem. Private companies can move fast because when they break something, they eat the cost quietly, patch it, and move on. When a government agency breaks something, it’s someone’s disability check, someone’s tax refund, someone’s immigration status. The stakes per mistake are just higher, so the speed that works for a bank’s chatbot doesn’t automatically work for a system deciding who gets benefits.

The Optimist: Sure, but that’s an argument for careful adoption, not for falling behind entirely. So what’s actually stopping agencies from moving carefully but still quickly?

The Skeptic: Procurement, mostly. Government contracts for new technology can take years. By the time an agency finishes the paperwork to buy an AI tool, the tool it bought is two generations behind what a private company is already using. That’s not a security problem on its face, but it becomes one, because agencies end up bolting new AI features onto old procurement-approved systems that were never designed to talk to each other securely.

The Optimist: Okay, so what does that actually lead to? Walk me through the failure, not just the friction.

The Skeptic: Take a case management system built in the 2000s. An agency wants an AI layer on top to summarize documents or flag anomalies. Instead of rebuilding the system, they add an API (a way for two pieces of software to exchange data) so the AI tool can pull records. Now you’ve got a modern AI product with broad data access sitting on infrastructure that was never audited for that kind of exposure. That’s the exact “old cracks” problem the banking piece described, except here the data involved is Social Security numbers, medical records, immigration files.

The Optimist: That’s fair, but banks have the same legacy mess and they’re still finding ways forward, hiring for it, budgeting for it. So what would it actually cost government to do the same thing properly, not cut corners, just do it right?

The Skeptic: Real money and real talent, and that’s the second wall. Government pay for security and AI roles is nowhere close to private sector. The people who know how to secure these systems well can go make double or triple the salary at a bank or tech company. So agencies are trying to hire the hardest jobs in tech with the weakest offer on the table.

The Optimist: So then the answer isn’t “agencies build it all in-house,” it’s “agencies buy trusted, pre-secured tools from vendors who already did the hard work.” That changes the pace question completely. You’re not waiting on a slow hiring pipeline, you’re waiting on a slow contract signature.

The Skeptic: Which introduces a different risk. Now you’ve got a third-party vendor with access to government data, and that vendor’s own security is the weak link. We’ve already seen breaches where the government’s data was fine, but a contractor’s system wasn’t. Outsourcing AI adoption doesn’t remove the security burden, it just moves it somewhere with less oversight.

The Optimist: So what’s the actual choice on the table then? It sounds like you’re saying agencies are stuck either way, slow and safe or fast and exposed.

The Skeptic: Not stuck, just honest about the tradeoff. The realistic path is narrow: adopt AI first in places where a mistake is annoying, not catastrophic. Let AI draft a first version of a public records response. Don’t let it make a benefits eligibility decision unsupervised. Keep a human checking the output where the cost of being wrong is high.

The Optimist: That’s reasonable, but it’s also slower than what taxpayers and lawmakers are going to demand once they see private industry moving fast. So what happens when political pressure says “move faster than that”?

The Skeptic: Then you get what we always get: a rushed rollout, a headline-grabbing failure, a temporary freeze on the program, and a new set of hearings about what went wrong. That cycle has happened with government tech modernization for twenty years. AI doesn’t break that pattern, it just raises the stakes of it, because the failures involve automated decisions at scale instead of just a broken website.

The Optimist: Then maybe the honest answer is agencies can keep pace on the parts of AI that are low-stakes and high-volume, and they’ll always lag on the parts that touch real consequences for people, and that’s not actually a failure, that’s the system working the way it should.

The Skeptic: I can live with that framing, as long as nobody pretends the lag is temporary. It’s structural. Budgets, incentives, and hiring don’t change just because the technology got more exciting.

Both sides end up agreeing on more than they started with: government can realistically move fast on low-risk, high-volume AI uses, and realistically should move slower on anything touching direct consequences for individuals. What’s unresolved is whether political and public pressure will respect that distinction, or whether the push to “keep up” with the private sector ends up forcing agencies into the high-stakes uses before the security and staffing problems are actually solved.


This post is a follow-up responding to a discussion question raised in Banks Are Rebuilding With AI, But the Old Cracks Are Still There: “Could government agencies realistically keep pace with private-sector AI adoption while maintaining security standards?”