The federal government adopted frontier AI faster than any enterprise technology in memory. The Pentagon's GenAI.mil platform reached almost 1.7 million users with more than 100,000 custom agents built on it, per Nextgov, and began carrying commercial models certified for controlled unclassified information — including ChatGPT at Impact Level 5 in early July. On the civilian side, GSA's OneGov agreements put offerings from OpenAI, Google, and Anthropic into agencies at promotional prices between $0.47 and $1, with roughly 3.4 million federal employees gaining access. OpenAI's newest models went live for government use one day after their public release, via FedRAMP-authorized channels.
Now the scaffolding is wobbling. FedScoop reported on August 11 that the flagship OneGov deals expire September 30 with no public plan forward — while a Thomson Reuters study it cites found 27% of government professionals already using unsanctioned AI tools. Adoption became a dependency before governance became a habit.
The lesson generalizes to every security and intelligence organization watching this unfold. AI that summarizes, correlates, and drafts is now table stakes; the differentiating questions are the unglamorous ones. What data can the model see, and under whose authority? Is every output attributable and auditable after the fact? Who is accountable for an action an assistant recommended? When the contract, model, or vendor changes — as the government's may on September 30 — does the institution retain its data, its workflows, and its records?
Adoption became a dependency before governance became a habit. Security programs cannot afford that order of operations.
That order of operations is the design argument behind our assistant layer. AI FORCE — Assistants is in development, and it is designed so that Sentinel, Oracle, Scribe, and Guide do their monitoring, correlation, and documentation work inside the platform, against data the institution governs, producing output the institution can audit. The human role is structural, not decorative: assistants surface and draft; people decide and act.
Governance
AI assistants operate within APEX, using governed, auditable data. They do not bypass authority, workflows, or oversight.
Government proved this year that AI adoption can move at consumer speed. September will show what that speed costs when the governance underneath it is still being negotiated. Institutions that get the order right — governed first, then fast — will not have to find out.