Executive Summary
American commercial industry leads the world in software development and artificial intelligence (AI). That advantage does not automatically transfer to the military. The federal cybersecurity compliance process is a major barrier between America’s most advanced technologies and the warfighters who need them. The Authorization to Operate (ATO) is the federal government’s formal mechanism for assessing and approving software systems. However, the ATO process and its governing framework—the Risk Management Framework (RMF)—are described as ineffective, slow, duplicative, and in need of reform.1 Bureaucratic delays can carry a devastating cost. A former intelligence officer describes just how high those stakes can be: “I firmly believed that software was the reason that a bunch of civilians had died. . . . We had critical fixes like known operational issues that were causing operational risk that were sitting on the shelf waiting to go through the ATO process.”2
Prior research has documented ATO process inefficiencies within specific service contexts and cataloged security shortfalls. This paper is the first analysis to examine not only the process itself but the foundational legal authorities, competing stakeholder incentives, and governance structures that collectively produce delays. This paper also assesses why reforms have not solved these issues, despite sustained attention over more than a decade. A summary of the analysis is captured in Figure 1.
Figure 1. Summary of Analysis

Source: Author’s analysis based on 2013 OMB Memo; 2024 GAO Critical Cybersecurity Challenges; 2019 GAO Cloud Computing Security; 2024 GAO Cloud Security; 2024 DoW Cybersecurity Reciprocity Playbook; 2021 GAO Weapon Systems Cybersecurity; 2016NIST About RMF; 2021, 2023, 2025 and 2026 NDAAs; 2024 cATO Evaluation Criteria; 2019 AF Fast-Track ATO; 2025 FedRAMP Built a Modern Foundation; 2025 DoW Cybersecurity Risk Management Construct; and practitioner experiences.
The first half of the military software approval process remains almost entirely unaddressed, and it is the most significant time suck for new commercial entrants. Reciprocity, which allows reuse of ATOs to help reduce duplication, has fallen short of its intended utility and remains a barrier to scaling across the services. The recommendations in this paper identify the highest-return opportunities available that complement rather than duplicate existing reform efforts. These are not exhaustive recommendations for every single point of friction, but a prioritized set of interventions designed to produce the greatest impact given current AI capabilities and policy reform momentum.
Recommendation 1: Publicly release critical controls and authorizing officials. Federal organizations should publish their AO authorities and critical controls to help programs and vendors identify an appropriate AO with bandwidth to evaluate the system. This does not require revealing individual identities, system vulnerabilities, or specific implementation details. Following Karickhoffs’s principle, publishing critical controls establishes clear public standards without exposing vulnerabilities, and publishing delegated authorities would allow AI to assist with AO identification. Opacity creates administrative drag without enhancing security, and administrative barriers discourage the commercial innovation the military needs.
Recommendation 2: Leverage AI to standardize to machine-readable formats. AOs should be required to feed process standards and documentation templates into a centrally managed, AI-enabled tool to standardize ATO submissions. This tool would normalize RMF forms and control taxonomies, assist in generating contract language, and enable automated form population. The military and intelligence community (IC) should also adopt Open Security Controls Assessment Language, the machine-readable format developed by the National Institute of Standards and Technology (NIST) that renders compliance documents as structured, interoperable data. OSCAL establishes a standardized output format that accommodates variation in underlying tools while ensuring that compliance artifacts are interoperable.
Recommendation 3: Budget and deploy continuous, automated AI red teams. Programs must incorporate the cost of AI red teaming into budget plans through a dedicated percentage tax on overall budget dollars or by requiring program managers to explicitly include estimates within formal program estimates. Once a system meets critical security controls, program offices and AOs should stop treating the remaining NIST controls as a compliance checklist and instead implement continuous, automated AI red teaming through the system life cycle. Agentic AI can execute realistic, on-demand threat assessments continuously and at scale, providing real-time security insights while optimizing the deployment of scarce, highly skilled human cyber talent. Currently, the scarcity of personnel possessing deep technical expertise, mission context, and RMF mastery creates cybersecurity compliance theater and delays.
Recommendation 4: Experiment with AI reciprocity agents. An AI reciprocity agent would continuously monitor and pull new assessment reports to feed AI red teams, shifting from static, point-in-time assessments to more timely threat information. This capability would introduce critical security risks—primarily the data aggregation threat—requiring a joint military, IC, and federal AI task force to govern and audit the agents with strict guardrails. This recommendation should not be implemented until there has been a proof of concept with low-impact, unclassified systems to validate accuracy and security guardrails. Systems such as Nuclear Command, Control, and Communications (NC3) should be permanently excluded.
Recommendation 5: Increase reciprocity and cybersecurity incentives. The U.S. Department of War—also recognized as the U.S. Department of Defense—and IC chief information officers (CIOs) should mandate automatic reciprocity for defined system classes that meet standardized critical controls, shifting the default posture to a “presumption of adequacy” backed by continuous AI red teaming and an explicit “no list” for specific high-risk platforms or missions. A valid ATO issued by any DoW or IC AO would grant immediate, service-wide fielding rights. The Defense Innovation Board (DIB) previously recommended skipping pre-authorization compliance entirely, but a system that was never assessed and subsequently compromises sensitive data cannot be rectified through financial penalty.3 Instead, the DoW and IC should set clear expectations through published critical controls, establishing an organizational bias toward rapid scaling of technology while excluding mission systems such as NC3, next-generation fighter aircraft, and nuclear submarines.
Finally, the military and the broader federal government need a more nuanced approach to cybersecurity incentives than the binary ATO status quo. Contracting mechanisms such as award feeds could incentivize contractors to respond rapidly to relevant threats discovered by AI red teaming. AOs and CIOs could establish guardrails that automatically remove systems that fail to prioritize and resolve known vulnerabilities. Contractors and program managers could receive cybersecurity report cards that follow their professional records, creating accountability that persists beyond any single program.
These recommendations carry real risks that must be managed: Aggregation of vulnerability data, automation bias, cognitive off-loading, and AI accuracy limitations all require deliberate governance structures, phased implementation, and continuous human oversight. The current ATO system already accepts significant risk. Assessment personnel rarely possess deep technical expertise in the latest innovative commercial software, the threats to that software, mission context, and RMF mastery simultaneously, which produces compliance theater rather than real security. AI red teaming and reciprocity agents offer an opportunity to more actively manage the already widespread risks. By transitioning the compliance workforce from attempting to master every technology and threat to governing and auditing AI red teams and agents, the government can scale scarce expertise in ways that human staffing models cannot. Some personnel will still need deep technical knowledge to train models, validate outputs, and build guardrails so that the red teams and agents do not turn against the mission systems. But the alternative of continuing to accept the compounding risks of an under-resourced, checklist-driven compliance system is not a winning risk management strategy.
Download Full Report
Outpaced: AI and Policy’s Role in Transforming Cybersecurity Compliance- “CITI Hearing: Too Critical to Fail: Getting Software Right in an Age of Rapid Innovation,” House Armed Services Committee, 118th Congress, March 13, 2024, https://armedservices.house.gov/calendar/eventsingle.aspx?EventID=3558.
- Bonnie Evangelista, host, Defense Mavericks, podcast, “The Power of Continuous Software Delivery in Defense with Bryon Kroger,” accessed April 23, 2024, www.defensemavericks.com/the-power-of-continuous-software-delivery-in-defense-with-bryon-kroger/.
- Defense Innovation Board, Scaling Nontraditional Defense Innovation (Washington, D.C.: DoD, January 2025, https://stib.cto.mil/wp-content/uploads/2026/01/2025-2_DIB-ScalingNontraditionalDefenseInnovation_250113PUBLISHED_9ee4ae.pdf.