OpenAI reveals first federal agency customer for ChatGPT Enterprise

Just a few days after OpenAI’s multimodal AI model won a FedRAMP High Authorization as a service within Microsoft’s Azure Government cloud, the generative AI company says that it’s partnered to offer ChatGPT Enterprise to its first federal agency customer: the U.S. Agency for International Development. 

Anna Makanju, OpenAI’s vice president of global affairs, told FedScoop that USAID plans to use the technology to help reduce administrative burden and “make it easier for new and local organizations” to partner with the agency.

Makanju said OpenAI is “actively pursuing” a FedRAMP Moderate accreditation for ChatGPT Enterprise, which would clear the generative AI platform to handle moderately sensitive federal data like personally identifiable information or controlled unclassified information outside of Microsoft’s Azure Government service. She said the company had nothing to share, at least for now, regarding potential work with cloud providers beyond Microsoft. 

ChatGPT Enterprise, released last August, is meant for larger organizations and is supposed to offer more advanced analytics and customization, though other federal agencies have already started using the software in more limited ways. 

That USAID is ChatGPT’s first federal agency customer isn’t surprising. Under Administrator Samantha Power, USAID has made artificial intelligence a key focus. Earlier this year, she met with both Makanju and the CEO of Open AI competitor Anthropic, Dario Amodei. Both of those discussions focused on how generative AI could be used in the context of distributing aid, among other topics. Overall, the agency’s focus on artificial intelligence has ramped up, with new work meant to guide both potential use cases of the technology and possible threats to safety, security, and democratic values. 

Generative artificial intelligence applications can have myriad use cases, but the federal government still faces significant concerns about the security of government data and potential ingrained bias within the software, among other issues. The Biden administration’s October executive order on artificial intelligence discourages federal agencies from outright banning the use of generative AI, but several agencies have taken steps to limit or block use of the tools.

We of course understand some agencies have hesitations or questions about how this technology can be integrated safely and effectively into their operations,” Makanju told FedScoop. “We also continue to advocate for the development of policies that delineate appropriate use cases, such as limiting the use of consumer tools to public, non-sensitive data — akin to how government agencies utilize search engines.” 

Makanju recently answered a series of emailed questions about OpenAI’s approach to government customers. The following has been edited for clarity and length. 

FedScoop: OpenAI has met with USAID and is working with Los Alamos National Laboratory. Can you say what other federal agencies OpenAI is in conversation with — and what use cases for generative AI do you imagine for the government? 

Anna Makanju: I believe that the best way for government officials to understand advanced AI models is to use these tools. These tools can also enable governments to serve more people more efficiently — and already, nearly 100,000 government users across federal, state, and local levels are utilizing the consumer version of ChatGPT. USAID recently became the first U.S. federal agency to adopt ChatGPT Enterprise. The agency plans to leverage ChatGPT to reduce administrative burdens for staff, and make it easier for new and local organizations to partner with USAID.

We are also trying to make it easier for the US government to use our services by making ChatGPT Enterprise accessible through multiple Government-wide Acquisition Contracts.

We’re also focused on education and hands-on experimentation with AI technology within government agencies. Recently, we supported the GSA Federal AI Hackathon on July 31 and participated in the FHFA Generative AI Tech Sprint, demonstrating our dedication to innovation and practical AI applications.

While it is currently primarily an efficiency tool, we hope to see significant and important breakthroughs being enabled by this technology. In the private sector, we have seen Moderna accelerate their ability to conduct clinical trials. We hope to see them bring life-saving vaccines to market faster with our tools. We hope to see similarly impactful results for [U.S. government] agencies.

FS: What impact did the Biden administration’s executive order have on OpenAI, particularly around government use of generative AI systems?

AM: The executive order sought not only to encourage the development of safe, secure, and trustworthy AI but to encourage the U.S. government to use the technology. While we have been encouraging agencies to save time with these tools for several years, there was a lot of uncertainty on what was permissible or desirable in terms of that use, and the EO seeks to help agencies with these questions. Notably, the executive order’s establishment of chief AI officers within agencies is playing an important role in promoting AI fluency and encouraging generative AI pilots across the government. 

FS: Right now, OpenAI use within the government is primarily happening through Microsoft Cloud. Do you envision that happening through another cloud provider anytime soon?

AM: Government customers can engage with OpenAI directly through our ChatGPT products or APIs, both of which are hosted on Microsoft’s Azure Cloud. Additionally, Microsoft offers its own separate product, Azure OpenAI. While we continuously assess opportunities to expand our offerings, we do not have any updates to share regarding integration with other cloud providers at this time.

FS: How is OpenAI thinking about the Federal Risk and Authorization Management Program, or FedRAMP? 

AM: OpenAI is actively pursuing FedRAMP Moderate Accreditation, recognizing the importance of meeting the rigorous security and compliance standards expected by federal agencies. The introduction of FedRAMP’s Emerging Technology (ET) Prioritization Framework, as highlighted in the recent executive order, underscores the government’s commitment to integrating innovative solutions securely. 

AI continues to evolve, so we hope to work closely with federal stakeholders to ensure that the FedRAMP security risk evaluation process allows government users to access the latest AI tools as they come online. 

FS: The Biden administration just announced progress on some of its AI goals, and, in particular, that Apple had signed onto the voluntary commitments. To what extent did signing onto the voluntary commitments change OpenAI’s approach? Were there stipulations or procedures that OpenAI had already committed to, or were there particular changes that the company made in response to these White House guidelines? If so, what were they? 

AM: The voluntary commitments introduced by the Biden administration closely align with what OpenAI had been doing for some time. These commitments not only reinforced our existing practices but also provided a valuable framework to standardize and formalize efforts across the industry and internationally.

Areas such as external security testing, information sharing regarding AI risks with governmental bodies, and the development of systems to identify AI-generated content were already focal points for us. The voluntary commitments have spurred us to accelerate initiatives in these domains. 

We view the growing participation of industry leaders like Apple as a positive step toward unified standards in AI safety. This collective effort enhances the overall trustworthiness of AI systems and promotes a collaborative environment for addressing the challenges and opportunities presented by AI.

FS: What has OpenAI’s involvement with the Department of Homeland Security’s AI Safety and Security Board looked like thus far? How is the company working with DHS on some of the safety risks the agency has started to point out, particularly in regard to large generative models?

AM: OpenAI is actively engaged with the Department of Homeland Security’s AI Safety and Security Board and our CEO, Sam Altman, is a board member. OpenAI has participated at both the CEO and staff level, and we have provided our views as to the role of AI developers in identifying and mitigating risks to critical infrastructure.

This involvement underscores our commitment to collaborating with government, other industry leaders, and civil society to ensure the safe and secure deployment of AI technologies. And as part of our research around preparedness, we continue to be in dialogue with DHS, and have briefed them on our work, including how we assess the risks associated with LLMs and biological threats.

FS: We’ve been covering the generative AI guidance issued by federal agencies extensively. Some agencies seem to be blocking ChatGPT, while others have slowly moved ahead with examining the technology. What do you make of these varied responses?

AM: Adoption of new technologies raises new considerations and takes time — especially within government. We are encouraged by agencies like DHS that are proactively exploring how generative AI can support their missions, including issuing guidelines for using commercial generative AI services, like ChatGPT.

FDA has plans to overcome challenges in building medical device surveillance system, GAO says

The Food and Drug Administration has faced a handful of challenges as it builds a surveillance system to monitor the safety and efficacy of medical devices after they enter the market, but the agency has plans in place to address those issues as it eyes expansion of the program, according to a new watchdog report. 

The FDA’s active postmarket surveillance system relies on data pulled from electronic health records, wearable devices, mobile health applications and more to evaluate the safety of a medical device. As the agency establishes the system to better evaluate authorized tools in the U.S market, it has run into funding challenges for active surveillance and found “limited use of unique device identifiers in electronic health records and billing claims,” according to the Government Accountability Office. The latter point has made identifying devices used by patients “more difficult,” per the GAO.

Though patients and health professionals can report issues with medical devices through the agency’s Medical Device Reporting, a 2012 federal law required the FDA to establish the postmarket surveillance system, a move that could help address the fact that faulty medical devices are linked to more than 1.7 million injuries and 83,000 deaths over a “recent 10-year period,” according to the GAO. The oversight of medical device products has held a place on the watchdog’s high-risk list since 2009. 

“We have previously reported on challenges FDA has faced in its oversight of the safety of medical products, including medical devices,” the report states. “In 2012, we found that FDA’s process for identifying adverse events associated with medical devices … may not fully capture cybersecurity vulnerabilities for certain devices.”

Despite the challenges facing the FDA in its creation of the system, the GAO found that the agency has taken steps to address both issues by encouraging device providers to include unique identifiers, which should result in faster and more accurate identification of devices as well as patients. That change would result in “significantly less effort from staff,” the report said.

On the funding issue, the FDA cited the costs necessary to establish and maintain this system at $8 million per year, and it plans to allocate $5 million from annual appropriations to the system. Additionally, the agency has requested another $3 million in the fiscal year 2024 appropriations but did not receive the requested funds. In response to the lack of funds from Congress, the agency has used device user fees to fund the surveillance activities. 

The GAO report states in a footnote that the “FDA did not make a similar request in the agencies’ FY2025 budget justifications.”

Meanwhile, the FDA told the GAO that by December, it plans to begin active postmarket surveillance on two medical devices, with hopes to continue expanding the number of devices evaluated over the next five years.

To build the surveillance system, the GAO noted that the FDA has established the necessary cloud-based data infrastructure “necessary to collect evidence of medical device performance while protecting patient privacy,” and established a partnering coordinating center to organize a network of information sources.

NASA has probed 200+ potential instances of devices brought abroad without authorization

In the past three years, NASA has investigated more than 200 reports of either space agency devices or systems being accessed outside the country without prior authorization, which would violate internal policy regarding where mobile technology units may be brought abroad.

The reports of unauthorized foreign access investigations, obtained by FedScoop through a public records request, occur when a NASA device is detected overseas without a clear prior record of a planned trip. These reports are similar to databases that FedScoop has obtained from other agencies, including the Federal Emergency Management Agency and the U.S. Agency for International Development — and reflect the government’s longstanding approach to restrict the use of its devices abroad. The documents do not show the results of the investigations or which countries the pings were from. 

These reports appear to occur for several reasons, including: a device was pinged or geolocated on non-U.S. cellular networks, a device not cleared for travel was pinged abroad, or a device had connected to a NASA system from outside the country. The documents were obtained through a public records request for reports about lost or internationally carried devices from the past three years, as well as for other information explaining rules for mobile device security abroad. 

NASA’s Security Operations Center (SOC) monitors connections made to networks run by the space agency. Connections made abroad are flagged to the SOC, which then investigates whether the employee linked to that device was on authorized travel, according to Jennifer Dooren, a deputy news director at the space agency. She said that when a device doesn’t have prior authorization, “that device is restricted from accessing NASA’s networks and systems.”

Her statement continued: “After review and approval, NASA employees are authorized to take government IT devices abroad on official government travel. Some NASA users may be required to perform authorized federal government work on NASA IT within designated countries. Users must follow all IT devices and travel requirements. For security purposes, it’s not appropriate for NASA to disclose details on NASA device configurations or potential individual security incidents.” 

The agency did not address FedScoop’s questions about the extent to which NASA employees are currently traveling to Russia, or whether Russia — or any other designated country of concern — has ever taken possession of a NASA device.

There are risks with taking government devices abroad, said Sean Costigan, the managing director of resilience strategy at the software company Red Sift. The reports of devices brought abroad without authorization emphasize the importance of policies and protocols designed to protect government devices before government workers travel. China and Russia, he said, maintain “aggressive intelligence collection efforts that pose a heightened risk when government-furnished property is mishandled abroad.” 

Greg Falco, a Cornell engineering professor focused on cybersecurity and aerospace, said the number of devices reported seemed to be “inordinate,” though he said the issue was likely due to poor communication or, potentially, a cumbersome loaner device policy. “The risks are largely relating to eavesdropping or theft, where foreign entities may target data or software on a machine of interest and monitor activity,” he said.

Documents also show that NASA issued an interim directive at the end of last year governing travel with government devices, along with other related rules. According to the policy, which represents the agency’s most-current version of rules on bringing devices abroad, space agency users can bring government devices to all countries, provided they meet certain technical and specific requirements and have approval, except for Russia and states on the agency’s Designated Countries List. Those countries include Taiwan, which the U.S. does not officially have diplomatic relations with, as well as Israel, which is listed as having “missile technology concern,” based on the Commerce Department’s methodology. Other countries on the list include North Korea, Iran, and China. 

NASA employees are supposed to use specially configured loaner devices when visiting these countries. 

“Operating outside the U.S. increases these risks, mainly where telecommunication networks are owned or controlled by the host government. IT devices are always at risk for introducing malicious software, and such risks are greater when devices leave the user’s physical control,” the policy states. These risks are greatest when traveling to the Russian Federation or countries on the Designated Countries List, it adds. 

The document also spells out what to do in the scenario that a device is confiscated by a foreign government or by U.S. authorities, including the Transportation Security Administration and Customs and Border Protection. NASA employees are supposed to attempt to use their credentials to retain control of the device; if they’re asked for access codes to use the devices, they’re supposed to attempt to enter the device manually before giving out a password. 

The interim directive, which will remain in effect until December and will be replaced by another policy, comes amid growing concerns about the cybersecurity of the space industry. Last August, the Office of the Director of National Intelligence released a brief warning that “foreign intelligence entities” could be targeting the commercial space industry and trying to steal technology assets.

Namrata Goswami, an independent space policy expert, said “the consequence of any malicious foreign cyber actor getting access to a NASA network could mean them lurking in the network without discovery, getting access to export control technologies, and sniffing out encrypted passwords. This could have long-term strategic consequences for the United States specifically related to space technologies, which might have dual-use civil-military applicability for adversary nations to use against the U.S.”

Costigan, the Red Sift cyber expert, said that given the space industry’s emerging technologies and strategic significance, the sector is “a prime target for espionage activities aimed at acquiring intellectual property and national security advantage.” 

“NASA devices used abroad, and their transmission of data across foreign networks, would make especially attractive targets,” he added.

White House, OPM issue ‘call to action’ to improve the federal hiring experience

A new memo sent to federal agencies Wednesday aims to improve the hiring experience for job seekers and officials who hire them in what the White House termed “a call to action” to reduce the time and burden of that process.

The joint document from the White House Office of Management and Budget and the Office of Personnel Management directs agencies toward tools, resources and strategies that it says will strengthen workforce planning, improve the application experience, and make things easier for hiring managers and human resource managers. 

“We aim to continuously improve the federal government’s ability to recruit, hire, and retain a diverse and skilled workforce to strengthen the way agencies deliver on their missions for the American people,” Rob Shriver, OPM’s acting director, said in a statement announcing the memo. “This memorandum builds on that success and is a culmination of years of data-driven and innovative thinking about the federal hiring experience.”

Specifically, the memo includes guidance that agencies should be developing hiring objectives that are informed by data-driven workforce planning; taking advantage of pooled hiring actions; ensuring that announcements have a job title that “resonates with job seekers”; promoting collection and use of data on the time it takes to hire people; and ensuring that systems used in hiring are being effectively used to measure and track the priorities in the memo.

To ensure the government actually meets the goal of improving the process, OPM will be monitoring the progress on the memo through hiring experience metrics, according to a release from the agency. 

Those metrics — which focus on the experience of applicants, managers and HR professionals — will be based on existing satisfaction surveys and USAJobs, a fact sheet provided by the agency said. Agencies will also share the headway they’ve made on the memo at quarterly meetings with the President’s Management Council, the memo said.

The U.S. government is a massive employer, hiring over 350,000 people a year and processes 22 million applications each year, according to numbers in the memo. The guidance comes as the Biden administration is working to foster a diverse federal workforce and ramp up hiring to meet the needs of the artificial intelligence era.

“Many tech, data, and AI professionals — and beyond — are eager to serve their country,” Jennifer Anastasoff, Tech Talent Project’s co-founder and executive director, said in a statement in the release. “It’s exciting to see the federal government looking to best-in-class recruitment and retention strategies to attract and keep folks who are critical to delivering services, enforcing laws, and protecting our country. This initiative will allow agencies to build the diverse talent pool necessary to meet today’s challenges.”

The next steps for OMB and OPM include conducting research on the application portion of the process and analyzing barriers that agencies encounter in carrying out the memo. OPM will also develop “automation tools to streamline sharing of information regarding applicants within and between agencies, to the extent allowable,” in addition to several other actions, the memo said.

CFTC wants to transform enforcement work through AI and data ‘marathon’

Few agency workers across the federal government are more closely and publicly associated with their area of expertise than Ted Kaouk is with data. 

A Naval Academy grad with a PhD in English from Maryland, Kaouk carved out that association during lengthy chief data officer stints with the Department of Agriculture and Office of Personnel Management, plus a three-and-a-half-year term as chair of the Federal CDO Council. 

Despite the seen-it-all quality to Kaouk’s federal government career, serving as chief artificial intelligence officer and CDO at the Commodity Futures Trading Commission since December has kicked things up a notch. 

“We ingest and manage over 15 billion records per day. Per day,” Kaouk said of the CFTC, the independent federal agency charged with regulating the U.S. derivatives markets. “So hopefully it gives a sense of the volume of data that we’re managing.”

That data, Kaouk told FedScoop, is what helps the CFTC oversee market participants. And it essentially serves as a foundation for Kaouk’s work within the agency as it undergoes what he calls a “significant” transformation of its oversight and surveillance enforcement capabilities.

The evolution was already underway when Kaouk joined the agency at the end of 2023, part of a set of digitally minded priorities from CFTC Chairman Rostin Behnam.

“He really likens this initiative to a marathon,” Kaouk said of the agency head. “It’s not a sprint, but it’s a continuous effort to ensure our regulatory framework remains … robust and adaptive in an increasingly complex financial landscape.”

The CFTC in recent months has been especially attuned to that landscape in the age of artificial intelligence, issuing a request for comment in January on the uses and risks the technology poses to the derivatives market, which encompasses futures options or contracts for underlying assets such as commodities, bonds, stocks and currencies. The comment period closed in late April and CFTC staffers are currently reviewing submissions, an agency spokesperson said.

In May, a CFTC advisory committee’s subcommittee on emerging and evolving technologies released a report on responsible AI in financial markets. The report’s authors noted that AI has a clear value proposition for the CFTC and its regulatory mission, specifically its ability to automate processes such as surveillance and fraud detection. 

But there remains a “lack of direct knowledge about the CFTC-registered entities currently leveraging AI,” the report noted, underscoring a lack of transparency around everything from the quality of data training to the extent of human involvement in autonomous trading models.

As the agency’s first chief AI officer, Kaouk is pursuing an optimistic approach to the technology and how it can be used to root out fraud manipulation and market abuse.

The CFTC wants to “send a strong signal to bad actors that misconduct will be identified and punished,” he said. “I personally feel that we can harness that data to develop and deploy sophisticated analytics and AI capabilities.”

Compiling the CFTC’s AI use case inventory is in progress and the agency is on track to meet Office of Management and Budget timelines, Kaouk said. In the meantime, he and his team are full steam ahead on a handful of pilots that flex the technology’s data-related muscles. 

For starters, there’s a machine-learning tool that detects anomalies in algorithms that’s focused on improving data quality. There’s another tool that uses AI/ML techniques to identify spoofing behavior in agency data. And there’s a generative AI pilot the agency is in the process of launching that will complement and streamline existing legal research, software development workflows and “general knowledge work,” Kaouk said.

The use case to flag instances of spoofing — the practice in which traders place a bid or offer on a contract or option and then cancel before execution — would be an especially helpful tool for the CFTC’s enforcement arm. 

“The spoofing use case involved using various AI techniques to improve the staff’s ability to identify buy-and-sell offer patterns that may be evidence of potentially disruptive trading patterns that warrant further investigation,” Kaouk said. 

Though the CFTC is an independent federal agency, exempting it from some OMB AI requirements of Chief Financial Officers Act agencies, Kaouk said they have “taken some additional steps” beyond federal guidance and President Joe Biden’s AI executive order, specifically with the establishment of a new section focused on AI and enterprise analytics that sits within the CFTC’s data division. 

“We’re going to be leveraging our existing data governance board to include AI governance,” he added. “So a data and AI governance board, that’s not a requirement. But we feel it’s important for our compliance and our efforts to be able to do that.”

The CFTC also plans to develop an integrated data and AI strategy — another move that is not required of the agency — and is looking to provide training to its workforce in the coming months on AI governance and ethics.  

Having previously led the development of USDA’s first data strategy — which included the creation of an enterprise analytics and AI platform — and guiding OPM through the same process, Kaouk finds himself uniquely well positioned to oversee the CFTC’s data and AI journey. 

There’s still the matter of handling those 15 billion records per day, which comprises everything from swap transactions and price volume figures to whistleblower complaints and consumer tips. But Kaouk believes that lessons learned at USDA and OPM about improving the accessibility and usability of data tools for agency staffers at scale will guide his way.

“At the CFTC, I’m really looking to kind of leverage some of those principles to advance our data and AI capabilities,” he said. “So we’re excited to be moving ahead with exploring how generative AI may be used at the commission in the future.”

U.S. Digital Corps announces AI-focused cohort

The General Services Administration’s 2024 cohort of U.S. Digital Corps fellows will mostly focus on artificial intelligence and AI-related projects, the agency said Tuesday. 

The two-year paid fellowship welcomed a total of 70 fellows to its third-ever cohort, with over 40 focused on AI in response to the National AI Talent Surge, according to the press release. The fellows are employed across the government to support priority technology initiatives, such as the Department of Homeland Security’s use of AI to strengthen cybersecurity, drug capture and other agency responsibilities.

“Growing the U.S. Digital Corps is crucial to driving innovation across the federal government, especially as emerging technologies like AI evolve,” GSA Administrator Robin Carnahan said in the release. “GSA is focused on delivering great value to our customer agencies and the American people, so we are proud to help lead the Biden-Harris Administration’s efforts to bring tech talent into government to deliver those results.”

The most recent group of fellows will support 19 agencies across the federal landscape. Six new agencies have partnered with USDC for this cohort, including the Federal Emergency Management Agency, the Internal Revenue Service and the U.S. Geological Survey. 

Fellows at FEMA are expected to help the agency aid disaster survivors by offering a more streamlined, accessible and equitable process for individuals to apply and receive disaster support. 

Additionally, USDC participants at the Department of State will apply research and analytics to improve consular design — which includes passport and visa services — for both U.S. citizens and foreign nationals, per the release.

IRS should bring back Technology Retirement Office, watchdog says

The IRS should consider resurrecting an office it shuttered last year to better manage the decommissioning of its legacy IT systems, the Treasury Inspector General for Tax Administration recommended in a report last week.

In January 2023, the tax agency sunsetted its Technology Retirement Office, which was established in August 2021 to “strategically reduce the information technology footprint across the enterprise,” according to the report.

Without that office or something akin to it, the IRS lacks an agency-wide program to effectively “identify, prioritize, and execute the updating, replacing, or retiring of legacy systems,” a project that should be a top of mind given that agency spending on operations and maintenance of IT infrastructure jumped 35% over the course of four years, from $2 billion in fiscal year 2019 to $2.7 billion in FY2023, the report explains. That uptick “will likely continue” until most of the IRS’s legacy systems are decommissioned, TIGTA said.

The watchdog recommended that the IRS’s chief information officer either re-establish the Technology Retirement Office or create “a similar enterprise-wide program” to oversee the decommissioning of legacy IT systems. The IRS agreed in part with the recommendation, telling TIGTA that it will produce a roadmap that charts “milestones toward delivering new capabilities” and continue its work on the removal of legacy systems “as new capabilities become available.”

TIGTA also recommended that the IRS properly apply its definition of “legacy system” and make sure that that term is programmed into queries to effectively pinpoint all such systems. The tax agency agreed with the recommendation and said it would update the query definition that is currently programmed.

The IRS was credited by TIGTA in its report for “fully and effectively” implementing two previous recommendations: 

“The IRS implemented a policy requiring system information updates to the As-Built Architecture. System information was updated within a year of our review for 732 of 733 systems and the remaining system was updated just over one year of our review,” the report said. “In addition, specific system information in the As-Built Architecture is complete. All 733 systems in the As-Built Architecture had the required information on the managing organization(s), application age, and programming language.”

In a mid-year report to Congress in June, Erin Collins, the national taxpayer advocate, wrote that the IRS has “turned a corner” in its yearslong journey to modernize IT systems and improve customer service. 

“Many of the IRS’s plans to improve transparency rely on updating the agency’s technology,” Collins wrote. “As the IRS’s modernization of technology involves the implementation of artificial intelligence (AI), such as in existing voicebots and chatbots, the IRS must remain transparent about its use of AI, particularly as those uses affect taxpayer rights and data privacy.”

White House pushes for government coordination in global quantum competition

The White House is calling for more funding and interagency coordination for the advancement of international cooperation in quantum information science and technology, or QIST. 

A document released Monday by the Office of Science and Technology Policy details a series of QIST-related recommendations from a subcommittee within the National Science and Technology Council, including that the U.S. government create long-term funding mechanisms for QIST collaboration and cooperation and “establish and track” global metrics for QIST and the competitiveness of “enabling technologies.” The report calls for enhanced “interagency coordination of international cooperation practices to reinforce an integrated U.S. government-wide portfolio for international QIST engagement.”

The motivation for international QIST cooperation, OSTP said in the document, is to strengthen international engagements, promote access to resources and markets, guide QIST-related policies and practices on the global stage and more. The office, however, also points to challenges that complicate the development of effective international collaboration, such as mismatches with foreign partners on “diverse topics” like funding systems and technical capabilities.

”While the United States has supported international cooperation in QIST for decades, opportunities exist to adjust and strengthen its approach that will better position the nation to both leverage international engagements and advance U.S. priorities related to QIST,” the report states.

The report continues: “The United States is also experiencing an increase in international requests for collaboration that could divert attention from ongoing efforts if not coordinated and prioritized effectively.”

OSTP noted that a frequent challenge for the nation in the quantum space is that a foreign country will approach U.S. agencies to “individually propose formal and informal partnerships,” and agencies’ staff could be “unaware of ongoing partnerships that could be leveraged for cooperation.”

To address the issue, the White House suggested that agencies bolster formal and informal mechanisms for international coordination that are not as resource-intensive or time-consuming as memoranda of understanding or agreements. Specifically, agencies that lead and fund QIST research and development should “identify trusted partners in the international community that can accelerate ongoing work.”

“Agencies should incentivize staff to allocate time and resources to develop cooperative relationships with partners, when appropriate, that will have long-lived impacts,” the document states. “In addition, agencies should reduce bureaucratic hurdles, when appropriate, to streamline the development of new formal international arrangements, while leveraging existing bilateral and multilateral agreements and arrangements.”

Gundeep Ahluwalia leaving Department of Labor after 8 years as CIO

Gundeep Ahluwalia is stepping down from his role as Department of Labor CIO after nearly eight years on the job.

In a letter to staff, obtained by FedScoop, Ahluwalia wrote that Friday will be his last day at the department, which he joined in August 2016 as deputy CIO. After roughly two months in that job, he was named CIO in October 2016.

“As I think back over the last eight years, there have been so many successes and milestones that propelled DOL’s digital infrastructure by leaps and bounds above other agencies,” Ahluwalia wrote to staff. “When the team chose the slogan and decided to be the ‘best in federal service’ almost seven years ago, many of us had our doubts, but as the saying goes, ‘When the going gets tough, the tough get going!’ and that is exactly what happened. Our successes in creating novel funding mechanisms, TMF wins, legendary TechDay, creating resilient infrastructure, websites, applications, mobile applications, data infrastructure, cybersecurity, AI, and emerging technologies are all things I can talk about for days!”

In his note, Ahluwalia called the department’s biggest accomplishment during his time its “ability to attract talent and create leaders.”

“We have a formidable leadership factory,” he said. “I have never seen so many talented, competent, and diverse group of professionals in one place. The team is always thinking of ways to get it done, constantly innovating to improve delivery at a lower cost.”

Ahluwalia, a winner of multiple FedScoop 50 awards, oversaw the Department of Labor’s IT portfolio during a period of major transformation, including the department’s work to modernize unemployment benefits delivery with states during the early days of the COVID-19 pandemic.

Under his leadership, DOL has also been a frequent winner of Technology Modernization Fund awards — five times in total for projects such as data modernization, cybersecurity, faster processing of permanent labor certifications and streamlining the Integrated Federal Employee Compensation System.

Ahluwalia spoke with FedScoop earlier this year at the 2024 AWS Innovate Day about how new technologies like artificial intelligence could impact Labor’s multi-faceted mission.

“Every time I say gen AI, my team makes me put a dollar in the jar now,” he joked. “But I think AI — and all the other capabilities that we’ve had: [robotic process automation], blockchain — we need to be mission-focused rather than thinking of it from a technology perspective, and that’s what my team is trying to do right now.”

Ahluwalia pointed to examples like worker’s compensation claims and injuries submitted to the Occupational Safety and Health Administration as mission areas that can be made more efficient with AI.

Ahluwalia did not reveal what he would do after leaving the Labor Department.

Federal News Network first reported Ahluwalia’s departure.

NIST releases three encryption standards to prepare for future quantum attacks

The National Institute of Standards and Technology has officially released three new encryption standards that are designed to fortify cryptographic protections against future cyberattacks by quantum computers.

The finalized standards come roughly eight years after NIST began efforts to prepare for a not-so-far-off future where quantum computing capabilities can crack current methods of encryption, jeopardizing crucial and sensitive information held by organizations and governments worldwide. Those quantum technologies could appear within a decade, according to a RAND Corp. article cited by NIST in the Tuesday announcement.

“Quantum computing technology could become a force for solving many of society’s most intractable problems, and the new standards represent NIST’s commitment to ensuring it will not simultaneously disrupt our security,” Laurie E. Locascio, director of the Department of Commerce’s NIST and undersecretary of commerce for standards and technology, said in a statement. “These finalized standards are the capstone of NIST’s efforts to safeguard our confidential electronic information.”

The new standards provide computer code and instructions for implementing algorithms for general encryption and digital signatures — algorithms that serve as authentication for an array of electronic messages, from emails to credit card transactions.

For general encryption, the finalized Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) is a standard under which small encryption keys can be easily exchanged by parties quickly, according to the release. Meanwhile, for digital signatures, NIST released the final  Module-Lattice-Based Digital Signature Algorithm (ML-DSA) as the primary standard and the Stateless Hash-Based Digital Signature Algorithm (SLH-DSA) as a secondary line of defense based on different math.

“We encourage system administrators to start integrating them into their systems immediately, because full integration will take time,” Dustin Moody, a NIST mathematician who leads the post-quantum standardization project, said in a statement included in the release.

Future preparedness 

The standards are based on four algorithms that NIST selected in 2022 after a six-year competition to craft new quantum-ready encryption methods. Those algorithms were CRYSTALS-Kyber, CRYSTALS-Dilithium, Sphincs+ and FALCON. In 2023, NIST released draft versions of the three standards that were finalized Tuesday to solicit feedback. According to the agency, the standards haven’t substantially changed since then.

Additionally, while the newly finalized standards are based on the CRYSTALS-Kyber, CRYSTALS-Dilithium, and Sphincs+ algorithms, another draft standard for digital signatures based on FALCON is on the way. That standard will be called the fast-Fourier transform over NTRU-Lattice-Based Digital Signature Algorithm (FN-DSA), NIST’s announcement said. 

The agency is also in the process of evaluating two other sets of algorithms for general encryption and digital signatures “that could one day serve as backup standards,” NIST said. 

During a White House event Tuesday, Locascio said there will be scenarios in which the first three standards might be insufficient, which is why NIST and its global partners will keep working on generating and testing additional algorithms.

“We will ensure a strong pool of alternates and backups to provide resiliency and redundancy in the case of any yet unknown leaps in quantum mathematics,” Locascio said. “Now, while we know that these leaps and technological advances are inevitable, we do not wait for that future. We act now.”

Scott Crowder, vice president of quantum adoption and business development at IBM, which developed three of the four algorithms NIST selected with its collaborators, told FedScoop in an interview ahead of the announcement that the motivation for releasing the standards now has a couple of aims. 

The first is mitigating risks from bad actors collecting information now that they’ll try to decrypt when quantum computing is fully realized. For secure government work and industry areas where security is key, “that data has long-term value,” Crowder said. The second is giving organizations time to implement them, he said. 

In a way, the situation shares some similarity with the two-digit year abbreviation software bug that was projected to wreak havoc in 2000, known as Y2K. Whereas developers needed to find and change the places in code with a two-digit year ahead of 2000, here organizations need to find cryptographic deployments and change them, Crowder said. Though, the difference between the situations, he said, is that cryptography isn’t static and must evolve for different threats. 

The IBM-developed algorithms are CRYSTALS-Kyber, which is now the general encryption standard ML-KEM; CRYSTALS-Dilithium, which is now the primary digital signature algorithm ML-DSA; and FALCON, the forthcoming standard that will be called FN-DSA. The other finalized algorithm, which was called Sphincs+ and is now SLH-DSA, was co-developed by a researcher who was later hired by IBM.

Crowder said that following the release of the NIST standards, more compliance agencies around the world are likely to follow. 

Government, industry security

In addition to the standards, other work to prepare the U.S. government for post-quantum cryptography is also underway. 

The National Security Agency, for example, released its Commercial National Security Algorithm Suite 2.0 in 2022, outlining requirements for future quantum-resistant algorithms in national security systems. That same year, the Office of Management and Budget directed agencies to inventory cryptography on certain systems and estimate funding needed for migration to post-quantum standards.

Based on those estimates, the White House said the approximate funding needed to make the transition between 2025 and 2035 would be $7.1 billion. That estimate was part of a congressionally mandated report released last month that outlined a plan for migration to post-quantum cryptography, or PQC, standards in the federal government. OMB is required by statute to release guidance on agency migration plans within one year of the first NIST standards being published.

At the White House event Tuesday, Anne Neuberger, deputy national security advisor for cyber and emerging technology, said that through the process of inventorying cryptography, the government learned that it would be “wise” to do it in a more automated way. Neuberger also highlighted a need for prioritization.

“We’re learning that it’s important when you do those inventories to identify what are the most sensitive systems? What’s the most high-value data? Indeed, what’s the data that you’d care if an adversary could use a quantum computer in nine or 10 years to decrypt it?” Neuberger said. “We have lots of that in the intelligence community. We have lots of that in our Department of Defense.”

On an IBM press call ahead of the announcement, Lily Chen, a mathematician and NIST fellow, said “the PQC standardization process has been a community effort.” NIST worked with cryptographic researchers, industry and government for evaluation and feedback on the algorithms. That work with industry will need to continue as organizations make the transition, she said.

Similar to the government, some companies have also started looking at post-quantum standards ahead of the NIST announcement to ensure the safety of their information.

Richard Marty, the chief technology officer at LGT Financial Services who also spoke on the IBM call, said it isn’t an option for his company to write off the issue, sometimes called Q-day, as an industry or global problem that it will deal with later.

“We want to be ready for this, and we want to implement solutions as early as possible to specifically also address the threat of ‘harvest now and decrypt later,’” Marty said. “The less old our data is once Q-day happens, the better is our standing in the market, and we can keep up that trust with our clients.”