NIST narrows in on risks related to chem-bio AI models


The National Institute of Standards and Technology’s Artificial Intelligence Safety Institute is seeking information on the development of chemical and biology-focused artificial intelligence models.  

In a Federal Register posting Friday, the AISI said it is specifically interested in potential benchmarks and evaluation tools for understanding these models, as well as guidance on mitigating the kind of security risks they might raise. 

The focus on these kinds of AI models comes amid growing excitement that they might be used to advance scientific goals — like identifying new medications — but also concern that the technology could create myriad national security risks. 

“By reducing the time and resources required for experimental testing and validation, chem-bio AI models can accelerate progress in areas such as drug discovery, medical countermeasure development, and precision medicine,” the posting states.

It continued: “The dual use nature of these tools presents unique challenges — while they can significantly advance beneficial research and development, they could also potentially be misused to cause harm, such as through the design of more virulent or toxic pathogens and toxins or biological agents that can evade existing biosecurity measures.” 

Some of the topics addressed by the request for information specifically concern national security issues. Other sections of the RFI address various security considerations, including how two models interact and the potential for these models to harm biodefense and biosecurity. 

Responses are due by Dec. 3. 

GAO finds spotty agency compliance with IDEA Act requirements

The reporting that agencies are required by a 2018 law to do on various website and digital services benchmarks is often incomplete and inconsistent, according to a new report from the Government Accountability Office.

The congressional watchdog found that full compliance with the 21st Century Integrated Digital Experience Act — which mandates annual reports from the 24 Chief Financial Officers Act agencies on federal website standards and eight modernization requirements — is lacking, resulting in submitted reports with “varying levels of content and detail.”

“The lack of detailed guidance contributed to the varied reporting, and the reporting requirement ended without producing consistent reports that could be used to reliably determine agency performance and government-wide progress,” the GAO stated.

On the law’s modernization callouts — requiring websites and digital services to be accessible, consistent, customizable, encrypted, mobile-friendly, not duplicative, searchable and user data-driven — the GAO found some agencies that had addressed all eight requirements and others that had completed none, per submitted 2022 and 2023 reports.

“In addition, agencies submitted 84 (or 70 percent) of the 120 total required annual 21st Century IDEA reports,” the watchdog noted. “Further, the contents of the reports, including the extent to which they addressed the eight modernization requirements, varied significantly.”

In 2023, 109 out of 192 modernization requirements — eight per each CFO Act agency — were met, up from 84 the previous year. But over the same time period, the number of unaddressed requirements climbed from 28 to 35. 

There were several positives in the GAO’s report, including the singling out of seven agencies that met all eight requirements in 2023: USAID, the Environmental Protection Agency, the Nuclear Regulatory Commission and the departments of Commerce, Education, Homeland Security and Interior. 

The GAO’s report also examined four offices identified by the Office of Management and Budget as High Impact Service Providers (HISPs) — which provide or fund “customer-facing services that have a high impact on the public” — that are meeting the 21st Century IDEA Act mark. 

The public-facing websites of State’s Bureau of Consular Affairs, DHS’s Federal Emergency Management Agency, Interior’s Fish and Wildlife Service and DHS’s Transportation Security Administration, the GAO said, all leveraged resources from the General Services Administration’s Technology Transformation Services to “meet the requirements related to modernizing federal websites and digital services and enhancing the user’s customer experience.” 

Those resources include FedRAMP, Search.gov, the U.S. web design system, Login.gov, and various survey platforms, the GAO reported. All four HISPs additionally made use of OMB’s customer experience team.

Federal cyber officials search for funding solutions to keep up with growing demands

Keeping up with zero trust implementation and other governmentwide cybersecurity mandates will require different approaches, including a “fundamental change” in how those efforts are funded, a pair of federal officials said Thursday. 

Speaking during an ATARC Federal Zero Trust Summit event, State Department and Cybersecurity and Infrastructure Security Agency tech leaders shared potential solutions around funding for technology transformation, including via a shift that would establish cybersecurity projects similarly to modernization efforts.

Donald Bauer, the chief technology officer within State’s Office of Technology Services, said there is a “need” for “fundamental change in the way the government’s approaching funding some of these efforts. What if Congress or the appropriators created another lane called cybersecurity? I think we’ve probably reached a point in our ecosystem, as a federal government, where … we have our modernization money and we have our cyber money.” 

Bauer said 25% of his team’s budget goes towards cybersecurity — primarily remediation — but they have faced a 28% cut in modernization funds. 

“The squeeze is on, but there’s no relief in sight,” Bauer said. 

Some of that relief can come from the Technology Modernization Fund. Shelly Hartsook, the deputy associate director of capacity building at CISA, pointed to the TMF as well as advancing the continuous diagnostics and mitigation (CDM) program to help agencies build toward their own cyber stack. 

While CDM, a program that aims to deliver cybersecurity tools and integration services to agencies that want to improve security posture, “does not provide every tool that every agency might want,” Hartsook said, it “does provide a lot of them.”

“That’s really where we’re trying to go in the future,” she continued, “where you might only be able to make an incremental investment based on your budget situation, working with the program so that these things are working in concert. And that we’re helping build towards your own cyber stack and not a competing set of tooling that’s tied into CDM.” 

Hartsook, a TMF board member, pointed to the funding vehicle as something that could still help agencies looking to fund zero trust implementation projects and initiatives. 

“I know it is not the be all, end all, but we do still want to see zero-trust proposals,” Hartsook said. “For folks who are not seeing that budget line item increase for their own shop, again, the TMF is still an option around that.”

But Bauer said his dealings with TMF and other avenues have been a mixed bag, calling out a “huge disconnect” in interactions with his Office of Management and Budget representative on funding issues.  For TMF, he said, “it’s not just ask and you get it. You have to compete, compete, and it’s a mortgage of your future. You’re borrowing future dollars for today.”

“But if Congress were to say, ‘Hey, here’s the cybersecurity funding effort, we’re going to give you 5 million against cyber,’ I’m happy to show you where every single penny goes for that particular investment,” he added. “I feel like that’s the disservice that I felt, like I’ve gotten when I see an executive order come over [that] says I have to comply and there’s not” enough funding for it.

Zero trust isn’t Bauer’s only tech-related worry: the CTO also expressed concern about executive branch guidance, specifically the White House’s artificial intelligence executive order. 

“I have AI coming at me in seven different directions, from people who want to dump a bunch of data in there to get an answer, which I have to make sure that they don’t do that,” Bauer said. 

Bauer said his organization also needs “a lot of help” in understanding how to unwind legacy technology. 

“I’m sorry, I just don’t have the latest and greatest tools — I have plain old vanilla … servers,” Bauer said. “I pride myself on not being bleeding edge because I am 24/7. I don’t have the luxury of putting something out there that might work or might not.”

But State’s Office of Technology Services does “a lot of our own software,” Bauer noted, and his organization is getting ready to have dynamic scanning using artificial intelligence.

“It raises the level of your whole organization, because what happens with us as we run it through our scans and it comes back and says, ‘here’s a vulnerability,’” Bauer said. “We force our developers that didn’t own that code but have similar technology to go and look for that same vulnerability in their software, so that we bring the whole level of the organization up.”

GSA issues final draft solicitation for Ascend blanket purchase agreement

The General Services Administration on Tuesday issued the final draft solicitation for pool 1 of its Ascend blanket purchase agreement — a governmentwide, one-stop-shop for agencies to buy cloud technologies.

The BPA seeks to address the government’s need for simplified procurement procedures and cost savings regarding cloud solutions and baseline cybersecurity requirements. The contract, per the posting, is aimed at ensuring that cloud services and cloud-enabling professionals are “continuously and securely operated and maintained for confidentiality, integrity and availability.” 

Pool 1 of the Ascend contract is focused specifically on infrastructure-as-a-service and platform-as-a-service cloud offerings, whereas pools 2 and 3 are tailored to software-as-a-service and cloud-related IT professional services, respectively.

GSA invited those interested in participating in the Ascend BPA acquisition to review the posting on eBuy. “Anticipated award dates are yet to be determined,” the solicitation said. “More information is to follow.”

“It remains GSA’s intent to award the Ascend BPA in a phased manner as a featured part of GSA’s cloud marketplace,” the posting continued. “We plan to make multiple awards in each pool each with its own specific scope that will allow all federal agencies and other eligible entities to acquire and implement secure, integrated commercial IaaS, PaaS, and SaaS cloud solutions including cloud-focused labor services.”

This isn’t the first draft solicitation GSA has issued for the contract. The agency in May issued a first draft of the contract for pool 1, and then based on the feedback received, revised the solicitation. 

Laura Staunton, assistant commissioner of the Office of Information Technology Category within GSA’s Federal Acquisition Service, said in a September blog post detailing those revisions that: “The Ascend Blanket Purchase Agreement (BPA) … will meet the government’s demand for more comprehensive, secure and compliant cloud-based solutions. It allows GSA to develop a solution for federal, state, local, tribal and territorial governments that will make buying cloud less complicated.”

Interested parties are encouraged to respond to the final draft by Oct. 18 with recommended answers or solution rationale, questions and comments.

White House issues guidance for purchasing AI tools to US agencies

New federal guidance for acquiring artificial intelligence solutions directs U.S. agencies to take steps to manage risks, promote competition and share information within the executive branch.

The White House Office of Management and Budget on Thursday publicly released its anticipated memorandum on responsible AI acquisition in government (M-24-18), charting an initial path forward for agencies to buy products that use the booming technology in a safe and responsible way and placing new criteria on those contracts. 

“The AI used by federal agencies will likely either be built by a contractor on behalf of an agency or purchased by a federal agency for use,” Jason Miller, deputy director for OMB and COO of the federal government, said during a press call. “This new memo provides agencies with the tools and information they need as they acquire AI, capturing its promise while managing its risks.”

The memo carries weight as the U.S. government is the largest single buyer in the country with an annual spend of over $750 billion. Technology accounts for a large piece of that spending. In 2023, the federal government spent more than $100 billion on IT products and services, including AI, according to the White House.

Under the memo, which was required by President Joe Biden’s executive order on the technology from last year, AI will generally be treated as a type of IT acquisition. 

Moreover, agencies will be required to take steps to promote competition within the AI market, such as taking interoperability into consideration and preventing “vendor lock-in.” The guidance also establishes requirements to share information about AI acquisition with other agencies, including lessons learned and best practices, and creates a working group led by the federal CIO and administration for federal procurement policy to inform acquisition strategies in the future. 

OMB defines AI covered by the memo as instances in which a tool, software or system was designed for the specific purposes of “researching, developing, or implementing” AI, as well as instances in which AI is integrated into other types of systems, activities, and processes. It notes, however, that “common commercial products” with AI are excluded. 

Generally, that definition wouldn’t cover products like a word processing system, but in cases where such a system is more customized to the agency’s needs or used primarily for AI, it likely would be covered by the memo. 

To help agencies make determinations of what constitutes an AI acquisition, the memo advises them to consider actions such as asking vendors to report proposed AI uses in cases where the agency hasn’t explicitly required an AI system, and requiring contractors to notify stakeholders when AI is integrated into systems and services under a contract.

An administration official told reporters that the White House has been working with various groups across the federal government to develop the guidance. “This is no surprise to them,” the official said, adding that the aim of the guidance was to achieve the administration’s goals and be actionable so that agencies can meet deadlines and effectively manage the technology.

Deadlines to comply with the memo are coming up over the next several months.

By Nov. 1, agencies must identify contracts with rights- and safety-impacting AI, which are uses that require additional risk management steps. And by Dec. 1, agencies must ensure that contracts with rights- and safety-impacting systems are brought into compliance with certain requirements under the memo and that new contracts are consistent with the guidance. The memo then applies to any applicable AI contract issued 180 days after the memo, as well as renewals and extensions of existing contracts.

Those deadlines are happening simultaneously with existing deadlines from OMB’s memo on AI governance, including the deadline for extension requests for rights- and safety-impacting uses later this month and deadline for agencies’ annual AI use case inventories in December.

White House official: Next phase of zero trust will focus on operations

The federal government is in a “great place” following an agencywide deadline on zero-trust architecture implementation and now looking ahead to more challenging aspects of the cybersecurity model, according to a White House official. 

Mike Duffy, the acting federal chief information security officer, said in an interview with FedScoop that the next phase of zero-trust architecture implementation will focus largely on operations, taking near-term technical controls and leveraging those into a “longer-term technology transformation effort” and more defensible architectures. 

“We are ready to take off and prepare for addressing those more complex challenges of an agency’s architecture,” Duffy said. For a specific agency, that could mean “really honing in on a high-value asset that they know needs to apply a particular type of zero-trust principles or architecture. That is really the shift.”

Duffy expressed confidence in what’s to come for agencies’ zero-trust objectives following the Sept. 30 implementation deadline that aligned with Office of Management and Budget guidance. While agencies are still currently in the “high 90% range” — a figure previously reported by the federal CIO and confirmed by Duffy — the acting CISO said agencies continue to be “very focused, budgeted, resourced” to make sure they are “truly covering all critical assets.”

There’s also interest from agencies in shared services opportunities for additional cybersecurity and zero-trust strengthening efforts, Duffy added. 

“How can the federal government, either through [the Cybersecurity and Infrastructure Security Agency] and the Continuous Diagnostics and Mitigation program and others, provide additional capability and support, as CISA already has been doing?” Duffy said. “We’ve spent a lot of time convening through both the federal CISO council and through other forums, but just making sure that agencies who have found success are sharing those lessons learned with others to apply within their own unique environments.”

The acting federal CISO touted “tremendous progress” on agency progression to almost complete zero-trust implementation at the current standards and pointed to a scorecard on Performance.gov that “gives a sense of where agencies are with those foundational elements.”

“We are positioned and ready to take advantage” of the defensible architecture side of the next phase, Duffy said. There is still, however, a “final mile” where agencies often must apply additional resources for complex architectures that have not been fully resourced well enough to take on new capabilities for zero trust.

“I’m hopeful that it’s a matter of proper resourcing, which you’ve seen in the administration’s cyber priorities,” Duffy said. “That’s something that OMB can work with the agency to see how we can prioritize and deploy capabilities in support of that. There are operational technologies that are certainly challenging to agencies as they think about how they can resource and support a zero-trust architecture in those environments.”

This “final mile” still includes security controls and compensating controls that agencies are “always considering,” Duffy said. 

“CIOs and CISOs recognize that these can be challenging environments,” he said, “and applying zero trust as quickly as we have has been a tremendous achievement.”

CHIPS office eyes $100 million competition focused on manufacturing and AI


The National Institute of Standards and Technology’s CHIPS Research and Development Office plans to initiate competition with up to $100 million in funding focused on the sustainable manufacturing of semiconductor chips and artificial intelligence, according to a posting to the Federal Register published Wednesday. 

The upcoming Notice of Funding Opportunity is meant to boost support for new materials in chip manufacturing and comes as the Biden administration continues to invest in the domestic tech industry. The effort will focus on improving the performance of new chips and increasing the quantity of chips that can be manufactured, as well as on addressing issues with energy and water efficiency and other environmental concerns raised by chip manufacturing. 

There is a particular emphasis on artificial intelligence-powered autonomous experimentation, or AI/AE, an approach meant to accelerate the design and construction of new chip manufacturing technologies. The hope is to work against typically slow development timelines in the chip industry, which stand to hamper American semiconductor industrial policy goals. 

There’s growing concern that just over 10% of the world’s chips are now made in the United States, a sharp decline from decades earlier. The CHIPS Act, and subsequent efforts like AI/AE competition, are supposed to reverse — or at least mitigate — this trend. 

“If successful, these techniques can enable the co-optimization during materials discovery of multiple metrics important to next-generation microelectronics including microelectronics performance, manufacturing readiness, manufacturing economics, human health and safety, and environmental impact, including but not limited to PFAS mitigation and elimination, waste reduction and manufacturing water/energy efficiency,” the posting explains.

It continues: “By leveraging AI/AE and working in close partnerships with industry, CHIPS R&D intends to allow for the more rapid and cost-efficient discovery, design, validation, and deployment of sustainable materials and processes compared to traditional R&D approaches.”

Money appropriated toward the competition is supposed go toward the purchase of new equipment at universities, new technologies, expanded workforce, and other basic and applied research. Ultimately, the office hopes to fund at least two awards.

GSA begins COMET II contracting process

The General Services Administration is seeking sources for market research through the agency’s eBuy program for its $1 billion CIO Modernization and Enterprise Transformation II (COMET II) acquisition.

The request for quotes, which was shared in an email with FedScoop, aims to provide industry with the draft COMET II Performance Work Statement (PWS) as well as gain feedback on the initial task orders and the PWS, according to the posting. The multi-award blanket purchase agreement from the GSA aims to provide services and IT products to support GSA IT transformation, modernization, creative and maintenance efforts, according to the post. 

Contractors who are ultimately selected for awards must “be able to build secure applications, platforms, IT development services and products by utilizing human centered design … thinking.” Additionally, the agency added agile software development methods and responsible use of artificial intelligence and machine learning, as applicable, to resolve user problems and deliver.

“The COMET II BPA Contractors must be able to expertly deliver in the overarching objectives, either individually or through teaming arrangements,” the RFQ states. “The BPA will provide a streamlined process to support the purchase of IT products and agile delivery services.”

GSA is also looking for contractors who can deliver custom code development and “utilization of existing marketplace products. COMET II BPA vendors must be skilled with integration of commercial off the shelf … solutions,” along with software as a service or hybrid solutions to make an effective and economical solution for the government. 

The GSA’s first of these blanket purchase agreements, COMET, came after the agency’s CIO Application Maintenance, Enhancements and Operations (CAMEO) project in 2019. This BPA was used to launch an agencywide contract-writing system and modernize its point-of-sale system in 2020. In 2019, however, the GSA awarded 12 spots to both large and small businesses to modernize backend procurement systems.

This RFQ is set to close Wednesday.

Harnessing AI innovation across federal agencies

As artificial intelligence continues transforming the federal government, agencies are investing in innovative AI applications to enhance mission effectiveness, security and efficiency. In a recent video interview series, produced by Scoop News Group for FedScoop and underwritten by Broadcom, federal agency leaders and industry experts discuss their AI initiatives, the benefits they are experiencing and the infrastructure challenges they are working to overcome. The series also looks at the merits of “private AI.”

Advancing mission-critical work

Dr. Colin Crosby, U.S. Marine Corps service data officer and deputy Department of the Navy chief data officer, emphasizes the dual use of AI for decision support and battlefield applications. “We have to be ready to spin up GPUs when we need them and then scale back when the heavy workloads are done,” says Crosby, highlighting the need for flexible AI infrastructure to support diverse mission requirements.

Meanwhile, Garrett Berntsen, Deputy Chief Digital and AI Officer for Mission Analytics at the DOD, discusses the critical role of AI in battlefield awareness and command and control functions. “AI can be super powerful both for doing that fusing of the data across different types and locations and for all kinds of warfighting functions from analysis of the battlefield prediction,” he says. According to Berntsen, DOD is also investing heavily in computing power and upskilling personnel to meet AI’s growing demands.

In addition, NASA Digital Transformation Culture and Communication Lead Krista Kinnard talks about how AI helps astronauts evaluate their equipment in space and optimizes project management on the ground. “We are using AI not only to explore and discover but also to run NASA more efficiently,” says Kinnard, stressing the importance of thoughtful AI implementation to manage costs and energy usage​.

Improving disaster management

Federal agencies are also using AI to improve disaster relief. U.S. Army Corps of Engineers CIO Dovarius Peoples pointed out that AI is revolutionizing disaster relief and infrastructure management. “We’re leveraging AI to better predict where flooding may occur and respond more effectively,” says Peoples.

Department of Homeland Security Deputy CIO for AI & Emerging Technology Chris Kraft also highlights AI’s transformative impact on agency operations, including border security and disaster management. “We are leveraging AI across our missions… improving the experiences of the people we serve and enhancing our national security,” says Kraft. DHS is also focused on using AI responsibly, ensuring it is rigorously tested for bias and privacy concerns.

Streamlining operations

IRS Chief of Artificial Intelligence Randy Soper discusses AI’s potential in enhancing taxpayer services and compliance. “We’re really excited about the potential that AI brings to the agency to deliver on the promises of the Inflation Reduction Act,” he says. In addition, Soper shares how the IRS is balancing between on-premises and cloud solutions to manage data security and costs effectively​.

U.S. Senate Federal Credit Union CIO Mark Fournier details how AI is helping the organization manage complex data loads and streamline operations. “We’re doubling down on upskilling our internal talent to handle AI and integrate it into our mission,” says Fournier, while also emphasizing the need to balance immediate AI applications with long-term strategic planning.

Advancing cybersecurity efforts

In her interview, Melissa Vice, director of the Vulnerability Disclosure Program in the DOD’s Cyber Crime Center, explains how AI supports cybersecurity efforts within the DOD. “We are focusing on implementing AI to provide solutions at speed and scale, helping us protect sensitive data across the defense industrial base,” she says, noting the critical role of secure data management in law enforcement and intelligence activities​.

In addition, Defense Information Systems Agency CTO Steve Wallace describes the growing role of generative AI in enhancing cybersecurity and operational efficiency. “We see AI sitting sidesaddle with analysts to help decompose attacks and respond quickly,” he says, underscoring the need for cautious adoption and measured investment in AI technologies.

Embracing private AI

While federal agencies are embracing AI to improve operations, the challenges of managing data security, upskilling personnel and investing wisely in AI infrastructure remain at the forefront.

Broadcom Global Head of AI Chris Wolf says private AI brings several benefits to federal space, including the ability to maintain privacy and control, lower costs and improve service delivery. “These are things that are really at the heart of the solution that we’ve been looking to drive,” says Wolf. “We want to make sure that an organization can just make one singular investment in AI infrastructure and future-proof it.”

Broadcom’s VMware Private AI solution provides governments an open architectural approach to leveraging AI while maintaining privacy, control and compliance. “This approach is not just about ensuring data privacy but about providing a scalable, efficient way for businesses to adopt generative AI technologies,” says Krish Prasad, senior vice president and general manager of Broadcom’s VMware Cloud Foundation Division.

This video series was produced by Scoop News Group, for FedScoop and sponsored by Broadcom.

GSA isn’t fully compliant with geospatial data requirements, watchdog finds

The General Services Administration is not fully compliant with a key piece of the Federal Aviation Administration Reauthorization Act that governs processes related to geospatial data, a new watchdog report found.

In a report released Monday, the GSA’s Office of Inspector General flagged unreliable geospatial datasets that contain “inaccurate latitude and longitude coordinates” and data quality deficiencies, undercutting the agency’s compliance with the Geospatial Data Act of 2018. As a result, the datasets are not meeting the legislative goals of improving public health and other services, spurring economic growth and advancing science, according to the OIG. 

OIG suggested that GSA’s chief information officer address four recommendations that include implementing controls to ensure that specific datasets contain accurate coordinates based on physical location, correcting geospatial data quality deficiencies, strengthening the data validation process and establishing a process to make sure GSA searches existing data before procuring new data. Specifically, OIG found issues with the GSA’s Inventory of Owned and Leased Properties (IOLP) and the Federal Real Property Profile Management System (FRPP MS). 

In response to its audit, the OIG said that “GSA implemented corrective actions designed to address our findings and improve the management and oversight of its agency-wide GSA compliance. … Notwithstanding these corrective actions, we identified deficiencies in GSA’s compliance with the” Geospatial Data Act.

OIG recommended that the agency implement controls to ensure that IOLP and FRPP MS datasets have the right coordinates for each property’s physical location based on the Federal Geographic Data Committee’s Real Property Asset Data Standard (RPADS). The  GSA disagreed with that recommendation, saying that the committee’s standard “was established prior to the enactment of the GSA and is not subject to the GSA’s authority or control” and that implementing controls to align with this standard would be “premature.” The agency also expressed concern about the security implications of following the standard. 

OIG, however, defined RPADS as an “appropriate data standard as defined under the GDA” and insisted that GSA is required to comply with this standard. 

Additionally, GSA did not concur with a recommendation to establish a process for searching existing geospatial data before procuring new data, and instead stated that “the audit did not identify an instance of GSA purchasing duplicative geospatial data. GSA also asserted that its geospatial data purchases are immaterial.”

OIG reaffirmed this recommendation because the law requires GSA to “search all sources prior to purchasing geospatial data” and that the agency “does not have an effective process in place to meet this requirement.”

The agency partially concurred with OIG’s recommendation to correct data deficiencies identified in the report, “but did not clearly state the reason why it partially concurred with this recommendation.” In comments regarding the report, GSA “asserted that IOLP and FRPP MS datasets are highly accurate but did not dispute that the data errors we identified should be corrected.” OIG reaffirmed the recommendation.