AI, AI, AI – It’s Always About AI … But What About Cybersecurity?

Nina Sawyer, M.S.
Director of Data Engineering

On June 2, 2026, the White House issued a new executive order (EO), “Promoting Advanced Artificial Intelligence Innovation and Security,” focused on accelerating AI innovation. Much of the order emphasized maintaining U.S. leadership in artificial intelligence.

However, our team at Aquia found the juiciest — and most powerful — sections to be those centered on cybersecurity modernization, vulnerability management, and the collaboration between government and industry. Strengthening cybersecurity across federal systems and critical infrastructure is our bread and butter, after all, so seeing clear signals that AI and cybersecurity are being treated as deeply connected operational priorities was enough to make us sit up and pay attention.

To put it bluntly: AI is not just the new thing to secure. It is also becoming a vital part of that security toolkit. For years, organizations have treated AI and cybersecurity as parallel conversations. This executive order suggests those conversations are beginning to merge. Below are the top things you should know.

Our Key Takeaways

1. Federal Agencies Are Being Directed to Accelerate Cyber Defense Efforts

The order establishes aggressive timelines for federal agencies to prioritize cyber defense activities. This signals continued emphasis on cyber modernization and operational resilience.

Notable actions include:

  • Prioritization of cybersecurity efforts for National Security Systems.

  • New Cybersecurity and Infrastructure Security Agency (CISA) guidance and Binding Operational Directives (BODs) for civilian federal agencies.

  • Expansion of AI-enabled cybersecurity services and defensive tooling.

  • Increased support for state, local, and critical infrastructure organizations.

2. AI Is Being Positioned as a Cybersecurity Enabler

Rather than focusing solely on AI governance requirements, the order highlights AI’s ever-expanding role in strengthening defensive cybersecurity capabilities.

We expect to see growing interest in:

  • AI-assisted threat detection

  • Vulnerability discovery and prioritization

  • Security operations automation

  • Critical infrastructure protection

It’s important to note that CISA is especially directed to support programs that expand the use of AI-enabled security tools, and agencies are encouraged to increase access to advanced cybersecurity technologies.

3. Creation of an AI Cybersecurity Clearinghouse

One of the more operationally significant provisions is the establishment of a voluntary AI cybersecurity clearinghouse.

The clearinghouse is intended to:

  • Coordinate vulnerability discovery efforts

  • Reduce duplication across security researchers and organizations

  • Validate identified vulnerabilities

  • Prioritize remediation activities

  • Facilitate patch distribution

This reflects a broader trend toward centralized coordination between government, technology providers, and critical infrastructure operators.

4. New Framework for "Covered Frontier Models"

The order directs several agencies to establish a process for identifying advanced AI systems whose cyber capabilities exceed a threshold that agencies have yet to define publicly.

Developers may voluntarily engage with the government to:

  • Determine whether a model qualifies as a "covered frontier model"

  • Provide limited pre-release access for evaluation

  • Coordinate secure deployment and trusted-partner testing

Importantly, the order explicitly states that these activities are voluntary and do not create a licensing or pre-approval requirement for AI development.

5. Increased Focus on Criminal Misuse of AI

The Department of Justice is directed to prioritize enforcement against actors who use AI to:

  • Gain unauthorized access to computer systems

  • Damage information systems

  • Facilitate cybercrime

  • Support fraud or other unlawful activity

The order does not create new criminal statutes, but signals increased enforcement attention on AI-enabled cyber offenses.

What to Watch For

The order leaves a few important points open to development in a way that will make or break overall implementation. Organizations supporting federal agencies, critical infrastructure, or AI development will need to keep their ears to the ground as the following initiatives land:

  • CISA guidance and BODs

  • Criteria used to define a "covered frontier model"

  • Structure and operating procedures for the AI cybersecurity clearinghouse

  • Potential grant funding opportunities related to AI-assisted vulnerability detection

  • Expansion of federal cybersecurity hiring initiatives

The Bottom Line

We see significant potential in several aspects of this order, particularly its emphasis on vulnerability management, AI-enabled defense, and public-private collaboration.  Coupled with the protection of critical infrastructure, this suggests a continued convergence of AI policy and cybersecurity strategy across the federal landscape.

As federal agencies begin implementing the order's requirements over the coming months, additional guidance will provide greater clarity regarding expectations for both government and industry stakeholders. Having long operated at the intersection of cybersecurity, emerging technology, and federal modernization, we’re looking forward to helping our customers translate these strategic priorities into practical, secure outcomes.

Is your team looking for guidance regarding the responsible adoption and deployment of AI? Check out our free Federal AI Guardrail Framework, or send us a note at federal@aquia.us.

Aquia

Securing The Digital Transformation ®

Aquia is a cloud and cybersecurity digital services firm and “2024 Service-Disabled, Veteran-Owned Small Business (SDVOSB) of the Year” awardee. We empower mission owners in the U.S. government and public sector to achieve secure, efficient, and compliant digital transformation.

As strategic advisors and engineers, we help our customers develop and deploy innovative cloud and cybersecurity technologies quickly, adopt and implement digital transformation initiatives effectively, and navigate complex regulatory landscapes expertly. We provide multi-cloud engineering and advisory expertise for secure software delivery; security automation; SaaS security; cloud-native architecture; and governance, risk, and compliance (GRC) innovation.

Founded in 2021 by United States veterans, we are passionate about making our country digitally capable and secure, and driving transformational change across the public and private sectors. Aquia is an Amazon Web Services (AWS) Advanced Tier partner and member of the Google Cloud Partner Advantage Program.

Previous
Previous

So You Want to be Human-Centered … But What Does That Mean in Practice?

Next
Next

M-26-14 Just Ended the Era of Tool-Stack Zero Trust