Zero trust first, AI second
Why data readiness determines AI success
Why it matters
- Stronger data controls make AI safer to deploy
- Clear use cases prevent costly, insecure AI adoption
- Zero trust investments accelerate long-term AI readiness
Zero trust is the foundation for safe AI adoption in government. At its core, zero trust means never automatically trusting a user, device or system simply because it is already inside the network.
As agencies accelerate AI adoption, zero trust and AI shouldn’t be treated as separate initiatives.
That’s a key theme Josh Salmanson, Vice President of Leidos’ Defensive Cyber and Resilient Network practices, highlights across two recent episodes of Billington CyberSecurity’s Federal News Network Cyber and AI Outlook series.
Agencies that have already invested in strong data and identity controls are better positioned to adopt AI securely and effectively. Salmanson joined officials from Department of Homeland Security (DHS), U.S. Government Accountability Office (GAO), and Pacific Northwest National Laboratory to discuss what it takes to operationalize AI responsibly in government. Across the conversations, a consistent theme emerged: AI readiness depends on having the right security, data and identity foundations in place.
Why is AI risky without a clear use case?
Salmanson is candid about where he sees the most risk in current AI adoption patterns – and it isn’t the technology itself.
I think where AI is riskiest is where you don't know exactly what the use case actually is.
Josh Salmanson
VP Leidos Defensive Cyber & Resilient Network
He’s seen customers come to meetings simply saying, “I need AI,” without a clear sense of the problem they’re solving or how their data currently exists to support it. That’s not where the conversation should start. Understanding the mission need, and how the data flows through the systems supporting it has to come first.
How does zero trust maturity affect AI readiness?
Salmanson drew a direct line between two efforts many agencies still treat as separate: zero trust maturity and AI readiness. When an agency already has strong controls over who, or what, is allowed to access its systems, he explained, it’s in a much better position to adopt new AI tools with confidence. Without that foundation, it is difficult to know where data is coming from, who or what is accessing it, and ultimately how to protect it.
What stands between agencies and safe AI adoption?
If the destination is clear, the path there is still difficult. Much of what stands between agencies and safe AI adoption isn’t lack of ambition or awareness.
For many agencies, the barrier to the zero trust maturity that would facilitate safe AI adoption is technical debt. Technical debt is the accumulated cost of keeping old, patchedtogether technology running instead of replacing or properly modernizing it. Salmanson pointed to long-standing gaps in data stewardship, a growing number of “machine identities” (AI tools and automated systems that now need their own credentials and permissions, the same way an employee does) operating alongside human identities, and legacy environments that were never built to handle the sheer volume of data AI systems generate and move.
These challenges of technical debt and data stewardship aren’t solved by introducing another tool. They require strengthening the underlying environment: understanding where data resides, who or what has access to it, and how identities, systems and data interact. These are the fundamental principles of zero trust.
There are mandates and timelines in place, and the clock is ticking for government agencies. It might feel like accelerating toward the finish line is the goal; however, these modernization efforts require understanding the current state of a network environment before vision-boarding the future state. The goal isn’t simply to move faster toward AI. The goal is to build the trusted foundation that allows agencies to move faster safely.
How can agencies prepare for secure AI adoption?
Salmanson sees agencies and industry increasingly converging around the need to bring zero trust, data readiness and AI adoption together.
Everybody's rushing to get to that combined space where they're zero trust ready as well as data ready for AI.
What does this mean for agencies moving forward?
Building the foundation now — starting with data, identity and access can help agencies prepare for the next wave of AI capabilities while maintaining the security and trust their missions require.
The opportunity is to prepare for what’s next in AI, and create an environment where agencies can adopt and scale new capabilities with greater confidence.
The full conversations
Salmanson’s comments are part of two full episodes of the Billington Cyber and AI Outlook series on Federal News Network, featuring perspectives from DHS, GAO and Pacific Northwest National Laboratory alongside his own:
- Risk, Trust, and Governance in AI-Enabled Cyber
- Operationalizing the Capabilities that AI Brings to Government Organizations
Key takeaways
- AI adoption should begin with a defined mission need, not a technology-first request
- Zero trust strengthens the data, identity and access controls required for secure AI
- Addressing technical debt now helps agencies scale future AI capabilities with confidence