
As a security reporter for ProPublica, my main research over the past two decades has been on how the federal government and its IT contractors, like Microsoft, have navigated significant industrial transitions. Artificial intelligence is the subject of today’s media.
Everyone is in a rush to use this emerging technology because it has hand on home consumers, businesses, and the federal government. If only we can choose AI quickly enough, President Donald Trump and his cabinet claim that it will change the country, making us more successful, effective, and safe.
However, this communication is not fresh. When the United States sabotaged the industrial revolution of cloud computing, President Barack Obama’s management used nearly identical speech a decade and a half ago.
In my monitoring, which includes some warning tales and useful training for policymakers who encourage the use of AI and governmental agencies adopt the technology, I’ve examined how the federal government handled this change over the past two decades and how it has handled it improperly.
Lesson 1: There is no such thing as a free meal.
Therefore, a number of attacks connected to Russia, China, and Iran in the first 2020s left the federal government reeling. The Biden administration contacted big tech firms to offer support to the United States to strengthen its threats. Satya Nadella, the CEO of Microsoft, made the pledge to give the govt$ 150 million in technical services to help improve its online security in response. Additionally, it provided government users with “free” security upgrades.
Then: The Trump administration made a number of agreements with technology companies last year that would allow federal agencies to “purchase organization AI tools at government-friendly pricing.” Organizations had pay$ 1 for ChatGPT from OpenAI. Google’s Gemini for 47 percent. xAI’s Grok for 42 percent. The administration hoped that low-cost pricing would enable “powerful AI capabilities” to be acquired by provincial teams to improve mission delivery and administrative efficiency.
The conclusion: Be afraid of discounts. Our research into Microsoft’s ostensibly clear dedication revealed a more intricate, profit-driven agenda. National customers may be permanently locked in after the upgrades were installed because switching to a company after the free trial would be laborious and expensive. The consumer may then have no choice but to pay the higher subscription fees. The strategy was successful, according to a former Microsoft marketer, who told me, “it was successful beyond what any of us could have imagined.” Microsoft has stated that its” sole objective” during this time was to” support an urgent request by the Administration to improve the security posture of federal agencies who were consistently being targeted by sophisticated nation-state threat actors.”
Agencies looking to purchase AI tools at discount rates now must consider how the costs may skyrocket in the future. The General Services Administration advises organizations to” set usage limits and often survey use information” and warns that “usage fees can increase quickly without proper tracking and management regulates.”
Lesson 2: Resources are only as powerful as monitoring plans are.
The federal government moved its delicate computing and information needs to data centers run by private companies in the Obama administration. The management acknowledged the potential risks by creating the Federal Risk and Authorization Management Program, or FedRAMP, in 2011 to help ensure the security of the cloud computing services that it was urging U.S. companies to apply.
However, in my new analysis of the system, I discovered it was invincible to Microsoft, which essentially wore down the FedRAMP team over the course of five years as the company sought program authorization for a significant cloud offering known as GCC High. Despite severe reservations about the product’s cybersecurity, FedRAMP finally granted it, in part because it lacked the resources to continue. Microsoft responded to questions by saying,” We stand by our products and the thorough methods we’ve taken to ensure that all FedRAMP-authorized items meet the security and compliance requirements required.”
Then: This minuscule island within the General Services Administration has actually fewer resources today to manage the cloud technology that the government rely on, including AI. According to FedRAMP, it nowadays operates” with the absolute minimum of assistance staff” and” with limited customer service.” The Department of Government Reliability of the Trump administration targeted the program very quick.
The conclusion: Former employees told me that FedRAMP, which a White House memo from 2024 stated “must be an expert system that can assess and evaluate the protection claims” of cloud providers, is now essentially a rubber stamp for the tech sector. The effects of this reduction on national security are profound as federal companies adopt AI tools that use vast amounts of sensitive data. FedRAMP then “operates with strengthened supervision and responsibilities mechanisms,” according to a GSA spokesperson.
Lesson 3:” Self-employed” reviews are simply so far-sighted.
The government has also long relied on ‘third-party assessors’ to evaluate safety statements made by cloud service providers like Google and Microsoft. These companies are supposed to be independent experts who can in theory advise FedRAMP about whether a product complies with national standards. However, their freedom is indicated by the fact that they are paid by the businesses they are evaluating.
This arrangement, according to my new research, creates an intrinsic conflict of interest. According to a former FedRAMP critic, two inspectors in the case of Microsoft’s GCC High recommended the product despite being unable to completely specialist it. One of those companies denied this consideration, while the other refused to respond to my inquiries.
FedRAMP, in our opinion, is well aware of how the financial agreement between cloud businesses and their assessors may skew standard findings regarding cybersecurity issues. In order to avert ignominy their technical clients and lose business, the program also created a “back channel” to encourage assessors to discuss concerns they might not otherwise increase in official reports.
These third-party examination companies have grown even more significant in the screening process then that FedRAMP has been reduced to being a “paper pusher,” as one former GSA established put it. The GSA claimed in response to questions from ProPublica that FedRAMP’s program “does not build a professional auditors ‘ professional interest to meet ethical and legal performance expectations.” It did not respond to inquiries about the rear route of the program.
The conclusion: Largely, the swing has reverted to the pre-FedRAMP period, when each national agency was in charge of overseeing the products it sourced. According to the GSA, FedRAMP’s goal is to “make sure authorities have sufficient information to make these chance choices.” The issue is that organizations frequently lack the personnel and resources to conduct rigorous reviews, which means that the entire structure relies on the claims made by cloud companies and the evaluations of third-party companies.
The Federal government is rushing toward AI, the article. Our Reporting Provides Three Warning Legends. primary appeared on ProPublica.




