Who’s doing what on AI security in the US government?
A brief review of the EO, NSPM, and what we don’t yet know
We’re excited to share that Horizon is launching an AI Rapid Response Fellowship, a focused effort to address the urgent shortage of government staff with the domain expertise to respond to fast-moving AI security challenges. The program will move experienced technical and policy talent into federal offices on an accelerated timeline, with placements beginning as soon as possible. See full details and apply here.
Frontier AI systems are rapidly improving across many dimensions. The full extent of their capabilities, and their real-world implications, are still being debated. But those who follow the field closely—even if they disagree strongly on policy prescriptions, or the exact pace of progress—seem generally aligned on the AI’s trajectory: we are likely to see even more capable models at least somewhat soon, and that access to these capabilities will keep diffusing to a wider range of actors.
This trend has drawn the policymakers’ attention. Earlier this month, the White House responded with two major policy updates: an executive order (EO) on advancing AI innovation and security and a companion national security presidential memorandum (NSPM-11) on AI in the national security enterprise.
If you have not been in government or the policy world—and honestly, even if you have—these can be complicated documents to decipher. And much goes unwritten as well: for example, export controls were not mentioned in either the EO or NSPM, but within the weeks after their release became a big part of the same broad policy debate.
This post summarizes what we know so far about who’s doing what: what the EO, NSPM, and domain experts say about which parts of the government are leading on AI security, and how that may evolve (spoiler: probably a lot!).
If you’re considering AI security work in government near-term—through the AI Rapid Response Fellowship we just launched or otherwise—we hope this post can help orient you to the landscape, even as many details (big and small) are likely to keep changing.
Who’s doing what in government
Caveats: Presented with lots of uncertainty, and in no particular order…
The White House
The White House sits at the center of the AI security response. Many White House components contributed to the development of both the EO and the NSPM, and the White House plays central coordination and consulting roles in the major initiatives of both directives.
Power in the White House is somewhat informal and can shift quickly, but the following offices have had at least a somewhat prominent role:
Chief of Staff. White House Chief of Staff Susie Wiles has been, per reporting, a central figure in the AI-security response. She took part in the high-level White House meetings with Anthropic and Treasury Secretary Bessent on how to respond to Mythos, and reportedly pushed for the voluntary-framework approach the EO ultimately took. The Chief of Staff is explicitly named in various core EO and NSPM workstreams.
Office of the National Cyber Director. ONCD reportedly led much of the EO’s drafting and is consulted at nearly every step, including the binding directives ordering agencies to shore up their cyber defenses. It’s a relatively small office (at a few dozen staff) with a large mandate, and the office has seen some AI-focused staff depart in recent weeks.
Office of Science and Technology Policy. OSTP’s director, Michael Kratsios, is a consulted or reviewing party across much of the EO, including on developing a classified benchmark that measures models’ cyber capabilities. Under the NSPM, he co-leads the “compute roadmap,” which is meant to ensure that national security agencies have enough computing power to run advanced AI.
National Security Council. The NSC is traditionally the President’s in-house body for national security policy, and has previously functioned as a central node for cross-cutting work on emerging tech issues. However, reporting on the EO’s drafting suggests its cyber staff was not central to the process, and the EO doesn’t assign NSC a role. Under the NSPM, the National Security Advisor (currently Marco Rubio) is named to review several deliverables before publication, including the joint AI security strategy.
Office of the Vice President. Vice President JD Vance has been engaged in early AI security discussions: in April, he and Treasury Secretary Bessent questioned major AI and tech CEOs about model security in the run-up to Mythos’s release. Even as OVP has no formal tasking in either document, the office is generally involved in White House and interagency AI policymaking processes.
Office of Management and Budget. Under the EO, OMB reviews whether existing federal grant money can be steered toward AI vulnerability-detection work. Under the NSPM, it co-leads the policy governing how AI can be used on classified and military systems, plus the compute roadmap noted above.
Outside advisors. David Sacks, the administration’s former AI and crypto czar (now co-chair of the President’s Council of Advisors on Science and Technology), has remained an influential voice and reportedly intervened to delay an earlier version of the EO. Various tech and finance CEOs, such as Marc Andreessen and Jensen Huang, also sit on the Council and have been influential in shaping policy.
Treasury Department
Treasury is historically responsible for securing the banking and finance sector. It wasn’t a major leader on AI policy prior to Mythos, but Treasury Secretary Scott Bessent has recently been among the most active voices in AI policy: he convened the largest banks’ CEOs the day Mythos was announced, called its capabilities a “step function change,” and has reportedly pushed for faster action on risks to the financial system and critical infrastructure more broadly, expanding Treasury’s remit beyond its historic scope.
The EO assigns Treasury major roles in two new initiatives:
Treasury will lead the development of a new “AI cybersecurity clearinghouse” that will coordinate with AI companies and critical-infrastructure operators to scan software for vulnerabilities, validate findings, and prioritize how patches get distributed.
Treasury will co-lead on the classified benchmark that will measure models’ cyber capabilities to determine which count as “covered frontier models,” and on the voluntary framework through which developers can share models with the government pre-release.
Because Treasury is relatively new to work on AI, there’s limited public information about which specific office(s) will lead on it and what their capacity is. But likely players include:
AI Transformation Office (AITO) is the central office coordinating AI adoption and governance across Treasury, established in 2025 and led by Chief AI Officer Paras Malik (who is also Counselor to Secretary Bessent). Its formal remit is mostly internal, but the office recently ran an AI Innovation Series with the Financial Stability Oversight Council, which convened banks, tech firms, and regulators on AI strategy, cybersecurity and risk management, and financial-stability implications.
Office of Cybersecurity and Critical Infrastructure Protection (OCCIP) executes Treasury’s work on financial sector security, including sharing cyber threat information, encouraging baseline protections, and coordinating incident responses. Among other AI-related work, OCCIP coordinated Treasury’s AI Executive Oversight Group. OCCIP sits within the Office of Domestic Finance, which also oversees other AI-relevant offices.
Office of the Chief Information Officer (CIO), currently Sam Corcos, runs Treasury’s enterprise IT and information security and could be involved in work that touches Treasury’s internal systems, such as standing up the technical infrastructure for the clearinghouse.
National Security Agency
NSA is the Department of War’s signals-intelligence and cybersecurity agency and has one of the government’s deepest benches of technical cyber talent. Its director also serves as commander of US Cyber Command and as “National Manager” for the security of classified and military networks. NSA has long worked at the frontier of emerging-technology security.
The EO gives NSA a central role: the NSA Director will determine whether a model is designated a “covered frontier model,” informed by the classified benchmark NSA will help develop. (Housing this evaluation work inside an intelligence agency has drawn debate, with OpenAI and others arguing the evaluation component should instead sit under a civilian agency – see CAISI section below.) The NSA is also a consulted party on Treasury’s AI cybersecurity clearinghouse.
The NSPM also features NSA prominently:
It tasks NSA’s AI Security Center to build partnerships with willing companies to secure frontier technology, including against distillation attacks.1 This work could include conducting joint AI red-team exercises, assisting with personnel vetting, supporting joint security R&D that the private sector couldn’t undertake alone, and hardening data center security.
NSA also co-leads the development of a joint strategy for AI risk management, including setting baseline security practices for the national security enterprise.
A key office for this work at NSA is its AI Security Center (AISC). Per reporting, AISC works with CAISI (see below) on evaluations and is also supplying technical expertise to a new internally-announced NSA/Cyber Command task studying how to safely deploy leading commercial AI models on the most highly classified systems. AISC is housed within the Cybersecurity Collaboration Center, which works with defense contractors, industry, and federal agencies to harden the defense industrial base, protect against nation-state cyber threats, and secure emerging technologies.
Department of Commerce – Center for AI Standards and Innovation (CAISI)
NIST is the Commerce Department’s standards and measurement agency. Its AI model evaluation work primarily runs through CAISI, which holds voluntary agreements with the frontier developers and has a mandate to lead evaluations of national-security-relevant capabilities, including cyber and bio. It has also conducted evaluations of foreign AI capabilities (e.g. DeepSeek V4).
Under the EO, NIST’s only role is as a consulted party in developing the classified benchmark and voluntary framework. Commerce isn’t mentioned in the NSPM. Some expressed surprise over this limited scope, given the relevance of CAISI’s existing work in this space. Political dynamics appear to make CAISI’s future involvement uncertain. Recent reporting and speculation suggest some AI evaluation work may be shifting from CAISI to other parts of the executive branch, such as NSA (see above). On the other hand, OpenAI, among others in industry, publicly pushed to preserve CAISI’s evaluations role and to give it a more central role. What happens here remains very much an open question.
Department of Energy and the National Labs
DOE has funded AI and computing research for decades and has had a dedicated AI office since the first Trump administration. Its labs operate some of the world’s most powerful supercomputers, which are used for AI research and were the first to host frontier models in classified settings.2
The EO doesn’t task DOE, but the NSPM gives the Secretary of Energy several assignments, including:
Applying AI to national security missions through DOE’s flagship AI-for-science Genesis Mission (for which we have a separate fellowship at Horizon!)
Supporting the compute roadmap, including by commissioning new high-security computing facilities and an AI “test range” for national security use cases
Helping develop joint AI data and model exchanges for missions across the national security enterprise
DOE’s Office of Strategy and Technology Roadmaps (OSTR) is a likely home for a significant share of the relevant work as the historic focal point for AI at DOE, including on the Genesis Mission’s.3 OSTR coordinates work on critical and emerging technologies across DOE programs, the 17 national labs, and interagency partners. Its director also serves as DOE’s Deputy Chief AI Officer.
The National Labs are administratively intertwined with DOE, but are independently operated and also work on behalf of other agencies and clients. The three NNSA weapons labs (Los Alamos, Lawrence Livermore, and Sandia) house classified facilities and deep CBRN expertise, and are possible homes for classified evaluation work. The labs hosting supercomputers (Lawrence Livermore, Oak Ridge, and Argonne) are also especially relevant on the compute side.
DOE’s role could grow further in the future. If CAISI’s position in frontier-model evaluation shrinks (see above), the National Labs are a plausible place for some of that work to land, as one of the few places in government with a large in-house science workforce, prior evaluation experience, and infrastructure to run classified assessments. In mid-2025, when CAISI’s future was also uncertain, OSTP Director Michael Kratsios pointed to DOE (alongside DoW and the IC) as a place where the work of evaluating AI’s CBRN risks could sit. Generally, the National Labs’ breadth across fields, including all CBRN domains, could also come to matter more if government AI security efforts expand beyond cyber.
Department of War
DOW houses NSA (covered above) and is a major player on AI policy by way of its enormous research budget, its procurement power as a dominant buyer for military technology, and the strategies and directives it develops that govern how the military adopts AI and autonomous systems.
Beyond NSA’s taskings, the EO directs DOW to harden the cyber defenses of its own information systems. The NSPM also tasks it with:
Reviewing its rules for autonomy in weapons to account for the rapidly evolving capabilities of AI systems (DoD Directive 3000.09)
Reforming procurement processes so it can adopt frontier models faster
Helping develop the national-security compute roadmap (described above)
Helping develop joint AI data and model exchanges for missions across the national security enterprise
Some of the likely relevant offices for this work include:
The Chief Digital and AI Office (CDAO), which leads DOW’s AI adoption efforts.
US Cyber Command (CYBERCOM) is the combatant command responsible for directing and coordinating military cyberspace operations. Its commander, Gen. Joshua Rudd, is also the Director of NSA.
The Office of the Under Secretary of War for Policy (OUSW(P)) has coordinated the military’s autonomous weapons rules since their origin. It also oversees the Assistant Secretary of War for Cyber Policy (ASW(CP)).
DARPA, as well as other components under the Under Secretary for Research & Engineering (OUSW(R&E)), perform and fund cutting-edge R&D. They may play a role in the NSPM’s workstreams on advancing methodologies for evaluating the properties of AI systems and on the technical foundations of AI security, such as robustness and control (e.g. see DARPA’s AI Forge initiative, organized in collaboration with NSF).
Department of Homeland Security – Cybersecurity and Infrastructure Security Agency (CISA)
CISA, housed in the Department of Homeland Security, runs operational cyber defense for most of the civilian federal government and coordinates risk assessment and security guidance across all 16 critical-infrastructure sectors. In recent years it has emerged as a critical player in AI policy.
The EO gives CISA central operational roles:
Issuing binding government-wide directives to speed up cyber defense of civilian federal systems4
Standing up or expanding programs that deliver AI-enabled defensive tools to agencies
Helping agencies, state and local governments, and critical-infrastructure operators get access to cybersecurity tools, including, in some cases, covered frontier models
Co-leading the classified frontier-model benchmark with Treasury and NSA, and consulting on Treasury’s clearinghouse
A few of the leading offices include:
The Cybersecurity Division leads CISA’s operational cyber defense efforts. Among other relevant offices, it houses the Joint Cyber Defense Collaborative AI initiative, which has focused on partnering with leading AI companies on cyber defense.
The National Risk Management Center, which leads AI risk assessments for critical infrastructure.
Which offices play a role at CISA, and in the interagency, will also partly be contingent on capacity. Some have expressed concern that CISA has limited capabilities to implement responsibilities: it has had no recent Senate-confirmed director and is on its third acting director, and has lost about a third of its staff over the past year.
The Intelligence Community (beyond NSA)
The IC is historically responsible for analyzing adversaries’ technological capabilities and intentions, and for helping policymakers understand the opportunities and risks that emerging technologies present.
NSA is among the IC’s most prominent players on AI security, but the broader community is also tasked in the NSPM:
The Director of National Intelligence is the lead for prioritizing collection and analysis of foreign AI, including adversary models, applications, and the governance and policies abroad that could threaten US security.
The DNI will also co-lead on the joint data and model exchanges and on an AI curriculum for the national security workforce.
Beyond NSA and the Office of the Director of National Intelligence (ODNI), other IC components that may be particularly relevant for ongoing AI security efforts include (note no specific ones were called out in the EO or NSPM):
The CIA is generally among the more powerful and involved intelligence agencies, and can be expected to play a role in the IC’s AI mandate. Its work includes both AI integration into its work and the broader analysis of emerging tech trends and capabilities. This work is performed in relevant directorates, such as for Digital Innovation and Science & Technology, as well as multiple relevant mission centers (see organization).
The Intelligence Advanced Research Projects Activity (IARPA), the IC’s counterpart to DARPA, funds high-priority E&D and could be a vehicle for AI security work (see note on DARPA above).
The FBI, the lead federal agency for investigating cyber intrusions, handles the operational enforcement of computer-crime laws through its Cyber Division.
State Department
State traditionally works on the international elements of science and technology. Its AI work has included coordinating with allies, participating in international summits and standards bodies, and more recently standing up initiatives like Pax Silica, a multi-country coalition aimed at securing the global AI supply chain.
State isn’t named in the EO and receives only one formal tasking from the NSPM: to co-develop a strategy to engage allies and partners on foreign-AI threats and share intelligence findings with them as appropriate. But State is likely to at least be informally involved with any future international dimensions of the AI security agenda. State offices may also exercise informal influence via Marco Rubio, who is both Secretary of State and acting as National Security Advisor.
State’s work on AI security would likely involve:
Under Secretary for Economic Affairs (“E”) which covers economic and technology diplomacy, including running Pax Silica. It houses the Bureau of Cyber Space and Digital Policy.
Under Secretary for Arms Control and International Security (“T”), which handles nonproliferation, arms control, and the security dimensions of emerging tech. It houses the recently established Bureau of Emerging Threats, among other relevant offices.
Other generally powerful places that have done some tech work are “P” (Political Affairs) and the Secretary’s Office of Policy Planning.
Department of Commerce – Bureau of Industry and Security
BIS administers dual-use export controls. BIS is not tasked by either the EO or the NSPM, which focus mainly on cyber security, AI evaluations, and domestic infrastructure. But BIS is likely to stay relevant to AI security broadly, given its focus on the diffusion of strategically sensitive technology.
BIS’s AI work has historically centered on the hardware layer (such as chips and semiconductor manufacturing equipment), but last week Commerce, with BIS support, used export controls to restrict foreign access to a specific frontier model itself. If this use of export controls becomes more regular, BIS’s remit could extend beyond hardware into frontier models themselves.
Office of Personnel Management
OPM is the agency responsible for managing the federal civilian workforce. It’s been increasingly involved in strengthening government technical capacity, most significantly through its Tech Force program, launched in 2025, which places technologists into time-limited federal tours.
The EO directs OPM to expand cybersecurity hiring through Tech Force, and the NSPM tasks it with creating an “AI National Security Strategic Reserve,” a vetted pool of outside AI experts the government can tap when needed. (You can read more about these initiatives and other work at OPM in our upcoming interview with OPM Director Scott Kupor.)
What we don’t know yet
Because AI’s implications cut across so many domains and jurisdictions, the set of involved players will likely continue shifting, and there’s still much we don’t know about who will do what on AI security in the future.
First, it’s hard to predict which agencies will play leading roles. The list above covers the agencies with the deepest historical involvement in AI security work and those most heavily tasked in the recent presidential directives. But this landscape can change quickly and unpredictably. For example, Treasury had very limited involvement in AI policy six months ago, and few observers then would have predicted its current role. Commerce has historically played a huge role, seemed initially less involved in the EO and NSPM, and then became more central again in the weeks since.
Six months from now, things may look different again, as other federal agencies are pulled in and grow more engaged within their own domains. Some of this can be predicted based on agencies’ legal authorities, in-house capabilities, and reporting on leadership priorities, but the crystal ball here is far from perfect.
Second, a lot depends on whether and how AI capabilities further advance, and in which domains the biggest implications emerge. The current set of leading players is a consequence of frontier models transforming the cyber domain specifically. Some, like former Trump White House AI advisor Dean Ball, expect AI to have far-reaching implications for biology, another dual-use domain, and for AI-bio to have a “Mythos moment” soon. If that happens (many are also skeptical5), we’d likely see a different set of players involved in the response, with offices historically involved in bio incidents playing a more prominent role.
Takeaways if you’re considering working on this near-term
There’s widespread agreement that the federal government cannot keep pace with AI-enabled security challenges unless it can recruit and deploy people who understand the technology. If you’ve been considering pivoting into public service, even just as a trial, the next six months may be among the best and most important times to do so.
A few other thoughts that might be relevant as you think about if and where to start:
If you’re an expert at the intersection of AI and security-relevant domains right now (e.g. AI-cyber), your knowledge and skills are extremely scarce and valuable. But even if your background is only in one relevant domain and you’d be willing to rapidly upskill in others (e.g. your background is in AI and you can learn cyber), your expertise is just as needed. Some agencies tasked with important roles in the directives have only a small handful of FTEs on AI (if that), so adding a single additional expert can meaningfully expand what an office can do.
The boundaries between “technical roles” and “policy roles” are blurry, and quickly getting blurrier in the AI space. Technical experts will be tapped for fast-moving judgment calls, e.g. a scientist at DARPA or another technical agency might advise informally on policy conversations where technology understanding really matters. And similarly, policy staff will increasingly need to understand the fundamentals of the technology.
Security clearances will affect your options for where and on what timeline you can enter this work. Clearances are unusually valuable right now for immediate entry, but many relevant roles don’t require one.6 (See our full guide to clearances here.)
Opportunities to get involved:
Applications are open for our Rapid Response Fellowship cohort, designed to move experienced technical and policy talent into federal offices on an accelerated timeline.
US Tech Force is recruiting ~1,000 technology specialists to build the future of American government technology, and per the EO they’ll be recruiting for AI security-related roles. Apply here.
Keep an eye out for news on the forthcoming AI National Security Strategic Reserve, which will source tech experts outside government ready to be “on call” to support AI-related national security challenges. We’ll post updates here as news emerges.
For more about these offices and the shape of future AI security work:
It’s always good to dig into the raw materials yourself, so read the EO and NSPM.
Our online resource emergingtechpolicy.org has many guides with more background on federal agencies working on AI policy, including on most of the agencies covered above (see: Executive Office of the President, intelligence community, BIS, and the rest). Some of these are now a little outdated (we’re working on it!) but do provide good historical context on the office’s role and authorities.
Distillation is where an adversary copies a model’s capabilities by systematically querying it and training a clone on the responses. This builds on earlier government attention to the problem, with OSTP having issued a policy memorandum in April 2026: Adversarial Distillation of American AI Models.
In 2024, Anthropic and DOE ran the first evaluation of a frontier model in a Top Secret environment.
It has gone through a few name changes. Between 2023 and 2025, the office was known as the Office of Critical and Emerging Technologies, which in turn had replaced the Office for AI and Technology (2019-2023).
One of CISA’s most significant tools is the Binding Operational Directive, a compulsory order every civilian agency must follow, used in the past to mandate things like patching specific vulnerabilities on a deadline or hardening cloud environments. CISA has already issued BOD 26-04 in response to the EO, which discusses AI-accelerated cyber threats and requires highest-risk vulnerabilities to be treated within three days.
For example, they note disanalogies between the cyber and bio fields that will make it harder for AI to cause capability jumps (e.g. bio capabilities requiring much more interaction with the physical world, as in “wet lab” work). These are very reasonable objections (much of the relevant literature is summarized in the 2026 International AI Safety Report). We’re mainly just using the bio example to illustrate how bureaucratic dynamics might shift.
For example, some of the work at DOE, NIST/CAISI, OPM, and parts of Treasury is unclassified. NSA and the broader intelligence community generally require full clearances, often TS/SCI with a polygraph, which can generally take up to a year or more.



The CISA staffing detail buried in the DHS section is the real story for me. No confirmed director, down about a third of its staff, and yet its mandate keeps expanding: CIRCIA reporting, now co-leading the classified frontier model benchmark with Treasury and NSA. Capacity is shrinking while the job description grows. I would want to see whether the AI Rapid Response Fellowship and Tech Force actually reach CISA specifically, since on paper it now has one of the most technically demanding roles in the entire directive. I cover DHS and CISA capacity issues on Cyber & Statecraft.
This is a persuasive CTA; I am convinced, and will apply.