AI is rewriting the government cybersecurity playbook
How agencies can advance AI without compromising security
Technology has a habit of presenting every new threat as unprecedented. Usually, it’s not. AI didn’t invent phishing, identity theft, ransomware or social engineering, but it made each one easier to produce and weaponize.
In 2025, the FBI received more than 22,000 complaints involving AI-related activity, associated with more than $893 million in reported losses, according to the agency’s 2025 IC3 Report. It also fielded more than 32,000 government impersonation complaints, nearly double the previous year, associated with approximately $798 million in losses.
State agencies in particular are frequent targets. In 2025, Minnesota’s cybersecurity monitoring service, for example, analyzed more than 222 million security events, launched 650,000 automated investigations and identified more than 107,000 threats that could have affected government services, according to the state’s 2025 Cybersecurity Incident Report (pdf).
Generative AI can draft messages that read like an agency staffer’s and use public information to personalize it and produce a cloned voice or video that makes an urgent request feel all the more real.
The economics of modern attacks are also advancing. What once required a highly skilled team can be conducted by a lone actor with only limited technology.
During my years working with and leading health and human services organizations, I saw how trust is built into everyday operations. A caseworker, for example, trusts the person requesting access. A finance team trusts that a payment change came from an authorized manager. Contact center representatives trust callers’ voices. While those assumptions were always vulnerable, AI has quickly turned them into lucrative targets.
CISA and NIST are developing additional guidance to help agencies manage these emerging risks, use AI to strengthen cyber defenses and safely oversee AI systems that can complete tasks with limited human direction.
Related: AI and the New Front Line of Government Fraud Defense
Zero trust is not a product
Like many terms in our line of work, the phrase “zero trust” has been marketed so aggressively that it risks losing meaning. It’s not a box to buy or a switch to flip, but rather, an operating model built on a simple idea: no user, device, application or workload receives permanent trust simply because it is inside the network.
NIST’s zero-trust architecture shifts the focus from defending a network to protecting individual resources. Access decisions are based on factors including identity, device health, context and risk, then reevaluated as conditions change.
For agencies, that means stronger identity controls, multifactor authentication, least-privilege access, segmentation, encryption and rapid removal of unnecessary permissions. It also means watching what happens after access is granted.
I have sat through enough incident reviews to know the first question is often, “How did they get in?” The better question is, “Why were they able to move so fast and so far once they did?” Effective security must not only prevent unauthorized access, but also limit what any user or system can do after gaining entry.
Innovation and security must move together
As I wrote recently, the question is no longer whether AI belongs in public service, but how agencies can use it responsibly and securely. AI can help reduce administrative work, improve constituent service and strengthen program integrity. But it cannot operate without clear limits, human oversight and strong data protections. As agencies put more AI tools to work, cybersecurity must advance at the same pace. Every new connection, workflow and source of data creates value, but it can also create another opening for attackers.
Related: Partnering with the USDA and FBI to combat nearly $1 million in organized EBT fraud
Build security into the operating model
Here’s how I guide my public sector teams: Security cannot be separated from systems. Processes and people delivering Medicaid, eligibility, payments, public health and other essential services must be designed into modernization, application maintenance, cloud operations, access management and frontline support.
Conduent helps government agencies operate secure, scalable IT environments through managed services, application maintenance, cloud capabilities and responsive user support. Our teams can help strengthen controls, improve monitoring, reduce fragmentation and align modernization with NIST- and GovRAMP-informed requirements while keeping services available.
Protecting programs as threats evolve
Cybersecurity and program integrity are increasingly connected. The same AI capabilities that help agencies improve service delivery can also help bad actors create false identities, manipulate applications and target benefit payments. As fraud schemes grow more sophisticated, agencies need tools that can identify risk earlier without slowing access for eligible residents.
Conduent’s VeriSight Anti-Fraud Solutions help agencies protect Medicaid, SNAP, WIC, TANF and other essential programs with AI-enabled tools that work alongside existing systems. These capabilities can validate application data, identify unusual enrollment and transaction patterns, prioritize higher-risk cases for review and help stop suspicious payments before funds are lost. Just as important, they give agency staff clear insights while keeping people in control of final decisions.
By connecting cybersecurity, fraud prevention and day-to-day program operations, agencies can better protect public funds, preserve access to benefits and act with greater confidence.
The threat era will reward speed, discipline and skepticism. Government leaders do not need to distrust everyone. They need systems that verify everything, detect change quickly and limit the damage when trust is abused.
The attackers are not waiting for the next budget cycle, procurement meeting or steering committee. Government security cannot wait either.
How can agencies protect benefits as fraud becomes more sophisticated?
Learn how VeriSight Anti-Fraud Solutions help detect risk, protect public funds and strengthen program integrity. Visit www.conduent.com/government-solutions/fraud-prevention-and-program-integrity for more information.