This is the second post in a three-part series on AI security and governance for Federal Civilian agencies. The first post examined why M-25-21 changes the operating landscape and why AI risk is broader than public GenAI.Bottom line up front: Federal Civilian agencies need more than policy language to govern AI responsibly. They need an operating model. This post outlines a six-part lifecycle, Discover, Classify, Control, Test, Monitor, and Report, that connects M-25-21 requirements to enforceable, repeatable execution.A workable model for Federal Civilian agencies has six parts:DiscoverClassifyControlTestMonitorReportEach one addresses a specific governance gap. Taken as a whole, they give agencies a way to move from policy intent to day-to-day execution. 1. Discover: You can’t govern what you can’t seeThe first step is visibility.M-25-21 requires agencies to maintain AI use case inventories. But building an accurate inventory is hard when AI use is spread across users, endpoints, SaaS tools, code repositories, cloud environments, applications, APIs, and models.Security and governance teams may know about the officially approved AI pilots. They may not know about shadow AI use, embedded AI in existing SaaS platforms, developer AI tools, or AI dependencies inside application code.Zscaler AI Asset Management helps agencies identify AI usage and AI assets across multiple layers of the environment. This includes public GenAI destinations, embedded AI in SaaS, AI-enabled desktop tools, browser extensions, developer tools, code repositories that invoke models or agents, and cloud AI services connected to agency data.An AI inventory can’t just be a list of tools. Agencies also need context: whether a tool is approved, who is using it, whether sensitive data is involved, whether it connects to internal systems, whether an external model is being called, and whether an agent can access agency data or invoke tools. They also need to understand whether the AI asset touches PII, CUI, financial data, health data, law enforcement data, benefits data, inspection data, regulatory data, or source code.Without that context, governance is mostly guesswork. With it, agencies can start making risk-based decisions. 2. Classify: Not every AI use case has the same riskM-25-21 puts special emphasis on risk, especially for high-impact AI.High-impact AI refers to uses where AI output serves as a principal basis for decisions or actions that have a legal, material, binding, or significant effect on rights or safety.For Federal Civilian agencies, this could apply to eligibility or benefits support, grants and loans, healthcare or public health workflows, immigration or travel-related services, regulatory oversight, inspections and enforcement, fraud detection, safety-related determinations, housing assistance, employment-related actions, law enforcement support, emergency management, or other citizen-facing services.Not every use case will be high-impact. A tool that summarizes internal meeting notes is very different from an AI system that influences a benefits decision, inspection outcome, enforcement action, or citizen service determination. Classification is how agencies draw that line.Agencies need to classify AI use cases based on mission impact, data sensitivity, user population, external exposure, model provider, autonomy, human oversight, connected systems, and potential effects on rights, safety, benefits, or services. They also need to consider whether the system is public-facing and whether it uses authoritative agency data.Zscaler helps provide the technical context behind these decisions. It can help identify whether an AI application is connected to sensitive data, whether users are sending protected information to AI tools, whether AI assets exist in cloud environments, and whether an agency-built AI system should be prioritized for testing and guardrails.Zscaler doesn’t replace agency judgment. The CAIO, AI Governance Board, CIO, CISO, privacy officials, legal teams, and mission owners still own the governance decisions. But better evidence leads to better decisions. 3. Control: Enable AI use with policy-based guardrailsAI security can’t be limited to “allow everything” or “block everything.”Federal agencies need policy-based AI enablement. They need a way to allow approved AI tools, restrict risky tools, protect sensitive data, coach users, isolate higher-risk sessions, and apply different controls based on user role, mission function, data type, and destination.For example, an agency may allow approved GenAI tools for general productivity while blocking prompts that contain PII, CUI, source code, credentials, or procurement-sensitive information. It may apply stricter controls for users handling benefits, grants, healthcare, tax, law enforcement, or regulatory data. It may isolate higher-risk AI destinations in the browser, log AI activity for governance review, inspect AI responses for harmful content, or coach users when they attempt risky behavior.Zscaler helps apply these controls inline through the Zero Trust Exchange. For user access to public and embedded AI tools, Zscaler can inspect traffic, enforce access policy, apply data loss prevention, and use AI Guard to inspect prompt inputs and response outputs.Some of the highest-risk AI behavior can happen before an agency has formally reviewed a use case. An employee may paste citizen PII into a public AI tool to summarize a case note. A grants specialist may upload procurement-sensitive information into an AI assistant. A developer may paste source code or configuration secrets into an external coding tool. A regulator may use a public AI tool to summarize inspection records. Or an employee may use an embedded AI feature in a SaaS application without realizing data may be processed by an AI service.Zscaler can detect sensitive content and enforce policy before the data leaves the agency-controlled path. This is how agencies can support AI productivity while reducing unmanaged exposure. 4. Test: AI applications need assurance before they go liveEmployee use of public GenAI is one type of risk. Agency-built AI applications are another.As Federal Civilian agencies mature, many will build or operate their own AI systems. These may include citizen-facing AI assistants, internal knowledge assistants, program support chatbots, benefits guidance tools, regulatory support applications, inspection support tools, fraud detection workflows, cybersecurity copilots, research assistants, data analysis systems, AI-enabled case management, or agentic workflows connected to internal systems.For these systems, access control alone isn’t enough. Agencies need to test whether the AI application behaves as intended.AI systems can fail in ways traditional applications don’t. They can be vulnerable to prompt injection, jailbreaks, hallucination, data leakage, unsafe tool use, off-mission responses, toxic output, or manipulation across multi-turn conversations. For public-facing or mission-sensitive systems, those failures can damage public trust.Consider an AI assistant giving incorrect guidance about disaster assistance, student aid, veterans services, taxpayer obligations, public health recommendations, immigration processes, small business loans, housing assistance, food safety, benefits eligibility, regulatory compliance, or grants requirements. The issue isn’t only technical accuracy. It’s fairness, accountability, mission integrity, and trust.Zscaler’s AI red teaming capabilities help agencies test AI applications before deployment. Red teaming can evaluate systems for prompt injection, jailbreaking, data leakage, hallucination, trustworthiness, toxicity, bias, code execution, phishing, unsafe responses, RAG precision, URL validation, mission alignment, and custom agency-specific risks.Agencies can also create custom probes that reflect their own mission language, policies, authoritative sources, and risk scenarios.A benefits agency could test whether an assistant avoids making unauthorized eligibility determinations. A regulatory agency could test whether an assistant stays aligned to approved regulatory guidance. A public health agency could test whether responses remain grounded in authoritative medical or scientific sources. A grants agency could test whether an assistant provides accurate application guidance without exposing applicant data. A law enforcement or investigative agency could test whether the system refuses inappropriate requests for sensitive information. A citizen services agency could test whether the system escalates to a human when confidence is low.Red teaming helps agencies find weaknesses before citizens, employees, or adversaries do. 5. Monitor: AI risk doesn’t stand stillAI governance isn’t a one-time approval.Models change. Prompts change. SaaS platforms add new AI features. Developers introduce new dependencies. Users find new tools. Agents gain new capabilities. Data sources evolve. Attack techniques change.M-25-21 emphasizes ongoing governance, risk management, and accountability. For AI security leaders, this means agencies need telemetry that shows how AI is actually being used over time.Zscaler helps monitor AI interactions by showing which AI tools are being accessed, who is using them, which prompts trigger data protection policies, which responses violate policy, which embedded AI tools appear in SaaS workflows, which AI assets exist in cloud, which applications connect to sensitive data, and how usage trends change across the agency.It can also help track policy actions, red team findings, guardrails, and changes in AI behavior over time.This helps agencies move from static governance to continuous governance. It also gives governance teams a clearer view of actual behavior, not just intended use. The distinction is important, especially when AI adoption moves faster than formal review cycles. 6. Report: Governance needs evidenceFederal AI governance requires evidence.CAIOs, CIOs, CISOs, Chief Data Officers, privacy officials, legal counsel, acquisition officials, mission leaders, and AI governance boards all need different views of AI risk.A CAIO may need to understand AI adoption across the agency. A CISO may need visibility into data leakage and threat exposure. A privacy officer may need evidence of controls around PII. A Chief Data Officer may need to understand data access and data quality implications. A mission owner may need assurance that an AI system behaves within scope. Legal, civil rights, and acquisition leaders may need insight into fairness, third-party services, embedded AI risks, or documented control decisions.Zscaler helps provide operational evidence for those governance conversations. That evidence can include AI usage trends, AI application inventories, user and group activity, sensitive data exposure attempts, prompt and response policy actions, embedded AI discovery, AI assets in cloud environments, model and agent relationships, connected data resources, red team results, guardrail status, and policy enforcement history.This is how agencies make AI governance measurable instead of purely procedural.To learn more about how Zscaler supports the AI security lifecycle for Federal Civilian agencies, reach out to your Zscaler account team for a detailed overview of our AI Security capabilities.Next in this series: Extending Zero Trust to AI: What Federal Civilian Agencies Can Do Now
[#item_full_content] This is the second post in a three-part series on AI security and governance for Federal Civilian agencies. The first post examined why M-25-21 changes the operating landscape and why AI risk is broader than public GenAI.Bottom line up front: Federal Civilian agencies need more than policy language to govern AI responsibly. They need an operating model. This post outlines a six-part lifecycle, Discover, Classify, Control, Test, Monitor, and Report, that connects M-25-21 requirements to enforceable, repeatable execution.A workable model for Federal Civilian agencies has six parts:DiscoverClassifyControlTestMonitorReportEach one addresses a specific governance gap. Taken as a whole, they give agencies a way to move from policy intent to day-to-day execution. 1. Discover: You can’t govern what you can’t seeThe first step is visibility.M-25-21 requires agencies to maintain AI use case inventories. But building an accurate inventory is hard when AI use is spread across users, endpoints, SaaS tools, code repositories, cloud environments, applications, APIs, and models.Security and governance teams may know about the officially approved AI pilots. They may not know about shadow AI use, embedded AI in existing SaaS platforms, developer AI tools, or AI dependencies inside application code.Zscaler AI Asset Management helps agencies identify AI usage and AI assets across multiple layers of the environment. This includes public GenAI destinations, embedded AI in SaaS, AI-enabled desktop tools, browser extensions, developer tools, code repositories that invoke models or agents, and cloud AI services connected to agency data.An AI inventory can’t just be a list of tools. Agencies also need context: whether a tool is approved, who is using it, whether sensitive data is involved, whether it connects to internal systems, whether an external model is being called, and whether an agent can access agency data or invoke tools. They also need to understand whether the AI asset touches PII, CUI, financial data, health data, law enforcement data, benefits data, inspection data, regulatory data, or source code.Without that context, governance is mostly guesswork. With it, agencies can start making risk-based decisions. 2. Classify: Not every AI use case has the same riskM-25-21 puts special emphasis on risk, especially for high-impact AI.High-impact AI refers to uses where AI output serves as a principal basis for decisions or actions that have a legal, material, binding, or significant effect on rights or safety.For Federal Civilian agencies, this could apply to eligibility or benefits support, grants and loans, healthcare or public health workflows, immigration or travel-related services, regulatory oversight, inspections and enforcement, fraud detection, safety-related determinations, housing assistance, employment-related actions, law enforcement support, emergency management, or other citizen-facing services.Not every use case will be high-impact. A tool that summarizes internal meeting notes is very different from an AI system that influences a benefits decision, inspection outcome, enforcement action, or citizen service determination. Classification is how agencies draw that line.Agencies need to classify AI use cases based on mission impact, data sensitivity, user population, external exposure, model provider, autonomy, human oversight, connected systems, and potential effects on rights, safety, benefits, or services. They also need to consider whether the system is public-facing and whether it uses authoritative agency data.Zscaler helps provide the technical context behind these decisions. It can help identify whether an AI application is connected to sensitive data, whether users are sending protected information to AI tools, whether AI assets exist in cloud environments, and whether an agency-built AI system should be prioritized for testing and guardrails.Zscaler doesn’t replace agency judgment. The CAIO, AI Governance Board, CIO, CISO, privacy officials, legal teams, and mission owners still own the governance decisions. But better evidence leads to better decisions. 3. Control: Enable AI use with policy-based guardrailsAI security can’t be limited to “allow everything” or “block everything.”Federal agencies need policy-based AI enablement. They need a way to allow approved AI tools, restrict risky tools, protect sensitive data, coach users, isolate higher-risk sessions, and apply different controls based on user role, mission function, data type, and destination.For example, an agency may allow approved GenAI tools for general productivity while blocking prompts that contain PII, CUI, source code, credentials, or procurement-sensitive information. It may apply stricter controls for users handling benefits, grants, healthcare, tax, law enforcement, or regulatory data. It may isolate higher-risk AI destinations in the browser, log AI activity for governance review, inspect AI responses for harmful content, or coach users when they attempt risky behavior.Zscaler helps apply these controls inline through the Zero Trust Exchange. For user access to public and embedded AI tools, Zscaler can inspect traffic, enforce access policy, apply data loss prevention, and use AI Guard to inspect prompt inputs and response outputs.Some of the highest-risk AI behavior can happen before an agency has formally reviewed a use case. An employee may paste citizen PII into a public AI tool to summarize a case note. A grants specialist may upload procurement-sensitive information into an AI assistant. A developer may paste source code or configuration secrets into an external coding tool. A regulator may use a public AI tool to summarize inspection records. Or an employee may use an embedded AI feature in a SaaS application without realizing data may be processed by an AI service.Zscaler can detect sensitive content and enforce policy before the data leaves the agency-controlled path. This is how agencies can support AI productivity while reducing unmanaged exposure. 4. Test: AI applications need assurance before they go liveEmployee use of public GenAI is one type of risk. Agency-built AI applications are another.As Federal Civilian agencies mature, many will build or operate their own AI systems. These may include citizen-facing AI assistants, internal knowledge assistants, program support chatbots, benefits guidance tools, regulatory support applications, inspection support tools, fraud detection workflows, cybersecurity copilots, research assistants, data analysis systems, AI-enabled case management, or agentic workflows connected to internal systems.For these systems, access control alone isn’t enough. Agencies need to test whether the AI application behaves as intended.AI systems can fail in ways traditional applications don’t. They can be vulnerable to prompt injection, jailbreaks, hallucination, data leakage, unsafe tool use, off-mission responses, toxic output, or manipulation across multi-turn conversations. For public-facing or mission-sensitive systems, those failures can damage public trust.Consider an AI assistant giving incorrect guidance about disaster assistance, student aid, veterans services, taxpayer obligations, public health recommendations, immigration processes, small business loans, housing assistance, food safety, benefits eligibility, regulatory compliance, or grants requirements. The issue isn’t only technical accuracy. It’s fairness, accountability, mission integrity, and trust.Zscaler’s AI red teaming capabilities help agencies test AI applications before deployment. Red teaming can evaluate systems for prompt injection, jailbreaking, data leakage, hallucination, trustworthiness, toxicity, bias, code execution, phishing, unsafe responses, RAG precision, URL validation, mission alignment, and custom agency-specific risks.Agencies can also create custom probes that reflect their own mission language, policies, authoritative sources, and risk scenarios.A benefits agency could test whether an assistant avoids making unauthorized eligibility determinations. A regulatory agency could test whether an assistant stays aligned to approved regulatory guidance. A public health agency could test whether responses remain grounded in authoritative medical or scientific sources. A grants agency could test whether an assistant provides accurate application guidance without exposing applicant data. A law enforcement or investigative agency could test whether the system refuses inappropriate requests for sensitive information. A citizen services agency could test whether the system escalates to a human when confidence is low.Red teaming helps agencies find weaknesses before citizens, employees, or adversaries do. 5. Monitor: AI risk doesn’t stand stillAI governance isn’t a one-time approval.Models change. Prompts change. SaaS platforms add new AI features. Developers introduce new dependencies. Users find new tools. Agents gain new capabilities. Data sources evolve. Attack techniques change.M-25-21 emphasizes ongoing governance, risk management, and accountability. For AI security leaders, this means agencies need telemetry that shows how AI is actually being used over time.Zscaler helps monitor AI interactions by showing which AI tools are being accessed, who is using them, which prompts trigger data protection policies, which responses violate policy, which embedded AI tools appear in SaaS workflows, which AI assets exist in cloud, which applications connect to sensitive data, and how usage trends change across the agency.It can also help track policy actions, red team findings, guardrails, and changes in AI behavior over time.This helps agencies move from static governance to continuous governance. It also gives governance teams a clearer view of actual behavior, not just intended use. The distinction is important, especially when AI adoption moves faster than formal review cycles. 6. Report: Governance needs evidenceFederal AI governance requires evidence.CAIOs, CIOs, CISOs, Chief Data Officers, privacy officials, legal counsel, acquisition officials, mission leaders, and AI governance boards all need different views of AI risk.A CAIO may need to understand AI adoption across the agency. A CISO may need visibility into data leakage and threat exposure. A privacy officer may need evidence of controls around PII. A Chief Data Officer may need to understand data access and data quality implications. A mission owner may need assurance that an AI system behaves within scope. Legal, civil rights, and acquisition leaders may need insight into fairness, third-party services, embedded AI risks, or documented control decisions.Zscaler helps provide operational evidence for those governance conversations. That evidence can include AI usage trends, AI application inventories, user and group activity, sensitive data exposure attempts, prompt and response policy actions, embedded AI discovery, AI assets in cloud environments, model and agent relationships, connected data resources, red team results, guardrail status, and policy enforcement history.This is how agencies make AI governance measurable instead of purely procedural.To learn more about how Zscaler supports the AI security lifecycle for Federal Civilian agencies, reach out to your Zscaler account team for a detailed overview of our AI Security capabilities.Next in this series: Extending Zero Trust to AI: What Federal Civilian Agencies Can Do Now