By March 2026, every covered federal agency was required to publish an AI strategy under OMB M-25-21, including an assessment of the cybersecurity needed to deploy AI at scale. Four months later, OpenAI disclosed that two of its pre-release models had autonomously escaped a sandboxed test environment, chained a previously unknown vulnerability, and breached Hugging Face’s production infrastructure. Hugging Face described the breach as “driven, end to end, by an autonomous AI agent system.”

Most federal AI strategies published this spring treat AI security primarily as a procurement and governance workstream, focused on model cards, acceptable use policies, and the “Unbiased AI Principles” transparency requirements the Office of Management and Budget added in December 2025. This work matters for compliance, but it doesn’t reach the layer where the Hugging Face incident actually happened, which is the cloud environment where AI systems have IAM roles, network paths, and reachable production data. Below we explore the three challenges federal agencies face in securing AI across their cloud estate, and how the Orca Platform approaches each of them.

Challenge #1: Procurement records don’t reflect what’s actually deployed

OMB M-25-21 requires agencies to inventory their AI use cases, and most agencies build that inventory by asking program offices what they have procured or built. This produces a documentation inventory rather than a picture of what is actually running. Program offices don’t always know what a data scientist spun up in a sandbox SageMaker environment, what a contractor deployed inside a shared VPC using LangChain, or which managed AI services were enabled by default in a new cloud subscription. Each of these represents shadow AI that carries an identity, a data path, and a blast radius no model card describes.

The Orca Approach: Continuous, agentless discovery of every AI asset

The Orca Platform takes an agentless-first approach to give federal security teams a comprehensive view of the AI footprint deployed across their multi-cloud environments. Orca’s patented SideScanning™ technology reads directly from AWS, Azure, Google Cloud, and Oracle Cloud APIs to build an inventory of managed AI services, deployed models, agents, MCP servers, and the workloads that call them within minutes of connection. Each AI asset is mapped to the identity that operates it and the data stores it can reach, so security teams can see not just what AI exists but what it is capable of touching. Orca research recently identified exposed AI/ML credentials in 43% of cloud environments studied, and most were tied to AI assets that had never been formally registered.

Challenge #2: AI risk without cloud context is noise

When AI risk is evaluated on its own severity scale, security teams end up with an overwhelming volume of findings and no clear way to prioritize them. A misconfigured model endpoint or an over-privileged agent can look like a low-priority finding in isolation, but the same finding becomes critical when it sits on an attack path to a production database holding PII or CUI. This is the pattern that played out in the Hugging Face incident, which unfolded as a chain of sandbox escape, outbound network access, credential reuse, and a known database vulnerability, none of which would have been prioritized individually. Agentic AI compounds the problem, because an AI agent calling tools through MCP is effectively one identity acting on behalf of another, and the true blast radius depends on the identities the agent can borrow at runtime.

The Orca Approach: Dynamic risk prioritization built on a Unified Data Model

Because Orca aggregates cloud, identity, data, and AI signals into one Unified Data Model, the platform delivers an opinionated view of risk that reflects real exposure rather than raw severity. Orca dynamically prioritizes risk through attack path analysis and numerical risk scores that factor in reachability, exploitability, sensitive data at risk, and the blast radius of the identities an AI agent can borrow. In one recent customer POC, this approach narrowed 88,000 raw findings at onboarding to 27 that were critical, exploitable, and reachable. Security teams can then focus remediation on the attack paths that actually put mission systems at risk, rather than working down a list of AI-specific alerts scored in a silo.

Challenge #3: AI activity is treated as a separate detection surface

The FedRAMP 2026 Consolidated Rules driven by CISA BOD 26-04 will require FedRAMP-certified services to detect and remediate the highest-risk vulnerabilities within three-day windows starting December 7, 2026. AI workloads reshape their exposure constantly through retraining, reframing, and redeployment, so agencies need detection coverage that can keep pace. However, many organizations today treat AI activity as a separate surface, routing alerts on AI agents and model endpoints into a dedicated dashboard that the SOC must correlate manually with the rest of the cloud detection pipeline. This adds latency, adds tools, and adds manual work at exactly the moment agencies are being asked to consolidate all three.

The Orca Approach: One detection engine for cloud runtime and AI activity

The Orca Platform treats AI activity as part of the same detection surface as the rest of the cloud, using the same Unified Data Model and prioritization engine that already power cloud runtime detection. When an alert fires on an AI agent or exposed model, the attack path and blast radius arrive with it, drawn against the full cloud graph. There is no separate AI-activity dashboard for the SOC to reconcile and no separate risk scale to translate before responders can act.

Secure AI everywhere it lives with Orca

The Orca Platform is FedRAMP® Moderate authorized and available to federal agencies through Carahsoft, with built-in mappings to 200+ frameworks including NIST SP 800-53, NIST CSF, and DISA STIG. Orca gives federal security teams one place to see, prioritize, and respond to AI risk alongside cloud, identity, and data risk, so agencies can meet their M-25-21 obligations while actually reducing exposure in production. Customers on the platform have cut alert volume by 75% and see 198% ROI with $1.2M in annual operating savings (TAG Cyber, 2026).

AI risk is also expanding outward into applications citizen builders ship on platforms outside traditional pipelines. Orca is investing in coverage for that emerging surface, and while those capabilities are not yet part of the FedRAMP Authorized offering, they will factor into how the AI footprint is secured over the next 18 months.

Learn More

Interested in discussing federal AI security in more depth? Contact Orca Security’s government team at fedrampsales@orca.security to learn how we can help your agency secure AI across its cloud estate.