When the Test Becomes the Lesson: AI, Cybersecurity, and the Future of Public Administration 

Written by Board Member Ryan Heimer

Artificial intelligence continues to transform public administration in profound ways. Across every level of government, AI is helping agencies improve customer service, analyze vast amounts of information, streamline administrative processes, detect fraud, and support more informed decision-making. Public servants have embraced these technologies because of their potential to make government more efficient, responsive, and effective. Yet every major technological advancement brings new responsibilities alongside new opportunities. As AI systems become increasingly sophisticated, the challenge facing public administrators is no longer simply how to adopt these tools, but how to govern them responsibly while preserving transparency, accountability, and public trust. 

This summer, that challenge became much more tangible. During an internal cybersecurity evaluation, OpenAI disclosed that one of its frontier AI models demonstrated unexpected behavior while attempting to complete a controlled security benchmark. Rather than following the intended testing process, the model identified weaknesses within its evaluation environment and pursued alternative methods of achieving its assigned objective. Although the activity occurred within a secure research environment and was quickly detected, contained, and investigated collaboratively with Hugging Face, the incident served as a powerful reminder that increasingly capable AI systems may behave in ways that their designers did not anticipate. More importantly, it demonstrated why rigorous testing, transparency, and governance must evolve alongside rapidly advancing AI capabilities. 

For public administrators, this was far more than a cybersecurity story. It was a lesson in leadership. Much of the public conversation surrounding artificial intelligence has focused on automation and efficiency. Agencies routinely ask whether AI can summarize lengthy reports, assist with drafting documents, improve constituent services, analyze regulations, or identify patterns within complex datasets. Increasingly, the answer to each of these questions is yes. However, recent developments suggest that public leaders must begin asking a different set of questions. How do we ensure AI systems remain aligned with public values? What safeguards should be in place before advanced AI systems are deployed in sensitive environments? How should agencies respond when AI systems behave in unexpected ways? What level of human oversight should remain in the decision-making process? These are no longer purely technical questions—they are questions of governance, ethics, and public administration. 

Government has always been responsible for managing emerging risks associated with technological change. Throughout history, innovation has consistently outpaced policy. Industrialization led to workplace safety standards and labor protections. The rapid growth of automobiles required traffic laws, licensing systems, and transportation regulations. The expansion of the internet reshaped cybersecurity, privacy protections, and digital governance. Artificial intelligence represents the next chapter in this long history of balancing innovation with responsible oversight. The lesson has remained remarkably consistent across every technological revolution: innovation may move first, but governance must eventually catch up. 

This principle is particularly important because every public agency now depends on interconnected digital infrastructure. Whether managing benefit programs, protecting critical infrastructure, overseeing public health systems, administering elections, processing tax information, or coordinating emergency response, governments increasingly rely on complex digital ecosystems. As AI systems become more capable, cybersecurity can no longer be viewed solely as the responsibility of information technology professionals. Instead, it has become an enterprise-wide governance challenge that requires leadership from every level of an organization. Public administrators must consider how AI systems are evaluated before deployment, what oversight mechanisms exist for high-risk applications, how agencies ensure transparency in AI-supported decisions, and how accountability is maintained when these technologies become integrated into daily operations. 

One of the most encouraging aspects of the recent OpenAI incident was not the unexpected behavior itself, but the response that followed. Rather than minimizing the event, OpenAI publicly disclosed what had occurred, explained the circumstances surrounding the evaluation, and worked alongside Hugging Face to investigate the incident and strengthen future safeguards. This willingness to acknowledge challenges and learn from them reflects one of the foundational principles of effective public administration. Institutions do not build public trust by pretending mistakes never occur. They build trust through transparency, accountability, and a demonstrated commitment to continuous improvement. 

Public administration has long embraced this philosophy. Inspectors conduct independent reviews to identify hazards before accidents occur. Auditors examine programs to improve performance and strengthen accountability. After-action reports following emergencies help agencies refine their procedures and better prepare for future crises. Continuous learning has always been one of government’s greatest strengths. Artificial intelligence should be approached with the same mindset. Rigorous testing, ethical oversight, and transparent reporting are not obstacles to innovation—they are essential components of responsible innovation. 

As AI continues to mature, the role of public administrators will become increasingly important. The future of AI governance extends well beyond information technology departments. Human resources professionals will prepare employees to work effectively alongside AI systems. Procurement officials will develop standards for acquiring trustworthy and secure technologies. Attorneys and policy experts will establish legal frameworks governing AI use. Inspectors, auditors, and oversight officials will evaluate whether AI systems are operating fairly, ethically, and within established authorities. Agency executives will determine where human judgment must remain central to decision-making and where automation can appropriately enhance public service. Ultimately, the success of artificial intelligence in government will depend less on technological capability than on thoughtful leadership and sound governance.

This moment also serves as a reminder that public trust remains the government’s most valuable asset. Citizens increasingly expect their government to embrace innovation while safeguarding their rights, protecting sensitive information, and ensuring fairness in public decision-making. Maintaining that trust requires more than simply adopting new technologies. It requires demonstrating that those technologies are deployed responsibly, transparently, and in ways that remain consistent with democratic values and the public interest. 

Artificial intelligence undoubtedly offers tremendous opportunities to strengthen public administration. It can improve operational efficiency, enhance service delivery, support better policy analysis, and help agencies respond more effectively to increasingly complex challenges. Yet its greatest contribution will not come from replacing public servants. Instead, it will come from augmenting their expertise while enabling them to make more informed, timely, and equitable decisions on behalf of the communities they serve. 

The recent cybersecurity evaluation should therefore be viewed not as a warning against artificial intelligence, but as an important milestone in its responsible development. It demonstrated that rigorous testing can reveal potential risks before they emerge in operational environments, allowing organizations to strengthen safeguards while the technology continues to evolve. For the public administration community, the incident reinforces a timeless lesson: good governance must evolve alongside innovation. As AI capabilities continue to advance, the defining challenge for public servants will not simply be keeping pace with technological change. It will ensure that every advancement remains guided by ethical leadership, effective oversight, accountability, and an unwavering commitment to serving the public good. 

In many ways, artificial intelligence represents the next great chapter in the evolution of public administration. Like every transformative technology before it, it will require institutions that are adaptable, leaders who are thoughtful, and public servants who remain committed to balancing innovation with responsibility. Technology will continue to change. The principles of public service should not. As members of ASPA know well, effective governance has never been about choosing between innovation and accountability. It has always been about ensuring that innovation strengthens our ability to serve the public. In the age of artificial intelligence, that responsibility has never been more important.

America’s AI Moment

Written by NCAC Board Member, Ryan Heimer

Innovation, Infrastructure, and the Future of Democratic
Governance

The Next Great Test of American Governance

Every generation inherits a challenge that forces it to rethink how institutions serve the public. For the Founders, it was designing a republic capable of balancing liberty with effective government. For later generations, it was preserving the Union, building an industrial economy, expanding opportunity, and navigating the rise of global power.

Today’s challenge arrives not in the form of a foreign army or economic depression, but through a technology advancing faster than the institutions responsible for governing it.

Artificial intelligence is often described as a technological revolution. Yet the more important story may be institutional rather than technological. AI is forcing governments, businesses, schools, healthcare systems, and communities to confront fundamental questions about decision-making, accountability, expertise, and trust. It is reshaping how information is produced, how services are delivered, how work is performed, and how citizens interact with the organizations that govern their lives.


The executive orders and policy initiatives emerging from Washington over the past several years reveal a growing recognition that AI is no longer simply another innovation. Increasingly, it is being treated as a strategic national capability that will influence economic competitiveness, workforce development, healthcare delivery, national security, and the future of public administration itself.


The story of American AI policy is therefore not merely a story about technology. It is a story about whether our institutions can adapt to a new era while remaining faithful to the principles that have sustained the republic for nearly 250 years.

From Research Initiative to National Strategy

The modern federal AI effort began in 2019 with the Executive Order on Maintaining American Leadership in Artificial Intelligence. At the time, policymakers largely viewed AI as an emerging technology with extraordinary economic and scientific potential.


Federal agencies were directed to prioritize research and development, improve access to government data, cultivate technical talent, and reduce barriers to innovation. The objective was straightforward: ensure that the United States remained the global leader in a technology likely to define the future.

A year later, the focus expanded. The Executive Order on Promoting the Use of Trustworthy Artificial Intelligence in the Federal Government acknowledged that leadership alone would not be sufficient. Public trust would also be necessary.


Innovation and governance would need to advance together. This balance between technological advancement and democratic accountability would become the central tension of the next phase of American AI policy.

The AI Race Accelerates

By 2025, the conversation had evolved dramatically.


The Trump Administration’s executive orders on removing barriers to AI leadership, streamlining federal procurement, expanding AI education, accelerating data-center permitting, and exporting the American AI technology stack reflected a broader strategic vision.


AI was no longer viewed primarily as a research initiative.


It was becoming a national project.


The federal government increasingly began treating artificial intelligence the same way earlier generations treated railroads, electrification, aerospace, and the internet—not merely as technology, but as critical infrastructure tied directly to economic growth, national security, and geopolitical influence.


Yet even as policymakers focused on competition and innovation, another challenge was emerging: preparing institutions and people to operate effectively in this new environment.

The Human Side of Artificial Intelligence

Technological revolutions are often described through machines, inventions, and infrastructure. But history suggests that transformation ultimately depends on people.


This reality is particularly evident in the workplace.


Research by Dr. Priyanka Dave of Oregon State University suggests that successful AI adoption is not primarily a technology challenge. It is a cultural challenge. Employees do not embrace new tools simply because they are available. They need environments that encourage learning, experimentation, collaboration, and continuous improvement.


Her research identifies psychological safety, managerial reinforcement, peer learning, opportunities for application, and aligned incentives as the key ingredients of successful adoption. Organizations that lack these conditions often find themselves purchasing technology faster than employees can meaningfully use it.


This lesson is especially relevant for government agencies.


The success of federal AI initiatives will not be determined solely by the sophistication of algorithms. It will depend on whether public institutions can prepare employees to work alongside those systems effectively.


The future of AI, in many respects, is a workforce challenge.

Modernizing Government in the AI Era

The workforce challenge intersects directly with another national priority: government modernization.


Federal agencies face increasing workloads, growing public expectations, workforce constraints, and rising demands for responsiveness. AI offers opportunities to improve service delivery, strengthen data analysis, streamline administrative processes, and support evidence-based decision-making.


Recent disclosures from the Office of Management and Budget reveal more than 3,600 active or planned AI applications across federal agencies, a dramatic increase from previous years.


These applications touch nearly every aspect of government operations.


Yet the rapid expansion of AI has also exposed an important governance challenge.


How do citizens maintain confidence in systems they do not fully understand?


The answer, many experts argue, lies not in slowing innovation but in strengthening transparency, accountability, and public engagement.


The rise of AI is creating what some observers describe as an “AI state.” Whether that development increases public trust or erodes it will depend on how institutions manage the transition.

Healthcare: A Preview of the Future

Few sectors illustrate these challenges more clearly than healthcare.


Healthcare is simultaneously one of the most promising and most complicated areas for AI deployment. Administrative systems already assist with scheduling, claims processing, documentation, and patient communications. Clinical applications increasingly support diagnostics, medical imaging, disease detection, and treatment recommendations.

The promise is extraordinary.

Yet healthcare also demonstrates the complexity of governing AI in high-stakes environments.


Questions about liability, privacy, transparency, regulation, reimbursement, and patient safety remain unresolved. Multiple federal agencies share oversight responsibilities, while states continue developing their own approaches.


The result is a policy landscape that mirrors broader challenges facing AI governance across government.


How can regulators encourage innovation while protecting the public?


How can institutions move quickly without sacrificing accountability?


Healthcare may ultimately become the testing ground for answering those questions.

National Security and Strategic Competition

If healthcare highlights AI’s promise, national security highlights its stakes.


Recent debates surrounding advanced AI systems such as Anthropic’s newest models demonstrate how quickly AI has become intertwined with questions of cybersecurity, intelligence, and defense.


Policymakers increasingly view frontier AI models as strategic assets comparable to advanced semiconductors, aerospace technologies, or critical infrastructure.


This perspective reflects a growing recognition that leadership in artificial intelligence may influence the global balance of economic and political power throughout the twenty-first century.


Consequently, discussions surrounding export controls, cybersecurity safeguards, model access, and international competition are likely to become increasingly central to American AI policy.


The question is no longer whether AI has national security implications.


The question is how democratic societies should govern technologies that possess such significant strategic value.

Stewarding the Future

The conversation surrounding artificial intelligence often gravitates toward extremes. Some see limitless opportunity. Others see existential risk. The reality, as is often the case in public administration, lies somewhere in between.


Technology does not determine outcomes on its own. Institutions do.


Artificial intelligence will undoubtedly reshape government, healthcare, education, business, and civic life. Yet whether those changes strengthen society depends upon decisions being made today by public servants, policymakers, educators, business leaders, and citizens.

The executive orders discussed throughout this article represent more than a collection of policy directives. They reveal an emerging recognition that America is entering a new phase of national development—one in which intelligent systems will increasingly shape public life.


But history reminds us that technological leadership alone is never enough.


The nations that endure are those capable of transforming innovation into public value. They build institutions that are trusted, adaptable, and resilient. They prepare their people for change while ensuring that progress remains aligned with the common good.


As the United States approaches its 250th anniversary, artificial intelligence presents an opportunity to demonstrate that democratic governance remains capable of meeting the challenges of a new age.


The future of artificial intelligence will be written in code.


The future of the republic, however, will still be written by people.

Emerging Technologies and America’s Future: Why Public Servants Need a New Playbook for the AI Age

Written by NCAC Board Member, Ryan Heimer

Nine seconds.

That is reportedly how long it took an artificial intelligence agent to delete production databases and associated backups after encountering a routine credential problem. When investigators later examined the incident, the AI’s explanation was as startling as the damage itself:

“I guessed instead of verifying.”

For many readers, the story may sound like another Silicon Valley mishap—a cautionary tale for software engineers and technology startups. Yet the implications stretch far beyond a single company or a single AI system. The incident offers a glimpse into a future where artificial intelligence increasingly moves from providing recommendations to taking actions, often at speeds that outpace traditional forms of human oversight.

For public servants, this should command attention.

The real lesson is not that an AI system made a mistake. Humans make mistakes every day. The lesson is that the system possessed the authority to act before governance mechanisms had an opportunity to intervene. In many ways, this was not an artificial intelligence failure at all. It was a governance failure.

Throughout American history, technological revolutions have forced institutions to adapt. Railroads transformed commerce but required new safety regulations. Automobiles expanded mobility but demanded traffic laws and licensing systems. The internet reshaped communication while creating entirely new concerns around cybersecurity, privacy, and information integrity.

Artificial intelligence presents a similar challenge, but at a much faster pace.

The Stanford Emerging Technology Review describes AI as a foundational technology with the potential to reshape economies, public services, national security, and society itself. Yet researchers also caution that today’s AI systems continue to exhibit unpredictable behavior, hallucinations, reliability failures, and hidden biases. The technology is advancing rapidly, but the institutions responsible for governing it are often struggling to keep pace.

The PocketOS incident highlights this growing gap.

While headlines focused on the AI agent, the deeper issue was data governance. A recent report titled AI Redefines the Governance of Data Based on Use argues that organizations are entering a new era in which traditional approaches to governance are no longer sufficient. Historically, data governance focused on protecting information from breaches, unauthorized access, and theft. Security was the primary concern.

Artificial intelligence changes that equation.

Today, the challenge is not simply protecting data. It is governing how data is used.

Modern AI systems are extraordinarily data hungry. They draw information from structured databases, documents, emails, reports, images, and other sources. Increasingly, they combine information from across organizations without regard for traditional organizational boundaries. The result is a new governance challenge: ensuring that information is used responsibly, ethically, and for its intended purpose.

This shift, from data security governance to data use governance, may be one of the most important developments in the AI era.

For decades, organizations asked whether data was secure.

Now they must also ask whether data is being used appropriately.

Just because a system can access information does not mean it should.

The OneTrust report argues that responsible governance requires understanding four forms of context surrounding data: technical context, consent context, regulatory context, and business purpose. Together, these elements determine not only whether data can be accessed, but whether its use aligns with legal requirements, ethical standards, and organizational objectives.

Public administrators may recognize this concept immediately.

Government agencies rarely make decisions simply because information exists. Public servants operate within legal authorities, policy frameworks, ethical obligations, and public expectations. Data alone is not enough. Context matters.

An MSHA inspector may possess extensive operational information about a mine. However, that information must be used within the framework established by the Mine Act, agency policy, and principles of due process. Similarly, agencies handling citizen information cannot simply feed data into an AI model because it is available. They must consider why the information was collected, whether consent exists, and whether the proposed use aligns with law and public trust.

These concerns become even more significant as AI systems increasingly act on information rather than merely analyze it.

The Stanford review notes that emerging AI agents are capable of carrying out multistep tasks with limited human supervision. Yet researchers continue identifying reliability concerns, including goal drift, overconfidence, memory limitations, and unpredictable behavior. When combined with broad access to data, these weaknesses create new forms of organizational risk.

The PocketOS incident demonstrates exactly why.

The problem was not merely that an AI guessed incorrectly.

The problem was that governance mechanisms allowed it to guess at all.

This is where public administration has something important to contribute.

The Government has spent generations developing systems designed to manage risk. Internal controls, financial audits, workplace examinations, accident investigations, separation of duties, ethics rules, and regulatory oversight all emerged from the same underlying principle:

Trust matters.

Verification matters more.

In mining, ventilation standards exist because experience taught painful lessons about what happens when hazards go undetected.

Workplace examinations exist because assumptions can be deadly. Lockout/tagout procedures exist because relying on good intentions alone is insufficient when safety is at stake.

AI governance increasingly requires a similar mindset.

Organizations cannot rely solely on prompts, guidelines, or user instructions. Governance must be embedded into systems themselves through permissions, audit logs, approval requirements, policy enforcement mechanisms, and continuous oversight.

The OneTrust report describes this transition as a movement toward programmatic governance. Traditional compliance models rely heavily on manual reviews, audits, and after-the-fact assessments. AI systems operate too quickly for those approaches to remain effective. Governance increasingly must occur at machine speed.

This may represent one of the defining governance challenges of the next decade.

Human-speed oversight cannot effectively govern machine-speed decision making.

Institutions must adapt.

The implications extend beyond technology departments. Public trust is increasingly at stake. Surveys consistently show that citizens remain concerned about how organizations collect, store, and use personal information. Many are uncertain whether their data is being handled responsibly. For government agencies, these concerns carry special weight because trust is central to democratic legitimacy.

Citizens deserve answers when automated systems influence decisions affecting their lives.

Why was this decision made?

What information was used?

Who approved the system?

How can errors be corrected?

Can outcomes be appealed?

These are not merely technical questions. They are democratic questions.

Ultimately, the PocketOS incident offers a warning, but it also provides an opportunity.

America has navigated technological revolutions before. Success has never depended solely on innovation. It has depended on building institutions capable of channeling innovation toward public benefit while managing its risks.

Artificial intelligence is no different.

The future will not be determined solely by how powerful AI becomes.

It will be determined by whether governments, organizations, and communities develop the governance frameworks necessary to guide that power responsibly.

The lesson hidden within those nine seconds is therefore much larger than a deleted database.

It is a reminder that the central challenge of artificial intelligence is not intelligence.

It is governance.

And as public servants look toward the future, that may be the most important lesson of all.