FEDTECH: Federal agencies are under intense pressure to operationalize AI quickly. What are you hearing from agency leaders about what’s preventing them from moving faster?
DEPRETA: Everybody recognizes that AI is coming at us fast and furious. What has changed over the past several months is the realization that even if an organization is not ready for AI internally, the world is moving on without it. AI will affect every organization, whether it’s ready or not.
There are several barriers, but four stand out: infrastructure, trust, return on investment and human capital.
On infrastructure, agencies are not just dealing with data center modernization. They’re also dealing with network infrastructure, campus infrastructure and security architecture that were built years — and in some cases decades — before AI became a consideration. AI workloads place enormous demands on networks, and agencies need to rethink both capacity and architecture.
Trust and security are equally important. Agencies need platforms that can be trusted not only by humans but also by AI agents operating on their behalf.
We’re also seeing a shift in how organizations think about ROI. The value of AI isn’t simply automating an existing process. It’s about transforming the process itself. If you’re only measuring AI against the old way of doing business, you’re missing its real value.
Finally, there’s the human capital challenge. Agencies need people with the right skills, but modernization can also help by automating routine tasks and allowing employees to focus on higher-value work.
FEDTECH: How do you see zero trust evolving in the AI era? Is there a movement toward broader visibility into applications, workloads and machine-driven activity?
DEPRETA: Zero trust remains critically important, and the fundamentals still matter. Least-privilege access is still foundational.
What changes is that traditional zero trust was designed for a human-centric world. In an AI-driven environment, organizations must think differently because agents are making decisions and taking actions on their own.
In the traditional model, you’re limiting a user’s access to systems and data. In an AI world, you also have to limit what tasks an agent is allowed to perform. It’s not enough to control access; you need to control actions.
Visibility becomes extremely important. Agencies need discovery, observability and governance capabilities so they can understand what agents are doing, monitor activity and maintain compliance requirements.
We’re moving from a human-based zero-trust model to an agentic zero-trust model. That requires identity for every agent, visibility into machine-driven activity and the ability to enforce policies at scale.
FEDTECH: Given Cisco’s participation in Project Glasswing, how are you advising federal agencies? What is Cisco doing to help organizations prepare for this new era of AI capabilities?
DEPRETA: Mythos catalyzed efforts to understand how advanced AI models can identify vulnerabilities and generate attack paths at machine scale. Cybersecurity is the ultimate team sport, and while agencies are adopting agentic AI to scale detection and response at machine speed, they’re only as strong as the technology providers hardening their platforms and reducing the attack surface.
For Cisco, participation in Anthropic’s Project Glasswing and OpenAI’s Daybreak has transformed how we identify vulnerabilities and protect customers. Using frontier AI models, we were able to scan 1.8 billion lines of code in over 25 programming languages across Cisco’s portfolio in eight weeks. At human scale, that would have taken eight years.
