Thought Leaders

National Security Requires Securing Modern AI Workloads

mm
Add Unite.AI to your preferred sources on Google

While AI-driven coding practices and workload modifications claim to accelerate mission performance, they also introduce system vulnerabilities. The challenge is well understood – today’s vulnerability management practices cannot keep up with rapidly evolving AI tools, which ultimately increases risk to troops conducting operational missions.

Knowing your tools will succeed, whether it is an M27 IAR or the AI-driven tactical C2 putting fires on target, instills confidence in the field. When it comes to software systems, they can increase in reliability by eliminating software container risks through comprehensive Software Supply Chain (SSC) security.

Container Vulnerabilities Are an Increasing Risk in Defense Software

Every software-driven organization struggles with container-related security vulnerabilities. The Department of War (DoW) aims to field the best systems to operational troops, but this increases risk. The reason is because most mission systems rely on core software from Linux distributions and community software bases with overly large software baselines. Systems built on this open-source software typically contain known and unknown Critical Vulnerabilities and Exposures (CVEs).

To address this problem, curated images that include fixes for these CVEs dramatically reduce the attack surface. In addition, unnecessary code represents additional risk, since this code may conceal CVEs. Deploying hardened software images mitigates this risk by eliminating unnecessary code. Without hardening, excess code increases the vulnerable attack surface and introduces hidden CVEs. It is also critical to evaluate every CVE as part of the context in which it manifests itself. CVEs are exploitable in the environments, operating systems, and hardware where they are discovered to be reproducible. Intelligently scanning, profiling, and understanding the production software will determine whether each individual CVE impacts the target environment and identify which CVEs are duplicated and simply appearing in multiple packages.

AI Coding Tools Scale the Problem

AI coding tools are resource-intensive engines used to develop, train, and deploy models, but often focus on end states rather than optimizing operational compute and storage. As a result, they amplify security problems by indiscriminately using open-source distributions rather than curated and hardened images.

Today’s AI coding tools constantly change, have many open-source dependencies, and deploy more pervasively than traditional tools. Models, frameworks, and supporting services update daily or weekly rather than quarterly or annually, and every non-hardened software artifact implemented by these tools magnifies the risk. These are not new risks but with AI they are now accelerating. For example, vulnerability backlogs grow faster as more software is deployed. As evidence, the CVE list in 2025 averaged 132 new vulnerabilities per day, up 20% from the previous year, and triple the number from 2020.

Poor Vulnerability Management Yields Operational Consequences

Operational consequences from poor vulnerability management include:

  • Restrictions on ATO-accessible technologies, with fewer AI tools approved for production
  • AI deployment slowdowns as container stacks fail compliance on mission timelines
  • Inability to compete with adversary AI tactics, increasing mission risks
  • Recurring high financial costs required to manage vulnerability backlogs
  • Highly skilled engineers focused on chasing and patching CVEs rather than delivering new capabilities

With or without AI, vulnerability management practices for DoW solutions must meet mission timelines. AI-enabled platforms must improve cyber defense, not increase security exposure. Solutions of choice need to address runtime-relevant exposure, reduce CVE counts, and allow authorizing officials to distinguish noise from mission impact. Solving this problem keeps units from pursuing one-off hardening efforts, creating a consistent, data-driven pipeline.

The Winning Approach for National Defense

The best secure process is one that enables faster, safer AI-enabled operations, a stronger zero-trust container foundation, and high-fidelity software supply chain risk data for commanders.

Defense agencies should start with near-zero CVE images, then eliminate additional vulnerabilities by removing unused components versus patching them to reduce acceptable risk paths. Hardened images result in smaller attack surfaces and clearer risk narratives to accelerate accrediting AI-enabled systems, freeing cyber teams to focus on higher-priority missions instead of endless vulnerability triage.

In addition, software bills of materials (SBOMs), runtime bills of materials (RBOMs), and hardened images give operators and security teams a layered, runtime-accurate view of containerized AI workloads. This approach directly supports zero trust principles and aligns with the Enduring Security Framework (ESF) team’s software supply chain visibility requirements, showing what is in the software, its behavior, and delivery mechanisms.

Maturing DoW risk scoring and attestation practices should accompany containers with machine-readable artifacts and technical security bulletins. This allows developers and operators to subscribe to needed containers and receive consistent risk scores and alerts if new issues arise. For Command, this acts as a practical “check engine light” on critical software stacks, enabling decisions to move beyond commercial discovery into direct mission alignment at the speed of AI-driven operations.

Austin Sedaghatpour is Public Sector Mission Lead at RapidFort, where he supports government agencies in securing the software supply chain by eliminating risk at the source. He works with mission and technology leaders to reduce vulnerabilities and attack surface across modern software environments through RapidFort’s continuous threat elimination platform. Previously, Austin represented the Government of Israel through the Ministry of Foreign Affairs and the Ministry of Economy and Industry, advancing U.S. Israel partnerships in cybersecurity, innovation, investment, and technology commercialization.