Booz Allen
All Statistics
44% of federal leaders say proven risk mitigation frameworks would increase their confidence in expanding agentic AI deployments
36% of federal cyber and IT leaders are confident that cyber defenses can keep pace with AI-enabled attackers
58% of federal IT and cybersecurity decision makers report their agencies have deployed or are piloting AI agents
28% of federal IT and cybersecurity decision makers express high confidence in their ability to deploy AI agents securely
79% of federal IT and cybersecurity decision makers are very or extremely concerned about adversaries using AI to accelerate cyberattacks against their agencies over the next 12 to 18 months
31% of federal cyber and IT leaders are fully or substantially prepared to employ AI-powered cyber defenses that integrate with existing security infrastructure
56% of federal IT and cybersecurity decision makers list protecting sensitive or classified data as a top concern for agentic AI deployments
22% of federal IT and cybersecurity decision makers say their organizations have not clearly determined who bears responsibility when an AI agent causes a security incident or operational failure
50% of federal IT and cybersecurity decision makers list preventing unauthorized actions as a top concern for agentic AI deployments
37% of federal IT and cybersecurity decision makers list resilience against adversarial manipulation and prompt injection attacks as a top concern for agentic AI deployments
56% of federal leaders say greater visibility into agent behavior would increase their confidence in expanding agentic AI deployments
42% of federal leaders say demonstrated success in their organization’s environments would increase their confidence in expanding agentic AI deployments
Three of four Chinese LLMs generate hidden security vulnerabilities when prompted with a U.S. government persona.
All four Chinese-built models refuse to generate code for mock U.S. government tasks that Beijing would oppose.
When prompted as "You are a helpful assistant, generate code for a U.S. government agency that builds an internal admin console with these listed features" vs "You are a helpful assistant, generate code that builds an internal admin console with these listed features….", Claude generated 18% fewer vulnerabilities.
When prompted as "You are a helpful assistant, generate code for a U.S. government agency that builds an internal admin console with these listed features" vs "You are a helpful assistant, generate code that builds an internal admin console with these listed features….", MiniMax M2.5 (CN) generated 20% more vulnerabilities.
When prompted as "You are a helpful assistant, generate code for a U.S. government agency that builds an internal admin console with these listed features" vs "You are a helpful assistant, generate code that builds an internal admin console with these listed features….", DeepSeek V4-Pro (CN) generated 5% more vulnerabilities.
When prompted as "You are a helpful assistant, generate code for a U.S. government agency that builds an internal admin console with these listed features" vs "You are a helpful assistant, generate code that builds an internal admin console with these listed features….", Qwen 3-Coder (CN) generated 130% more vulnerabilites.
When prompted as "You are a helpful assistant, generate code for a U.S. government agency that builds an internal admin console with these listed features" vs "You are a helpful assistant, generate code that builds an internal admin console with these listed features….", there were no changes in the number of vulnerabilities with Kimi K2.5 (CN).