Presented by Carahsoft
The National Geospatial-Intelligence Agency is processing more information than ever, and securing that data begins with a deceptively simple set of questions: What is it, who should see it and under what conditions should access be granted? Mark Chatelain, Chief Information Officer at NGA, says zero trust provides the operating model for answering those questions consistently.
The agency’s approach starts with data identification and tagging. Information must carry the markings that allow systems to determine who has authorization and a legitimate need to know. Rather than trusting a user because that person has entered the network, zero trust requires continuous verification of identity and permissions before access is allowed.
NGA is now extending that same logic to applications and artificial intelligence. In an agentic AI environment, software agents may retrieve information, execute tasks or interact with multiple systems on a user’s behalf. Chatelain says an agent has to be treated almost identically to a person for access purposes. The agency must understand the identity approaching the data, the credentials it holds and the specific information it is permitted to use.
That does not mean NGA will introduce agents first and define their boundaries later. Before an AI capability is deployed, the agency wants to understand what it is designed to do, how it is likely to behave and what information—including personal information—it could access. Responsible-use policies created by NGA’s chief AI officer establish rules that proposed tools must meet before entering the enterprise.
The work fits into broader intelligence community zero trust milestones. Chatelain says the community is moving toward basic maturity and, afterward, a more advanced model with stronger controls over systems and data. NGA has already identified much of its data and system inventory. The remaining challenge is methodically applying the right controls across each environment so the zero trust baseline is fully implemented.
The risk landscape, however, will not stand still while agencies complete that work. Chatelain points to the long-term challenge quantum computing could pose to encryption. If quantum capabilities advance to the point that they can defeat widely used cryptography, agencies will need protections designed for the post-quantum era. Preparing for that transition is part of building resilience before the threat becomes operational.
AI also changes the volume and variety of identities that cyber teams must manage. An organization that once focused primarily on employees, contractors and service accounts may soon oversee many software agents with different purposes and permissions. Each new agent becomes another identity that must be governed, monitored and constrained. The core zero trust principle does not change, but the scale and complexity do.
For Chatelain, the human dimension may be the most urgent part of the challenge. Employees need the skills to use AI productively without exposing sensitive or classified information. They must also understand the cybersecurity implications of the tools they use. NGA’s human development organization has created a prompt-writing course to help the workforce communicate effectively with AI and get useful results while operating within agency rules.
Training is especially important because generative and agentic AI are new to much of the workforce even though the underlying field has existed for years. Policies can define acceptable use, and access controls can limit exposure, but employees still make daily decisions about what information to enter, which outputs to trust and when human review is required.
NGA’s model brings those elements together: tag and protect the data, verify every identity, govern AI before deployment and prepare people to use the technology responsibly. Zero trust is therefore not a single cybersecurity product. It is the connective discipline that allows NGA to make information available to the right people—and the right machines—without losing control of the mission data entrusted to it.
