Technology adoption has never moved this fast. It took 75 years for the telephone to reach 100 million users, but ChatGPT reached that same milestone in just two months. That rate of adoption is outpacing the growth of skilled security professionals, leaving many organizations, especially in the State, Local and Education (SLED) space, vulnerable as they rush to deploy artificial intelligence (AI) and large language models (LLMs) in the cloud. For Government IT and security leaders navigating this shift, understanding where true security gaps exist and how to close them has become an urgent priority.
Moving Beyond Guardrails to Build Real AI Security
One of the most common misconceptions in AI deployment is confusing guardrails with genuine security. Guardrails steer a conversation, redirecting a user away from a restricted topic, but they do not block malicious activity outright. A determined user can often push past a guardrail with the right prompting, much like navigating around a soft boundary rather than hitting a wall. Compliance carries a similar risk of false confidence. Meeting a checklist of requirements does not guarantee an environment is actually secure, and agencies that treat compliance as the finish line often overlook deeper vulnerabilities in how AI systems handle data, access and prompts.
This distinction matters most under the shared responsibility model that governs public cloud environments. Cloud providers secure the infrastructure itself, but agencies remain responsible for their data, applications, prompts and access controls, including when building custom LLMs or integrating third-party AI tools. Recognizing where that line falls, and building real inspection and enforcement around it, is the first step toward closing the gap between perceived and actual security.
Designing AI Security from Day One
Just as migrating on-premises applications to the cloud works best when systems are redesigned for that environment rather than lifted and shifted, AI deployments require security to be built from day one. Adding protection after an LLM or AI tool is already in production is significantly more difficult and costly than building it in from the outset. This is especially true for agencies developing their own LLMs, where a substantial share of the data used for training and ingestion is unique to the Public Sector, from municipal codes to regional regulations that vary by jurisdiction.
Without careful data governance, sensitive information can become permanently embedded in a model, potentially compromising its integrity and accuracy. Once proprietary or sensitive data is used to train an LLM, it becomes part of that model’s knowledge, and no simple guardrail can fully guarantee it will never surface again. For Government and education agencies handling citizen data, tax records or other sensitive information, this makes upfront planning around data sanitization and access control essential rather than optional.
Meeting New AI Threats with Purpose-Built Defenses

Traditional network security, firewalls and static, point-in-time scans were built for a world of predictable web traffic, not the dynamic, prompt-driven nature of generative AI. New categories of threats, including prompt injection, model poisoning, data leakage and unauthorized access through AI assistants, now require dedicated defenses. Real-world incidents illustrate the stakes: hidden text embedded in an email, invisible to the user, can trigger an AI assistant connected to that inbox to leak sensitive files or data without the employee ever clicking a link or opening an attachment.
Because these attacks exploit the AI’s own decision-making rather than network vulnerability, effective defense requires inspecting and controlling the full conversation between a user, an AI model and its data sources. That means:
- Filtering malicious prompts and jailbreak attempts before they ever reach the LLM
- Applying real-time signature-based defenses to block known threats immediately
- Validating the architectural data flow between AI models and connected services
- Monitoring AI behavior continuously, not just traffic, to catch anomalies like off-hours data requests
Aligning Growing AI Investment with Strong Security Foundations
Across Public and Private Sector organizations alike, leadership recognizes the need to invest in AI, and budgets are following. The challenge is that this funding is sometimes redirected from existing security budgets, without a clear plan for what the AI is meant to accomplish or how it will be governed. Deploying AI tools like Copilot without addressing what data they can access, and how that access is controlled, opens the door to serious exposure, particularly for agencies managing sensitive citizen or financial records.
Compounding this is the rise of shadow AI, where employees use multiple AI tools without agency oversight or a clear usage policy. Many professionals are uncertain about which skills or certifications will keep them relevant as AI reshapes their roles. Addressing this requires visibility into what AI tools are already in use across the network, paired with governance that allows innovation to continue without leaving critical data unprotected.
Moving Forward with Confidence
AI adoption is not slowing down, and for Government agencies, the opportunity to modernize services and operations is real. However, agencies can only realize those benefits by making AI security a foundational requirement rather than an afterthought. Agencies that build visibility, governance and layered defenses into their AI strategy from the start will be far better positioned to innovate without compromising the trust citizens place in them.
To see how Fortinet’s security solutions can help your agency protect its AI and cloud environments, schedule a product demo with Fortinet and Carahsoft today.