As federal agencies and the national laboratories continue to adopt AI into increasingly important workflows, they are grappling with a difficult question: how can they put AI to use in situations where security, data sovereignty, and governance are critical considerations?
At the 2026 NLIT Summit, Ian Brooks, Ph.D., Director of Global Industry AI Solutions for Government at Cloudera, led a session on AI-assisted software development. He showed how developers can make use of AI-assisted coding in a typical development environment that is linked to a private inference service, allowing for greater control over both sensitive data and the AI infrastructure.
In this Q&A, Brooks talks about his takeaways from NLIT, the role of private AI in secure environments, why data readiness is so fundamental and how governance may define the next phase of federal AI adoption.
Q: Earlier this year, you spoke at NLIT about AI-assisted software development in environments where data sovereignty, security and governance are critical to success. How did this topic fit into some of the broader conversations you heard at the summit?
Brooks: As organizations deploy AI across more of their workflows, one of the hardest questions is how to do it securely. That has become even more complicated in the environments represented at NLIT, where organizations are working with sensitive data and classified networks. Many conversations are coming back to, “How do we actually do this securely? How do we make this work in classified networks?”
This was a large part of the session I presented. We looked at how developers can use AI-assisted coding tools in an integrated development environment (IDE) connected to a private inference service. The goal was to show how developers can benefit from AI-assisted coding while still maintaining control over where the model runs and how the data is handled.
There are plenty of reasons organizations might choose this kind of private AI approach. Data sovereignty is a big one, along with enterprise data security, control over the model, and access management. It also lets organizations control their own infrastructure and costs, instead of depending on outside models and unpredictable per-token pricing.
NLIT also gave me a chance to see how the labs are approaching these architecture challenges in different ways, including during a Lawrence Livermore session on AI gateways that can route traffic to different LLMs based on factors like token costs.
That’s what I value most about NLIT. It’s a chance to connect with customers, see what the labs are working on, and talk with partners about what matters right now. You walk away with a much clearer sense of how these organizations are actually using AI day-to-day.
Q: For organizations working with sensitive or classified data, what does it take to gain the benefits of modern AI without giving up control of the models, infrastructure or data?
Brooks: For some government environments, there are security realities that aren’t going to change simply because AI technology is advancing. Organizations like the NNSA aren’t going to take classified data and move it into a public environment just to use an AI model. Those workloads need to remain in highly secure environments, and the AI capabilities have to be able to operate where that data resides.
That’s where private AI comes into the conversation. With private AI, organizations can host their own large language models on infrastructure they control, run them through their own inference services, and maintain control over access to the model endpoint. They can also take advantage of open-source models that make sense for a particular use case while keeping sensitive information within the appropriate environment. In other words, you can bring the model to the data rather than moving sensitive data to the model.
AI-assisted software development is a useful example. Developers want access to coding assistants and the productivity benefits that come with them, but organizations also have to understand what happens to the code, prompts, and other information developers provide to those tools. In a sensitive environment, you can’t separate that question from the security discussion.
The purpose of my demonstration at NLIT was to show that those priorities don’t necessarily have to compete. A development environment can point to a privately controlled inference service, allowing the AI capability to operate where the organization needs it. Ultimately, the architecture has to conform to the security and data requirements of the mission, not the other way around.
Q: The push to operationalize AI has put renewed attention on data readiness. Why is the data foundation so important for mission use cases, and where should agencies focus first?
Brooks: Data readiness has always been important, but AI is putting a spotlight on it. As organizations adopt AI across more use cases, they’re finding gaps in their data foundations that may not have been apparent before. AI depends on having data that is accessible, trusted and well managed, so those gaps become much harder to work around.
I like to compare it to building a house. If your foundation is solid, you can build whatever you want on top. If it’s shaky, you’ll keep running into problems no matter what you try to add. The same goes for AI.
That means looking at the whole data lifecycle—how you bring data in, manage it at scale, put the right security and governance in place, and get it ready for things like analytics, data warehousing and AI.
Data access is where the challenge really shows up. In a recent study, Cloudera found that almost 80% of enterprises say limited data access holds back their AI and data projects. In the public sector specifically, only 16% say they can access all their data whenever they need it.
Even the best AI model can’t fix a shaky foundation. If the data is hard to access, poorly managed, or not properly governed, you’ll still run into problems. For mission-critical work, AI readiness starts with making sure your data is usable, trusted, secure, and available when you need it.
Q: As agencies move from individual AI experiments toward broader deployments, where does governance become the limiting factor, and what needs to be governed?
Brooks: Governance is the area I’m watching most as organizations move from AI theory to real-world use. It’s one thing to show an LLM can do a task. It’s another to roll out those capabilities across the whole organization.
That’s when new questions come up. How will you handle model governance? What about data governance? And as organizations start using more agent-like AI, how will you govern those agents?
I break AI governance into three parts: the model, the data, and the agents. For models, organizations need to know which ones they’re using, where they run, and who can access them. For data, it’s about controlling what information models can see and making sure that access fits security and mission needs. Agent governance is a new layer, since now you have AI that can interact with other systems or take action, not just generate answers.
To me, this is all part of the maturity curve. Organizations may start by asking how they can use an LLM, but governance needs to be part of that conversation from the beginning. If you wait until you’re ready to scale to address how models, data and agents will be governed, those questions can quickly become roadblocks.
Q: What is the biggest takeaway from NLIT 2026 that federal IT leaders should carry into the next phase of AI adoption?
Brooks: Governance is probably the biggest takeaway for me.
There are still plenty of technical questions organizations are working through today: which models make sense, where they should run, how inference should be managed, and how to control costs. I think we’re going to get increasingly comfortable with many of those questions. As that happens, the conversation is going to shift from how to use AI to figuring out how to govern it at scale.
That’s an important shift because federal IT leaders need to think beyond any single model or use case. The data foundation needs to be solid. The infrastructure has to meet mission security needs. And AI controls have to mature as adoption grows.
That’s where I see the conversation going. We’ve spent plenty of time asking how to use LLMs and what they can do. Now, the next phase is making sure organizations have the right governance in place to use these tools sustainably as they become a bigger part of the enterprise.
Building the Foundation for Private AI
As AI becomes a bigger part of federal operations, agencies will need to think beyond individual models and use cases. The next phase will depend on having the data, infrastructure and governance in place to use AI securely and at scale while maintaining control over sensitive data and systems.
Learn more about how Cloudera helps public sector organizations build a secure, governed data foundation for AI.








