Skip to content

Operating Models

The CMMC suspension is an organizational knowledge test

Cybersecurity certification was never going to be just another audit for the companies that build and support U.S. defense systems. Preparing for it changed budgets, architectures, hiring plans, subcontractor relationships, and the everyday work connecting cyber teams with engineers, contracts staff, and program leaders.

Then, on July 13, 2026, the Department of Defense (DoD) suspended the planned transition to Phase II of the Cybersecurity Maturity Model Certification (CMMC) program. The Department also halted later implementation milestones and opened a 60-day review of the program.

The announcement brought meaningful relief from the coming expansion of third-party assessments. It did not, however, abolish CMMC or erase the contractual duty to protect defense information. Phase I continues, and the underlying safeguarding and reporting requirements remain in force.

That leaves defense organizations with a harder question than whether to keep preparing for an assessment: Which parts of the CMMC effort were merely certification overhead, and which parts became necessary organizational capability?

The distinction matters because a compliance program leaves behind more than policies and evidence. It also changes who talks to whom, how work moves between teams, where decisions are recorded, and whether an organization can accurately explain the security of its systems. Those capabilities are slow to build and surprisingly easy to lose.

Financial agents will be proven in the exception queue

Anthropic has released agent templates for financial services, including work such as preparing pitchbooks, screening Know Your Customer (KYC) files, reviewing valuations, reconciling ledgers, and supporting the monthly close.

These are not toy tasks. They sit inside governed processes with source systems, deadlines, approvals, materiality judgments, and audit expectations. Their automation will be judged less by the clean case than by what happens when the evidence does not line up.

Enterprise AI scales through the operating model

OpenAI's account of the next phase of enterprise artificial intelligence describes rapid growth in organizational use and increasing demand for agents that can operate across real workflows. The direction is clear: companies are moving beyond isolated conversations toward systems that research, update records, create artifacts, and complete multi-step work.

That movement makes the operating model—not access to the model—the limiting factor.

Agent security starts before the agent acts

The National Institute of Standards and Technology (NIST) has opened a request for information on securing artificial intelligence agent systems. The timing is right. Organizations are moving from systems that generate suggestions toward systems that can call tools, manipulate records, send messages, and coordinate multi-step work.

The security question is no longer only what a model might say. It is what the complete system is allowed to do—and whether the organization can reconstruct what happened afterward.

Governance needs an evidence system

The new year has opened with a practical test for artificial intelligence governance. California's Transparency in Frontier Artificial Intelligence Act (TFAIA), enacted through Senate Bill 53 (SB 53), is now operative. It asks covered frontier developers for published frameworks, safety reporting, incident processes, and protections for employees who raise serious concerns.

The particulars apply to a defined group of companies. The lesson travels much further: a governance commitment is only as real as the evidence an organization can produce when somebody asks how the commitment works.

AI security overlays can connect two professions

The National Institute of Standards and Technology's (NIST) August 14 concept paper proposes security-control overlays tailored to artificial intelligence (AI) systems. The work adapts controls from NIST Special Publication 800-53 to generative, predictive, single-agent, multi-agent, and developer use cases.

The practical promise is not a new checklist. It is a better conversation between two professions that too often approach the same system with different maps.

An AI action plan becomes real at the handoff

The White House's July 23 release of America's Artificial Intelligence (AI) Action Plan outlines more than 90 actions across innovation, infrastructure, international engagement, and security.

Any plan of that scale contains choices people can debate. The implementation lesson is less partisan and more practical: strategy succeeds or fails in the handoff from an announced action to an accountable operating system.

The backlog of oversight is part of the architecture

The U.S. Government Accountability Office's (GAO) May 29 report identifies 54 open recommendations under the Department of Defense (DoD) Chief Information Officer's purview. They span cybersecurity, information-technology acquisition, business-systems modernization, and financial management.

It is tempting to treat that list as legacy administration while attention shifts to artificial intelligence and autonomy. That would be a mistake. The unresolved management system is part of the architecture on which new capability has to run.

READER-NEUTRAL SUBSCRIPTION

Follow Field Notes via RSS.

Copy this address into the RSS reader you already use. New notes will appear there automatically—no account, email address, or tracking required.