The U.S. Department of Energy (DOE) has identified significant gaps in its governance of artificial intelligence and cybersecurity, according to a new inspector general report. The report highlights a disconnect between the rapid deployment of emerging technologies and the department's ability to effectively oversee and manage associated risks. Auditors warn that without improved coordination and oversight, the DOE's increasing reliance on advanced digital systems could expose critical infrastructure to heightened operational and security threats, particularly from state-sponsored actors and criminal organizations targeting high-value assets.
A key concern is the DOE's highly decentralized security model, which complicates efforts to implement consistent cybersecurity and AI governance across its program offices, sites, and national laboratories. The report underscores the need for stronger, enterprisewide risk management to address these vulnerabilities and safeguard national security interests as the department continues to modernize its technology landscape.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
A new inspector general report identified gaps in AI governance, cybersecurity oversight, funding, and enterprise coordination as major management challenges for the Department of Energy in 2026. The report warned that decentralized security practices, outdated requirements at some sites and contractors, and weak centralized visibility increase risk to critical infrastructure.
The Department of Energy published an AI strategy and related AI compliance planning to guide expanding use of artificial intelligence in operations, energy systems, and national security. The inspector general report says governance development still lags behind DOE's pace of AI adoption.
Before the inspector general's 2026 risk warning, the Department of Energy had already launched an enterprise cybersecurity collaboration office as part of efforts to improve coordination across the department. The report says this step was not sufficient to resolve broader structural weaknesses.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.