Before You Can Ask the Question, You Have to Own the Data

Lessons from DOE’s NLIT 2026 Panel on Trusted AI and Classified Data

By Ian Lee, Director of Advanced Computing Solutions, ShorePoint

The federal national laboratory community is under pressure to move faster with AI — and justifiably so. Decades of irreplaceable scientific data (results that may not be able to be reconstructed or re-run) sit in classified archives: fusion diagnostics, stockpile simulations, and experimental results that took generations to produce. The promise of large language models and agentic AI search is that this knowledge could finally become accessible to the researchers and analysts who need it, at the speed of a natural language query rather than a manual keyword search.

But a panel at the 2026 NLIT Summit, a leading event for IT and cybersecurity professionals affiliated with the U.S. Department of Energy national laboratories, surfaced a challenge that architectural elegance alone cannot solve: before that promise is possible, someone has to do the hard, unglamorous work of getting the data ready. And in classified environments, that work is neither quick nor inexpensive.

Separating the Data from the Reasoning

The panel opened with a central problem that will be familiar to anyone working at the intersection of AI and classified operations: traditional approaches force a choice between mission acceleration and data sovereignty. Complete air-gapping preserves security but stalls the mission. Centralized cloud architectures enable capability but compromise sovereignty.

The architectural response discussed — what panelists called the Genesis paradigm — separates the problem into three tiers. Tier 1 (the Vault) holds immutable, air-gapped data: it is never directly accessed by AI systems. Tier 2 (the Reference Librarian) is a governed knowledge layer that understands what exists, verifies authorization, and surfaces only what a given user or system is entitled to receive. Tier 3 (the Scholar) is where AI reasoning happens — operating entirely on what the knowledge layer hands it, never touching the underlying vault.

The architecture is conceptually sound. It operationalizes Zero Trust at the data object level rather than the network perimeter, which is the right framing for environments where the threat model includes insider risk and where compartmentalization matters more than perimeter hardening. Policy-as-code enforcement, attribute-based access control (based on a user’s verified clearance, role, need-to-know or other characteristic), and immutable provenance for model certification all have natural homes in this three-tier model.

But the audience’s most persistent question was not about the architecture. It was about the gap between the architecture and the current state.

The Real Constraint Is Not the Architecture

The honest answer to “how do we get there from where we are” involves confronting several foundational problems that no elegant architecture resolves on its own.

The first is data tagging. For a governed knowledge layer to function — to enforce need-to-know, honor classification requirements, and prevent unauthorized users from even inferring the existence of compartmented datasets — every data object needs accurate, machine-readable metadata. In practice, classified archives contain decades of data tagged inconsistently, tagged by hand, tagged to standards that have since changed, or not tagged at all. Getting from that state to one where the Reference Librarian can make reliable access decisions is a sustained, resource-intensive undertaking. It is not a one-time migration. It is an ongoing operational commitment.

The panel discussion around Trusted Data Format (TDF), a standard originating in the Intelligence Community built to embed access control rules directly into data objects, illustrated both the promise and the challenge. TDF is technically mature and purpose-built for this problem. But adopting it at scale means re-tagging existing data — one object at a time, with authoritative classifications decisions behind each tag. This is not a technology implementation. It is a sustained human undertaking that depends entirely on having clear, consistent classification guidance to draw from.

That brings the second foundational problem: classification guidance is often incomplete, inconsistent across laboratories, and treated as a point-in-time artifact rather than a living document. The panel surfaced this as one of the genuinely difficult unsolved problems in the space. Building a semantic knowledge layer requires a shared lexicon — a common understanding of what terms mean, which classification levels apply to what categories of information, and how those determinations should be made when guidance is ambiguous.

That lexicon does not currently exist across the national laboratory enterprise.

Creating it is not a technology problem. It is a policy and governance problem, and one that requires sustained commitment from senior leadership, not just practitioners.

Data Rights: A Question the Field Hasn’t Answered

The panel also surfaced a governance question that sits upstream of the technical architecture: when AI systems are trained or fine-tuned on classified data held by multiple laboratories, who owns the resulting model?

This is not hypothetical. As laboratories move toward joint training pipelines and shared AI compute infrastructure, the question of model ownership — and the related questions of data rights, liability, and mission authority — will become operational. The panel framed it as a three-way problem: the laboratory contributed the data, the platform operator provided the infrastructure, and the government mission owner funded the work. The fine-tuned model that comes out the other end reflects all three contributions. Current frameworks are not well-equipped to answer who controls it, who can access it, and what happens if the partnership changes.

Leaders who are planning shared AI infrastructure investments should be forcing this question into the contract and governance layer now, before the infrastructure is built. Retrofitting data rights frameworks onto operating systems is significantly harder than building them in from the start.

When the Framework Doesn’t Fit

A thread that ran through both the panel and adjacent sessions at NLIT was the gap between compliance checkbox exercises and genuine risk management. The Risk Management Framework (RMF) provides a structured process for authorizing systems to operate in classified environments. But RMF was not designed with AI systems in mind and applying it to AI models that continuously retrain on classified data creates gaps that existing control checklists aren’t equipped to close.

AI-specific failure modes like prompt injection, model drift, and data contamination don’t map cleanly onto existing control checklists. The risk is that organizations satisfy the paperwork without ever honestly assessing whether decision-makers understand the actual risk posture of the system they are authorizing. The goal is not demonstrated compliance. It is genuine understanding of what the system will and won’t do safely.

What Leaders Should Actually Be Deciding

The panel framing was architectural. But the most useful takeaway for federal leaders is not architectural. It is sequencing.

The question of which AI architecture to adopt is premature if the underlying data cannot support it. Before investing in sophisticated AI compute infrastructure, leaders should be asking three prior questions:

First: what is the actual state of data tagging and metadata quality across the archives that AI systems would need to reason over? Not the theoretical state — the operational state. A frank audit here will surface the gap between the target architecture and the current reality faster than any vendor briefing.

Second: does authoritative, consistently interpreted classification guidance exist for the data domains in scope? If the classification guidance is incomplete or interpreted differently across organizational units, the governed knowledge layer cannot make reliable access decisions regardless of how sophisticated the access control technology is. This is a policy investment, not a technology investment.

Third: have data rights and model ownership questions been answered for any shared or multi-party infrastructure? If the answer is no, those questions should be resolved before infrastructure commitments are made, not after.

The architectural patterns discussed at NLIT represent a genuine advance in thinking about how to deploy AI in classified environments without compromising data sovereignty. But architecture is not the bottleneck. The bottleneck is the foundational data work that has to precede it — the tagging, the governance frameworks, the shared lexicons, the classification guidance — and the organizational will to treat that work as the mission-critical investment it actually is.

The Work Ahead

The national laboratory community is not short on architectural ambition. The panels at NLIT demonstrated sophisticated thinking about zero-trust data fabrics, federated learning governance, and DDIL-constrained operations. What the community is short on is a shared, honest accounting of where the data actually stands today — and a commitment to doing the preparation work that no vendor will propose and no acquisition vehicle will fund by default.

The goal of enabling scientists and analysts to query decades of classified archives through natural language interfaces is both achievable and worth pursuing. But the path there runs through unglamorous, sustained data preparation work. Leaders who understand that — and invest accordingly — will be positioned to move quickly when the architecture is ready. Those who skip to the architecture first will find themselves rebuilding the foundation later, under time pressure, at greater cost.

Article prepared based on the NLIT 2026 Summit panel: “Unlocking Classified Data with Trusted AI: Zero-Trust Fabrics, RAG, and Federated Learning”

A Public Benefit Corporation means the mission remains the mandate, even when it is hard. Learn more about OrangeSlices PBC



Not Yet an OrangeSlices Insider? Learn more about the OS PBC Insider Corporate and Individual Plans here. Plans start at $295 annually.

LEAVE A REPLY

Please enter your comment!
Please enter your name here