Executive Summary American commercial industry leads the world in software development andartificialintelligence(AI). That advantage does not automatically transfer to the military. Thefederal cybersecurity compliance process is a major barrier between America’s mostadvanced technologies and the warfighters who need them. The Authorization toOperate(ATO)is the federal government’s formal mechanism for assessing andapproving software systems. However, the ATO process and its governingframework—the Risk Management Framework(RMF)—aredescribed as ineffective,slow, duplicative, and in need of reform.1Bureaucratic delays can carry a devastatingcost. A former intelligence officer describes just howhighthose stakes can be:“I firmlybelieved that software was the reason that a bunch ofcivilians had died. . . .We hadcritical fixes like known operational issues that were causing operational risk that weresitting on the shelf waiting to go through the ATO process.”2 Prior research has documented ATO process inefficiencies within specific servicecontextsand catalogedsecurityshortfalls.This paper is the first analysis to examinenot only the process itself but the foundational legal authorities, competingstakeholder incentives, and governance structures that collectively producedelays.This paper also assesseswhy reforms have notsolved these issues,despite sustainedattention over more than a decade.Asummary oftheanalysis is capturedin Figure 1. Source: Author’s analysis based on2013 OMB Memo;2024 GAOCritical Cybersecurity Challenges;2019GAO Cloud Computing Security;2024GAO Cloud Security;2024DoW Cybersecurity ReciprocityPlaybook;2021GAO Weapon Systems Cybersecurity;2016NISTAbout RMF;2021,2023,2025and2026 NDAAs;2024 cATO Evaluation Criteria;2019 AFFast-Track ATO;2025FedRAMP Built a ModernFoundation;2025DoW Cybersecurity Risk Management Constructand practitioner experiences. The first half of themilitary software approvalprocess remains almost entirelyunaddressed,and it is the most significant timesuckfor new commercial entrants.Reciprocity, which allows reuse of ATOs to help reduce duplication, has fallen short ofits intended utility and remains a barrier to scaling across the services.Therecommendationsin this paperidentify the highest-return opportunities available thatcomplement rather than duplicate existing reform efforts. These are not exhaustiverecommendations for every single point of friction, but a prioritized set of interventionsdesigned to produce the greatest impact given current AI capabilities and policy reformmomentum. Recommendation 1: Publiclyreleasecriticalcontrols andauthorizingofficials. Federal organizations should publish theirAOauthorities and critical controls to helpprograms and vendors identify an appropriateAOwith bandwidthtoevaluate thesystem.This does not require revealing individual identities, system vulnerabilities, orspecific implementation details. FollowingKarickhoffs’sprinciple, publishing criticalcontrols establishes clear public standards without exposing vulnerabilities, and publishing delegated authorities would allow AI to assist withAOidentification.Opacity creates administrative drag without enhancing security, and administrativebarriers discourage the commercial innovation the militaryneeds. Recommendation 2: Leverage AI tostandardize tomachine-readableformats. AOsshould be required to feed process standards and documentation templates into acentrally managed, AI-enabled tool tostandardizeATO submissions. This tool wouldnormalizeRMF forms and control taxonomies, assist in generating contract language,and enableautomated form population. The military andintelligence community(IC)shouldalsoadopt OpenSecurityControlsAssessmentLanguage, the machine-readable format developed bythe National Institute of Standards and Technology(NIST)thatrenders compliance documentsasstructured, interoperable data. OSCALestablishes a standardized output format that accommodates variation in underlyingtools while ensuringthatcompliance artifacts are interoperable. Recommendation 3: Budgetand deploycontinuous,automated AIredteams. Programs must incorporatethe cost ofAI red teaming into budget plansthrough adedicated percentage tax on overall budget dollars or by requiring program managersto explicitly include estimates within formal program estimates.Onceasystem meetscritical security controls, program offices andAOsshouldstoptreatingtheremainingNIST controls as a compliance checklistand instead implementcontinuous, automatedAIredteaming through the system lifecycle. Agentic AI can execute realistic, on-demand threat assessments continuously and at scale, providing real-time securityinsights while optimizing the deployment of scarce, highly skilled human cyber talent.Currently, the scarcity of personnel possessing deep technical expertise, missioncontext, and RMF mastery creates cybersecurity compliance theaterand delays. Recommendation 4: Experiment with AIreciprocityagents. An AIreciprocityage