AIAI EngineerDec 6, 2025· 16:31

Government Agents: AI Agents Meet Tough Regulations — Mark Myshatyn, Los Alamos National Lab

Mark Myshatyn, Enterprise AI Architect at Los Alamos National Laboratory, describes how the lab is building AI agents for scientific research under strict federal regulations. He showcases an agent that reads fusion capsule papers, designs a hypothesis, and runs simulations on high-performance computing assets, integrating 60+ years of physics models. He stresses the need for explainability, isolation, and governance in government AI tools, citing OMB memoranda M2521 and M2522 mandating faster AI adoption with real-world impact. The lab partners with frontier labs like OpenAI for chem-bio safety work, and with NVIDIA and HPE for the Venado supercomputer. He urges startups to build for DoD IL5 environments and continuous compliance to succeed in federal procurement, noting Los Alamos holds petabytes of never-internet data and specializes in sensors like the ChemCam on Mars.

  1. 0:00Intro
  2. 1:21Agent Demo
  3. 3:37Lab Mission
  4. 4:32Partnerships
  5. 5:39Regulations
  6. 7:58Compliance
  7. 9:57Co-creation
  8. 11:01Why Collaborate
  9. 11:49Gov-Ready Design
  10. 14:49Closing

Powered by PodHood

Transcript

Intro0:00

Mark Myshatyn0:13

Allright, good morning. My name is Mark Myshatyn, I'm our Enterprise AI Architect at Los Alamos National Laboratory. Today, you know, this is an AI conference—what's a nuclear science lab doing here? The reality is we've actually been doing Applied AI/ML for almost 70 years.

This is actually one of our scientists in 1956 playing Los Alamos chess in front of one of our first supercomputers, Maniac 1. And what's unique about this is we—if you look at it—there's actually no bishops on the chessboard.

You know, we've been doing applied statistics and applied machine learning since we didn't have the memory needed to hold an entire chessboard in a computer at once. And that's fascinating to say, back when this photo was taken, it was after the Manhattan Project, we were pushing the edge of developing Monte Carlo methods that we still use today.

And for us, you know, AI didn't come as a complete surprise, but the opportunity that's come with agents, with things we can do, has been incredible. Even to us, it has been along the ride for quite some time.

Agent Demo1:21

Mark Myshatyn1:21

Let's see if I can make this full screen. So what we have going on here—this is actually a demonstration. You can find it on our YouTube channel if you can't see it on this screen here. But we've looked at generative AI not only from a strict model standpoint, but also from an agentic standpoint, as a way for us to move science faster.

You know, we, like much of the federal government, are under a squeeze to do better, faster, cheaper, and more to protect our country. And in this case, going from not just what a model knows, but what we can let a model know, was really the change that happened here.

We started with a problem of GoDesign, an ICF—an Inertial Confinement Fusion capsule—for our sister lab at Livermore, across the bay here. And we said, read a paper. Go read lots of papers that you think are tangential to this first paper, and then come up with a design for a fusion capsule.

It created a hypothesis. And the thing that's kind of uniquely ours is this isn't a generic, you know, chatbot that spits back a bunch of code. What you'll see here in a second, we're actually executing that code on our high-performance computing assets.

And we are actually running, you know, thermodynamic and hydrodynamic tests on some of these types of problems where our model, you know, isn't just an LLM, it's all of the, you know, 50, 60-plus years of math and science that we've done to bring the management and the development of our nuclear stockpile and stewardship of that stockpile, bring those tools into an agentic era.

So we're looking at this as a chance for agents to move faster and for science to move faster, because the risk, at the same time, is starting to move faster. You can see here, it actually did come up with a design that it thought optimized that yield, and we were simulating a slice through an ICF capsule.

But, okay, that's one nice toy problem. What does that mean for the other 20,000 researchers that we have at our laboratory? For those of you not familiar, we're 40 square miles of labs, test sites, test plants. We have 13 nuclear facilities.

Lab Mission3:37

Mark Myshatyn3:37

And so we're huge. We have a huge breadth of what we're trying to accomplish with AI and getting our mission moving faster. For our National Security AI Office, you know, what you just saw, that's the first thing that we're charged with: push the science of AI faster.

Don't just sit there and consume commercial tools or open-source tools. We write our stuff. We write our own models. We also realize that we can't do everything. We don't have the hubris to understand or to say here, "Oh, we understand everything.

We don't need anyone's help." We absolutely need those partnerships from commercial industry, from academia. And then, just like the rest of you all here, we're looking at how do we bring AI and Gen AI tools into our workflows.

You know, we have a huge footprint. We have to do payroll. We have to do procurement. We have to do cybersecurity. And so our office is kind of in there, "How do we do that?" And it really does come down to some of what we're doing with our partners.

Partnerships4:32

Mark Myshatyn4:32

We have some great academic partners. We couldn't—at the time these slides were released for public review, we didn't get the screenshot on there. We also announced a partnership with the UC family of schools on the academic side of developing, you know, the future of AI.

But we're also working with all the frontier labs. You know, here's a couple press releases where we've actually done chem-bio safety work with OpenAI. And we've been able to acknowledge that work that we've done with them. But we have a place where we've been doing—we're a safe place to do dangerous things, and we've been doing that for decades.

So it's a neat partnership to have these frontier labs that really can't afford to hire anyone they want, still come to us as a source of data and a source of partnership. There in the middle, that last picture, we actually have science of AI in the hardware space.

That's our Venado supercomputer. It's over 2,500 nodes of Grace Hopper superchips. And we brought it through a partnership with NVIDIA and HPE to build a supercomputer that can help us push the boundaries of what does it mean to do AI research.

Regulations5:39

Mark Myshatyn5:39

And then more recently, we've also brought OpenAI's models onto this system, brought it up to our classified networks. And we're getting to work on the really hard problems that are unique to our data and our mission space. When we talk about agency, you know, partnerships take trust.

You know, certainly having labs trust you with early access to their models or model weights. As we talk about sharing responsibility with our partners, certainly the responsibility of what our AI tools and services do starts to matter. There were previous administrations that had certain executive orders out.

Those were replaced largely in January when the new administration took change. But this piece of OMB memorandum just came out in April, M2521, and there's M2522. And it starts to codify, like, what things should the U.S. government start to worry about when we're fielding these AI systems?

It tells the government to go faster. That's important. But it also says these government-type workloads, they have real-world impacts. You know, for us, we are not a T-shirt company. If our data gets out, that's, you know, geopolitical challenges show up, kinetic challenges show up.

People can die if we do this wrong. And this—I won't bore you—it's like 25 pages, reasonably well written for an OMB memorandum, as far as readability and comprehensiveness. But it says we as the U.S. government need to move faster into bringing this into everything we do.

It's not enough to just buy, you know, pick your favorite office add-in tool and say, "We can type PowerPoints faster or summarize our emails faster." We got to go deeper into our mission. And that comes with trust. So who here is part of a software-as-a-service company or startup?

Okay, handful of hands here. So you've probably seen something similar to this, especially if you've been in the cloud space recently, that as us as customers start to trust you with our data, your responsibility also comes up. That's easy to do for our open, public, unrestricted data, like the open science work, like I showed off of our ICF capsule agent.

But as we get into controlled and classified, as we get into classified and the DoE space, as we get into restricted, formerly restricted data, where the physics of how nuclear weapons work don't expire, that will forever be classified.

Compliance7:58

Mark Myshatyn7:58

It's born classified and stays classified. It takes an element of trust in you all as our builders, as our providers. And this is really some of the most interesting and frustrating conversations we have with companies trying to sell us tools and services is, "Great, you have your SOC 2 report.

I have NIST 853. This is actually rev 4. It's over 1,000 different security controls and enhancements." And the U.S. government has put a lot of legislation in place to do traditional cybersecurity work. FedRAMP certainly tried to make this easier by coming in and saying, you know, "200 of your security controls, 300, 400, have been vetted with a third-party authorizer.

You have some continuous monitoring." Has anyone here been downstream of the FedRAMP process?

Yeah.

Mark Myshatyn8:47

Yeah, I see a couple smiles. So you know how much of a pain this has been. And much like everything else in the governmentright now, it is changing. There's a new FedRAMP program out there saying, "If we're going to trust you with our data, if we're going to trust you with the outcomes of our agents, you have to start thinking about your continuous monitoring, your continuous security posture."

If you work with the DoD, that gets even harder. DoD has what they call their Security Requirements Guide, or CCSRG. It talks about if you're touching this type of data level, so it takes that three types or three types of FedRAMP.

It layers on two more impact levels, as the DoD calls them, and says, "This is how you're going to access that service if you have PII or mission data or operational data or finance data." And then they add another copy of this book, you know, CNSSI 1253 on top of that.

So if you're looking at this saying, "It's a lot of governance," it is. But the fun part is,right now, where we are today from those April 3rd memorandums is AI use cases, AI governance is still on the drawing board.

Co-creation9:57

Mark Myshatyn9:57

Like, we are in that 180-day rulemaking period that these pieces of OMB memoranda put out saying agencies have to go develop their strategies, their plans for developing, you know, AI implementations, how do you govern pilots, what's considered high risk, low risk in your context.

And there's some prescriptive guidance out there. NIST, back in 2023, released their AI risk management framework.

Morning breakout sessions will begin in five minutes.

Mark Myshatyn10:27

Five minutes for morning breakout sessions.

Please wait for the breakout session of your choice.

Mark Myshatyn10:30

But the fun part is you can develop the future with your customersright now. You know, this is a clean sheet of paper from a technology perspective that we largely haven't had to tackle. And it's fun in the U.S.

government space to say, "We can invent part of the future together with commercial industry, make hopefully better, less obnoxious, less obstructive decisions so we can keep moving mission faster." And if it sounds like this is a lot of lawyers and paperwork, it probably is.

Why Collaborate11:01

Mark Myshatyn11:01

There's no getting around. Some of these records and artifacts do have to exist. But the reason you'd want to collaborate with us is we're doing things that are either incredibly hard or can't be done in commercial industry. At least at Los Alamos, we are sitting on petabytes of data that has never seen the internet, will never see the internet.

We have subject matter expertise in chem-bio materials, physics, materials, composites, certainly cybersecurity and the design of high-performance computing, some of the partnerships I mentioned earlier. And they can be your partnerships too. You know, we firmly believe that if we're talking about taking care of the country, taking care of our national competitive advantage, that's not just a bunch of scientists sitting on a mountainside in Los Alamos that are going to figure that out.

Gov-Ready Design11:49

Mark Myshatyn11:49

We really do want your help and your engagement with us to, you know, push the boundaries of what we know. This was originally meant to be an architecture talk, so I'm finishing up with an architecture slide. If you are interested in bringing agentic tools, agentic services to the federal government, there's really four things to think about.

You know, we want to see that you've built for explainability. Our keynote this morning touched on that a little bit of how did you get to that decision? You know, if something goes wrong or if we have a bad day, we don't have shareholders that we're responsible to.

We have the U.S. citizens to be responsible to. We have whatever that outcome was that, you know, caused some press briefing. We need to be able to trust our agents the same way we trust our staff. When we talk about fielding things, again, we are not a T-shirt company.

Building for isolation matters. And I was looking forward to seeing Microsoft's demo on the

self-hosted AI Foundry pieces. But for us, we do that anyways. We look and leverage heavily open-source tools and services and models to do some of this work because we can't get it from a hyperscaler cloud provider. So as you're building your tools and services, take a look at some of those services and scope page, even if you are a SaaS startup.

If you can build in a DoD impact level five environment with that limited number of services from your cloud vendor, you can deploy anywhere. You know, you have the least common denominator out of that entire tech stack. If you can deploy your, you know, your tool, your application there, that makes our job easier.

That makes you more portable. And along with that comes build for governance. We also have some awkward conversations with customers where it's, "Well, we need a software bill of materials as we're doing this procurement with you." And, yeah, people look at us like, "I mean, I guess we can dump, you know, what we had in our build script."

And it's a little bit of an awkward conversation, but that's required per our regs. You know, the AI stuff is moving a mile a minute. The traditional cybersecurity stuff is moving faster, but not quite there yet. So if you can plan to have those conversations of how did you handle open-source dependencies, what are your patching plans, what, you know, help us fill this paperwork out if we're buying from you as a software as a service or platform as a service, that makes that entire partnership that much faster, that much more friendly.

And lastly, keep up the speed. We have also had some awkward conversations with some of our service providers saying, "Why is your federal stuff a year out of date?" You know, "Why is that service parity not happening a year, three years, five years from when you launched it in the commercial region?"

And that's not us just liking ourselves and wanting to have bravado that, "Oh, we're the government. We're a quasi-federal agency. We care about our data." No, this is rooted in export compliance law. This is things like we can't buy from you unless you're in theright places.

Closing14:49

Mark Myshatyn14:49

So it's if you can design for speed in your hard corners, that optimizes your chances of fielding your tools and services with us in different places that we have to operate to meet our mission. And with that, Los Alamos, we were founded on the idea that theright application of math and science can change the world overnight.

We've done that. We're not a stranger to how that feels to show up, and the world is now different. That's what we were founded to do. And when we look at AI, agentic tools, what we can do with frontier models, any of the above, we see it as the greatest opportunity and the greatest threat to national security.

But the opportunity is what keeps us showing up. We're not scared of the downside risk. We have to be here to help develop the future. One of my favorite anecdotes, because we are a nuclear science lab, we do a lot of nuclear non-proliferation work.

And because we do that type of work, we've gotten really good at specialty sensors. And what have we been able to do with that specialty sensor? We have a laser strapped to a car on Mars zapping rocks. Now, we built the ChemCam sensor.

So even if you're a little bit on the fence about should we engage with, you know, the nuclear enterprise of the U.S., there's other fundamental science that we do that's just pushing the boundaries that we as a human species know and can do and can grow into.

So with that, thank you so much for your time today. I really appreciate it. And I'll be available on the side for questions. Thank you.

Woo!