America Needs To Renegotiate Its Most Famous Software Marriage

Jul 27, 2026 - 11:32
0 0
America Needs To Renegotiate Its Most Famous Software Marriage

Every few months, an AI system arrives that makes the last one look quaint. The newest, a framework called Mythos, has been keeping policymakers and bank executives up at night for a specific reason: it showed how a single bug in an aging piece of Office software could hand an adversary the keys to the identity systems of every federal agency at once.

4 Fs

Live Your Best Retirement

Fun • Funds • Fitness • Freedom

Learn More
Retirement Has More Than One Number
The Four Fs helps you.
Fun
Funds
Fitness
Freedom
See How It Works

Mythos rattled bank executives and policymakers because it apparently turned the discovery and exploitation of software vulnerabilities, which once took elite state hackers months of effort, into an automated commodity. There is no doubt that the flaws in our systems will be found.

The question that matters now is: how far will the damage spread once they are?

For the federal government, the answer is simply: too far. The single greatest point of failure in American cyberspace is the procurement monoculture that lawmakers in Washington spent decades creating.

Microsoft everywhere, all at once

Consider what tools support a single day of government work. Microsoft commands an estimated 85% of federal productivity software and captures roughly a third of all federal software spending. Windows runs most agency computers. Outlook carries the government’s mail. Microsoft Entra ID decides who can sign in across most departments. When one company supplies the operating system, email, identity layer, and cloud for nearly every agency, a defect in that company’s products becomes a defect in American national security.

We have already suffered the consequences of this lock-in. In 2023, the China-linked group Storm-0558 forged Microsoft authentication tokens and read the email of the commerce secretary, the U.S. ambassador to China, and a member of Congress, downloading some 60,000 messages from the State Department alone. The government’s Cyber Safety Review Board concluded the intrusion “should never have happened” and called Microsoft’s security culture inadequate. In 2025, the SharePoint “ToolShell” campaign compromised more than 400 organizations, including the National Nuclear Security Administration.

A rational customer, if breached this often, would diversify. The federal government has not done this because Microsoft’s licensing terms are engineered to make diversification irrational and uneconomical. According to Microsoft’s published pricing, running Windows Server on a competing cloud can cost up to 400 percent more than on Azure. The Government Accountability Office found agencies forced to pay extra fees simply to use software they already own on rival infrastructure. The result is a market in which fewer than 1% of cloud customers switch providers in a given year.

Worse, security itself has become an upsell to line the company’s pockets. The State Department detected Storm-0558 only because it paid for Microsoft’s most expensive license tier, which included enhanced audit logging.

Agencies on cheaper tiers had no comparable visibility into their own email. As Senators Eric Schmitt and Ron Wyden put it, cybersecurity should be a core attribute of software, not a premium feature sold to deep-pocketed customers.

The ongoing China problem

Then there’s the China risk. For nearly a decade, Microsoft has used engineers based in China to maintain Department of War cloud systems, with the work supervised by American “digital escorts” who lacked the expertise to evaluate it. In response, the Pentagon terminated the program and ordered an audit.

Even now, Microsoft’s early-warning program for software vulnerabilities includes more than a dozen Chinese companies legally obligated to share what they learn with the Chinese government, and it has been suspected of serving as a leak vector for Chinese state hackers at least three times. The company is even reportedly folding DeepSeek, a Chinese AI model, into Copilot Cowork, the assistant it is actively installing across the executive branch.

These are demonstrable security risks for the United States.

Toward a less binding relationship

A solution to this problem does not require punishing Microsoft for its historic success. All that needs to happen is to make the government a customer who can walk away. Federal cloud contracts can prohibit licensing terms that lead to vendor lock-in. FedRAMP should pursue multi-cloud solutions, such as the Pentagon’s Joint Warfighting Cloud Capability, to build resilience and diversity in AI procurement. And the Federal Trade Commission should see its investigation of Microsoft’s bundling and licensing practices through, and pursue remedies as necessary to curb cloud practices that threaten national security.

Every advancement in AI beyond Mythos means every software vulnerability will be found faster than the last. A government wired through one company shares these flaws, everywhere, all at once. A more diversified system, with more vendors, can contain the fallout.

The current architecture of the United States’ security was built by contract, and it can be rebuilt the same way.

***

Aiden Buzzetti is the president of the Bull Moose Project. Evan Swarztrauber is Principal at CorePoint Strategies and a former policy advisor at the Federal Communications Commission.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Fibis

I am just an average American. My teen years were in the late 70s and I participated in all that that decade offered. Started working young, too young. Then I joined the Army before I graduated High School. I spent 25 years in, mostly in Infantry units. Since then I've worked in information technology positions all at small family owned companies. At this rate I'll never be a tech millionaire. When I was young I rode horses as much as I could. I do believe I should have been a cowboy. I'm getting in the saddle again by taking riding lessons and see where it goes.

Comments (0)

User