Reporting AI Concerns in Your Agency
Marcus Bell, a permitting technician at a county planning department, noticed something off in the new AI tool that pre-sorted permit applications. Three applications from the same low-income zip code had been auto-flagged as "high review priority," which in practice meant they sat in a slower queue. He had a hunch the tool was treating that neighborhood differently. But he froze. Who do you even tell? Would it look like he was attacking a project his director championed? Could he get in trouble for poking at a system above his pay grade? He sat on it for three weeks. The applications kept piling up.
Marcus's hesitation is the real failure point in most agencies. The problem is rarely that employees do not see issues. It is that they do not know how to report them, which protections apply, or whether speaking up is safe. This lesson fixes that. By the end you will know what to flag, where it goes, what to write down, what the protections actually cover, and where they stop.
Start from the premise, because it changes how the rest of this reads. AI systems affect citizens' lives, and when they fail or turn biased, real people absorb the cost. The only reliable way those problems get caught is that someone inside the agency speaks up. Raising a concern is not disloyalty and it is not an attack on a colleague's project. It is essential professional responsibility, and how you respond in the first week often determines whether a problem gets fixed or compounds quietly for a year.
What actually counts as an AI concern
You do not need proof. You need a reasonable observation. If something about how an AI tool behaves, or how it is being used, sits wrong with you, that is enough to raise. Common categories:
- Biased or unfair outcomes. The tool seems to treat a group, neighborhood, or applicant type differently, like Marcus saw.
- Wrong or fabricated output. The AI produced a confident answer that turned out to be false, and it went into real work.
- Privacy or data exposure. Sensitive or personal information was entered into a tool that should not have it, or the tool exposed data it should not.
- Unapproved use (shadow AI). A colleague is using a personal AI account for official work outside approved tools.
- Safety or rights impact. The tool influences a decision about someone's benefits, freedom, safety, or eligibility in a way that worries you.
A useful rule: if a member of the public would be upset to learn the AI did this, it is worth reporting. That threshold is deliberately low, because the cost of raising something that turns out to be fine is measured in minutes, while the cost of staying quiet is measured in the people the system kept getting wrong while nobody looked.
Why capable people stay silent
Marcus was not indifferent and he was not unobservant. He froze, and the freeze had three distinct causes that are worth separating because each has a different remedy. The first is fear of retaliation, which is the one everyone names. The second is uncertainty about whether the thing is serious enough to be worth anyone's time, which is really uncertainty about the threshold. The third is simply not knowing where to send it, which is not courage at all but logistics.
Only the first of those is about bravery, and it is also the one the law addresses directly. The second dissolves once you accept that the threshold is a reasonable observation rather than a proven case, and that a report which turns out to be nothing costs the agency a few minutes of somebody's attention. The third dissolves with a name and an email address written down in advance. Two of the three obstacles that kept a real problem sitting in a queue for three weeks are solved by preparation you can do this afternoon.
There is a matching obligation on the other side. If agencies want problems surfaced early, they have to maintain mechanisms that employees can find, reach, and trust. A reporting route that is technically documented but that nobody in the building can name is not a functioning mechanism. If you are in a position to influence that, the useful questions are whether the process is clear, whether it is genuinely accessible to staff at every level, and whether the people who would use it believe it is safe. Where any of those answers is no, that gap is doing more damage than any single unreported concern.
Four kinds of concern, and where each one goes
Different concerns go to different places, and matching them well is most of what makes a report effective. Most agencies have more than one channel. You do not have to pick perfectly; pick the closest one and let them route it. But knowing the map in advance turns a three-week hesitation into a same-day email.
Performance issues or bugs. The system is crashing, producing obviously wrong results, or performing far worse than expected. This goes to your immediate supervisor or team lead, the system's owner or administrator, or your agency's help desk or IT support. Document the specific problem in the form "when I entered X, the system returned Y, which is incorrect because Z," provide examples, note the frequency, and describe the impact in terms of how many people are affected. This is usually the fastest category to resolve, because the team acknowledges the bug and works it.
Data handling concerns. You believe the system is using personal information in ways that are not authorized, retaining data longer than necessary, or sharing it without proper authorization. This goes to your agency's privacy office or data protection officer, the security office or chief information security officer, or the legal office, and to your supervisor where that is appropriate in your chain. Be specific about what you observed, in the form "I saw the system accessing employee medical information, which I don't believe is authorized for this purpose." Document dates, times, and specific instances, explain why it concerns you, and note any policy or regulation you believe is being violated. Speed matters here more than in any other category.
Bias or fairness concerns. You believe the system is making systematically biased decisions, denying benefits to certain groups at higher rates, or skewing a recommendation toward one demographic. This goes to your agency's equal employment opportunity officer, the civil rights or compliance office, the AI governance team or responsible AI official where one exists, your supervisor, and in serious cases the inspector general. Describe the pattern rather than the impression, supply the numbers if you have them, explain why it is problematic, and describe the impact on the people affected. These route to compliance and legal because they carry legal implications rather than only operational ones.
Suspected illegal activity. You believe the system is being used in a way that violates law, such as accessing information without authorization or using data collected for one purpose for a completely different, unauthorized one. This goes to your agency's legal office immediately, the inspector general, and the security office. Be very specific about the violation you believe occurred, document everything carefully, keep copies of your evidence, and write clearly and factually. This is the most serious category and it needs attention from offices with actual legal authority.
Where a serious legal violation appears to be going ignored, external channels exist: government whistleblower hotlines, the Office of Inspector General at your agency or at a higher level, congressional oversight committees, and law enforcement. Note the ordering that runs through all of this. Internal channels first, external escalation second. That sequence is not only etiquette; as the next section explains, it affects what protection you carry.
If you do not know who your agency's responsible AI official is, or who staffs your inspector general's hotline, that is your one homework item from this lesson. Find out this week, before you need it.
The report that gets action
Vague reports get ignored. Specific reports get fixed. The difference is documentation, and documentation is also the thing that protects you later. Write it before you report, not after. Use this template every time, and keep a copy for yourself.
- What I observed: One or two factual sentences. What the tool did, not what you think it means.
- When and where: Dates, times, the tool's name, the case or record IDs involved.
- Why it concerns me: The category (bias, error, privacy, and so on), the specific policy, regulation, or principle you believe it violates, and the potential impact on the public or the agency.
- Evidence: Screenshots, record numbers, the exact AI output. Capture it before it changes.
- Scope and impact: Is this one case or a pattern? How many instances have you seen, who is affected, and what are the consequences?
- My position: What your role is and how you came to know about this, which is what tells the reader why your observation carries weight.
- What I have done so far: Whether you paused use, told anyone, or kept working.
- Recommended action: What you think should happen. This one is optional, but it is often the line that moves a report from a complaint to a proposal.
Then handle the documentation itself carefully. Keep it private and secure. Do not post it on a shared drive or forward it casually around the office. If there is any chance you will need it for a formal complaint or a legal proceeding, treat it as confidential from the first day rather than deciding that later, once copies already exist in three inboxes.
Marcus's report, done right
Here is what Marcus eventually filed. "Observed: the intake tool auto-assigned three applications from zip 60628 to high-priority slow review on June 3 and 4 (records P-2291, P-2298, P-2304). Concern: possible geographic bias; these applicants face longer wait times. Evidence: attached screenshots of the priority flags and the queue. Scope: 3 of 4 applications from that zip this month were flagged; only 1 of 30 from other zips. Action so far: none changed; reporting before the next intake batch." That report took twenty minutes and triggered a real audit of the tool's logic.
Notice what makes it work. It leads with observation rather than accusation. It carries dates, record numbers, and a comparison rather than an impression. And the scope line does the heavy lifting, because two rates side by side turn "this feels wrong" into something a reviewer can either confirm or refute. Marcus did not claim the tool was biased. He described what he saw precisely enough that somebody with access could check.
That restraint is a tactic as well as an honesty. A report that asserts bias invites a defensive answer about intent, which is unfalsifiable and goes nowhere. A report that lays out two rates and asks whether the difference is expected invites an investigation, because the only way to close it is to look at the data. Write to make checking easy, and the reader has to either produce an explanation or find the problem.
What the protections cover, and where they stop
Fear of retaliation is the main reason people stay quiet, so it is worth being exact about this rather than reassuring. Government employees who report illegal activity, violations of law, or gross mismanagement are protected from retaliation in most government jurisdictions. In the United States the instruments named in this curriculum are the Whistleblower Protection Act (5 U.S.C. 2302), the Intelligence Community Whistleblower Protection Act, and the qui tam provisions of the False Claims Act. Other jurisdictions have their own whistleblower frameworks, and they differ, so check the one that governs your employment rather than assuming it mirrors the federal picture.
Where these laws apply, they protect federal employees from demotion, termination, or suspension; from harassment or a hostile work environment; from loss of assignments or opportunities; and from other forms of retaliation. That is a real shield and it exists precisely so that people in Marcus's position can act.
Now the part that matters more, because it is the part people do not hear. Protection is not total. If your agency can show it would have taken the same action regardless of your report, you may not be protected. And protection depends on how you report: these protections typically apply when you report to an inspector general, your agency's legal office, or your supervisor, and they may not apply if you go directly to the media without first reporting internally. Reporting through a designated channel is not a formality. It is the condition on which the protection commonly rests.
Two more things follow from that. Do not assume any channel is anonymous unless the channel itself tells you in writing that it is, and do not build your decision to report on an assumption of anonymity you have not confirmed. And do not treat "I raised a good-faith concern" as a guarantee of outcome. The standard for whether you should report is a reasonable concern, and you do not need to be right about the tool. The standard for whether you are legally protected afterwards is a separate question with its own tests, answered by law and by the facts of your case rather than by your sincerity.
None of this is a reason to stay quiet. It is a reason to report deliberately: through a designated channel, in writing, with your own dated copy kept, so that the record shows what you raised, when, and to whom. That record is what turns your account of events into evidence if you ever need it, and it costs you nothing on the days you never do.
If you face retaliation
Retaliation is itself a violation, and it is separately reportable. If you believe you are being retaliated against for a report, document it immediately: dates, times, what happened, and who witnessed it. Contemporaneous notes carry weight that a reconstruction written months later does not, and the pattern is usually only visible in the accumulation of small things rather than in any single incident.
Then escalate it as its own matter. Depending on your jurisdiction, that can go to your agency's office of inspector general, your personnel office, or an external body with authority over the question. Do not fold it into follow-up on the original concern, because the two need separate records and often separate reviewers. And if you believe you are being retaliated against and your agency is not protecting you, seek legal advice from an employment attorney. Some take such cases on a contingency basis; confirm the terms directly with the attorney rather than assuming them.
The 90-second decision: report or not
When you spot something and feel the same freeze Marcus felt, run this quick path. Is there potential harm to a person or the public? If yes, report. Is sensitive data involved? If yes, go to privacy now. Is it a pattern rather than a one-off? If yes, escalate to governance. Do you believe a law is being broken? If yes, legal office and inspector general, not the group chat. When in doubt, tell your supervisor and let them route it. The cost of a report that turns out to be nothing is a few minutes. The cost of silence can be a wronged applicant, a data breach, or a headline.
One qualifier belongs on that path. Speed and accuracy pull against each other, and the anti-pattern of reporting something you have not understood is real. The resolution is not to slow down but to separate the two acts: raise the observation promptly and factually, and do the understanding in the open with the people who have access. "Here is what I saw, and I do not yet know whether it is expected behaviour" is a complete and credible report. It protects your standing precisely because it does not claim more than you know, and it still starts the clock.
A concern, followed all the way through
Take a second case to see the full arc. You are a case worker in a social services agency and you notice that the new AI system for flagging fraud is flagging significantly more cases from certain neighborhoods than others. You are concerned about bias. Here is the sequence.
Step one, document. Note the date you first noticed the pattern, the specific neighborhoods affected, how you identified it (you disaggregated the flagging data), your hypothesis that the system may be biased, and the impact, which is that people in those neighborhoods are more likely to be investigated. Keep the note secure. What you have written is a description of what you observed and how, which is exactly what a reviewer needs and is different from an allegation.
Step two, report. Send it to your agency's equal employment opportunity officer or civil rights compliance office, and consider copying your supervisor and the AI governance team where one exists. Say something like: "I've noticed that the AI fraud detection system is flagging cases from one neighborhood at a materially higher rate than another comparable neighborhood. This pattern raises fairness concerns. I'm attaching documentation." Attach the rates you actually measured rather than describing them loosely.
Step three, follow up. After a reasonable period, check in: "I reported a concern about the fraud detection system on this date. What's the status of the review?" Two to four weeks is a reasonable window before following up, and asking what the investigation timeline is gives you a marker to check against later. Good-faith investigations take time, and slow is not the same as ignored.
Step four, escalate if needed. If the internal review goes nowhere and you believe the system is still causing harm, escalate to your agency's inspector general or to external oversight. At each stage your concern has been documented and routed through designated channels, which is the posture in which the statutory protections are most likely to apply, and it is also simply the sequence most likely to get the system fixed.
Anti-Patterns
Each of these is a way a legitimate concern loses its force, its protection, or both.
- Reporting without documentation. You raise it verbally, the person you told says they will handle it, and nothing happens. Without a record you cannot track what was reported, cannot follow up against anything specific, and have no evidence you ever raised it if you later need to escalate. Document first, then report.
- Going to the media first. Bypassing internal channels for journalists or social media risks losing whistleblower protections, may breach security agreements you signed, and can inadvertently disclose classified or otherwise sensitive information. Report internally first, to the legal office, inspector general, or compliance office. If internal reporting genuinely fails, then consider what comes next.
- Reporting without understanding the context. You flag something unusual before checking what it is, such as a system accessing classified information that is in fact authorized because it runs on a classified system. Your credibility takes the damage, and a real concern you raise later is taken less seriously. Ask questions and confirm your understanding before escalating.
- Expecting immediate action. You report, nothing visible happens within days, and you conclude you are being ignored or covered up. Good-faith investigations take time, and unfounded accusations of a cover-up cost you the standing you will need. Follow up after a reasonable period and ask for the timeline.
- Assuming the protection is automatic. Treating "I reported in good faith" as a guarantee against consequences. Protection is not total, it depends on the channel you used, and an agency may still act if it can show it would have done so regardless. Reporting deliberately and in writing is what puts you in the strongest position the law allows.
- Assuming a channel is anonymous. Unless the channel states in writing that it accepts anonymous reports and explains what that means in practice, do not plan around anonymity or make disclosures you would not make under your own name. Ask what the channel does with your identity before you use it, not after.
- Waiting for certainty. Marcus sat on his observation for three weeks looking for proof he was never going to find at his desk. The threshold for raising a concern is a reasonable observation, and the people with access to the model and the data are the ones who can actually confirm or dismiss it.
Practice Prompts
Do these while nothing is wrong. They are the difference between knowing this lesson and being able to use it under pressure.
- Find your people. Identify by name and contact detail the person you would report an AI concern to in your agency: the responsible AI official or AI governance contact, the privacy officer, and the inspector general hotline. Write them somewhere you will find them in a hurry.
- Read your own policy. Locate your agency's whistleblower protection policy and check whether it addresses reporting concerns about AI systems specifically or only in general terms. Note the channels it names, because those are the ones that carry the strongest protection posture.
- Draft a report on something real. Take an actual observation from your work, even a minor one, and write it up against the template in this lesson. Notice which fields you cannot fill in, because those are the details you would need to start capturing now.
- Rehearse the dead end. Write down what your next step would be if you reported a serious AI concern and nothing happened. Knowing the answer in advance is what keeps a stalled review from becoming a dropped one.
- Check your own rights. Confirm what you would do if you believed you were being retaliated against: who you would tell, what you would document, and where you would seek advice. Do this while it is hypothetical.
- Run the scope test. Take a concern you have about any system and try to express it as a comparison of two rates, the way Marcus did. If you cannot get to numbers, write down exactly what data you would need and who holds it.
Reflection
Think about a time you observed something in your agency that concerned you, whether or not it involved AI. How did you handle it, and would you handle it the same way now? Most people who stayed quiet can name the specific fear that stopped them, and it is worth naming yours precisely, because the vague version is unmanageable while the specific version usually has an answer. Was it fear of retaliation, uncertainty about whether the thing was serious enough, or simply not knowing where to send it? Each of those has a different fix, and only the first is about courage. Then turn the question outward. In your agency, what is the actual mechanism for an employee to raise a concern? Is it clear, is it reachable, and would the people in your team trust it? If the honest answer is no, that itself is a finding, and improving it may protect more citizens than any single report you ever file.
Glossary
- Whistleblower: An employee who reports illegal activity, violations of law, or gross mismanagement.
- Whistleblower protection: Legal protections that prohibit retaliation against employees who report concerns, subject to conditions that vary by jurisdiction and by the channel used.
- Retaliation: Adverse action taken against an employee because they reported a concern, including demotion, termination, suspension, harassment, or loss of assignments and opportunities.
- Inspector General: An independent office that investigates complaints about illegal activity or mismanagement, and one of the channels through which whistleblower protections most commonly apply.
- Qui tam: A legal provision that allows private citizens to sue on behalf of the government for fraud or violations of law.
- Documentation: A written record of incidents, observations, and concerns with dates, times, and details, kept secure and treated as confidential.
- Designated channel: A reporting route the agency or the law recognises for this purpose, such as an inspector general, the legal office, or your supervisor, as distinct from an informal conversation.
- Good faith: Raising a concern you reasonably believe to be genuine. It is the threshold for whether you should report, and it is not by itself a determination of what protection you carry.
- Shadow AI: Use of an unapproved AI tool or a personal account for official work, outside the tools the agency has cleared.
Related Lessons
This lesson is what you do when something is wrong; several others tell you how to recognise it. Understanding AI Bias gives you the vocabulary and the tests behind a fairness concern like Marcus's, and When Government AI Goes Wrong catalogues the failures that have already happened so you can spot the shape of one early. PII and AI: The Bright Red Lines and Data Sensitivity and Classification define the data handling that a privacy concern is measured against. For where a report goes once it leaves your hands, Oversight Mechanisms: IG, GAO, Congress covers the institutions on the receiving end, and Government AI Policy Landscape explains the framework under which agencies designate a responsible AI official in the first place.
Closing
Marcus lost three weeks to a question he could have answered in an afternoon: who do I tell, and what happens to me if I do. The report itself took twenty minutes. That gap between the hesitation and the act is where most agency problems live, and it closes with preparation rather than courage. Before you need any of this, find out three things: who your responsible AI official is, what your agency's whistleblower policy says, and where the inspector general's channel is. Write them down. If you can answer those three questions today, then on the day you see something, the only decision left is whether the concern is reasonable, which is a much smaller thing to decide alone.
Key Takeaways
- You do not need proof, just a reasonable concern. If the public would be upset to learn the AI did this, it is worth reporting, and the people with access to the system are the ones who can confirm or dismiss it.
- Raising a concern is professional responsibility, not disloyalty. Problems in government AI only surface if someone inside says something, and how you respond early determines whether it gets fixed or compounds.
- Match the channel to the concern. Bugs go to the system owner or IT, data issues to privacy and security fast, bias to civil rights, compliance and AI governance, and suspected illegality to the legal office and the inspector general.
- Know your channels before you need them. Find your responsible AI official, your privacy officer, and your inspector general contact this week, not during an incident.
- Document first, then report. Dates, specific examples, impact, the policy you believe is at stake, your position, and a recommended action. Capture evidence before the output changes, and keep the file secure.
- Protection is real but not total. Federal instruments protect against demotion, termination, harassment, and loss of opportunities, and an agency may still act if it can show it would have done so regardless of your report.
- The channel you choose affects the protection you carry. Protections typically apply to reports made to an inspector general, the legal office, or your supervisor, and may not apply if you go to the media without reporting internally first.
- Do not assume anonymity. Unless a channel states in writing that it takes anonymous reports, plan on the assumption that your name travels with your report.
- Retaliation is separately reportable. Document it immediately with dates, times, events, and witnesses, escalate it as its own matter, and seek employment law advice if your agency is not protecting you.
- Keep your own dated copy. A record of what you reported and to whom is what proves the concern was raised, and it costs nothing on the days you never need it.
Frequently Asked Questions
Am I protected if I report something and it turns out the system was fine? The threshold for raising a concern is that you reasonably believe it is genuine, so being wrong about the tool does not make the report improper. Whether you are legally protected afterwards is a separate question, decided by the applicable statute, the channel you used, and the facts of your case. Report through a designated channel, in writing, and keep your own copy, which is the strongest position available to you either way.
Can I report anonymously? That depends entirely on the channel, and you should find out before you use it rather than after. Some routes accept anonymous reports and some do not, and an anonymous report can also be harder to investigate because nobody can come back to you for the detail that would confirm it. Do not plan around anonymity you have not verified in writing.
What if the problem is my own supervisor, or the project my director champions? Then use a channel that does not run through them. That is one of the reasons the inspector general, the privacy office, the civil rights or compliance office, and the ethics office exist as separate routes. Concerns about waste, fraud, abuse, or a normal channel that is itself part of the problem are exactly the cases those offices are built for.
How long should I wait before following up? Two to four weeks is a reasonable window, and when you follow up, ask specifically what the timeline for the review is. Good-faith investigations take real time, and interpreting a slow process as indifference can push you into accusations you cannot support. A stated timeline gives you something concrete to check against later.
Should I go outside my agency if nothing happens? External channels exist, including inspector general offices at a higher level, government whistleblower hotlines, congressional oversight committees, and law enforcement, and they are appropriate where internal reporting has genuinely failed and harm is continuing. Sequence matters: going external before reporting internally can cost you protection, and going to the media specifically carries the added risks of breaching agreements you signed and disclosing sensitive material.
What do I do if I think I am being retaliated against? Document it the day it starts, with dates, times, what happened, and witnesses, and treat it as a separate matter from the original concern rather than an addendum to it. Report it to your inspector general, personnel office, or the external body with authority in your jurisdiction, and get advice from an employment attorney if the agency is not protecting you. Contemporaneous records are what make a pattern visible.
Skill.re