←
AI for Government
Proficient · M40 · lesson 40 of 50 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Rights-Impacting and Safety-Impacting AI Safeguards
📖
now learning

Rights-Impacting and Safety-Impacting AI Safeguards

15 min

Carla Jimenez, a program director at a state human services department, inherited an AI tool that scored families for child-welfare risk. It had been running for eight months. When her new governance board reviewed it, the first question was simple and devastating: "Is this rights-impacting?" Nobody knew. There was no determination on file. No extra safeguards. No appeal path for a family scored "high risk." The tool had been treated like a routine IT system, but it was helping decide whether a caseworker showed up at someone's door. Carla's board gave her ninety days to either bring it into compliance or shut it off.

This is the work of a program manager in the era of federal AI guidance: figuring out which AI uses carry extra obligations, and then making sure those obligations are actually met. Office of Management and Budget memorandum M-24-10, issued in 2024, draws a sharp line. Most AI is ordinary. But two categories, rights-impacting and safety-impacting AI, trigger a required set of minimum practices. Your job is to identify them and implement the safeguards. Federal AI policy is revised over time, so confirm the memorandum, the practices and the dates that currently bind your agency with your chief AI officer and counsel before you rely on any summary, including this one.

Why These Safeguards Exist

Rights-impacting and safety-impacting safeguards are the federal government's structural response to a decade of high-profile AI failures. They are not abstract ethics. They are operational controls, and each one corresponds to a documented failure mode it is designed to catch. Reading the record first makes the practices feel less like paperwork and more like the specific things that were missing when public systems hurt people at scale.

The Michigan Integrated Data Automated System, MIDAS, operated from 2013 to 2015 with a false positive rate above 90 percent, wrongly accusing unemployment insurance claimants of fraud and seizing wages, tax returns and assets. The Sixth Circuit in Cahoo v. SAS Analytics allowed constitutional due process claims to proceed, and the state paid over $20 million in settlements. What was missing was not one control. There was no meaningful impact assessment, no subgroup analysis, no human oversight of automated adjudication, no explanation to the people affected, and no redress.

The Internal Revenue Service contracted with ID.me in 2021 for mandatory facial recognition authentication, then reversed course within eight weeks of public disclosure in January 2022 after bipartisan congressional pressure. The Treasury Inspector General for Tax Administration issued report 2023-40-034 finding the agency had not completed a Privacy Impact Assessment consistent with the E-Government Act of 2002. The correction was a live-agent authentication path as an opt-out. The case is instructive because the agency recovered, but the cost was public trust and very nearly the whole digital identity modernization program.

Allegheny County's Family Screening Tool, used to triage child welfare cases, drew ACLU reports in 2022 and 2023 documenting disability discrimination concerns, and the Department of Justice Civil Rights Division opened an investigation in 2024. The tool remains in operation under scrutiny. It is the closest analogue to Carla's system and it illustrates the hardest problem in this space: subgroup testing is genuinely difficult when the child-welfare data itself reflects historic bias, and that difficulty is a reason to measure carefully rather than a reason to skip measuring.

Europe supplies two cases that public managers should know. The Dutch childcare benefits scandal, the toeslagenaffaire, ran from 2013 to 2019 using nationality as a risk variable in a tax administration classifier, falsely flagged tens of thousands of families, and contributed to the resignation of the Rutte III cabinet in January 2021; the Dutch data protection authority fined the tax administration 2.75 million euro. The Dutch SyRI welfare fraud system was struck down by the District Court of The Hague in February 2020 on privacy grounds under Article 8 of the European Convention on Human Rights, one of the first judicial invalidations of a public sector AI system.

Two more cases round out the pattern. COMPAS, the recidivism prediction tool, was the subject of the 2016 ProPublica investigation showing disparate error rates by race; Wisconsin v. Loomis, decided by the Wisconsin Supreme Court in 2016, permitted its use with caveats. Clearview AI scraped more than 30 billion facial images and sold access to law enforcement, drawing multiple state CCPA enforcement actions and European Data Protection Board fines, with federal subscriptions at agencies including Customs and Border Protection, the Drug Enforcement Administration and the Federal Bureau of Investigation coming under review. It shows how hard auditing commercial AI becomes when the vendor's own training practices are the problem.

It is tempting to say these failures would have been prevented by the safeguards that federal guidance now requires, and the source material for this lesson says exactly that. State it more carefully. The minimum practices would have surfaced these failure modes earlier, when the affected population was smaller and the fix was cheaper, and they would have created the redress paths that turned each case into a years-long crisis by their absence. They are not a guarantee that a system will not cause harm. A completed impact assessment has never by itself made a wrong decision right. What the practices reliably do is convert an emergency into routine accountability, because the artefacts exist when GAO, an inspector general or a reporter asks.

The Two Categories That Change Everything

Section 5(b)(i) of M-24-10 defines rights-impacting AI as AI whose output serves as a principal basis for a decision or action concerning a specific individual or entity that has a legal, material, binding or similarly significant effect on rights, benefits, services or due process. In plainer terms for a screening meeting: it affects a person's legal rights, civil liberties, privacy, equal opportunity, access to critical resources, or access to government benefits and services.

The memorandum lists presumed rights-impacting categories. They include AI affecting the eligibility, amount or conditions of government benefits; AI determining access to housing, education or employment; AI used in criminal justice or immigration enforcement in ways that materially affect individuals; AI providing medical diagnosis or treatment recommendations used as a principal basis for clinical action; AI making hiring, promotion, retention or disciplinary decisions for federal employees; AI used in child welfare risk assessments; AI used in loan, credit or financial assistance decisions; and AI used in voting access, election administration or political participation in ways that materially affect individuals. Carla's tool sits squarely in the sixth of those.

Section 5(b)(ii) defines safety-impacting AI as AI whose output controls or significantly influences outcomes related to human life or health, climate or environment, critical infrastructure, or strategic assets. Presumed categories include AI controlling the physical movement of vehicles or robotics in public spaces; AI making safety-critical medical triage or treatment decisions; AI operating critical infrastructure such as energy grids, water systems or transportation networks; and AI used in emergency response or 911 dispatch.

A single tool can be both. The test is not how sophisticated the AI is. It is what happens to a person if it gets it wrong. A simple spreadsheet model that denies benefits is rights-impacting. A drafting assistant that produces internal memos usually is not, but that conclusion depends on how the output is used rather than on what the tool is called: the moment a generated summary becomes a principal basis for a decision about a specific person, the analysis changes and the designation question has to be asked again.

Principal Basis Does Not Mean Sole Basis

This is the interpretation point that determines most close calls, and getting it wrong is how systems avoid designation on a technicality. A system that generates a recommendation which an adjudicator is trained to follow is rights-impacting if the recommendation is a principal factor in the decision, even when the adjudicator holds nominal final authority. The typical disability adjudication workflow in the Social Security Administration's Office of Hearings Operations is the reference example. The Council of the Inspectors General on Integrity and Efficiency has applied this test in reviews of AI-assisted adjudication.

The practical consequence is that "a human signs the decision" is not a designation defence. If the human almost always agrees, if the workflow gives them no time or tools to disagree, or if disagreeing requires extra justification while agreeing requires none, the model is functionally the principal basis. That is a question about the operating process, not about the model architecture, and it should be answered with data on override rates rather than with an assurance from the vendor or the program office.

Designating Systems Beyond the Presumed List

Section 5(c) explicitly permits and encourages agencies to designate additional systems that are not on the presumed list. The test is whether the output would reasonably be expected to affect the interests at stake. In practice, cautious chief AI officers designate liberally, while risk-averse ones designate narrowly to avoid the burden of the minimum practices. Both the spirit of the memorandum and GAO oversight favour broad designation.

The asymmetry is worth stating plainly, because it settles most arguments. Designating a system as rights-impacting imposes documented safeguards; it does not prevent the system from operating. Declining to designate, and then finding out later that the system did affect people's rights, is legally and politically costly and arrives with all the artefacts missing. When the call is close, the cheaper error is to designate.

Section 5(c) also permits rescission of a designation when later evidence shows the impact is trivial. That escape valve matters, because it means agencies are not condemned to carry a designation forever when a system's actual use turns out to be narrow. Designation is a judgment you document and revisit with evidence, not a permanent label you avoid applying because it cannot be removed.

A Decision Test You Can Run in a Meeting

Use this four-question screen on every AI use case in your inventory. Any "yes" means presume the use is covered until proven otherwise, and record the determination either way.

  1. Does its output influence a decision about a specific person? Benefits, employment, enforcement, liberty, services.
  2. Could an error deny, delay or reduce something that person is entitled to?
  3. Does it touch human safety, health or critical infrastructure?
  4. Would a member of the public reasonably expect a human, not a machine, to be making or shaping this call?

Carla's tool answered yes to the first two on sight. That ended the debate about whether safeguards applied, and the only remaining question was which ones and by when. Note what the screen is: an agency triage device that gets you to the right analysis quickly. It is not a substitute for the definitions in section 5(b) or for counsel on a genuinely hard case, and a "no" on all four should still be written down with the reasoning, because the document you will be asked for later is the determination itself.

The Minimum Practices in Detail

Once a use is designated, a specific set of minimum practices attaches. The source enumerates nine, and they must all be met before operation unless a waiver under section 5(d) is in place. Translate each into an operational requirement with an owner and evidence, because that is the form an audit will ask for.

  1. Complete a pre-deployment AI Impact Assessment. Section 5(c)(i) requires a documented assessment covering intended purpose and scope of use; the target population and distinguishing subgroups; data provenance, quality and representativeness; model design and testing results including subgroup accuracy; risks of algorithmic discrimination and their mitigations; risks to safety, privacy and performance drift with a monitoring plan; risks of misuse and the governance around them; alternatives considered and why they were rejected; stakeholder engagement conducted; and residual risk accepted by a named official. Existing agency templates, including the Department of Homeland Security impact assessment, the Veterans Affairs clinical assessment and the Department of Health and Human Services use case assessment, are reasonable starting points. The assessment is a gate on deployment, not a post-hoc exercise.
  2. Test for performance in a real-world context. Section 5(c)(ii) requires pre-deployment testing in conditions that approximate production rather than lab benchmarks alone. That includes distribution-shift testing, operator-in-the-loop testing, adversarial robustness testing where appropriate, and performance on documented subgroup slices.
  3. Independently evaluate the AI. Section 5(c)(iii) requires evaluation by personnel independent of the development team. That can be internal, such as the chief AI officer's evaluation team, the inspector general or the agency civil rights office, or external, such as an independent contractor, the NIST AI Safety Institute or a federally funded research and development centre.
  4. Identify and mitigate algorithmic discrimination. Section 5(c)(iv) requires analysis of the system's impact on protected groups under civil rights law: subgroup accuracy and error-rate analysis, disparate impact statistical analysis, and documented mitigations where disparities are found. Mitigation options include re-sampling, re-weighting, threshold adjustment and system redesign.
  5. Ensure meaningful human oversight, decision rights and operator training. Section 5(c)(v) requires that humans in the loop have the training, the time and the authority to review and override. Rubber-stamp oversight fails the test.
  6. Provide notice and explanation. Section 5(c)(vi) requires that individuals subject to rights-impacting AI receive notice that AI is used and an explanation of the decision sufficient to understand and contest it.
  7. Maintain human alternatives and opt-out where appropriate, and provide timely redress. Section 5(c)(vii) requires that, where appropriate rather than universally, individuals may opt for human-only processing, and that systems offer accessible redress. The IRS live-agent opt-out, the Medicare appeal system and the Social Security reconsideration process are working prototypes.
  8. Conduct ongoing monitoring. Post-deployment performance must be monitored for degradation, distribution shift and emerging harms, with dashboards covering subgroup accuracy and incident tracking.
  9. Train operators on limitations, risks and safe use. Training should be documented, periodic and covered in competency assessments.

Several of these connect to sources your agency already uses. The NIST AI Risk Management Framework 1.0 is voluntary and non-binding, but its MEASURE and MANAGE functions, including MEASURE 2.11, are the clearest available guidance on discrimination testing and continuous risk control, and the NIST AI 600-1 Generative AI Profile published in 2024 extends it to generative systems. GAO-21-519SP on AI accountability sets out the oversight criteria auditors will apply. The Blueprint for an AI Bill of Rights from the Office of Science and Technology Policy supplies the notice and explanation principle that practice six operationalises, and section 5(c)(vi) parallels Article 86 of the EU AI Act.

The Statutory Foundation Underneath

The minimum practices did not invent new legal duties out of nothing. They operationalise statutes that already applied to your program before anyone deployed a model, which is why an agency cannot treat compliance with them as optional overhead.

Title VI of the Civil Rights Act of 1964 prohibits federally funded programs from discriminating on the basis of race, colour or national origin, and covers disparate impact as implemented through agency regulations under the doctrine recognised in Texas Department of Housing v. Inclusive Communities (2015). Title II of the Americans with Disabilities Act (1990) and Section 504 of the Rehabilitation Act (1973) prohibit disability discrimination in federally funded programs and have been applied to automated decision systems in Department of Justice enforcement actions. The Age Discrimination Act (1975) reaches age-based disparate impact. The Fair Housing Act (1968) covers algorithmic tenant screening. The Equal Credit Opportunity Act (1974) covers automated credit decisions. The equal employment opportunity laws cover algorithmic hiring tools.

Privacy and records obligations run alongside them. The Privacy Act of 1974 and Section 208 of the E-Government Act of 2002, which carries the Privacy Impact Assessment requirement, form the privacy overlay, and agency Senior Agency Officials for Privacy own those processes. FISMA security controls, Section 508 accessibility requirements, Title VI disparate impact review and agency civil rights offices all intersect with the safeguards in this lesson. Executive Order 14110, the 2023 executive order on artificial intelligence that is no longer in force, established the use case inventory practice that agencies continue to run and that the memorandum relies on for public notice of waivers.

Two consequences follow. First, agencies that implement safeguards well avoid litigation and settlement costs, preserve the political legitimacy of their broader AI program, and generate evaluation artefacts, impact assessments, disparate impact studies and operator training records, that become the foundation for GAO responses, inspector general reports and FOIA releases. Second, many of these civil rights statutes create private rights of action. Adverse outcomes produced by a system with no safeguards attract litigation from the people affected, entirely independently of whether OMB is satisfied.

The Implementation Register: Turning Rules Into a Worklist

Carla turned the abstract requirements into a one-page register she could track and defend in an audit. Build the same for every covered system. Each row is a safeguard, and each safeguard carries an owner, evidence and a status.

  • Safeguard: for example, subgroup accuracy and error-rate analysis across demographic groups.
  • Required by: the rights-impacting determination, dated, with the section of the memorandum it maps to.
  • Owner: a named person, not a team.
  • Evidence: the document, test result or operating process that proves it is done.
  • Status: met, in progress, or gap.
  • Risk if gap: what happens to people and to the agency if this stays open.

For Carla's child-welfare tool the register exposed three red gaps: no impact assessment, no subgroup testing and no appeal path. Those three drove her ninety-day plan. The register's real value is that it converts an argument about whether the program is compliant into a list of named people with dates against their names, which is a much shorter conversation and a much better artefact when an oversight body arrives.

The Agency Implementation Playbook

At agency scale, the work runs in phases. Program managers usually inherit a mid-phase mess, so it helps to know where the whole sequence goes.

Phase 1, inventory to designation. Within 30 days, pull the agency's AI use case inventory entries. For each, apply the rights-impacting and safety-impacting tests and document the analysis in a standardised designation memo signed by the chief AI officer. Update the inventory with the resulting flags. Model designation memo templates circulated through the Chief AI Officer Council are a reasonable starting point.

Phase 2, gap analysis. For each designated system, assess compliance against the nine minimum practices and identify the gaps. Prioritise by the size of the affected population, the severity of the potential harm and the age of the system, because old systems tend to carry the least documentation and the most accumulated drift.

Phase 3, remediation planning. For each gap, document the remediation action, the owner, the milestone date, the resources required and the dependency chain. Submit the consolidated plan to the chief AI officer, the chief data officer, the senior agency official for privacy and the general counsel for signoff. Where a gap cannot be closed before deployment or before the applicable deadline, prepare a waiver or extension request rather than letting the date pass silently.

Phase 4, execution. Run the impact assessments and the subgroup accuracy testing. Conduct independent evaluations using a federally funded research and development centre, the NIST AI Safety Institute or an internal cross-team review. Implement human oversight procedures, train operators, deploy monitoring dashboards, draft notice and explanation language, implement opt-out and redress mechanisms, and publish updated inventory entries.

Phase 5, continuous operation. Run monthly dashboards on subgroup accuracy, drift, error trends and incidents. Run quarterly chief AI officer reviews. Refresh impact assessments and waiver reviews annually. Cooperate with inspector general audits and GAO engagements, and feed lessons back into the agency community of practice.

Phase 6, integration. Embed safeguards into the planning, programming, budgeting and execution process so that every AI system submission carries its safeguard costs. Embed them into procurement through contract clauses and data rights language. Embed them into hiring and training through approved curricula for operators, program managers and leadership. Embed them into congressional reporting through the annual AI strategy update.

Waivers, Extensions and What Neither One Buys You

Section 5(d) establishes a formal waiver process. The chief AI officer may waive specific minimum practices where the agency can demonstrate a legitimate government interest supporting the system's operation that cannot reasonably be achieved by a compliant alternative; mitigations that substantially reduce the risks the waived practice addresses; public notice of the waiver through the AI inventory; and annual review with continued justification.

Four properties of the mechanism matter more than the paperwork. A waiver is system-specific and practice-specific rather than a blanket exemption, so the officer specifies exactly which practice is waived and why. A waiver is not an exemption from transparency: the inventory entry must reflect it. A waiver does not insulate the agency from civil rights statute compliance, so a waiver from the section 5(c)(iv) disparate impact analysis still leaves the agency bound by Title VI, the Americans with Disabilities Act, the Equal Credit Opportunity Act and related statutes. And the OMB desk officer oversight channel remains available for waivers that appear abusive.

That third property is the one to take away from this lesson if you take away only one. A waiver relieves you of a documented practice. It does not discharge the underlying obligation the practice was designed to help you meet, and it does not make a discriminatory outcome lawful. Neither does a completed determination, a signed assessment or a green register. Those artefacts show that you looked; they are not a finding that nothing is wrong, and treating them as one is how programs end up defending a system they never actually examined.

Extensions are a different instrument. Section 5(d) also permits extensions where an agency needs more time to meet a practice but expects to come into compliance. An extension specifies milestones, the official accountable for each milestone and a target compliance date. Extensions are not waivers; they are deferred compliance plans, and confusing the two in a memo is a good way to attract an audit finding.

The source gives four situations where a waiver or extension is plausibly appropriate. A legacy system designated as rights-impacting where remediation is budgeted but will take 12 to 18 months calls for an extension. A national-security-adjacent system where public notice must be abstracted for security reasons may warrant a waiver with an abstracted inventory entry and classified documentation. A low-volume system where a formal independent evaluation would cost more than the system's total operating cost may warrant a waiver with internal cross-team review instead. A system used only in emergency operations for fewer than 30 days a year may warrant a waiver with abbreviated monitoring. In each case the waiver is documented, justified, posted and reviewed annually.

What does not qualify is equally clear: "we do not want to do the work"; "the vendor refused"; "the schedule slipped"; and "the program manager did not know about the requirement." Those are remediation problems, not waiver situations, and GAO and inspector general audits routinely identify such pretextual waivers and require remediation anyway. If a use cannot meet its safeguards and does not qualify for a defensible waiver, the right answer is to pause it. Carla turned her tool off for two weeks while the impact assessment and appeal path were built. It was uncomfortable. It was also exactly right.

What Good Looks Like

The failure cases get the attention, but three public examples show the practices working, and they are more useful as templates than the disasters are as warnings.

Veterans Affairs clinical AI for radiology implements the section 5 practices through the department's AI oversight committee, with published impact assessments, subgroup analysis, human-in-the-loop radiologist review and monitoring dashboards. The system continues to operate with productive feedback loops. Social Security Administration disability adjudication support pairs AI-assisted case triage with documented oversight, operator training, layered redress through reconsideration, an administrative law judge hearing, the Appeals Council and federal court, and ongoing monitoring. It is not perfect and GAO has flagged gaps, but it shows what functional oversight looks like at national scale. The Patent and Trademark Office classification AI published model cards in 2020, iterates on them, integrates user feedback, and continues to operate with little controversy.

What the three have in common is not that they are risk-free. It is that each produced evidence before it needed it, kept a human role that is substantive rather than nominal, and built a route for the affected person to push back. Those are the same three things missing from every failure earlier in this lesson.

Anti-Patterns

  • Treating a completed safeguard as proof the system is safe. An impact assessment, a determination memo and a green register show that you looked. They are not a finding that the system works, and they do not make a wrong decision right. Ask what the artefacts found, not whether they exist.
  • Treating a waiver or a determination as discharging the obligation. A waiver relieves a documented practice and leaves Title VI, the Americans with Disabilities Act, the Equal Credit Opportunity Act, the Privacy Act and the rest fully in force. A determination that a system is not rights-impacting is a judgment you must be able to defend with reasoning, not a shield.
  • Treating the minimum practices as a compliance checklist. They are designed to change decisions. If running them has never changed a design, a threshold or a deployment date in your agency, they are being performed rather than applied.
  • Waiving without mitigations. A waiver with no substantial mitigations is indefensible under section 5(d) and reads, correctly, as a decision to accept unmanaged risk.
  • Performing the impact assessment after deployment. The assessment is a pre-deployment gate. Running it afterwards produces a document that describes what you already did.
  • Treating subgroup accuracy as optional when the data are insufficient. If you cannot measure subgroup performance, you cannot confidently deploy for the affected subgroups. The remedy is to obtain the data, augment it, or limit the deployment, not to proceed unmeasured.
  • Nominal human oversight. Rubber-stamp review fails section 5(c)(v). Where the reviewer lacks the training, the time or the authority to override, the model is the principal basis for the decision no matter whose name is on it.
  • Designating narrowly to avoid the burden. Designation imposes documented safeguards and does not stop operation. Declining to designate, then discovering the impact later, costs far more and arrives with no artefacts.
  • Training operators once and forgetting. Training must be periodic, competency-based and refreshed when the system changes, or the override authority exists only on paper.
  • Ignoring private rights of action. Many civil rights statutes let affected individuals sue directly. An agency can be fully engaged with OMB and still be litigated by the person the system harmed.

Practice Prompts

  1. Run the screen across your inventory. Take every AI use case your office owns and apply the four-question test. Write a one-paragraph determination for each, including the ones you conclude are not covered, and note who signed it.
  2. Test the principal basis question with data. For one AI-assisted decision process, find the override rate. If reviewers almost never disagree, or disagreeing takes more effort than agreeing, write down what that implies about whether the model is the principal basis.
  3. Build the register. For one designated system, create a row per minimum practice with owner, evidence, status and risk if the gap stays open. Count the reds and put dates against them.
  4. Draft the notice and explanation. Write what an affected person actually receives: that AI is used, what it did, and how to contest the outcome. Read it aloud and ask whether someone could act on it.
  5. Trace one redress path end to end. Follow a hypothetical wrong decision from the person's complaint through to a corrected outcome. Time each step. Identify where it dead-ends.
  6. Draft a waiver you would actually defend. Pick a practice you cannot currently meet. Write the legitimate government interest, why no compliant alternative achieves it, the mitigations that substantially reduce the risk, the inventory entry text, and the annual review date. Then decide honestly whether it is a waiver or an extension.
  7. Pre-mortem against the record. Take the MIDAS failure list and check your system against each missing control in turn. Note every one you cannot evidence today.

Reflection

Carla's board asked a question nobody could answer, and the absence of an answer was itself the finding. Consider the AI systems in your own portfolio. For how many could you produce, this afternoon, a dated determination signed by someone with authority, and the reasoning behind it? A system with no determination on file is not automatically dangerous. It is unexamined, which is a different problem with the same eventual cost.

Then sit with the harder question, the one the waiver section is really about. If you found tomorrow that a covered system in your program could not meet a required practice, what would actually happen? Would the program pause, would a defensible waiver be prepared, or would the finding quietly become a risk register entry that ages? The answer tells you whether your agency's safeguards are controls or decoration, and it is better to learn it from a hypothetical than from an inspector general.

Glossary

  • Rights-impacting AI: AI whose output serves as a principal basis for a decision or action about a specific individual or entity with a legal, material, binding or similarly significant effect on rights, benefits, services or due process.
  • Safety-impacting AI: AI whose output controls or significantly influences outcomes related to human life or health, climate or environment, critical infrastructure, or strategic assets.
  • Principal basis: a factor that substantially drives a decision, which is not the same as the sole factor; a recommendation an adjudicator is trained to follow can be a principal basis even where a human signs the outcome.
  • AI Impact Assessment: the documented pre-deployment analysis of purpose, population, data, testing, risks, mitigations, alternatives, stakeholder engagement and accepted residual risk.
  • Designation: the agency's documented determination that a system falls into one of the covered categories, which triggers the minimum practices.
  • Waiver: a chief AI officer determination that a specific minimum practice will not be met for a specific system, supported by justification, mitigations, public notice through the inventory and annual review.
  • Extension: deferred compliance with a practice the agency still expects to meet, specified with milestones, accountable officials and a target date.
  • Meaningful human oversight: review by a person with the training, time and authority to override, as distinct from a rubber stamp.
  • Redress: an accessible route by which a person affected by an AI-assisted decision can contest it and have an adverse outcome corrected.
  • AI use case inventory: the agency's published list of AI systems in use, which also carries public notice of waivers.
  • Algorithmic discrimination: differential performance or outcomes across protected groups, identified through subgroup accuracy, error-rate and disparate impact analysis.

Closing

The categories in this lesson are not bureaucratic sorting. They are a statement about consequence: some AI decides things about people that people cannot easily undo, and those uses carry obligations that ordinary IT does not. The job of the program manager is unglamorous and specific. Determine which of your systems are covered and write the determination down. Meet each practice or hold a defensible waiver. Give the affected person notice, an explanation and a real way to push back. Keep watching after launch.

Carla's ninety days were uncomfortable, and she spent two weeks of them with the tool switched off. What she had at the end was not a perfect system. It was a documented one, with a named owner per safeguard, evidence behind each claim, subgroup testing that told her something she did not want to hear, and a family's route to contest a score that had previously ended at a call centre. That is what compliance looks like when it is done as engineering rather than as paperwork, and it is the difference between the failures at the start of this lesson and the three examples that still operate.

Key Takeaways

  • Two categories trigger extra duties. Rights-impacting AI is a principal basis for decisions with significant effect on rights, benefits, services or due process; safety-impacting AI controls or significantly influences life, health, environment, critical infrastructure or strategic assets.
  • Judge by consequence, not sophistication. A simple model that denies benefits is covered; a drafting assistant usually is not, until its output becomes a principal basis for a decision about a person.
  • Principal basis is not sole basis. A human signature does not defeat designation where the reviewer lacks the training, time or authority to disagree; check the override rate.
  • Designate broadly when the call is close. Designation imposes safeguards without stopping operation, and it can be rescinded on evidence; failing to designate is the expensive error.
  • Nine minimum practices attach, and all must be met before operation unless waived. Impact assessment, real-world testing, independent evaluation, discrimination analysis, meaningful oversight, notice and explanation, human alternatives and redress, ongoing monitoring, and operator training.
  • The statutes came first. Title VI, the Americans with Disabilities Act, Section 504, the Age Discrimination Act, the Fair Housing Act, the Equal Credit Opportunity Act, equal employment opportunity law, the Privacy Act and the E-Government Act already applied, and many create private rights of action.
  • A waiver relieves a practice, not an obligation. It is practice-specific and system-specific, must be posted in the inventory and reviewed annually, and leaves civil rights compliance entirely intact.
  • Extensions are not waivers. They are deferred compliance plans with milestones, accountable officials and a target date.
  • Safeguards reduce harm; they do not guarantee its absence. They surface failures earlier and create redress, which is why the agencies that keep the artefacts turn inquiries into routine accountability instead of emergencies.
  • When you cannot comply or waive, pause. Turning a non-compliant rights-impacting system off is uncomfortable and usually correct.

Frequently Asked Questions

Who makes the designation decision? The determination is documented by the program in a standardised designation memo and signed by the chief AI officer, with the analysis recorded and the inventory updated to reflect the flag. Program managers do the analysis and assemble the evidence; they do not make the call alone, and neither does the vendor. Involve counsel and the civil rights office on genuinely hard cases rather than resolving them inside the project team.

Our system only makes recommendations. Is it still covered? Possibly. Principal basis does not mean sole basis. If the recommendation is a principal factor in the outcome, the use can be rights-impacting even where an adjudicator holds nominal final authority. The way to answer it honestly is to look at how often reviewers depart from the recommendation and what it costs them to do so.

Does a waiver mean we are compliant? A waiver means a specified minimum practice does not apply to a specified system, on stated justification, with mitigations, public notice through the inventory and annual review. It does not exempt the agency from civil rights statutes, privacy law, records obligations or accessibility requirements, and it does not protect against a private right of action brought by someone the system harmed. It is a narrow instrument, not a clearance.

What if we miss a compliance deadline? Missing a date is a remediation problem, and the response is a documented remediation plan with milestones, accountable owners and oversight, plus an extension request where the agency expects to come into compliance. What does not work is silence. Schedule slippage, vendor refusal and lack of awareness are explicitly the reasons that do not support a waiver, and audits routinely identify pretextual waivers and require the remediation anyway.

We cannot measure subgroup performance because we do not collect demographic data. What now? Treat it as a blocker rather than an exemption. If you cannot measure subgroup performance, you cannot confidently deploy for the affected subgroups. The available remedies are to obtain the data through an appropriate and lawful route, to augment what you have, or to limit the deployment to a scope you can actually evaluate. Deploying unmeasured is the option that produced several of the cases in this lesson.

How does this interact with privacy and accessibility requirements? They stack rather than substitute. FISMA security controls, Privacy Act obligations, the E-Government Act Section 208 impact assessment, Section 508 accessibility requirements and Title VI disparate impact review all intersect with these safeguards, and different officials own each of them. Build the register so that each row names the requirement and the office, or you will do the same analysis three times and still miss one.