←
AI for Government
Strategic · M27 · lesson 27 of 47 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Federal/State/Local AI Alignment
📖
now learning

Federal/State/Local AI Alignment

15 min

Ciara Donnelly is the AI Policy Director for a state homeland security agency that administers three federally funded programs: an emergency management information system, a first responder communications network, and a predictive threat assessment tool that the Department of Homeland Security partially funds and has a significant interest in governing. When DHS issued updated AI governance requirements for federally funded public safety systems last fiscal year, Ciara received four separate memos within six weeks: one from her state's IT Policy Office interpreting the federal requirements for state agencies, one from DHS directly with implementation guidance, one from her agency's legal counsel raising state privacy law concerns, and one from the county emergency managers her programs serve asking what the new requirements meant for their local deployments. Each memo gave slightly different guidance. None addressed the specific case of a threat assessment tool that is partially funded by a federal agency, partially governed by state policy, and partially operated by county personnel. Ciara describes the experience as trying to find a rule that everyone agrees applies to a system everyone agrees is important. She eventually produced a governance alignment framework that reconciled the four memo streams. It took four months, three legal opinions, and one DHS-State-Local working group call that she convened herself because nobody else had.

The Structural Challenge of Vertical Alignment

The United States runs on a federal system, and most government AI deployments operate inside that system, touching federal requirements, state policy, and local implementation at the same time. When the three levels are well aligned, governance is efficient and largely invisible to the people delivering the program. When they conflict, which happens frequently in AI policy because the field is moving faster than any single level of government can comprehensively regulate, the result is what Ciara experienced: overlapping and sometimes contradictory guidance that program managers must reconcile in real time without clear authority from any single source.

Vertical AI alignment, the work of harmonizing AI governance requirements across federal, state, and local levels, is not a one-time policy task. It is an ongoing operational function, because the inputs arrive asynchronously and from parties that do not coordinate their calendars. Federal AI guidance is updated through OMB memoranda, agency-specific policies, and legislation at unpredictable intervals. State AI policies are in active development in many states, with significant variation in approach. Local governments are increasingly issuing their own AI governance requirements, particularly larger cities with substantial deployments in public safety, transportation, and social services.

The alignment challenge is structural rather than administrative. Each level of government has legitimate authority in its own domain, and the boundaries of those domains in AI governance are poorly defined because the field is new enough that the boundary questions have not been worked through. Federal agencies attach governance conditions to the grant instruments they fund. States set policy for the systems they administer. Localities operate the deployments that citizens actually encounter. Nothing in that arrangement automatically resolves a conflict between two of the three, and the program manager sitting at the intersection is rarely the person with authority to resolve it.

The practical consequence is that alignment work has to be treated as a standing responsibility with a named owner, a cadence, and a place to escalate. Ciara's four months of reconciliation happened because nobody had been assigned the work before the conflict arrived. Agencies that assign it in advance are not spared the conflicts, and no amount of coordination makes a genuine legal conflict disappear. What they gain is that the conflict is identified early, by someone whose job it is to look, and routed to the office that can actually resolve it instead of being absorbed silently by a program manager under delivery pressure.

Funding and Grant Conditionality

When a federal agency provides grant funding for an AI deployment, it typically attaches governance conditions to that funding. The conditions may require the use of specified technical standards, particular testing and reporting, federal approval before certain system changes, or federal access to system documentation. State and local agencies that accept the funding must meet the conditions attached to it. That obligation is real and enforceable through the grant instrument, and treating it as advisory because it arrived as guidance rather than as a regulation is one of the more expensive mistakes available to a recipient agency.

The obligations, though, come from the grant instrument and from the law and policy the instrument invokes, not from any framework or memorandum in the abstract. That distinction matters when you are deciding what actually binds your agency. Read the award terms, the notice of funding opportunity, and any incorporated agency policy, and identify for each requirement which document is the source of the obligation. A requirement that appears in a briefing slide but nowhere in the award terms is a different kind of thing from one written into the award, and only the award terms tell you which is which.

The difficulty arises when a federal condition conflicts with a state or local requirement. A federal data sharing condition may sit awkwardly against a state privacy statute. A federal transparency condition may sit awkwardly against a local procurement exemption for public safety systems. Where that happens, the conflict is a legal question about two specific instruments and the law behind each, not a question the program manager should resolve by choosing the requirement that seems more important. Document the conflict, name both sources, and route it to counsel before the award is accepted rather than after the deployment is running.

Technical Standards Compatibility

Federal AI governance frameworks establish technical standards that are increasingly referenced in grant conditions and procurement requirements. The most commonly encountered is the NIST AI Risk Management Framework, the voluntary guidance framework published by the National Institute of Standards and Technology. The framework itself is voluntary and non-binding: it imposes no obligation on any agency by its own force. What creates the obligation is the instrument that incorporates it, such as an award term or a contract clause requiring conformance. Keeping that distinction clear tells you what you are actually required to do and by whom.

State and local agencies that have already adopted a different governance framework must map their existing practices onto the referenced standard when they seek federal funding. The mapping is rarely mechanical. Two frameworks can address the same substantive concern with different terminology, different assessment methods, and different documentation expectations, so a practice your agency considers complete may not produce the artifact the federal reviewer expects to see. Do the mapping as a written crosswalk, requirement by requirement, and record every place where your existing practice covers the concern but produces different evidence.

The crosswalk has a second use beyond the funding application. It gives you a durable record of why your agency believes a given practice satisfies a given requirement, which is exactly what an auditor, an inspector general, or a successor in your role will need. Verbal understanding that two frameworks are equivalent does not survive staff turnover, and it does not survive a reviewer who was not part of the original conversation. Where the crosswalk cannot close a gap honestly, record the gap as a gap. An acknowledged gap with a remediation plan is a defensible position; an overstated equivalence is not.

Privacy and Open Government Law Conflicts

State privacy statutes, particularly in states with strong data protection laws, may impose restrictions on AI systems that are more stringent than federal requirements, or that pull against federal data sharing or transparency conditions. The direction of the conflict varies. A state may require that certain AI model documentation be made publicly available under its open government laws, while a federal agency requires that the same documentation be protected as sensitive under federal law. Both requirements attach to the same document, and neither office issued its requirement with the other in mind.

These conflicts require resolution through legal analysis and sometimes through formal waiver processes, not through the program manager's interpretation alone. That rule is worth stating flatly because the pressure runs the other way: the program has a deadline, the conflict looks technical, and a reasonable-sounding reading is always available to whoever is under the most pressure to proceed. A program manager who resolves a statutory conflict by choosing an interpretation has made a legal determination without the authority or the record to support it, and the agency inherits that determination if the choice is later questioned.

What the program manager can and should do is characterize the conflict precisely for the people who will resolve it. State which document imposes each requirement, which specific artifact or data element is subject to both, what each requirement asks for, and what the operational consequence of each possible resolution would be. Counsel resolving a conflict described that way can work quickly. Counsel handed a general question about whether federal or state law governs will take considerably longer, and will often come back asking for exactly the detail the program manager already had.

Local Implementation Variation

Even where federal and state requirements agree, local implementation produces variation. County emergency managers using the same state-administered threat assessment system will configure it differently, integrate it with different local data sources, and operate it under different local governance policies. The system is nominally one system. In practice it is as many systems as there are local configurations, and the state agency that administers it carries responsibility for a set of deployments it does not directly control and, in many cases, has never actually inspected.

The state agency therefore has to decide, in advance and in writing, how much local variation is acceptable. Some configuration choices are genuinely local business decisions. Others, such as connecting the system to an unvetted local data source or disabling a review step the state built in, change the system's risk profile and can create liability for the state program. Draw that line explicitly, publish it to local implementers with the reasoning attached, and build a way to see actual configurations rather than relying on an attestation that local practice conforms.

Localities are not simply subordinate in this arrangement, and it is a mistake to design the relationship as though they were. Many states impose requirements on local use of state-administered systems, and how far that authority reaches depends on state law and on how the locality is chartered, which differs across states and sometimes across localities within a state. Localities do at times decline to participate in programs that conflict with local ordinances, and whether that is available in a particular case is a legal question about the specific instruments involved. Neither the extent of state authority nor the availability of a local objection should be assumed as a general rule.

Practical Alignment Strategies

Ciara's four-month framework exercise produced three strategies she now applies to every new federal governance requirement affecting her state deployments. None of them is complicated. All three are things that are obvious in hindsight and that almost nobody does before the first painful reconciliation, because before that reconciliation the work looks like overhead rather than like the cheapest part of the process.

The first is to convene the cross-level working group early. The most consistent error in AI governance alignment is waiting for conflicts to surface before bringing the parties together. A working group that includes federal program staff, state policy and legal staff, and representative local implementers, convened when a new requirement is issued rather than after confusion has developed, can resolve most alignment questions in one or two sessions instead of through four sequential memo streams over six weeks. The parties are the same either way; only the sequence and the cost change.

The second is to produce a layered compliance matrix. For each AI system involving multiple governance levels, map every applicable requirement to its source authority, whether federal statute, federal guidance, state law, state policy, or local ordinance, along with its applicability to the specific system and its relationship to any conflicting requirement. The matrix does not resolve conflicts and should not be presented as though it does. It makes them visible and traceable, and when a conflict needs legal resolution, the matrix is the basis for the analysis and the record of when the agency identified the problem.

The third is to use federal requirement updates as alignment trigger points. When OMB issues a new AI governance memorandum, or a federal agency issues updated program-specific requirements, treat the update as a scheduled occasion to review whether state and local requirements still line up with the new federal standard. This converts reactive scrambling into a proactive review cycle, and it means the review happens while the requirement is still new rather than at the moment a program is trying to get an award accepted.

Communication Protocols Across Levels

Alignment depends on communication protocols: defined channels, defined frequency, and defined accountabilities for sharing information about AI governance changes across levels of government. Without them, information travels by memo, which means it travels late, in one direction, and to whoever happened to be on a distribution list. Vertical AI alignment is the governance equivalent of maintaining a shared road map among drivers each responsible for a different stretch of the same highway; the coordination is what prevents collisions at the intersections.

Ciara's agency now holds a standing monthly call with the DHS program office for each federally funded AI system it operates. The agenda covers any new federal governance requirements issued since the last call, any state policy changes that may affect the federal program, any local implementation issues needing state or federal resolution, and any audit, oversight, or litigation development at any level that the other parties should know about. The last item is the one most often left off and the one that most often turns out to matter, because it is where a problem at one level first becomes visible to the others.

The protocol sounds simple and was not. Establishing it required formal agreement with DHS about the call's scope and about what information could be shared across levels, since not everything discussed at one level can be repeated at another. It also required persuading local emergency managers to appoint a standing representative to a monthly call they had not previously attended, which took explaining what they would get from it rather than what was being asked of them. The benefit has been that Ciara has not received a surprise requirement memo since the protocol was established.

Anti-Patterns

  • Treating federal guidance as satisfying state or local obligations, or the reverse. Conformance with a federal framework does not discharge a state statutory duty, and a state approval does not discharge a federal award condition. Each obligation is discharged only by meeting the requirement of the instrument that imposes it. Track them separately in your compliance matrix, and never let a single sign-off be recorded as clearing requirements from more than one level.
  • Resolving a legal conflict between levels inside the program office. When a federal condition and a state statute pull in opposite directions, choosing the more reasonable-sounding reading is a legal determination made without the authority or the record to support it. Characterize the conflict precisely, name both source documents and the specific artifact at issue, and route it to counsel. Record the date you identified it, because that date is part of the agency's due diligence.
  • Assuming a uniform rule about what states may require of localities or what localities may decline. These arrangements turn on state law and on how each locality is chartered, and they differ across states and sometimes within one. Building an alignment plan on a general assumption about the hierarchy produces a plan that fails in exactly the jurisdictions where it matters most. Check the specific instruments for the specific jurisdictions in your program.
  • Letting a local attestation of conformance stand in for visibility into local configurations. A signed statement that local practice conforms tells you what the signer believes, not how the system is configured today. Where a local configuration choice can change the risk profile of a state-administered system, arrange to see the configuration itself, and make the reviewable elements explicit when you publish the acceptable-variation line.

Practice Prompts

  • Build the first page of a layered compliance matrix for one multi-level system: each applicable requirement, the document that imposes it, whether it applies to this system, and any requirement at another level it pulls against.
  • For a federally funded system you support, read the award terms and separate the requirements written into the award from those that appear only in guidance, slides, or correspondence. Write one paragraph on what your agency would be able to show a reviewer for each requirement in the first group.
  • Write the crosswalk between whatever governance framework your agency already uses and one framework referenced in a federal funding condition you have encountered. Mark each row as covered with equivalent evidence, covered with different evidence, or not covered, and note what the third category would take to close.
  • Draft the acceptable-variation line for a system your agency administers but localities operate: which configuration choices are local business decisions, and which change the system's risk profile. For each item in the second group, state how your agency would find out that the choice had been made.
  • Design the agenda and participant list for a cross-level working group on a requirement your program is currently absorbing. Name who from each level must attend for the session to resolve anything, and what each of them gets from attending.

Reflection

Think about the last governance requirement that reached a program you support from another level of government. How did you learn about it, how long after it was issued, and who else in your agency learned about it independently and reached a different conclusion? Then ask who owns vertical alignment for that program by name. If the answer is that it is handled as it comes up, you have Ciara's situation before the framework, and that cost is paid all at once, at the worst moment, by whoever is closest to the deadline.

Glossary

  • Vertical AI alignment. The ongoing work of harmonizing AI governance requirements across federal, state, and local levels for systems that touch more than one of them. Ongoing rather than one-time, because the three levels update their requirements independently.
  • Grant conditionality. The governance conditions a funding agency attaches to a grant instrument. The obligation comes from the terms of the award and the law and policy it invokes, which is why the award document rather than the briefing is the thing to read.
  • Layered compliance matrix. A mapping of every requirement applicable to one system against its source authority, its applicability, and its relationship to conflicting requirements at other levels. It makes conflicts visible and traceable; it does not resolve them.
  • Crosswalk. A requirement-by-requirement mapping between two governance frameworks, recording where an existing practice covers the same concern with different terminology, assessment method, or evidence, and where it does not cover it at all.
  • Acceptable variation. The written line a system owner draws between local configuration choices that are local business decisions and those that change the system's risk profile and therefore require review.

Closing

Ciara's framework did not give her authority she did not have, and it did not make the conflicts between her four memo streams disappear. What it did was change when she found out about them and who resolved them. The matrix showed which requirement came from which instrument. The working group put the parties in one room while the requirement was still new. The monthly call meant the next update arrived as an agenda item rather than as a surprise. That is the whole of vertical alignment as an operational discipline: not a way to make three levels of government agree, but a way to find the disagreements early, describe them precisely, and put them in front of the people who can actually settle them.

Key Takeaways

  • Vertical AI alignment is an ongoing operational function, not a one-time policy exercise. Federal, state, and local requirements are updated asynchronously, so alignment has to be actively maintained by a named owner rather than assumed to persist once established.
  • Federal grant conditionality creates binding governance requirements for recipients. Accepting federal funding means accepting the conditions attached to it, including conditions more stringent than your own baseline. The obligation comes from the award terms, so read the award rather than the briefing.
  • A referenced framework and a binding requirement are different things. The NIST AI Risk Management Framework is voluntary and non-binding by its own force; what obligates an agency is the award term, contract clause, or agency policy incorporating it.
  • Layered compliance matrices make conflicts visible and traceable. Mapping each requirement to its source authority supports the legal analysis and records when the agency identified the problem.
  • Conflicts between levels require legal resolution, not program manager judgment. Choosing the more reasonable-sounding reading under deadline pressure is a legal determination made without authority or record. Characterize the conflict precisely and route it.
  • Do not assume a uniform rule about what states may require of localities or what localities may decline. These arrangements depend on state law and on how each locality is chartered, and they vary. Check the instruments for the jurisdictions actually in your program.
  • Convene cross-level working groups when requirements are issued, not when confusion has developed. The same parties resolve the same questions either way; only the sequence and the cost differ.
  • Standing communication protocols reduce surprise requirement memos. A regular call with federal counterparts for each funded system lets alignment issues surface as agenda items before they become compliance failures.

Frequently Asked Questions

If we conform to the framework named in our federal award, are we covered for state requirements too? No. Conformance with a framework referenced by a federal award discharges that award condition. It says nothing about a state statute, a state policy, or a local ordinance that applies to the same system, each of which is discharged only by meeting its own terms. Track the obligations from each level separately, and never record one sign-off as clearing requirements from more than one source.

Who should own vertical alignment in a state agency? Someone named, with standing to convene counsel and to speak for the agency in a cross-level working group. The role matters less than the fact that it is assigned before a conflict arrives. Where it is unassigned, the work defaults to whichever program manager is closest to the deadline, the person with the least authority and the most pressure to resolve it quickly.

What do we do when a federal condition and a state statute genuinely cannot both be met? Document both requirements and the specific artifact or data element subject to both, state the operational consequence of each possible resolution, and route it to counsel before accepting the award if the conflict is visible that early. Some conflicts resolve through a formal waiver process; some resolve through negotiation with the federal program office. Neither path is open to a program manager acting alone.

How much local variation should a state system owner tolerate? Draw the line by risk profile rather than preference. Choices that are local business decisions can stay local. Choices that connect the system to unvetted data or remove a review step the state built in change what the system does and belong on the reviewable side. Publish the line with its reasoning.

Is a working group worth the coordination cost for a small program? Compare it against the alternative rather than against zero. Ciara's reconciliation took four months, three legal opinions, and a call she convened herself, and it began only after confusion had spread across four offices. The same parties in one session while the requirement is new is the same work done earlier and once.