←
AI for Government
Visionary · M41 · lesson 41 of 46 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Speaking and Presenting on Government AI
📖
now learning

Speaking and Presenting on Government AI

15 min

General Counsel turned agency administrator Adaora Eze had built a national reputation for responsible AI in public benefits. Then a congressional subcommittee invited her to testify on her agency's use of automated eligibility tools. She had ninety days, five minutes of opening statement, and the certainty that one clumsy sentence would become the headline. She also had three speaking invitations stacking up: a national conference keynote, a reporter from a major outlet, and a closed-door briefing for forty state chief information officers. Each audience needed a different version of the same truth. The technology was the easy part. Adaora's real challenge was that at her level, what you say about AI in public is the policy, and the wrong words can undo years of careful work in a single news cycle.

At the top of public service, your influence over AI is exercised largely through speech: keynotes that set a field's direction, testimony that shapes law, interviews that build or damage public confidence. This is not polish. It is core work with its own discipline, and in government it is bounded by clearance processes and legal constraints that have no private-sector equivalent. This lesson uses Adaora's testimony as the spine and covers the four arenas where senior leaders speak, the evidence they are expected to speak from, and the rules they speak inside.

The core skill: translating without lying

Every speaking challenge about government AI reduces to one hard problem. You understand the technology in its full, hedged, technical complexity. Your audience needs a version they can act on. The failure modes are equal and opposite: over-simplify and you mislead; over-complicate and you lose the room and look evasive. The skill is compression without distortion, which means saying something true, useful and short, and being able to defend every word of it afterward in writing.

Adaora's worked example: her agency's eligibility tool flags applications for human review. The technically complete description runs three paragraphs of caveats. The compressed version for a subcommittee is one sentence: "The system never denies anyone; it sorts applications so our staff can review the complex ones faster, and a human makes every decision." Both statements are true. The second survives a hostile follow-up because it leads with what matters to the public: a human decides, and no one is denied by a machine.

The source supplies a useful minimum unit for building such sentences: a thesis, its evidence, and a qualifier. Its own worked example runs like this. The agency's use of AI for benefits adjudication is the thesis; that it is documented in the AI use case inventory and subject to meaningful human review by trained adjudicators is the evidence; that the agency continues to monitor for disparate impact and has published remediation steps is the qualifier. The qualifier is the part speakers cut when they are nervous, and it is the part that keeps the statement true when someone tests it.

At the top of government, your public words about AI become the policy. Say something true but careless and you spend the next year governing the misunderstanding. That is the reason the compression discipline is not a stylistic preference: an imprecise sentence delivered under oath becomes a commitment your program has to live inside.

Speak from primary evidence, not from the deck

What you cite matters as much as what you say, and the source sets out an explicit hierarchy. Primary evidence is statute, executive orders, OMB memoranda, publications from the National Institute of Standards and Technology, agency-authored documents, inspector general and Government Accountability Office reports, published impact assessments, and court opinions. Secondary evidence is peer-reviewed research and reputable journalism. Tertiary evidence is vendor material, to be used with care and never as the sole basis for a claim. Unverified social media and unattributed claims do not belong in any of the three.

The practical discipline follows directly: build your remarks from your own AI inventory entries, impact assessments, model cards, monitoring records and evaluation results rather than from a vendor's marketing. Vendor decks are written to sell and they use precision language loosely. If your only source for an accuracy figure is a supplier, either you cannot say it or you have to say whose number it is, and the second option invites the obvious follow-up about whether you verified it.

Nine audiences, one truth, different translations

The source's audience analysis is more granular than the usual advice to know your room, and each audience has a different vocabulary, prior knowledge and political context.

AudienceWhat they wantHow to speak
CongressA record, a narrative, and answers that hold upShort opening, long written statement, footnoted primary sources; expect questions ranging from deeply technical staff work to political framing
GAO and inspector general auditorsPrimary documentsProvide impact assessments, model cards, training records, monitoring dashboards, incident logs and override data; do not obfuscate
OMB desk officersImplementation of the memorandum they administerSpeak in the memorandum's own categories: assessment, inventory entry, minimum practices, waiver documentation, annual strategy
Peer AI officers across agenciesTemplates, tools and lessons including failuresCandour; this is the community of practice, and candid exchange is what makes coordinated action possible when a problem spans agencies
Program managers and operatorsWhat changes Monday morningWorkflow language: new forms, training content, escalation paths
Civil society organizationsDepth and honesty about harmsBrief accurately, acknowledge concerns, answer follow-ups, build a relationship before you need one
JournalistsAn accurate, quotable account on deadlineCoordinate with public affairs, be explicit about on-the-record versus background, correct errors in writing, respect deadlines
The general publicTo understand what the system does to themPlain language, accessible formats, language access, and venues people already use such as libraries, community centers and town halls
Academic audiencesTechnical accuracy and methodological rigorPrepare citations carefully and publish your slides

Two of these rows carry more risk than the rest. With auditors, the audit will conclude what it concludes; your cooperation determines only whether the record shows a learning organization or a defensive one. With civil society, the source's observation is that organizations with expertise, platforms and patience will engage deeply if you let them, and the well-known controversies over biometric scraping and identity verification illustrate what happens to agencies that decline the conversation until it is forced on them.

The rules you are speaking inside

Speaking about government AI is subject to legal constraints that distinguish it from commercial speech, and none of them is optional. The source enumerates them, and they are worth carrying exactly.

  • Hatch Act. At 5 U.S.C. 7321 to 7326, it limits political activity by federal employees. Speaking about AI in a professional capacity means staying on policy and program and avoiding partisan electoral commentary or fundraising.
  • Standards of Ethical Conduct. At 5 CFR Part 2635, these govern outside speaking engagements. Paid outside speaking about your official duties generally requires approval; unpaid speaking may still require clearance through the ethics official and public affairs.
  • Personal versus official speech. Personal speech must not create an apparent agency position. Use an explicit disclaimer that the views are your own and not your agency's, and understand that a disclaimer does not cure a disclosure problem.
  • Classification. Executive Order 13526 governs national security information. Do not disclose classified material, even inadvertently, and follow the classification markings on briefings and slides.
  • Controlled Unclassified Information. 32 CFR Part 2002 governs CUI. Law enforcement sensitive material, protected critical infrastructure information and for-official-use-only material are categories that arise routinely in AI topics. When in doubt, consult the senior agency official for CUI.
  • Privacy Act. Do not disclose personally identifiable information about individuals from a system of records except under a published routine use or with the individual's consent.
  • FOIA and trade secrets. Vendor commercial confidential information is protected under FOIA Exemption 4. In a presentation this often means abstracting algorithm details while still conveying intended use and evaluation results.
  • Federal Advisory Committee Act. When speaking as a member of a chartered advisory committee, follow the charter. Minutes are public and members disclose conflicts of interest.

The clearance chain itself is predictable and slow, and building time for it is a planning skill rather than an administrative afterthought. The source describes a typical sequence of draft, public affairs review, general counsel review, ethics review, and privacy review where personal information is involved. Congressional testimony adds OMB and the office of legislative affairs. Classified presentations add the security officer, budget presentations add the budget office. The source gives typical clearance as a few days for routine talks and several weeks for testimony, with public speech commonly running three to ten business days.

The penalties are real enough to state plainly. Hatch Act violations can result in removal. Unauthorized disclosure of classified material is criminal. The Privacy Act carries civil and criminal provisions. Improper release of vendor confidential information can lead to litigation. And being wrong in public on a topic subject to clearance can end a career and embarrass an agency, which is the outcome most likely to happen to a competent person in a hurry.

Preparing congressional testimony

Testimony is adversarial, permanent, and quoted out of context by design. The source lays out a ten-step preparation sequence, and the steps that people skip are always the same ones.

Start by understanding the ask: the chair's letter, the hearing title, the witness panel, and the member interests behind it. Hearings are usually scheduled around a news event or an audit report, so read the reports that will be cited and the last three hearings on similar topics. Then assemble the evidence base from primary sources: the applicable memoranda and executive orders, NIST publications, your own impact assessments and inventory entries, relevant court opinions and peer-reviewed research.

The written statement is the durable artifact and the source describes a structure for it: background and purpose; agency approach and principles; the specific programs at issue; safeguards and oversight; lessons learned from incidents; cooperation with oversight bodies; any specific legislative or appropriations request; and a conclusion, with primary sources footnoted and technical detail in appendices. Written statements for complex topics typically run twenty to a hundred pages on the source's account. The opening statement is a different document: five minutes, which the source puts at six hundred to seven hundred and fifty words, carrying one or two headline messages, one or two examples, and a forward-looking commitment.

Then prepare the questions and answers, rehearse with peers who will actually push back, and time the opening out loud. Reviewing recent hearing footage tells you what the room is like, which is information no briefing memo carries. On the day: arrive early, keep responses brief and substantive, stay calm and factual with a hostile questioner, and use the structuring move the source recommends, which is to accept the question and then answer it in named parts.

The work does not end when the gavel falls. Members submit written questions for the record after the hearing, and those responses become part of the same permanent record; the source puts the typical response window at two weeks and advises treating them with the care of the hearing itself. Archive everything, because your statements shape the next hearing and the next audit.

Adaora's own playbook layered four habits on top of that sequence. Decide the three things you need the public to remember and return to them regardless of the question; hers were that a human makes every decision, that the system reduces wait times, and that the agency audits it for fairness quarterly. Answer the question you were actually asked, briefly, then bridge, because evasion reads as guilt. Know your numbers cold and never guess, since "I do not have that figure and I will provide it for the record" is a strong answer while a wrong number is a future correction and a future headline. And write down the question you most fear, which for her was how many people were wrongly denied, then rehearse a true and calm answer before someone asks it live.

The source also names the recurring pitfalls: overclaiming accuracy, understating risk, promising timelines you cannot meet, speaking beyond your lane when deferring to a colleague with the relevant authority would be stronger, ignoring the political context, and forgetting that the written record lasts far longer than the hearing does.

Handling the four hard questions

Difficult questions about government AI fall into four categories, and preparing one answer per category is more efficient than preparing fifty answers to fifty questions. There is the harms question, meaning how could this cause harm. There is the incident question, meaning what about case X. There is the comparison question, meaning is this not just like the system that failed. And there is the trust question, meaning why should we believe you.

For the harms question, answer from your impact assessment: the risks you identified, the mitigations in place, the monitoring, and the redress available to someone the system gets wrong. Do not minimize and do not overclaim. The GAO AI Accountability Framework, published as GAO-21-519SP, and the NIST AI Risk Management Framework are the frameworks to cite as the basis of your approach.

For the incident question, the source supplies model answers built on the public record. On the identity verification episode: the agency learned that transparency must precede deployment, and the inventory and privacy assessment requirements of the 2024 OMB memorandum are designed to prevent a recurrence. On the Michigan unemployment fraud system: the failure spanned multiple safeguards, with no impact assessment, no subgroup analysis and no meaningful human review, each of which the memorandum's minimum practices address explicitly. On the Dutch childcare benefits scandal: the case demonstrates the cost of using a protected-class variable and failing to provide redress, and the source's suggested answer points to Title VI as the relevant United States civil rights anchor. Clear any comparative legal assertion of that kind with counsel before you make it in public, because a legal conclusion offered at a hearing is one the agency then owns.

For the comparison question, treat the invitation as an opportunity to say what makes your system defensible. Asked whether a system is like the biometric scraping case, the distinguishing facts are that your data is lawfully held under a published system of records notice, with a documented privacy impact assessment, opt-out where appropriate, and a redress path. Asked whether it is like COMPAS, the distinguishing facts are documented operator training and published subgroup analysis, against a case where the Loomis decision in Wisconsin attached caveats about how such a tool may be used. Comparisons to automation failures outside government, including the 737 MAX flight control case and the Tempe autonomous vehicle fatality, come up in almost every talk; the source's framing for the aviation case is that an override that is infeasible in practice collapses a human-on-the-loop design into a human-absent one.

For the trust question, do not answer with your own credibility. Point at the independent check: the inspector general audit, the GAO report, the published model card, the external evaluation, the academic peer review. In the source's words, the point is not that anyone should trust you; it is that an independent auditor, on the public record, can verify what you are saying. That is the structural answer, and it is the only one that improves rather than decays under scrutiny.

The general rules are short. Do not speculate, do not commit to timelines you cannot meet, do not minimize, do not overclaim, do not attack the questioner, and do not disclose what you cannot. Do cite, do defer where appropriate, do commit to follow up in writing, and do acknowledge what you do not know. With journalists specifically: do not lose composure on camera, do not assume anything is off the record unless it was explicitly agreed in advance with public affairs, and remember that confidentiality understandings with reporters are narrow and easily breached. When in doubt, say less.

The keynote, the interview, and the profile you build over years

A keynote is not a status update; it is leadership. The audience came for a point of view they can carry home. Pick one idea, build the talk around one concrete story, and give people one thing to do on Monday. Adaora opens with a single caseworker and a single applicant. A keynote that tries to cover everything moves no one, while a keynote with one sharp argument and one human story gets quoted for years, which is worth remembering when you are tempted to add a fourth theme.

A media interview runs on a different economy. A reporter will use thirty seconds of a thirty-minute conversation and they choose which thirty. Decide your one quotable sentence before the interview and say it clearly. Strip the jargon: "the model's precision and recall tradeoff" becomes "we would rather flag a few extra applications for a human to check than miss someone who needs help." Never speculate about ongoing investigations, personnel matters or classified programs. Adaora's rule is that if a sentence would embarrass the agency as a headline, do not say it, even hypothetically.

Single talks fade; a reputation compounds. A durable speaker profile comes from saying consistent things across many venues, being reliably accurate, and being known for one or two clear positions rather than commenting on everything. Adaora became the leader who insists a human decides, which is why the subcommittee invited her in the first place. Standing of that kind buys you the invitation and the benefit of the doubt in a hostile week. It does not buy agreement, and it does not survive a single avoidable inaccuracy.

Accessibility, plain language, and language access

These are legal obligations rather than presentation preferences, and they are the ones most often discovered too late. Federal presentations must meet Section 508 accessibility standards. The source's specifics: high-contrast palettes, sans-serif type at a twenty-four point minimum, alt text on every image, logical reading order, large-print and screen-reader-accessible handouts, accurate captioning on video, and real-time captioning available on request as a reasonable accommodation. Digital material is measured against WCAG 2.1 AA.

The Plain Writing Act of 2010 requires plain language in federal communications to the public. For AI topics the source translates that into concrete moves: define technical terms at first use, prefer a concrete example to an abstract claim, use short sentences and active voice, address people as "we" and "you" where appropriate, and replace bureaucratic constructions, so that "in accordance with" becomes "under", "utilize" becomes "use", and "facilitate" becomes "help".

Executive Order 13166 requires meaningful access for people with limited English proficiency in federally conducted and federally funded programs. For AI work this means translating the critical public-facing material into the main non-English languages spoken by the affected population, and it applies with particular force to the notice and explanation elements that the 2024 OMB memorandum requires for benefits determinations; the source cites section 5(c)(vi) for that requirement. Section 504 of the Rehabilitation Act requires reasonable modifications in federally conducted programs, which for AI means that notices and explanations must reach people with visual, auditory, cognitive and physical disabilities, including through assistive technology.

The source's closing point on this is the one to keep. A presentation with dense ten-point slides is inaccessible. A presentation full of undefined jargon is inaccessible. Uncaptioned video is inaccessible. An English-only presentation to an audience with limited English proficiency is inaccessible. Each of these is a legal and ethical problem before it is a stylistic one, because what it does is exclude the people the program exists to serve.

A message architecture you can fill in

Before any high-stakes appearance, complete this one-page worksheet. It forces compression and prepares you for pressure. Adaora completes a fresh copy for every keynote, interview and hearing.

ElementPromptYour answer (one sentence each)
AudienceWho is in the room and what do they fear? 
Message 1The single most important true thing 
Message 2The benefit to the public 
Message 3The safeguard that builds confidence 
EvidenceThe primary document behind each message 
QualifierWhat remains uncertain or unresolved 
The human storyOne named person who makes it real 
The worst questionWhat you most fear being asked, and the true answer 
The jargon banThree technical terms to replace with plain words 
ClearanceWho must review this and by when 
The askOne thing you want the audience to do 

Why candour is the only sustainable posture

There is a temptation, especially under hostile questioning, to oversell: to claim the AI is more accurate, more fair, more controlled than it is. This fails predictably, because government AI operates under audit. The inventory and impact requirements of the 2024 government-wide AI guidance, the accountability structure of the GAO framework, and the risk practices of the NIST AI Risk Management Framework mean the truth about your system is documented somewhere. If your public words contradict your own paperwork, the gap becomes the story.

The source's case study makes the point from the other direction. An identity verification deployment was implemented in 2021 with narrow procurement disclosure and essentially no public speaking. When the story broke in January 2022, the agency had no prepared spokesperson, no briefing materials, no testimony package and no quote-ready response, while its critics had a clear message and immediate press availability. The political imbalance was decisive within days, and the source records that a Treasury inspector general report, cited as 2023-40-034, later found the agency had not completed a privacy impact assessment.

The source argues that an early public briefing, setting out the problem being solved, the alternatives considered, the mitigations and the redress path, would likely have produced a very different outcome, since the technology was the same in both scenarios and only the speaking differed. That counterfactual is worth thinking with and worth qualifying. Better speaking would have changed the politics of the episode. It would not have completed the missing privacy assessment, and a program with an unfinished obligation is not rescued by describing it well. Communication changes how a program is received; it does not change what the program is.

The contrast cases in the source run the other way. It describes agencies that speak routinely about their AI work: publishing analyses of impact and presenting to committees, appearing before an authorizing committee on clinical AI with presentations that connect system design to outcomes for the people served, presenting model cards, evaluation results and examiner feedback at stakeholder conferences, and briefing an independent payment advisory commission on algorithm design. None of those programs is free of controversy or agreement with its critics. What they have is leaders who can stand up and explain what they are doing, why, what the risks are, how they are mitigated, and where the public can find out more.

Beyond any single appearance, the source gives three reasons this compounds. Speaking creates the institutional memory that survives turnover, because the testimony record, public speeches and interagency briefings are what a newly arrived AI officer inherits and reads. Speaking builds the peer network that supports you in a bad month. And speaking produces artifacts that researchers, advocacy groups and legislative staff cite, which is how policy actually moves. As the source puts it, silent agencies are governed by louder ones.

So the strongest rhetorical posture is also the most honest one: name the limits before your critics do. Adaora's testimony included the sentence, "The system is not perfect; here is exactly how we catch and correct its errors." That admission did more for the agency's credibility than any claim of perfection could have, because it gave the subcommittee a reason to believe the rest. Disclosure of a limit removes a reason to distrust you. It does not manufacture trust on its own, and it is worth nothing at all if the correction process you described does not exist.

Anti-Patterns

  • Certainty as reassurance. Overstating what a system establishes because a hedged answer sounds weak in the room. In a setting where inventories, assessments and audit reports exist, the hedge you skipped becomes the correction you file, and the correction is the story rather than the original answer.
  • The vendor deck as evidence. Quoting an accuracy or fairness figure whose only source is the supplier. Vendor material is tertiary evidence and never a sole basis; if you cannot point to your own testing, say whose number it is and expect the follow-up about whether you verified it.
  • The message with the qualifier removed. Delivering thesis and evidence while dropping the caveat under time pressure. The qualifier is what keeps the sentence true when someone tests it, and it is the first casualty of nerves.
  • Speaking beyond your lane. Answering a legal, security or privacy question because you are the one at the microphone. Deferring to the colleague with the relevant authority reads as competence, while a legal conclusion offered at a hearing becomes one the agency then owns.
  • Treating clearance as a formality to be outrun. Scheduling an appearance without the days the review actually takes, then choosing between a late withdrawal and uncleared remarks. Neither of those is a good option and both were avoidable at the calendar stage.
  • Communication as a substitute for compliance. Concluding from the failure cases that the problem was messaging. The identity verification episode involved a missing privacy assessment; better speaking would have changed the politics of that week and would not have changed the underlying gap.
  • Off the record as a shared assumption. Believing an understanding exists because you did not say otherwise. Assume every sentence may run unless public affairs agreed the terms in advance, and treat any hypothetical you would not want as a headline as a sentence you do not say.
  • Accessibility handled at the end. Building a deck of dense slides and uncaptioned video, then discovering the obligation the week of the event. Section 508, plain language and language access apply to how the material is built, not to a final polish pass.
  • The disclaimer as cure-all. Assuming "my personal views" makes any statement safe. It addresses the apparent-agency-position problem and does nothing about disclosure of protected information, which is the constraint most likely to end a career.

Practice Prompts

  • Take one AI system you are accountable for and write its thesis, evidence and qualifier in three sentences. Then have someone who knows the system well try to falsify each sentence.
  • Write the question you most fear being asked about that system, and draft an answer that is true, calm, and short enough to say in twenty seconds. Say it aloud to someone until it stops sounding defensive.
  • Build a one-page evidence pack for your next appearance drawn only from primary sources: inventory entry, impact assessment, monitoring results, audit findings. Note every claim you wanted to make and could not support from it.
  • Map the clearance chain for a talk you plan to give, with named reviewers and dates. If the total exceeds the time you have, you have found the problem while it is still fixable.
  • Prepare one answer for each of the four question categories: harms, incident, comparison and trust. Test the trust answer against the standard that it should point at an independent check rather than at your own credibility.
  • Take your last presentation and audit it against the accessibility specifics: contrast, type size, alt text, reading order, captions, handout formats, and language access for the affected population.
  • Rewrite the three most jargon-heavy sentences in your standard briefing into language a person receiving your agency's services would use, then check that the rewrite is still technically accurate.
  • Draft the five-minute opening statement you would give if invited to testify next month, at six hundred to seven hundred and fifty words, and time yourself reading it.

Reflection

Think about the last time you described an AI system to a non-technical audience, and ask what you left out. Some omissions are compression and some are convenience, and the difference is usually visible in hindsight: a compression survives being pointed out, while a convenience is the thing you hope nobody asks about. Now imagine the omitted item surfacing in an audit report six months later, next to the transcript of what you said. That comparison is the working test for whether a sentence is short or merely favorable, and it is worth applying before rather than after.

Then consider what you are known for. Senior leaders accumulate a public position whether they intend to or not, assembled from every talk, quote and briefing they have given. If you asked three people who have heard you speak what you insist on, would they give the same answer, and would it be the answer you want? A reputation for one clear commitment is what buys you the invitation, the benefit of the doubt, and the standing to say something unwelcome. Standing is slow to build, and it is the only thing in this lesson that a single careless sentence can spend entirely.

Glossary

  • Thesis, evidence, qualifier. The minimum unit of a defensible public statement about an AI system: the claim, the primary document supporting it, and what remains uncertain or unresolved.
  • Evidence hierarchy. Primary sources such as statutes, memoranda, NIST publications, agency documents, audit reports and court opinions; secondary sources such as peer-reviewed research and reputable journalism; tertiary vendor material, never used alone.
  • Opening statement. The short spoken portion of testimony, typically five minutes, distinct from the written statement that is published in the record and can run far longer.
  • Questions for the record. Written questions submitted by members after a hearing whose answers become part of the permanent record, typically due within about two weeks.
  • Clearance chain. The sequence of reviews a federal speaker's material passes through, commonly public affairs, general counsel, ethics and privacy, with OMB and legislative affairs added for testimony.
  • Controlled Unclassified Information. Sensitive but unclassified material governed by 32 CFR Part 2002, including law enforcement sensitive and protected critical infrastructure categories.
  • FOIA Exemption 4. The exemption protecting vendor commercial confidential information, which is why presentations abstract algorithm details while still conveying intended use and evaluation results.
  • System of records notice. The published notice describing a Privacy Act system of records, which establishes the lawful basis on which an agency holds and uses the data behind a system.
  • Section 508. The federal accessibility requirement for electronic and information technology, measured for digital material against WCAG 2.1 AA.
  • Plain Writing Act of 2010. The statute requiring federal communications to the public to use plain language, which for AI topics means defined terms, concrete examples, short sentences and active voice.
  • Language access. The obligation under Executive Order 13166 to provide meaningful access for people with limited English proficiency in federally conducted and federally funded programs.
  • On background. An agreed basis for speaking to a journalist that is neither on the record nor confidential, and which only exists if it was agreed in advance.

Closing

An AI program that cannot be explained to a legislature, to auditors, to the press and to the public cannot be sustained politically, however well it is engineered. That is the plainest argument for treating speaking as core work rather than as an obligation that interrupts it. The senior leaders whose programs survive scrutiny are not the most fluent speakers in government. They are the ones who can stand up and say what the system does, why they built it that way, what the risks are, how they are mitigated, and where anyone can go to check.

Adaora spent ninety days preparing five minutes, and the preparation was not rehearsal. It was deciding what was true, assembling the primary documents that showed it, clearing the language with the people whose job is to catch what she would miss, and choosing in advance which limit she would name before anyone made her. That sequence is available for every appearance you will make, and it is the difference between speech that holds up in the record and speech you spend the next year explaining. Say the true thing, say it short, name what you do not know, and make sure the paperwork behind you says the same.

Key Takeaways

  • At the top, public speech is policy. Keynotes, testimony and interviews shape law and public standing as much as any system you build, and every word is retrievable.
  • Compress without distorting. Build each claim as thesis, evidence and qualifier; the qualifier is what keeps the statement true when someone tests it, and it is the first thing nerves remove.
  • Speak from primary evidence. Statutes, memoranda, NIST publications, your own assessments and audit reports come first; vendor material is tertiary and never a sole basis.
  • Nine audiences, one truth. Congress, auditors, OMB desk officers, peer AI officers, operators, civil society, journalists, the public and academics each need different vocabulary for the same facts.
  • The legal constraints are not optional. The Hatch Act, 5 CFR 2635, EO 13526 classification, CUI under 32 CFR 2002, the Privacy Act, FOIA Exemption 4 and FACA all bind what you may say.
  • Clearance takes real time. A few days for a routine talk and several weeks for testimony, with OMB and legislative affairs added; the calendar is where this either works or fails.
  • Prepare four answers, not fifty. Harms, incident, comparison and trust cover almost every hard question, and the trust answer must point at an independent check rather than at you.
  • Accessibility is a legal obligation. Section 508, WCAG 2.1 AA, captioning, plain language and language access under EO 13166 determine who can actually receive what you say.
  • Name the limits before your critics do. Disclosure removes a reason to distrust you rather than creating trust, and it is worthless if the correction process you describe does not exist.
  • Communication is not compliance. Better speaking changes how a program is received; it does not complete a missing assessment, and treating it as a fix is how a messaging strategy becomes the finding.

Frequently Asked Questions

How much uncertainty should I admit in front of a hostile committee? All of the uncertainty that is material to the question, stated in the same breath as what you are doing about it. The record is the reason: your inventory entries, impact assessments and audit reports exist, and a confident claim that they contradict becomes a correction with your name on it. What makes candour survivable is structure rather than volume. Say what is established, say what is not yet established, say what you are doing to find out and by when, and commit to providing anything you do not have for the record.

Can I say a number a vendor gave me? Only with its provenance attached, and expect the follow-up. Vendor material sits at the bottom of the evidence hierarchy and is never a sole basis for a public claim. If your own testing has not reproduced the figure, the accurate sentence is that the supplier reports it and that your independent evaluation is either pending or produced something different. That answer is less impressive and considerably more durable than presenting a supplier's marketing figure as your agency's finding.

What actually requires clearance? More than most people assume. Official speech goes through public affairs, general counsel, ethics and, where personal information is involved, the privacy official; testimony adds OMB and legislative affairs; classified or budget material adds further reviewers. Paid outside speaking about your official duties generally requires approval, and unpaid speaking may still require clearance. The failure mode is almost never a refusal, it is a calendar: the source describes a few days for routine talks and several weeks for testimony, so the decision that matters is made when you accept the invitation.

Does a personal-capacity disclaimer protect me? It addresses one problem and not the others. Saying that the views are your own and not your agency's is how you avoid creating an apparent agency position, and it is genuinely necessary. It does nothing whatsoever about disclosing protected information: the Privacy Act, classification rules, CUI handling and vendor confidentiality apply identically whether you are speaking officially or personally. Most career-ending speaking incidents are disclosure problems, not attribution problems.

How do I answer "isn't this just like the system that failed"? Treat it as an invitation rather than an attack, and answer with specific distinguishing facts instead of general reassurance. Name what the failed system lacked, name the corresponding thing your system has, and point at where a third party can verify it: a published notice, a documented assessment, subgroup analysis, operator training records, a redress path. Where the comparison involves a legal conclusion, clear the wording with counsel first, because whatever you assert at a hearing becomes the agency's position.

Our program has a genuine problem. Should I speak about it at all? Yes, with counsel and public affairs involved and with the remediation defined before you go. What you cannot do is describe a correction process that does not exist, because the paperwork will eventually say otherwise and the gap between the two is a larger story than the original problem. Naming a limit before your critics do removes a reason to distrust the rest of what you say. It is not a substitute for fixing the thing, and audiences that have been told about a fix will check.