Your Agency's Approved AI Tools
Learning Objectives
After completing this lecture, you will be able to:
- Understand the key concepts of your agency's approved ai tools in a government context
- Complete hands-on exercises that reinforce practical skills
- Connect your agency's approved ai tools to your agency's AI initiatives
- Identify next steps for applying these concepts in your role
Key Topics Covered
- Navigating your agency's approved tool list
- Setting up accounts
- Understanding usage policies
- Configuring safety settings
Why This Matters for Government
Government agencies face unique challenges when it comes to AI adoption. This lecture addresses these challenges head-on by providing all government employees with the knowledge and frameworks needed to navigate AI in the public sector responsibly and effectively.
As part of the L1 (AI Aware) curriculum, this lecture builds on the foundational principle that every AI system in government ultimately serves citizens. Whether you are working with AI tools daily or setting strategy for your agency, understanding your agency's approved ai tools is essential for responsible, effective government AI adoption.
Lecture URL: https://skill.re/learn/govt/your-agencys-approved-ai-tools.php
======================================================================
TRANSCRIPT: Your Agency's Approved AI Tools
======================================================================
What you will learn: Navigating your agency's approved tool list. Setting up accounts. Understanding usage policies and restrictions.
Your agency probably has approved AI tools available to you. Maybe ChatGPT Enterprise. Maybe Claude through a government contract. Maybe specialized tools built specifically for your agency's needs.
But simply having access to a tool is not the same as knowing how to use it responsibly. This lecture is about understanding what tools are available to you, how to set them up, and most importantly, what you can and cannot do with them.
This is practical, on-the-ground information you'll use immediately in your work.
WHY THIS MATTERS FOR GOVERNMENT
Authorized AI tools exist for a reason: they've been vetted. They meet security requirements. They have been configured to protect government data. They have terms of service that comply with government regulations.
But unapproved tools are everywhere. It's easy to download something and start using it. The consequences of doing so are serious: data exposure, security vulnerabilities, loss of compliance.
Understanding and using your agency's approved tools is foundational to safe AI work.
FINDING YOUR APPROVED TOOLS
Different agencies organize this differently, but generally:
Start with Your IT Department
Your IT department should maintain a list of approved software and services. AI tools should be on that list with information about:
- What the tool does
- Who has access
- Licensing terms
- Security certifications
- Policies on what data can be used
If you can't find this information, ask your IT department directly.
Check Your Agency's AI Policy
Many agencies have published AI policies that include sections on approved tools. Look for:
- Your agency's AI governance policies
- Chief Information Officer (CIO) directives
- Chief Data Officer (CDO) guidance
- Any recent memos about AI
Ask Your Supervisor or Manager
Your supervisor should know what tools your team is authorized to use. They might have specific guidance about what each tool can be used for.
Check Your Agency's SharePoint or Intranet
Many agencies post AI tool guidance on internal sites.
If you can't find information after asking these sources, you have confirmation that your agency might not have clear AI governance. That's a problem—but at least you know not to proceed until you get clear authorization.
SETTING UP ACCOUNTS
Once you've identified an approved tool, here's what to expect:
Authentication
The tool might authenticate you through:
- Your government email and password
- A government authentication system (like Fed.gov login)
- A dedicated account for the tool
Use your official government email. Do not create personal accounts for work purposes. Do not use a personal email to access approved tools. This creates liability and breaks the chain of custody for data.
Access Controls
Some approved tools limit access based on your role. A classified version might only be available to people with clearances. A benefits determination tool might only be available to caseworkers.
You'll see this during login: "You don't have access to this tool."
That's correct. You're not supposed to have access. Don't try to work around it or ask someone else to do it for you.
Data Residency and Sovereignty
When you sign up, confirm where data is stored. Is it:
- On government servers in your country?
- On contractor-managed servers within your country?
- On cloud servers in other countries?
Different agencies have different requirements about where data can be stored. Understand your agency's requirements before you proceed.
Audit Logging
Approved tools should have audit logging enabled. This means your agency can see:
- When you logged in
- What data you accessed
- What you asked the tool to do
- What the tool returned
Don't be troubled by this. This is a feature, not a bug. It enables accountability and helps detect misuse.
USAGE POLICIES AND RESTRICTIONS
Every approved tool comes with policies about what you can and cannot use it for.
Common Restrictions:
- No PII or sensitive data. Most approved tools have policies restricting the use of personally identifiable information. Check if the tool you're using is approved for PII. If not, you cannot use it with PII data.
- Work-related purposes only. You can't use approved government AI tools for personal purposes. "Can I use this to help with my side business?" No.
- No classified information. Don't upload classified information to unclassified systems, even if they're approved.
- No data sharing with external parties. You can't ask the tool a question and then share the output with people outside your agency, unless you have explicit authorization.
- No commercial use. You can't use the tool to develop products or services you'll sell.
- Output attribution. If you use the tool to draft something, you might be required to disclose that AI was involved (especially for public-facing documents).
Using the Tool Responsibly:
Before you use an approved tool, ask:
- What is the policy on what data I can input?
- How should I describe what I'm asking the tool to do? Should I include context? Should I anonymize examples?
- Can I use the output in a public document, or only for internal use?
- Do I need to disclose that I used AI?
- What should I do if the tool returns something that contains what looks like confidential information?
ANTI-PATTERNS / MISUSE RISKS
Anti-Pattern 1: Assuming All AI Tools Are Approved
An employee is excited about a new AI service they found online. They start using it for work. It turns out it's not approved and doesn't meet security requirements.
The risk: Data exposure, security vulnerability, policy violation.
Anti-Pattern 2: Using Approved Tools Outside Policy Bounds
An employee has access to an approved tool that has clear policies against using it with PII. They upload a spreadsheet with PII anyway because "it's an approved tool so it must be safe."
The risk: Data exposure. The tool is approved for general use, not for PII processing.
Anti-Pattern 3: Not Reading the Policies
An employee gets access to an approved tool and starts using it without reading the usage policies or understanding the restrictions.
The risk: Accidental policy violation, data exposure, misuse.
Anti-Pattern 4: Sharing Tool Access
Multiple people share the same login for an approved AI tool. This violates audit logging and makes it impossible to track who did what.
The risk: Accountability breaks down. If something goes wrong, you can't determine who caused it.
PRACTICE / REFLECTION PROMPTS
- What AI tools does your agency approve? Find the list and review it.
- Pick one tool you're authorized to use. Read the usage policies. What are the restrictions? What can't you use it for?
- If you wanted to use an approved AI tool for a project you're working on, what data limitations would apply? Is there data you have that you can't use?
- If an approved tool returned output that seemed to contain sensitive information, what would you do?
KEY TAKEAWAYS
- Use approved tools, not unapproved ones. Your agency has approved tools for a reason. Use them.
- Understand the security requirements. Approved tools have been vetted to meet government security standards. Unapproved tools have not.
- Read the usage policies. Different tools have different restrictions on what data you can use and what you can do with outputs.
- Don't assume all approved tools are approved for all uses. A tool might be approved for general use but not for PII. Check the specific policy.
- Use official authentication. Use your government email and official authentication systems. Don't create personal accounts for work.
- Audit logging is your friend. It enables accountability and helps detect misuse.
TERMS / GLOSSARY ITEMS
Approved Tool: Software or service that has been vetted by your agency and authorized for use with government data.
Authentication: The process of verifying that you are who you claim to be (usually via password or multi-factor authentication).
Data Residency: The location where data is physically stored.
Audit Logging: The process of recording who accesses what data, when, and what they do with it.
Policy Compliance: Adherence to the rules and restrictions governing tool use.
Your agency has approved ChatGPT Enterprise for government work. You get an account.
You read the policies:
- No PII
- No classified information
- Work-related purposes only
- Output disclosure required for public documents
You have a task: review 50 citizen complaint letters and identify common themes.
How do you do this with ChatGPT Enterprise?
Option 1 (Wrong): Copy and paste the letters (which contain names, addresses, and case details) into ChatGPT. Ask it to summarize themes.
Why: This violates the "no PII" policy.
Option 2 (Right): Read the letters yourself. Write a summary: "In the past week, I received complaints about: slow processing (15 complaints), staff rudeness (8 complaints), unclear eligibility rules (12 complaints), other (15 complaints)." Ask ChatGPT to suggest ways to address each category.
Why: You're providing summary information without PII. You're using the tool for analysis, not for processing sensitive data.
That's the difference between compliant and non-compliant use.
10 minutes.
- What AI tools can you currently use at your agency? Make a list.
- For each tool, what are the restrictions on data types you can use?
- Is there work you want to do with AI that you can't do with approved tools? If so, what would need to change?
Your agency's approved tools are there for you to use. They've been vetted, secured, and configured to protect government data. Use them. Use them responsibly. Don't be tempted by unapproved alternatives.
Government AI CLUB Certification Program
Level 1: AI Aware | Your Agency's Approved AI Tools | Lecture 3.1
A GOVT.CLUB initiative.
<- 1.2.7 Reporting AI Concerns in Your Agency 1.3.2 Prompt Engineering Basics ->
Start Your CLUB Certification
This lecture is part of L1: AI Aware—8 hours of comprehensive government AI training.
Explore CLUB Certification
Related Lectures
L1 1.3.2—Prompt Engineering Basics 25 min - Hands-On Lab
L1 1.3.3—Evaluating AI Outputs 20 min - Hands-On Lab
L1 1.3.4—AI for Government Tasks: Summarization and Drafting 20 min - Hands-On Lab
Frequently Asked Questions
What will I learn in Your Agency's Approved AI Tools?
In this 20 min hands-on lab lecture, you will Navigating your agency's approved tool list. Setting up accounts. Understanding usage policies. Configuring safety settings
What level is Your Agency's Approved AI Tools?
This is a Level 1 (AI Aware) lecture, part of Chapter 1.3 \u2014 Practical AI Skills. It is designed for all government employees.
How long is lecture 1.3.1?
Lecture 1.3.1 (Your Agency's Approved AI Tools) takes 20 min. It is delivered as a hands-on lab format.
Do I need prerequisites for Your Agency's Approved AI Tools?
This lecture is part of L1 (AI Aware). Prerequisites: None.
What is the CLUB Certification?
CLUB (Community Leading Unified Benchmarks) is a maturity-based AI certification for government professionals with 5 levels (L1-L5), 215 lectures, and 25 chapters aligned with NIST AI RMF, OMB, and GAO frameworks.
Skill.re