AI for Government
Capable · M39 · lesson 39 of 43 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
The AI System Lifecycle
📖
now learning

The AI System Lifecycle

15 min

Learning Objectives

After completing this lecture, you will be able to describe, operate in, and supervise every stage of the federal AI system lifecycle in a way that is defensible under the NIST AI Risk Management Framework 1.0, OMB Memorandum M-24-10, the Federal Information Security Modernization Act (FISMA), the Privacy Act of 1974, Executive Order 14110, and the GAO AI Accountability Framework (GAO-21-519SP).

Specifically, you will be able to:

  1. Identify the seven standard phases of the federal AI lifecycle: requirements and authority; data preparation and training; evaluation and red-teaming; deployment and Authority to Operate (ATO); production monitoring; maintenance and retraining; and retirement and decommissioning.
  2. Explain how each lifecycle phase maps to the four NIST AI RMF functions (Govern, Map, Measure, Manage) and to the specific minimum practices OMB M-24-10 imposes on rights-impacting and safety-impacting AI.
  3. Identify the governance artifacts that must exist at each phase, including the authority-to-use memo, the Privacy Threshold Analysis, the Privacy Impact Assessment, the System of Records Notice where applicable, the Security Plan and Authority to Operate, the model card, the evaluation report, the monitoring plan, and the decommissioning plan.
  4. Describe the difference between traditional software lifecycle management under NIST SP 800-53 and the additional controls the AI lifecycle requires, including data drift monitoring, outcome monitoring, fairness re-evaluation, and model-level incident response.
  5. Identify the specific government-specific considerations at each phase: authorizing statute, constitutional and civil-rights obligations (Title VI, Title VII, Equal Protection), accessibility under Section 508, labor obligations under 5 U.S.C. Chapter 71, procurement obligations under the FAR, and records obligations under the Federal Records Act.
  6. Determine, for a given agency AI use case, whether a lifecycle phase has produced sufficient evidence to satisfy GAO, an Office of Inspector General, and congressional oversight.
  7. Design a retirement plan that preserves the records, audit trails, and review obligations required by the Federal Records Act and that addresses historical decisions made by the retired system.

These objectives are intentionally phrased in the active voice because lifecycle control is something the practitioner does; it is not passive observation of a vendor's process.

Key Topics Covered

This lecture covers the full federal AI system lifecycle. Specific topics include:

The seven standard lifecycle phases. Phase 1: Requirements and authority to use. Phase 2: Data preparation and model training. Phase 3: Evaluation and red-teaming. Phase 4: Deployment and Authority to Operate. Phase 5: Production monitoring. Phase 6: Maintenance and retraining. Phase 7: Retirement and decommissioning.

Governance artifacts per phase. What must be documented, signed, and filed at each step to satisfy OMB M-24-10, FISMA, the Privacy Act, the Federal Records Act, and the applicable sector-specific authorities (for example, HIPAA for health data, FERPA for education, FISMA for federal systems, CJIS for criminal justice).

Crosswalks to NIST AI RMF. Each lifecycle phase is mapped to the Govern, Map, Measure, and Manage functions, and to the RMF Playbook actions expected during that phase.

Crosswalks to OMB M-24-10 minimum practices. The six minimum practices for rights-impacting AI (pre-deployment testing, ongoing monitoring, human review, notice, opt-out, and consultation) and the six for safety-impacting AI (pre-deployment testing, ongoing monitoring, real-world testing where feasible, independent evaluation, contingency plans, and human decision-making) are tied to the specific lifecycle phases at which each practice is demonstrated.

Artifacts, not slogans. Every phase produces artifacts: requirements memo, data governance plan, model card, evaluation report, PIA and SORN as needed, Authorization to Operate, monitoring plan and dashboards, incident-response playbook, and decommissioning record.

Sector layering. DoD Directive 3000.09, FDA SaMD guidance, HHS Trustworthy AI Playbook, IRS model-governance practices, and DHS AI Roadmap layering onto the enterprise lifecycle for specific agencies.

Common failure modes. Why agencies that skip requirements produce drifting systems; why agencies that skip red-teaming produce embarrassing incidents; why agencies that skip monitoring produce discrimination cases; why agencies that skip retirement planning produce FOIA and IG exposure for years.

The VA benefits-eligibility case study. A complete worked example of the seven phases for a rights-impacting benefits-eligibility system.

The SSA disability-screening case study. A comparable worked example for a safety-and-rights-impacting disability-screening assistant.

The IRS fraud-detection case study. A worked example that highlights the interplay of the lifecycle with the Taxpayer Bill of Rights and the National Taxpayer Advocate's oversight role.

Why This Matters for Government

An AI system in the federal government is not simply software. It is a decision-making or decision-supporting apparatus that operates within a statutory structure (authorizing act, Administrative Procedure Act, civil-rights statutes, Privacy Act), an executive structure (OMB M-24-10, EO 14110, agency directives), and an oversight structure (GAO, Offices of Inspector General, congressional committees, the OMB Office of Information and Regulatory Affairs). Each phase of the AI lifecycle is the point at which one or more of these authorities attaches. Missing a phase means missing a duty.

Consider the contrast with traditional federal software. A software system is authorized to operate under NIST SP 800-53 and gets a FISMA Authority to Operate. That ATO focuses on confidentiality, integrity, and availability. It is sufficient for a payroll system or a case management system that does not make or influence consequential determinations.

An AI system adds new failure modes that the traditional ATO does not fully address. A model can be accurate on average and systematically wrong for a subpopulation, violating Title VI. A model can drift silently as the world changes while its inputs remain in-distribution, violating the accuracy requirement implicit in the Privacy Act's 'relevance and accuracy' standard. A model can be manipulated by adversarial inputs that the ATO's SP 800-53 controls never contemplated, violating FISMA. A model can be explainable in one population and opaque in another, violating the Administrative Procedure Act's reasoned-explanation requirement for agency action. None of these failure modes are discovered by the traditional ATO process alone. They require an AI-specific lifecycle with AI-specific phase gates.

This is the context OMB M-24-10 was drafted against. The memorandum imposes 'minimum practices' for rights-impacting and safety-impacting AI precisely because the traditional lifecycle under FISMA was insufficient. The minimum practices are lifecycle obligations: pre-deployment testing (phase 3), ongoing monitoring (phase 5), human review (phases 4-5), notice (phases 4-5), opt-out (phase 4), consultation (phase 1, reinforced through the lifecycle).

GAO's AI Accountability Framework (GAO-21-519SP) organizes federal oversight of AI the same way, around Governance (phases 1 and 4), Data (phases 1-2), Performance (phases 3 and 5), and Monitoring (phases 5-6). When GAO, an OIG, or a congressional committee opens an inquiry into a federal AI system, they request lifecycle artifacts. Agencies that can produce complete lifecycle artifacts usually close the inquiry within weeks. Agencies that cannot produce lifecycle artifacts spend months reconstructing what happened.

The examples are well documented. The Michigan unemployment MiDAS system was deployed without adequate evaluation or human review, producing tens of thousands of false-fraud accusations and settled litigation. VA paused several predictive analytics tools in 2023 after OIG found lifecycle documentation gaps. IRS rolled back automated audit-selection models after GAO found disparate audit rates uncorrelated with compliance risk. DHS CBP and TSA both made major adjustments to facial-recognition programs after the National Institute of Standards and Technology's Face Recognition Vendor Test demonstrated significant demographic disparity at specific algorithm-vendor combinations, exposing evaluation-phase gaps.

In each case, the fix was lifecycle discipline: specify requirements, curate and document data, evaluate for accuracy and fairness, deploy only with notice and human review, monitor in production, maintain through retraining, retire with an audit trail. Agencies that internalize this discipline at the practitioner level avoid the recurring pattern of high-profile failures.

This lecture is written for the L2 AI Practitioner -- the analyst, project lead, or team supervisor who will actually operate or supervise operations across these phases. You do not need to be an OMB lawyer; you do need to know which phase you are in, what artifacts are required, and which oversight body is going to ask for them first.

WHY THIS MATTERS FOR GOVERNMENT

The federal AI lifecycle is distinct from the commercial machine-learning lifecycle because it is constrained by statute, not just by product strategy.

Phase 1: REQUIREMENTS AND AUTHORITY TO USE.

Before you build anything, you define the problem and establish your authority. The first question is not 'what dataset?' but 'under what authority?' Does the agency have statutory authority to use AI for this purpose? Does the use trigger a System of Records Notice under the Privacy Act? Is it in-scope for the current AI use-case inventory? Is it rights-impacting or safety-impacting under OMB M-24-10?

Artifacts: requirements document, authority-to-use memo, initial risk tier classification, stakeholder-analysis memo, initial Privacy Threshold Analysis.

Government considerations: authorizing statute; constitutional obligations; Title VI, Title VII, Equal Protection; APA notice-and-comment where applicable; Privacy Act 552a; Paperwork Reduction Act; Federal Advisory Committee Act if external input is involved.

Phase 2: DATA PREPARATION AND MODEL TRAINING.

You collect, curate, clean, and label the data. You train the model. The government considerations here are severe: chain of custody for data (FISMA, 44 U.S.C. 3301); Privacy Act data-use limits; representativeness of the population served; historical bias in data that may embed past discrimination.

Artifacts: data governance plan, data quality assessment, bias audit of training data, data-use agreements with source systems, training logs, model card (draft).

Phase 3: EVALUATION AND RED-TEAMING.

You test the model against held-out data, demographic subgroups, adversarial inputs, and real-world-approximating scenarios. You document results.

Artifacts: evaluation report, demographic-disparity analysis, adversarial-robustness report, red-team findings, remediation plan, model card (final).

OMB M-24-10 minimum practice: pre-deployment testing. NIST AI RMF: Measure.

Phase 4: DEPLOYMENT AND AUTHORITY TO OPERATE.

You deploy the system into production. You obtain an Authority to Operate under FISMA that explicitly addresses AI-specific controls. You implement the OMB M-24-10 minimum practices: human review, notice to affected individuals, and opt-out mechanism where applicable.

Artifacts: Authorization to Operate, deployment plan, human-review procedures, notice materials, opt-out procedures, consultation record.

Phase 5: PRODUCTION MONITORING.

You monitor the system continuously. What to monitor: accuracy, fairness, drift, usage, user feedback, incidents. Government-specific considerations: Privacy Act accuracy requirements; APA reasoned-explanation requirements; civil-rights disparity.

Artifacts: monitoring plan, dashboards, quarterly performance report, incident log, incident-response playbook activations.

OMB M-24-10 minimum practice: ongoing monitoring. NIST AI RMF: Manage.

Phase 6: MAINTENANCE AND RETRAINING.

Models age. The world changes. You retrain on updated data, validate, and redeploy. Maintenance triggers a return to phases 2-4 under change-management discipline.

Artifacts: retraining trigger record, new evaluation report, updated model card, change-management ticket, updated ATO.

Phase 7: RETIREMENT AND DECOMMISSIONING.

Eventually the system is retired. You plan the transition, notify affected stakeholders, preserve records under the Federal Records Act, and review historical decisions the system made for any outstanding harm.

Artifacts: decommissioning plan, stakeholder notice, records-retention schedule, historical-decision-review report.

These seven phases form the durable structure of every federal AI system. The rest of this lecture walks through each phase in detail with the VA benefits-eligibility and SSA disability-screening case studies.

L2 2.1.1 -- Supervised vs. Unsupervised vs. Reinforcement Learning (60 min -- Video + Interactive)

L2 2.1.2 -- How Transformers and LLMs Work (60 min -- Video + Diagrams)

L2 2.1.3 -- Generative AI Deep Dive (60 min -- Video + Demos)

L2 2.1.4 -- Data Quality and AI Performance

L2 2.1.6 -- Hallucinations, Guardrails, and Prompt Injection

L2 2.1.8 -- Emerging AI Capabilities

L3 3.2.1 -- Establishing an AI Governance Board (for lifecycle governance)

L3 3.3.3 -- Monitoring AI in Production (deeper dive on Phase 5)

L3 3.3.4 -- Incident Response for AI (Phase 5 incident-response playbook)

L3 3.4.2 -- Decommissioning AI Systems (Phase 7 in depth)