AI for Government
Proficient · M23 · lesson 23 of 53 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Cross-Agency AI Coordination
📖
now learning

Cross-Agency AI Coordination

15 min

Learning Objectives

After completing this lecture, federal program leaders, interagency liaisons, and Chief AI Officer designees will be able to: first, navigate the principal federal coordination bodies that shape AI decisions, including the Federal CIO Council, the Federal CAIO Council, the OMB-OSTP National Science and Technology Council AI Subcommittee, the General Services Administration AI Center of Excellence, and agency-specific counterparts at DHS, DOD, HHS, and VA; second, design and execute formal interagency agreements such as Memoranda of Understanding, Interagency Agreements under the Economy Act (31 USC 1535), and reimbursable agreements under the GSA Franchise Fund, with specific attention to data sharing, vendor sharing, and joint operational commitments; third, coordinate vendor performance and incident response when a single vendor serves multiple agencies, using the CIO Council FedRAMP feedback loop and CISA-coordinated incident protocols; fourth, participate in federally-coordinated AI use case inventories required by OMB M-24-10 and section 5 of Executive Order 14110, including cross-agency de-duplication and shared-lesson packaging; fifth, structure shared services for common AI capabilities such as cloud-hosted foundation models, fairness audit services, and model evaluation harnesses through the GSA Multiple Award Schedule, the NASA SEWP vehicle, and the Defense Information Systems Agency enterprise services; and sixth, navigate the non-trivial legal constraints on interagency collaboration, including Privacy Act Systems of Records Notices, 44 USC chapter 35 Paperwork Reduction Act coordination, and agency-specific enabling statutes.

Key Topics Covered

The workshop covers ten interlocking topics. First, the federal AI coordination landscape including CIO Council, Federal CAIO Council, NSTC AI Subcommittee, GSA AI Center of Excellence, and the Chief Data Officer Council. Second, the legal and financial instruments available for interagency coordination, including the Economy Act, GSA assisted acquisition, the Franchise Fund, reimbursable agreements, and MOUs. Third, shared use case inventories under OMB M-24-10, including how the ai.gov inventory functions and how agencies share de-duplication intelligence. Fourth, joint vendor management patterns, including the CIO Council's vendor performance sharing, FedRAMP authorization leveraging, and coordinated cure notice intelligence. Fifth, interagency data sharing, including CMS-VA joint care analytics, Treasury-IRS-SSA taxpayer information coordination, and CBP-State-DHS traveler screening. Sixth, cross-agency incident response for shared vendors, including the CISA coordination role. Seventh, shared services for AI, including the GSA AI Multiple Award Schedule, the HHS Innovation Sandbox, and DISA's AI Capability Pilots. Eighth, coordination with state, local, tribal, and territorial governments through CISA's SLTT program and OMB guidance. Ninth, communication patterns with Congress, GAO, and the Inspector General community. Tenth, failure modes and recovery, drawn from interagency case studies including TSA Secure Flight, HealthCare.gov, and Login.gov.

Why This Matters for Government

Federal AI work rarely occurs inside a single agency. Veterans benefits decisions touch VA, SSA, and IRS. Border operations touch CBP, ICE, TSA, State, and HHS. Climate resilience AI touches NOAA, FEMA, EPA, DOT, and USDA. Cyber defense AI touches CISA, NSA, FBI, and every agency's CISO. An AI leader who tries to operate inside the boundary of a single agency is misreading the job. The second the system needs data from another agency, uses a vendor shared with another agency, or produces decisions that affect a citizen's interaction with another agency, cross-agency coordination becomes load-bearing. Agencies that invest in coordination infrastructure before they need it operate smoothly; agencies that try to stand it up during an incident fail.

The legal and financial architecture for interagency work is more flexible than most career staff realize. The Economy Act at 31 USC 1535 authorizes one agency to pay another for goods and services when it is in the government's interest and cheaper than contracting commercially. GSA's assisted acquisition and Franchise Fund services let agencies buy shared capabilities without building their own acquisition team. The E-Government Act of 2002 encourages shared services and is the statutory foundation for platforms like Login.gov, USAJobs, and Payments.gov. The Paperwork Reduction Act at 44 USC 3506 requires coordination when multiple agencies collect similar information from the public. These instruments, when used well, turn cross-agency AI work from a legal negotiation into a standard operating procedure.

Policy obligations also push toward coordination. OMB M-24-10 requires agencies to publish AI use case inventories and to coordinate with peer agencies when use cases overlap. Section 5 of Executive Order 14110 created the Federal AI Governance Board and directed agencies to coordinate on AI workforce, use case selection, and risk management. The CISA-led coordination for AI security incidents, building on CISA's role under the Cybersecurity Information Sharing Act of 2015, increasingly expects agencies to share indicators of compromise and vulnerability intelligence. Agencies that participate actively in these coordination bodies pull intelligence faster, spend less on duplicate capabilities, and demonstrate to Congress and GAO that they are meeting government-wide obligations. Agencies that sit on the sidelines cannot plausibly argue that the obligations do not apply to them, but they nonetheless forfeit the leverage that participation provides.

Finally, cross-agency coordination is the mechanism by which federal AI learns. A single agency cannot see the full vendor landscape, cannot independently evaluate foundation models at the scale the technology now requires, and cannot afford to duplicate evaluation work that the NIST AI RMF and the GSA Center of Excellence perform centrally. A CAIO who declines to participate in the Federal CAIO Council, the CIO Council AI Community, and the NIST AI RMF working groups is making their agency poorer by refusing to take the tax-funded intelligence that is already available. Cross-agency coordination is not a nice-to-have; it is the way federal AI actually works in 2026, and the capability to operate inside this coordination fabric is a core L3 competency.

The Federal Coordination Landscape

A federal AI leader should know ten principal coordination bodies by heart. First, the Federal CIO Council, chaired by the Federal CIO at OMB, which coordinates IT and AI policy across federal agencies and maintains several AI-focused working groups. Second, the Federal CAIO Council, established under OMB M-24-10, which convenes Chief AI Officers to share practice, coordinate use case inventories, and feed recommendations to OMB. Third, the NSTC AI Subcommittee, jointly hosted by OSTP and OMB, which coordinates federal AI research and development, including the National AI Research Resource pilot. Fourth, the GSA AI Center of Excellence, which supports agencies in AI pilot design, vendor evaluation, and procurement. Fifth, the Chief Data Officer Council, established by the Evidence-Based Policymaking Act, which coordinates federal data governance including AI training data.

Sixth, the Federal Acquisition Service within GSA, which hosts the Multiple Award Schedule, the Federal Acquisition Service Alliance, and the FedRAMP program office. Seventh, CISA's coordination function for AI security incidents, operating within the Department of Homeland Security. Eighth, the Department of Defense Chief Digital and AI Office (CDAO), which coordinates defense AI and operates the Joint AI Center's successor activities. Ninth, the National Institute of Standards and Technology, which operates the AI Safety Institute (USAISI) and the broader AI Risk Management Framework community. Tenth, the interagency Privacy Council and the SLTT (state, local, tribal, territorial) coordination bodies within DHS.

Each body has a charter, a meeting cadence, and decision or recommendation authority. A federal AI leader should have a named liaison in their agency for each, even if that liaison is the same person for several. Participation is the cost of admission; reading meeting minutes without attending misses the working-group coordination where most actual work happens. Agencies with active participation in these bodies pull vendor intelligence days faster, get early read on OMB guidance, and contribute to the shaping of NIST standards that their agency will later be measured against. Passive agencies are measured without their input.

Cross-agency coordination rests on a small set of well-defined legal and financial instruments. The Economy Act at 31 USC 1535 is the most common. It allows one agency to order goods or services from another federal agency when the head of the ordering agency determines that the order is in the government's interest, the services cannot be acquired as conveniently or cheaply by contracting with a commercial enterprise, and the performing agency can reasonably deliver. Economy Act orders must be documented in writing with specific terms and conditions. The GSA Franchise Fund operates under the Government Management Reform Act and enables GSA to provide administrative services including AI capabilities to other agencies on a fee-for-service basis without the Economy Act's commercial-alternative test.

Memoranda of Understanding are the next instrument, used for non-financial coordination such as data sharing, joint evaluation, or shared governance. MOUs do not create contractual obligations but do document agreed commitments, which is useful when agencies are working together without money changing hands. For data sharing, additional legal work is usually required: Privacy Act Systems of Records Notices may need to be modified, Computer Matching Agreements under 5 USC 552a(o) may need to be executed, and agency-specific statutes (for example, tax information under 26 USC 6103, education records under FERPA, health information under HIPAA) impose specific constraints. Getting data sharing legally right is often the critical path for cross-agency AI work, and agencies that maintain a template library of cleared agreements move much faster than agencies that start from scratch each time.

Reimbursable agreements are a fourth instrument, used when one agency performs work on behalf of another with reimbursement. These are commonly paired with assisted acquisition through GSA FEDSIM or 18F. The Acquisition Workforce Development Program at OMB promotes cross-agency acquisition expertise, which becomes critical when an interagency AI project needs a single, experienced contracting officer to manage a vendor serving multiple agencies. Finally, the Paperwork Reduction Act at 44 USC 3506 requires agencies that collect similar information from the public to coordinate through OMB; for AI systems that survey or query citizens, this is a mandatory coordination path.

Data Sharing and Joint Vendor Management

Data sharing is where interagency AI coordination earns its keep, and also where it most often fails. A federal AI team needs data that spans agencies in many mission-critical use cases. Veterans benefits adjudication needs SSA earnings records, IRS income data, and DOD service records. Federal fraud detection needs Treasury payment records, IRS taxpayer information, and agency-specific program data. Border screening needs State Department visa data, CBP entry-exit records, and TSA watchlist data. Each of these data flows has statutory and regulatory constraints, and a team that assumes they can simply pull the data across agency boundaries is headed for a Privacy Act lawsuit. The right sequence is: identify the specific data elements needed; determine the statutory and regulatory basis; execute the necessary agreements (SORN, CMA, MOU, data use agreement); implement technical safeguards that match the sensitivity; and establish monitoring to ensure ongoing compliance.

Joint vendor management is the other half. When the same vendor serves multiple agencies, coordination produces leverage and risk-sharing that no single agency can achieve. The CIO Council's vendor feedback loops allow agencies to compare notes on a vendor's performance and pool cure-notice intelligence. FedRAMP authorization leveraging lets an agency that inherits an authorization avoid duplicating the full Authority to Operate process. When a shared vendor has a performance issue or security incident, coordinated response among the affected agencies produces a unified cure notice that is harder for the vendor to ignore than agency-by-agency complaints. The GSA Multiple Award Schedule for AI, launched in 2024, consolidates many common AI procurements and offers a standard contractual baseline agencies can build on.

The governance discipline that supports this is the interagency working group structure. For any vendor or data sharing arrangement that touches multiple agencies, stand up a working group with named representatives from each agency, a clear charter, a documented decision process, and a recurring cadence. Avoid the ad hoc pattern where coordination happens only when something breaks; that pattern produces slow, conflict-prone response and often rewards the agency that shouts loudest rather than the agency with the strongest mission case.

Interagency Incident Response and Shared Services

When an AI incident spans agencies, coordination is the difference between a fast, contained response and a sprawling failure. CISA coordinates cyber incidents across the federal civilian executive branch, and its role has expanded to include AI-specific incidents through the AI Safety Institute partnership at NIST and the Cyber Safety Review Board's emerging AI focus. A CAIO whose agency experiences an AI incident touching a vendor or data shared with other agencies should notify CISA within the 72-hour window many agencies now require, participate in joint root cause analysis, and contribute to the public after-action when appropriate. Agencies that try to keep AI incidents internal when they are not internal risk both compounding the incident and losing credibility with peer agencies.

Shared services for AI are the positive case of coordination. The GSA AI Center of Excellence offers model evaluation and pilot design support that small agencies could not afford to build alone. The NIST AI RMF Community and the USAISI evaluation capability let multiple agencies share foundation model evaluations. The DISA AI Capability Pilots offer defense agencies shared inference and training infrastructure that would be wasteful to duplicate. The Login.gov shared identity service and the Payments.gov shared payments service, both operated by GSA, provide common infrastructure that many agency AI systems now build on. Using these shared services rather than building agency-specific replicas is often the right engineering, economic, and governance call. The discipline is to evaluate the shared service fairly against the build-your-own option, document the trade-off, and, when choosing the shared service, design the agency-specific pieces to integrate cleanly.

Finally, a word on SLTT coordination. AI systems used at the federal level often touch state and local operations, particularly in health, education, law enforcement, and emergency management. CISA's SLTT Engagement and FEMA's coordination with state emergency managers provide frameworks for this. A federal AI team designing a system used by state or local partners should engage those partners early, document the federal-state data relationship, and plan for the different privacy and public-records regimes that apply at each level. This is slow work but it is the only way federally-sponsored AI delivers real value at the point of service.

Anti-Patterns and Case Studies

Cross-agency AI coordination fails in predictable ways. The first anti-pattern is the parallel silo, where each agency builds its own version of a capability that would be more efficiently shared. The federal login landscape before Login.gov is the canonical case: every agency ran its own identity management, at enormous aggregate cost and poor user experience. The remediation is to evaluate shared services seriously and document trade-offs rather than defaulting to build-your-own.

The second anti-pattern is the undocumented handshake, where agencies share data or coordinate on a vendor based on personal relationships without formal agreements. This works until a lawsuit, a FOIA request, or a personnel change surfaces the informality, and suddenly the absence of a SORN, MOU, or CMA becomes a legal problem. The remediation is template-based agreement workflows and a named interagency program manager who tracks the paperwork.

The third anti-pattern is the abandoned working group, where a coordination body is chartered, meets briefly, and then slides into irrelevance. Working groups require clear charters, time-bounded deliverables, and escalation paths when participation flags. The Federal CAIO Council's AI Use Case Inventory working group is a counter-example of an active, deliverable-oriented group that produced visible guidance quickly.

The fourth anti-pattern is the vendor-by-vendor escalation race, where a shared vendor misbehaves and the affected agencies race to file the first cure notice rather than coordinate. Coordinated cure notices are more effective and build interagency trust. The CIO Council's vendor performance sharing was explicitly designed to prevent this pattern.

The fifth anti-pattern is the federal-only bubble, where a federal AI team designs a system that state and local partners will execute but does not engage those partners in design. The resulting system looks good in DC briefings but fails on the ground, which is how several federally-funded AI pilots in the late 2010s failed. The remediation is early SLTT engagement through CISA, FEMA, and sector-specific coordination. The sixth anti-pattern is the missing IG engagement, where an agency's Office of Inspector General is excluded from an interagency initiative and later issues a scathing oversight finding. Bringing IGs in early, through the Council of Inspectors General on Integrity and Efficiency, is a sign of confident rather than defensive program management.

L3 3.5.1 Data Infrastructure for Enterprise AI. L3 3.5.3 Building AI Centers of Excellence. L4 4.3.1 Drafting Agency AI Policies. L4 4.5 Cross-Agency Vendor Management.