Rights-Impacting and Safety-Impacting AI Safeguards
Learning Objectives
By the end of this lecture, you will be able to: (1) apply the OMB M-24-10 definitions of rights-impacting AI and safety-impacting AI, including the presumed categories at section 5(b) and the agency authority to designate additional systems under section 5(c); (2) run the pre-deployment AI Impact Assessment required by section 5(c)(i), covering intended purpose, benefits, potential risks, data quality, stakeholder impact, and mitigation; (3) implement the minimum practices in section 5(c)(ii) through 5(c)(vii), including identifying and mitigating algorithmic discrimination, ensuring meaningful human oversight, providing notice and explanation, offering opt-out where appropriate, maintaining redress, conducting ongoing monitoring, and training operators; (4) operate the waiver and extension processes in section 5(d), including CAIO determination, public notification via the inventory, and annual review; (5) trace safeguard requirements to statutory authorities including Executive Order 14110 sections 4 and 10, the Civil Rights Act Title VI, the Americans with Disabilities Act, the Rehabilitation Act Section 504, the Age Discrimination Act, the Fair Housing Act, the Equal Credit Opportunity Act, the Equal Employment Opportunity Act, and agency-specific statutes such as the Social Security Act, the Internal Revenue Code, and the Immigration and Nationality Act; (6) cross-reference the NIST AI RMF 1.0 MEASURE and MANAGE functions and the NIST AI 600-1 Generative AI Profile (July 2024); (7) build a remediation plan when an agency misses the December 1, 2024 certification deadline or when the system fails to satisfy a minimum practice; (8) coordinate rights and safety safeguards with FISMA, the Privacy Act of 1974, the E-Government Act Section 208 PIA, and agency Senior Agency Official for Privacy processes; and (9) study how safeguard failures manifest in real cases (IRS ID.me, Michigan MIDAS, Dutch toeslagenaffaire, Allegheny County Family Screening Tool, COMPAS, SyRI, Clearview AI) and how to prevent recurrence.
Key Topics Covered
Topic 1: Defining rights-impacting and safety-impacting AI under OMB M-24-10. The rights-impacting definition covers AI whose output serves as a principal basis for a decision or action about individuals or communities affecting civil rights, civil liberties, privacy, equal opportunity, access to critical resources, or access to government benefits and services. The safety-impacting definition covers AI whose output controls or materially influences outcomes affecting human life, health, climate, environment, or critical infrastructure. M-24-10 section 5(b) lists presumed categories; section 5(c) allows designation of additional systems.
Topic 2: Pre-deployment AI Impact Assessment. M-24-10 section 5(c)(i) requires a documented AIA covering intended purpose, stakeholders, potential benefits, potential risks (including disparate impact), data quality, testing results, and mitigations. The AIA is a gate on deployment, not a post-hoc exercise. Good examples: DHS AI impact assessments, VA clinical AI impact assessments, EPA EJScreen updates.
Topic 3: Algorithmic discrimination testing. Identifying and mitigating algorithmic discrimination requires benchmark datasets reflecting the deployed population, subgroup accuracy and error-rate analysis, statistical parity and equalized odds analysis where appropriate, and mitigation strategies (re-sampling, re-weighting, threshold adjustment, or system redesign). NIST AI RMF MEASURE 2.11 and the AI Bill of Rights framework from OSTP are guidance sources.
Topic 4: Meaningful human oversight. Human review must be substantive, not rubber-stamped. Operators need training, time, tools, and authority to override. GAO-21-519SP on AI accountability lists the oversight criteria. The Michigan MIDAS case illustrates oversight failure; the Social Security ALJ process illustrates functional oversight.
Topic 5: Notice and explanation. Individuals affected by rights-impacting AI must receive notice that AI is used and an explanation sufficient to understand and contest the decision. Section 5(c)(iv) tracks the EU AI Act Article 86 and AI Bill of Rights 'Notice and Explanation' principle.
Topic 6: Opt-out and redress. Where appropriate, individuals must have the option to decline AI-assisted processing (the IRS ID.me opt-out is the canonical example) and must have accessible redress when AI contributes to adverse outcomes.
Topic 7: Ongoing monitoring and operator training. Post-deployment monitoring must detect performance degradation, distribution shift, and emerging harms. Operators must be trained on the system's limitations.
Topic 8: Waivers, extensions, and remediation. Section 5(d) allows a CAIO waiver when a minimum practice cannot be met and mitigations are in place, with public notice via the inventory and annual review. Remediation plans for systems out of compliance must specify milestones, accountable owners, and oversight.
Topic 9: Integrating with existing federal frameworks. FISMA security controls, Privacy Act SORNs, E-Government Act PIAs, Section 508 accessibility, Title VI disparate impact review, and agency civil rights offices all intersect with rights and safety safeguards.
Why This Matters for Government
Rights-impacting and safety-impacting AI safeguards are the federal government's structural response to a decade of high-profile AI failures. They are not abstract ethics. They are the operational controls that, if they had been in place, would have prevented the failures that have already happened and the litigation, oversight action, and political damage that followed.
Consider the recent record. The Michigan Integrated Data Automated System, MIDAS, operated from 2013 to 2015 with a false positive rate above 90 percent, wrongly accusing unemployment insurance claimants of fraud and seizing wages, tax returns, and assets. The Sixth Circuit in Cahoo v. SAS Analytics allowed constitutional due-process claims to proceed, and the state paid over $20 million in settlements. The Internal Revenue Service contracted with ID.me in 2021 for mandatory facial-recognition authentication, then reversed course within eight weeks of public disclosure in January 2022 after bipartisan congressional pressure. The Treasury Inspector General for Tax Administration issued report 2023-40-034 finding the IRS had not completed a Privacy Impact Assessment consistent with the E-Government Act of 2002. Allegheny County's Family Screening Tool, used to triage child welfare cases, faced multiple ACLU investigations and a Department of Justice Civil Rights Division inquiry in 2024 regarding disability discrimination. In Europe, the Dutch childcare benefits scandal (toeslagenaffaire) used nationality as a risk variable between 2013 and 2019, falsely flagged tens of thousands of families, and helped cause the Rutte III cabinet's resignation in January 2021. The Dutch SyRI welfare fraud detection system was struck down by the District Court of The Hague in February 2020 on human rights grounds. COMPAS, the recidivism prediction tool, was the subject of the ProPublica investigation showing disparate error rates by race. Clearview AI faced CCPA enforcement and European Data Protection Board fines for scraping biometric data.
Every one of these cases would have been prevented, or at least dramatically reduced in harm and cost, by safeguards of the kind OMB M-24-10 now requires. The minimum practices are not a burden on deployment. They are a form of insurance against outcomes that every one of these agencies would have paid far more to avoid in hindsight. When a CAIO complains that the December 1, 2024 certification deadline is 'too much,' the right response is to ask which minimum practice the agency would have been willing to omit from the Michigan MIDAS design. The answer is none.
The statutory foundation is already there. Title VI of the Civil Rights Act of 1964 prohibits federally funded programs from discriminating on the basis of race, color, or national origin, and covers disparate impact as implemented by the agency regulations under the doctrine recognized in Texas Department of Housing v. Inclusive Communities (2015). The Americans with Disabilities Act Title II (1990) and Section 504 of the Rehabilitation Act (1973) prohibit disability discrimination in federally funded programs and have been applied to automated decision systems in DOJ enforcement actions. The Age Discrimination Act (1975) applies to age-based disparate impact. The Fair Housing Act (1968) covers algorithmic tenant screening. The Equal Credit Opportunity Act (1974) covers automated credit decisions. The Equal Employment Opportunity laws cover algorithmic hiring tools. The Privacy Act of 1974 and the E-Government Act of 2002 Section 208 provide the privacy and PIA overlays. OMB M-24-10's minimum practices are the operationalization of those statutes into the AI era, not a new burden.
Agencies that implement these safeguards well get three concrete returns. First, they avoid the litigation and settlement costs that uncontrolled systems produce. Second, they preserve political and public legitimacy for the agency's broader AI program; the IRS's non-ID.me tax services continued to expand because the IRS demonstrated willingness to reverse mistakes, which the agency could only do because the safeguards framework (notice, redress, opt-out) existed as a structural option. Third, they generate high-quality evaluation artifacts, AI Impact Assessments, disparate impact studies, operator training records, that become the foundation for GAO responses, OIG reports, and FOIA releases. The absence of these artifacts converts every inquiry into an emergency; their presence converts it into routine accountability.
Defining Rights-Impacting AI Under M-24-10
OMB M-24-10 section 5(b)(i) defines rights-impacting AI as AI whose output 'serves as a principal basis for a decision or action concerning a specific individual or entity that has a legal, material, binding, or similarly significant effect' on rights, benefits, services, or due process. The memorandum lists presumed rights-impacting categories: AI affecting eligibility, amount, or conditions of government benefits; AI determining access to housing, education, or employment; AI used in criminal justice or immigration enforcement in ways that materially affect individuals; AI providing medical diagnosis or treatment recommendations used as a principal basis for clinical action; AI making hiring, promotion, retention, or disciplinary decisions for federal employees; AI used in child welfare risk assessments; AI used in loan, credit, or financial assistance decisions; and AI used in voting access, election administration, or political participation in ways that materially affect individuals.
Critical interpretation point: 'principal basis' does not mean 'sole basis.' A system that generates a recommendation an adjudicator is trained to follow, the typical Social Security Administration disability ALJ workflow under SSA's Office of Hearings Operations, for example, is rights-impacting if the recommendation is a principal factor in the decision, even when the adjudicator has nominal final authority. The Council of the Inspectors General on Integrity and Efficiency (CIGIE) has applied this test in IG reviews of AI-assisted adjudication.
Section 5(b)(ii) defines safety-impacting AI as AI whose output 'controls or significantly influences outcomes' related to human life or health, climate or environment, critical infrastructure, or strategic assets. Presumed categories include AI controlling physical movements of vehicles or robotics in public spaces; AI making safety-critical medical triage or treatment decisions; AI operating critical infrastructure such as energy grids, water systems, or transportation networks; and AI used in emergency response or 911 dispatch.
Section 5(c) explicitly permits and encourages agencies to designate additional systems not in the presumed list. The test is whether the output would reasonably be expected to affect the interests at stake. Cautious CAIOs designate liberally; risk-averse CAIOs designate narrowly to avoid the minimum practices burden. The M-24-10 spirit and GAO oversight both favor broad designation. When the decision is close, designating a system as rights-impacting imposes documented safeguards but does not prevent operation; declining to designate when evidence later shows impact is legally and politically costly.
Section 5(c) further permits rescission of designation when later evidence shows impact is trivial. This is an important escape valve: agencies need not carry a designation forever if the system's actual use is narrow.
The Minimum Practices in Detail
Minimum practice 1 - Complete a pre-deployment AI Impact Assessment. Section 5(c)(i) requires a documented AIA. The AIA should cover: intended purpose and scope of use; target population and distinguishing subgroups; data provenance, quality, and representativeness; model design and testing results including subgroup accuracy; risks of algorithmic discrimination and mitigations; risks to safety and mitigations; risks to privacy and mitigations; risks of performance drift and monitoring plan; risks of misuse and governance; alternatives considered and why they were rejected; stakeholder engagement conducted; and residual risk acceptance by named official. Templates: DHS AI Impact Assessment, VA Clinical AI Impact Assessment, HHS AI Use Case Assessment.
Minimum practice 2 - Test the AI system for performance in a real-world context. Section 5(c)(ii) requires pre-deployment testing in conditions that approximate production, not just lab benchmarks. This includes distribution-shift testing, operator-in-the-loop testing, adversarial robustness testing where appropriate, and performance on documented subgroup slices.
Minimum practice 3 - Independently evaluate the AI. Section 5(c)(iii) requires evaluation by personnel independent of the AI development team. This can be internal (the CAIO's evaluation team, the OIG, the agency Civil Rights Office) or external (an independent contractor, the NIST AI Safety Institute, a Federally Funded Research and Development Center like MITRE).
Minimum practice 4 - Identify and mitigate algorithmic discrimination. Section 5(c)(iv) requires analysis of the system's impact on protected groups under civil rights law. Subgroup accuracy and error-rate analysis, disparate-impact statistical analysis, and documented mitigations where disparities are found.
Minimum practice 5. Ensure meaningful human oversight, decision rights, and operator training. Section 5(c)(v) requires that humans in the loop have training, time, and authority to review and override. 'Rubber stamp' oversight fails the test.
Minimum practice 6 - Provide notice and explanation. Section 5(c)(vi) requires individuals subject to rights-impacting AI to receive notice that AI is used and an explanation of the decision sufficient to understand and contest it. This tracks the AI Bill of Rights 'Notice and Explanation' principle and parallels EU AI Act Article 86.
Minimum practice 7 - Maintain human alternatives and opt-out where appropriate, and provide timely redress. Section 5(c)(vii) requires that where appropriate (not universally), individuals may opt for human-only processing, and that all systems offer accessible redress. The IRS ID.me opt-out pattern, the CMS Medicare appeal system, and the Social Security reconsideration process are prototypes.
Minimum practice 8 - Conduct ongoing monitoring. Post-deployment performance must be monitored for degradation, drift, and new harms. Dashboards with subgroup accuracy and incident tracking are the tools.
Minimum practice 9 - Train operators on system limitations, risks, and safe use. Training should be documented, periodic, and covered in competency assessments.
The minimum practices must all be met before operation unless a waiver under section 5(d) is in place.
Waiver and Exception Process
OMB M-24-10 section 5(d) establishes a formal waiver process. The CAIO may waive specific minimum practices when the agency can demonstrate: (a) a legitimate government interest supporting the system's operation that cannot be reasonably achieved by a compliant alternative; (b) mitigations that substantially reduce the risks addressed by the waived practice; (c) public notice of the waiver via the AI inventory; and (d) annual review with continued justification.
Important properties of the waiver mechanism. First, a waiver is system-specific and practice-specific, not a blanket exemption. The CAIO should specify exactly which practice is waived and why. Second, a waiver is not an exemption from transparency, the inventory entry must reflect the waiver. Third, a waiver does not insulate the agency from civil rights statute compliance; a waiver from section 5(c)(iv) disparate impact analysis still leaves the agency bound by Title VI, ADA, ECOA, and related statutes. Fourth, the OMB Desk Officer oversight channel remains available for waivers that appear abusive.
Section 5(d) also permits extensions when an agency needs additional time to meet a minimum practice but expects to come into compliance. Extensions should specify milestones, the official accountable for each milestone, and a target compliance date. Extensions are not waivers. They are deferred compliance plans.
The OMB Office of the Federal Chief Information Officer maintains guidance on waiver format and OMB M-24-10 implementation guidance updates. The Chief AI Officer Council and the Chief AI Officer Council Subcommittees have produced model waiver language that agencies share. Waivers are reviewed by GAO as part of agency AI audits.
Common waiver situations. First, a legacy system designated as rights-impacting where remediation is budgeted but will take 12 to 18 months; an extension is appropriate. Second, a national-security-adjacent system where the public notice requirement must be abstracted for security reasons; a waiver with an abstracted inventory entry and classified documentation may be appropriate. Third, a low-volume system where the cost of a formal independent evaluation exceeds the system's total operating cost; a waiver with internal cross-team review may be appropriate. Four, a system used only in emergency operations for less than 30 days per year; a waiver with abbreviated monitoring may be appropriate. In each case the waiver is documented, justified, posted, and reviewed annually.
What does not qualify as a waiver. First, 'we don't want to do the work.' Second, 'the vendor refused.' Third, 'the schedule slipped.' Fourth, 'the program manager didn't know about the requirement.' These are remediation problems, not waiver situations. GAO and OIG audits routinely identify such pretextual waivers and require remediation.
Agency Implementation Playbook
Phase 1: Inventory-to-Designation. Within 30 days: pull the agency's AI use case inventory entries. For each, apply the rights-impacting and safety-impacting tests. Document the designation analysis in a standardized designation memo signed by the CAIO. Update the inventory with the flags. The Chief AI Officer Council model designation memo template is a starting point.
Phase 2: Gap Analysis. For each designated system, assess compliance against the nine minimum practices. Identify gaps. Prioritize by the magnitude of affected population, the severity of potential harm, and the age of the system.
Phase 3: Remediation Planning. For each gap, document the remediation action, the owner, the milestone date, the resources required, and the dependency chain. Submit the consolidated remediation plan to the CAIO, CDO, SAOP, and General Counsel for signoff. Where a gap cannot be closed by the deployment or December 1 deadline, prepare a waiver or extension request.
Phase 4: Execution. Run AI Impact Assessments. Run subgroup accuracy testing. Conduct independent evaluations using MITRE, FFRDCs, the NIST AI Safety Institute, or internal cross-team review. Implement human oversight procedures, train operators, and deploy monitoring dashboards. Draft notice and explanation language, implement opt-out and redress mechanisms, and publish updated inventory entries.
Phase 5: Continuous Operation. Run monthly dashboards on subgroup accuracy, drift, error trends, and incidents. Run quarterly CAIO reviews. Run annual AIA refreshes and waiver reviews. Cooperate with OIG audits and GAO engagements. Feed lessons learned into the CAIO Council and agency community of practice.
Phase 6: Integration. Embed safeguards into the agency's Planning, Programming, Budgeting, and Execution process so every AI system submission includes safeguard costs. Embed into procurement through FAR clauses and Data Rights language. Embed into hiring through CAIO-approved training curricula for operators, program managers, and leadership. Embed into Congressional reporting through the annual AI Strategy update under M-24-10.
Failure modes to avoid. First, treating safeguards as a compliance checklist. The minimum practices are designed to change decisions, not merely to be checked. Second, waiving without mitigations. A waiver without substantial mitigations is indefensible under section 5(d). Third, performing the AIA after deployment. The AIA is a pre-deployment gate. Fourth, treating subgroup accuracy as optional when data are 'insufficient.' If you cannot measure subgroup performance, you cannot confidently deploy for the affected subgroups; the remediation is to get the data, use synthetic data augmentation, or limit deployment. Fifth, training operators once and forgetting. Training must be periodic, competency-based, and refreshed when the system changes. Sixth, ignoring the private right of action. Many civil rights statutes create private rights of action; adverse outcomes without safeguards attract litigation.
Case Studies: Failures and Successes
Michigan MIDAS (2013-2015). Rights-impacting but no meaningful impact assessment, no subgroup analysis, no human oversight of auto-adjudication, no explanation, no redress. False positive rate above 90 percent. Thousands of wrongful fraud determinations. Sixth Circuit in Cahoo v. SAS Analytics. $20+ million settlement. The failure was not one missing practice but seven.
IRS ID.me (2021-2022). No public notice until after deployment. TIGTA 2023-40-034 found no Privacy Impact Assessment. Public reversal within eight weeks. Correction: live-agent authentication as opt-out. Instructive because the IRS ultimately recovered, but the cost was public trust and the near-loss of the digital identity modernization program.
Allegheny County Family Screening Tool (2016-present). Used to triage child welfare cases. ACLU reports in 2022 and 2023 documented disability-discrimination concerns. DOJ Civil Rights Division opened an investigation in 2024. The tool remains in operation but under scrutiny. Instructive because of the difficulty of subgroup testing when child-welfare data itself reflects historic bias.
COMPAS recidivism tool. ProPublica 2016 investigation documented disparate error rates by race. Wisconsin v. Loomis (Wisconsin Supreme Court 2016) permitted use with caveats. Instructive because the tool is not federal but is the canonical academic reference on algorithmic disparate impact.
Clearview AI. Scraped 30+ billion facial images, sold access to law enforcement. Multiple state CCPA enforcements, EU EDPB fines. Federal agencies (CBP, DEA, FBI) had subscriptions reviewed. Instructive because of the difficulty of auditing COTS AI where the vendor's training practices themselves are problematic.
Dutch toeslagenaffaire (2013-2019). Belastingdienst risk classifier used nationality. Tens of thousands falsely accused. Rutte III cabinet resigned in January 2021. Dutch DPA fined the tax administration €2.75 million. Instructive as a foreign analog to Michigan MIDAS.
Dutch SyRI (2014-2020). System Risk Indication welfare fraud algorithm. District Court of The Hague in February 2020 struck it down on ECHR Article 8 privacy grounds. Instructive as one of the first judicial invalidations of a public-sector AI system.
Positive example: VA clinical AI for radiology. Section 5 minimum practices implemented via the VA's AI Oversight Committee. Published impact assessments, subgroup analysis, human-in-the-loop radiologist review, and monitoring dashboards. The system continues operating with productive feedback loops.
Positive example: Social Security Administration disability adjudication support. The OHO ALJ workflow includes AI-assisted case triage with documented oversight, training, redress (reconsideration, ALJ appeal, Appeals Council, federal court), and monitoring. Not perfect, GAO has flagged gaps, but demonstrates what functional oversight looks like at scale.
Positive example: USPTO Patent Classification AI. Model cards published 2020. Iterative updates. User feedback integrated. Continues operating with low controversy.
These cases together form the empirical basis for the minimum practices: each practice corresponds to a documented failure mode that the practice is designed to prevent. OMB M-24-10 is not a theoretical framework. It is a catalog of what has gone wrong, codified as what must not go wrong again.
Skill.re