AI for Government
Visionary · M1 · lesson 1 of 47 · in progress
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Academic and Research Collaboration
📖
now learning

Academic and Research Collaboration

15 min

Learning Objectives

After completing this lecture on Academic and Research Collaboration for government AI, you will be able to:

  • Design joint research programs between federal agencies (NIST, NSF, NIH, DARPA, IARPA) and academic institutions that advance agency mission while producing peer-reviewed evidence for policy.
    - Structure Intergovernmental Personnel Act (IPA) rotations and sabbatical exchanges between agencies such as GSA, OSTP, CISA, VA, and top AI research universities, with clear statements of work, intellectual property terms, and COI controls under 5 CFR 2635.
    - Negotiate Cooperative Research and Development Agreements (CRADAs), Other Transaction Authorities (OTAs), and Federally Funded Research and Development Center (FFRDC) task orders so research outputs are usable under OMB M-24-10 and consistent with NIST AI RMF GOVERN, MAP, MEASURE, and MANAGE functions.
    - Build publication partnerships that meet both academic norms (peer review, reproducibility, data sharing) and federal requirements for FISMA-bounded data, PII minimization, and NIST SP 800-53 controls.
    - Design funding strategies that blend appropriated funds, Small Business Innovation Research (SBIR), National AI Research Resource (NAIRR) pilot credits, and philanthropic capital without running afoul of the Antideficiency Act or augmentation-of-appropriations doctrine.
    - Evaluate when academic collaboration is the right tool versus in-house build, vendor contract, or FFRDC engagement, using lessons from IRS ID.me remediation, Michigan MIDAS litigation, SyRI in the Netherlands, and the Dutch childcare benefits scandal.
    - Translate research outputs into implementable guidance under Executive Order 14110, EU AI Act conformity patterns for transatlantic programs, and ISO/IEC 42001 management system requirements.

Key Topics Covered

This lecture covers five interlocking topics that together form a complete operating model for academic and research collaboration in US federal agencies:

  1. Joint research programs: NIST-led consortia (AI Safety Institute Consortium, AISIC), NSF Institutes for Trustworthy AI, DARPA and IARPA broad agency announcements, and VA academic affiliate agreements that predate AI but map directly onto AI evaluation workstreams.
    2. Sabbatical exchanges: IPA assignments, Presidential Innovation Fellows (PIF), US Digital Service tours, detail assignments under Title 5, and bidirectional flows where agency staff teach at universities while faculty embed in CISA, GSA, or DOD components.
    3. Publication partnerships: Pre-publication review, Section 508 accessibility, Paperwork Reduction Act (PRA) clearances when human subjects are involved, and coordination with agency Public Affairs Offices so findings reach both peer-reviewed venues and policy readers.
    4. Funding strategies: Grants.gov, BAAs, OTAs, NAIRR compute credits, philanthropic co-funding, and cost-share models; how to avoid augmentation-of-appropriations risk and how to structure multi-year commitments within annual appropriations.
    5. IP, data, and security terms: FAR Part 27 data rights, CRADA IP clauses, controlled unclassified information (CUI) handling under 32 CFR 2002, FedRAMP boundaries for computing environments, and human-subjects review when citizen data is involved.

Why This Matters for Government

Academic and research collaboration is not a nice-to-have for government AI leaders; it is the primary mechanism by which federal agencies obtain independent, peer-reviewed evidence that their AI systems work as claimed. Unlike a private firm whose customers can walk away, an agency holds a monopoly of service: the IRS is the only IRS, CBP is the only CBP, the VA is the only path to earned veterans benefits, and the Social Security Administration is the only payer of retirement and disability benefits. That monopoly raises the evidentiary bar. Citizens cannot choose a competitor if the agency's facial verification, fraud-detection, or eligibility-adjudication model fails them. Academic partnerships create a scientific record contemporaneous with deployment, rather than a retrospective reconstruction assembled after litigation, journalism, or inspector general reports force the issue.

The case record is unambiguous. The IRS rollout of ID.me facial verification in 2022 collapsed within weeks after public reporting, Senate letters from Wyden, Warren, and Menendez, a Treasury Inspector General for Tax Administration (TIGTA) review, and sustained pressure from civil society. A standing partnership with academic vision and biometrics laboratories, with published protocols for demographic performance testing anchored to NIST Special Publication 1270 on bias in AI and NIST Interagency Report 8280 on face recognition vendor test demographics, would almost certainly have surfaced the failure modes before the system ever interacted with a taxpayer. Michigan's MIDAS (Michigan Integrated Data Automated System) generated roughly 40,000 false fraud accusations between 2013 and 2015; court records and subsequent Auditor General reviews showed no external academic peer review of the underlying classifier, no published disparate impact analysis, and no IRB-equivalent human subjects protection for claimants. The state ultimately paid more than twenty million dollars in settlements and adopted legislation restricting fully automated adjudication, but the harms to unemployed workers and their families were irreversible. The Dutch childcare benefits scandal (toeslagenaffaire) forced the resignation of the Rutte III cabinet in January 2021 after tax authorities used risk models that disproportionately flagged dual-nationality families, while SyRI was struck down by The Hague District Court in 2020 for violating Article 8 of the European Convention on Human Rights due to inadequate scientific validation and transparency.

OMB Memorandum M-24-10 (March 2024) operationalized these lessons for US federal agencies. It directs each agency to designate a Chief AI Officer (CAIO), publish a use-case inventory, identify rights-impacting and safety-impacting AI, and apply minimum risk management practices that include independent evaluation, impact assessments, and ongoing monitoring. Few agencies have in-house capacity to perform model evaluation, red-teaming, disparate impact testing, and sociotechnical impact assessment at the depth M-24-10 requires. That capacity gap is precisely where academic collaboration, FFRDC engagement with MITRE, RAND, Aerospace, and IDA, and NIST AI Safety Institute partnerships become load-bearing. Executive Order 14110 (October 2023) layered additional obligations: NIST leads AI red-teaming guideline development, Commerce established the AI Safety Institute, and dual-use foundation model developers face reporting obligations that require evaluation methodologies built with the academic community. The National AI Research Resource (NAIRR) pilot, launched January 2024 by NSF with NIH, DOE, VA, NASA, NOAA, USDA, and other partners, is the single most important operational vehicle for academic collaboration created in the last decade because it allows university researchers to access agency-relevant compute, datasets, and models alongside federal staff under a coherent governance model.

For the Chief AI Officer or AI Visionary operating at L5, the practical implications are concrete. First, build academic partnerships before deploying rights-impacting AI, not after the press release. The CBP Biometric Entry/Exit program illustrates the inverse pattern: deployment preceded the academic relationships, and the DHS OIG (including OIG-22-49) found weak external validation as a result. Second, select the right contracting vehicle for the research question: grants for exploratory work, cooperative agreements where agency staff co-develop methodology, FAR Part 35 R&D contracts for agency-directed deliverables, CRADAs under 15 USC 3710a for federal labs including NIST, and Other Transaction Authorities for DOD, DHS, HHS BARDA, FAA, DOE, and NASA prototype work. Third, respect the governance layer: confirm the use case is in the agency's M-24-10 inventory, scope the AI Impact Assessment, align data sharing with the Privacy Act of 1974 and any applicable System of Records Notices, secure the FISMA and NIST SP 800-53 control baseline for shared computing environments, and bound disparate impact testing to NIST AI RMF MEASURE 2.11 and EEOC Uniform Guidelines. Fourth, negotiate IP and publication terms that honor both academic norms and federal data stewardship: government purpose rights, Bayh-Dole preservation (35 USC 200-212), a 30 to 90 day pre-publication security review, and an explicit agreement that review cannot suppress findings the agency finds inconvenient. Fifth, sustain funding over multi-year horizons using 5-year center grants modeled on NSF Science and Technology Centers or NIH P-series, FFRDC core support, and 501(c)(3) foundation co-funding (CDC Foundation, Foundation for the NIH, Reagan-Udall Foundation) cleared by agency counsel against the Antideficiency Act and augmentation-of-appropriations doctrine. This lecture makes those moves concrete through case studies of the NIST AI Safety Institute Consortium (AISIC), the VA National Artificial Intelligence Institute with its academic affiliate network covering over ninety percent of US medical schools, the NSF Institutes for Trustworthy AI, DARPA and IARPA broad agency announcements, and the contrasting weak-tie patterns at CBP and the IRS. The goal is not to prescribe one vehicle but to equip AI Visionaries to choose among the five vehicles, structure the governance layer, and build partnerships that produce evidence good enough to defend in GAO audits, congressional hearings, judicial review, and the court of public opinion.

Overview

Government agencies operate under statutory missions, appropriated budgets, and public-trust expectations that private firms do not share. When an agency deploys AI, citizens cannot choose an alternative vendor: the IRS is the IRS, CBP is CBP, and the VA is the only path to earned veterans benefits. That monopoly of service raises the bar for evidence. Academic and research collaboration is how agencies obtain independent, peer-reviewed evidence about whether AI systems work, for whom, and under what conditions.

The stakes are concrete. The IRS ID.me facial-verification rollout in 2022 illustrated what happens when agencies deploy AI-adjacent identity systems without independent evaluation: within weeks, Senators Warren, Wyden, and others demanded GAO review, Treasury IG opened inquiries, and the agency reversed course. A standing research partnership with academic vision and biometrics labs could have surfaced the failure modes before deployment. Michigan's MIDAS unemployment fraud detection system generated roughly 40,000 false fraud accusations between 2013 and 2015; court records showed no external validation, no academic peer review of the underlying model, and ultimately more than $20M in settlements plus legislation to restrict automated adjudication. In the Netherlands, SyRI was struck down by The Hague District Court in 2020 for violating Article 8 of the European Convention on Human Rights in part because it lacked transparent scientific validation. The Dutch childcare benefits (toeslagenaffaire) scandal forced the resignation of the Rutte III cabinet in January 2021.

These cases share a pattern: agencies built or bought AI, deployed it against citizens, and only learned about systemic errors through litigation, journalism, or inspector general reports. Academic collaboration changes that timeline. When NIST runs evaluations through the AI Safety Institute Consortium, when NSF funds university Institutes for Trustworthy AI, when the VA's academic affiliate agreements extend to algorithm auditing, agencies build a scientific record that is contemporaneous with deployment rather than retrospective.

OMB Memorandum M-24-10 (March 2024) made this operational. It directs federal agencies to identify rights-impacting and safety-impacting AI, designate Chief AI Officers, publish use-case inventories, and apply minimum risk management practices that include independent evaluation. M-24-10 does not mandate academic collaboration by name, but in practice many agencies lack in-house capability for model evaluation, red-teaming, and impact assessment at the required depth. Partnerships with universities, FFRDCs such as MITRE and RAND, and the NIST AI Safety Institute fill that gap.

Executive Order 14110 (October 2023) layered on top: it required NIST to develop AI red-teaming guidelines, directed the Department of Commerce to establish the AI Safety Institute, and created reporting obligations for dual-use foundation models. The National AI Research Resource (NAIRR) pilot, launched January 2024 by NSF with interagency partners including NIH, DOE, VA, NASA, NOAA, and USDA, was explicitly designed so academic researchers could access compute, data, and models alongside agency staff. For AI Visionaries at the L5 level, NAIRR is the single most important operational vehicle for academic collaboration created in the last decade.

LECTURE #

DURATION: ~120 minutes seminar including case discussion
FORMAT: Lecture with scenario-based breakouts and policy memo exercise
AUDIENCE: Agency heads, Chief AI Officers under OMB M-24-10, national AI leaders, research program managers
PREREQUISITES: L1-L4 foundation modules; familiarity with NIST AI RMF, OMB M-24-10, and FAR Part 35 research contracts

OPERATING MODEL FOR GOVERNMENT-ACADEMIC RESEARCH COLLABORATION

1) THE FIVE VEHICLES

Agencies have five primary legal instruments for engaging academia. Each has distinct rules and best uses.

(a) Grants under the DATA Act and 2 CFR 200. Used by NSF, NIH, DOE Office of Science, and mission agencies with research authorities. Researchers have substantial autonomy; agency involvement is limited. Good for exploratory work that does not require agency-specific data.

(b) Cooperative agreements. Similar to grants but with substantial federal involvement. Good when agency staff will co-develop methodology, as in NIST-academic measurement science programs or CDC public health AI pilots.

(c) Procurement contracts under FAR Part 35 (Research and Development Contracting). Agency directs the work; researcher delivers specific outputs. Used heavily by DOD, DHS S&T, and intelligence community mission research. Data rights under FAR 52.227-14.

(d) Cooperative Research and Development Agreements (CRADAs) under 15 USC 3710a. Allows federal labs and by extension FFRDCs to collaborate with non-federal parties. NIST uses CRADAs extensively. CRADAs permit flexible IP terms and protect proprietary data.

(e) Other Transaction Authority (OTA). Used by DOD, DHS, HHS/BARDA, FAA, DOE, and NASA for prototype and production OT agreements. Flexible, but requires Section 815 consortium or nontraditional contractor participation in many cases. DIU has executed more than $5B in OTAs since 2016, many involving academic teams.

2) THE GOVERNANCE LAYER

Before signing any vehicle, the agency Chief AI Officer (CAIO), per OMB M-24-10 Section 3, must confirm: (i) the use case is in the agency's inventory; (ii) for rights- or safety-impacting AI, an AI Impact Assessment has been completed or is scoped into the research; (iii) data sharing is consistent with the Privacy Act of 1974 (5 USC 552a), HIPAA where applicable, and agency System of Records Notices (SORNs); (iv) information security boundaries are defined under FISMA and NIST SP 800-53; and (v) the research plan identifies disparate impact testing anchored to NIST AI RMF MEASURE 2.11 and EEOC Uniform Guidelines.

3) IP AND DATA RIGHTS

The default under FAR 52.227-14 is government purpose rights. Universities typically want to publish, retain pre-existing IP, and license to spinouts. The negotiation usually settles on: (i) agency nonexclusive, irrevocable, royalty-free license for government purposes; (ii) university retention of copyright and patent subject to Bayh-Dole (35 USC 200-212); (iii) a pre-publication review window of 30-90 days for security and PII; (iv) march-in rights preserved; (v) data provided by the agency remains agency data and subject to the Privacy Act.

4) SECURITY AND COMPUTE

Where academic teams need agency data, options are: (i) synthetic or de-identified data; (ii) agency-controlled enclaves on FedRAMP Moderate or High environments (AWS GovCloud, Azure Government); (iii) NAIRR pilot compute with federated data access; (iv) FFRDC-hosted environments (MITRE's NII, RAND's secure computing); (v) classified SCIFs for DOD and IC work. Each option has cost, latency, and talent-retention tradeoffs. Universities that cannot support cleared staff at scale will need the enclave route.

5) PUBLICATION AND TRANSPARENCY

Agency pre-publication review must be bounded in time and scope to avoid chilling academic work. A strong template: review limited to (a) release of CUI, (b) exposure of vulnerabilities with active exploitation risk, (c) factual accuracy about agency programs. Review not permitted for: disagreement with findings, embarrassment, or policy preferences. The NIH, NASA, and NOAA have mature models here. DHS S&T and DOD research offices are catching up under EO 14110.

6) FUNDING STRATEGIES

Sustained academic partnerships require predictable funding. Single-year grants produce brittle relationships and high turnover. Stronger models: (i) 5-year center grants modeled on NSF Science and Technology Centers, AI Research Institutes, or NIH P-series; (ii) agency contributions to FFRDC core programs; (iii) philanthropic co-funding through 501(c)(3) foundations attached to the agency (e.g., CDC Foundation, Foundation for the NIH, FDA Reagan-Udall) which can accept non-appropriated gifts; (iv) NAIRR compute credits as in-kind support. The Antideficiency Act (31 USC 1341) and augmentation-of-appropriations doctrine must be respected; agency counsel must clear philanthropic co-funding models.

7) COMMON PITFALLS

(i) Using academic partners as cheap labor without integrating findings into policy. Research that sits on shelves is malpractice. (ii) Publishing findings without agency context so journalists misread results. (iii) Letting COI reviews under 5 CFR 2635 slip; dual-appointment faculty with vendor relationships trigger 18 USC 208 concerns. (iv) Sharing agency data under weaker terms than the Privacy Act requires. (v) Accepting vendor-funded academic work that is effectively marketing. (vi) Failing to brief Congressional committees, which guarantees appropriations trouble later.

CASE STUDY: NIST AI SAFETY INSTITUTE CONSORTIUM (AISIC)

Stood up in February 2024 with 200+ members including universities (Stanford, CMU, MIT, Berkeley), companies (OpenAI, Anthropic, Microsoft, Google), civil society (CDT, Data and Society), and standards bodies. AISIC is the largest single government-academic AI collaboration in US history. Its working groups produce guidance that feeds NIST AI 600-1 (Generative AI Profile) and supports EO 14110 deliverables. AISIC shows both the power of consortia (scale, diversity, speed) and risks (governance complexity, IP tensions, regulatory capture concerns).

CASE STUDY: VA ACADEMIC AFFILIATIONS

The Veterans Health Administration has academic affiliations with 90%+ of US medical schools. Originally for clinical training, these relationships now support AI evaluation work including the VA's National Artificial Intelligence Institute (NAII) launched in 2019 and extended under OMB M-24-10. The VA has learned to structure IRB review, data use agreements under the VA's Privacy Act SORNs, and VA Directive 1605.1 privacy controls so academic researchers can work on sensitive veteran data at scale.

CASE STUDY: CBP AND ACADEMIC COLLABORATION GAPS

Customs and Border Protection has deployed facial recognition at airports under the Biometric Entry/Exit program. Academic reviewers have criticized disparate performance across demographic groups. The DHS OIG issued reports (OIG-22-49 among others) identifying weak external validation. CBP's relationships with academia are thinner than the VA's. The policy lesson for AI Visionaries: an agency's academic partnerships precede its AI deployments, not follow them. Build the research infrastructure before the procurement.

Start Your CLUB Certification

This seminar is part of L5: AI Visionary, which totals 160 hours of government AI leadership training aligned to NIST AI RMF, OMB M-24-10, EO 14110, and ISO/IEC 42001. Completion of all L5 modules plus a capstone change-strategy memo qualifies the learner for CLUB Level 5 (AI Visionary) certification.

Explore CLUB Certification and the L5 capstone requirements at skill.re/govt.

L5
5.5.1 -- Publishing on Government AI
180 min - Workshop

L5
5.5.2 -- Speaking and Presenting on Government AI
180 min - Workshop + Practice

L5
5.5.3 -- Mentoring Next-Generation Leaders
120 min - Seminar + Program Design