Open Government and AI
Learning Objectives
By the end of this lecture, you will be able to: (1) articulate how the three pillars of Open Government (transparency, participation, collaboration) apply to federal AI systems under OMB Memorandum M-24-10 and Executive Order 14110; (2) operate the public federal AI Use Case Inventory that OMB requires every CFO Act agency to publish annually, including the enrichment required by OMB M-24-10 for rights-impacting and safety-impacting systems; (3) publish training data, evaluation datasets, and model cards on data.gov and code.gov using the Federal Data Strategy 2020 Action Plan and the Evidence-Based Policymaking Act (Title II of the Foundations for Evidence-Based Policymaking Act of 2018, commonly called the OPEN Government Data Act); (4) decide when to release model weights, when to release only inference APIs, and when to publish nothing beyond a capability description, using the NIST AI RMF 1.0 GOVERN 1.3 criterion on disclosure; (5) apply FOIA, the Privacy Act of 1974, and Trade Secrets Act section 1905 tests to determine what must, may, and must not be released about a given AI system; (6) read GAO reports such as GAO-23-106093 on federal AI inventories and translate the findings into concrete agency actions; (7) explain how 18F, USDS, GSA 10x, and the Technology Modernization Fund contribute open-source tooling like cloud.gov, login.gov client libraries, and the U.S. Web Design System to the AI ecosystem; (8) design a transparency program that respects FISMA controls, CUI marking under 32 CFR Part 2002, and ITAR/EAR export limits while still complying with the presumption of openness in the 2009 Open Government Directive M-10-06; and (9) critique your agency's current posture against peer agencies and against the OECD AI Principles on transparency and accountability.
Key Topics Covered
Topic 1: The statutory and policy basis for open government AI: the OPEN Government Data Act, the Federal Data Strategy, the 2009 Open Government Directive, Executive Order 13642 on Open Data, Executive Order 14110 section 10.1 on agency AI use case inventories, OMB M-24-10 sections 5 and 6 on transparency, and the President's Management Agenda priority on customer experience and digital services.
Topic 2: The federal AI Use Case Inventory: what fields OMB requires (name, purpose, stage of development, rights-impacting flag, safety-impacting flag, contracting vehicle, vendor), where inventories live (ai.gov/inventory plus individual agency pages such as HHS at hhs.gov/ai, VA at va.gov/ai, DHS at dhs.gov/ai), and how GAO-23-106093 and GAO-24-105980 found inventories incomplete at DHS, DOD, and State.
Topic 3: Open training data through data.gov: the Commerce Data Hub, NOAA big data partnerships, USGS landslide datasets, USDA crop data layers, Census Bureau microdata, and the problem of personally identifiable information, Controlled Unclassified Information, and law enforcement sensitive tags.
Topic 4: Open-source government AI code on code.gov, the 2016 Federal Source Code Policy M-16-21 requiring 20 percent of custom-developed code to be released, agile examples from 18F such as cloud.gov and federalist, the IRS Direct File public beta code release in 2024, and the NASA open science policy for Earth-observation AI models.
Topic 5: Model cards, datasheets, and system cards, the NIST AI RMF Playbook guidance on model cards, the Mitchell et al. 2019 model card framework adopted by NIST, and examples from Treasury, USPTO, and the National Library of Medicine PubMed model cards.
Topic 6: Limits on openness: FOIA Exemption 4 trade secrets, Exemption 7 law enforcement, the Privacy Act system-of-records notice requirements, the CUI framework, export control under ITAR and EAR, and the classified systems regime under Executive Order 13526.
Topic 7: Participation and collaboration. Notice-and-comment rulemaking under the Administrative Procedure Act, federal challenge.gov prize competitions, the Foundation for Evidence-Based Policymaking Act statistical learning agendas, and the OSTP Request for Information process on AI priorities.
Topic 8: Measurement: the Open Data Maturity Model, the OECD OURdata Index, GAO audits, and agency IG reports such as the DHS OIG report on CBP facial recognition transparency and the IRS TIGTA report on ID.me enrollment disclosures.
Why This Matters for Government
Open government and AI are joined by necessity, not ideology. A federal AI system that cannot be described to the public cannot be trusted by the public, and a system that cannot be trusted by the public cannot withstand the political pressure that follows its first mistake. The IRS learned this in 2022 when the agency's plan to require taxpayers to authenticate through ID.me using facial recognition was canceled within eight weeks of public disclosure, not because the technology failed, but because the disclosure had been late, partial, and reactive. By contrast, the U.S. Patent and Trademark Office published detailed documentation of its AI-assisted patent classification tool beginning in 2020, including model cards and error analyses, and the system continues operating with minimal controversy. Transparency did not protect the USPTO from every criticism, but it moved the debate from 'why are you hiding this' to 'how can we improve this,' which is the only debate governance can win.
The OMB M-24-10 memorandum, issued March 28, 2024, made four obligations concrete. First, each CFO Act agency must designate a Chief AI Officer. Second, each agency must publish an AI Use Case Inventory annually, with expanded fields for rights-impacting and safety-impacting systems. Third, each agency must certify minimum risk management practices for those flagged systems before December 1, 2024. Fourth, each agency must publish an AI Strategy describing governance, workforce, infrastructure, and public engagement. All four obligations rest on openness. An undisclosed system cannot be inventoried. An inventory without public access cannot be audited. A certification that nobody sees is a certification that nobody trusts.
Open government also supplies the raw material for better AI. The Census Bureau's release of decennial microdata under differential privacy, the NOAA Big Data Program's open climate datasets, the USGS Landsat archive, the National Library of Medicine's PubMed Open Access subset, and the Bureau of Labor Statistics' Current Population Survey all provide training data that permits external replication of federal models. When the Social Security Administration releases its Medical-Vocational Grid rules, external researchers can build shadow models and identify systematic errors, as Stanford's RegLab did when it found disability determination disparities. Without open data, those corrections happen only after an adverse GAO or OIG report and years of litigation.
The international comparison sharpens the case. The European Union AI Act, which entered into force August 1, 2024, requires high-risk AI providers to register systems in a public EU database. The OECD AI Principles, adopted in 2019 and updated in 2024, list transparency as one of five values-based principles. The UK Algorithmic Transparency Recording Standard, operated by the Central Digital and Data Office, requires every public-sector algorithm to be disclosed with a Tier 1 summary and a Tier 2 technical record. Countries that move first on transparency set the default, and the default becomes the floor for international cooperation. The United States had that leadership role under the 2013 Open Data Executive Order and the 2019 Federal Data Strategy; holding it through the AI transition is a policy choice, not a technical one.
Finally, open government AI is a civil service productivity strategy. When 18F built federalist.gov and released the source on GitHub, other agencies adopted the platform without procurement cycles. When USDS published the Digital Services Playbook, even state and local governments used it. When GSA's Technology Modernization Fund financed the shared identity service login.gov, the code that made it work became reusable across Veterans Affairs, the Small Business Administration, and the Office of Personnel Management. Open AI tooling, from evaluation harnesses to red-team datasets to safety classifiers, can follow the same model if agencies choose to release rather than hoard. The Chief Data Officer Council and the Federal CIO Council coordinate this work, and the Chief AI Officer Council established by OMB M-24-10 will now do the same for model artifacts. The cost of building twenty agency-specific document summarizers is roughly twenty times the cost of building one and sharing it. The latter is only possible in an open-government posture.
The Three Pillars of Open Government Applied to AI
Transparency, participation, and collaboration, the three pillars of the 2009 Open Government Directive M-10-06, map cleanly onto the AI lifecycle, but each requires specific adaptation.
Transparency for AI means disclosing the existence of the system (inventory), the function it performs (use case), the data it was trained on (dataset documentation), the model architecture and evaluation results (model card), the decision flows that rely on the output (process documentation), and the performance in production (monitoring dashboards). The NIST AI RMF 1.0 Playbook subcategory GOVERN 1.3 lists these as distinct disclosure decisions, each of which may be yes, no, or conditional. The DHS AI use case inventory, for example, discloses that Customs and Border Protection operates the Traveler Verification Service with facial comparison, but it does not disclose the underlying vendor algorithm accuracy parameters, which the DHS Privacy Office redacts under FOIA Exemption 4. Whether that redaction is correct is contested, the ACLU and the Electronic Privacy Information Center have argued it is not, but the inventory itself is the precondition for the argument. Without the inventory, there is nothing to contest.
Participation means giving the public a structured opportunity to shape the system before it is deployed and while it operates. The OSTP Request for Information on AI Priorities in July 2023 drew more than 10,000 responses and directly informed Executive Order 14110. The NIST AI Safety Institute Consortium, launched February 8, 2024, gave more than 200 organizations a formal role in shaping evaluation methodology. At the agency level, the VA's AI Oversight Committee held public listening sessions in 2024 on clinical decision support; the IRS Taxpayer Advocacy Panel reviews AI-assisted examinations; and the EPA EJScreen algorithmic environmental justice screening tool underwent three rounds of public comment before release.
Collaboration means treating outside expertise as an asset rather than a risk. The GSA 10x program funds internal teams but also partners with university researchers and civic tech organizations. The NIH Bridge2AI program uses a cooperative-agreement model to build biomedical AI datasets jointly with academic consortia. The Department of Defense Joint AI Center, renamed the Chief Digital and Artificial Intelligence Office in 2022, collaborates with Carnegie Mellon's Software Engineering Institute, MITRE ATLAS, and industry partners under the Tradewinds marketplace. The common thread is that government does not claim to be the sole source of expertise; instead, it builds the coordination structures that pool expertise.
Each pillar must be operationalized against legal constraints. Transparency cannot violate the Privacy Act. Participation cannot substitute for formal rulemaking when statutory due process applies. Collaboration cannot bypass the Federal Advisory Committee Act, which requires most standing outside-expert bodies to be chartered, balanced, and public. Experienced federal program managers learn to design around these constraints rather than ignore them, and the resulting programs, USDS's Digital Services Playbook, 18F's Methods library, the GSA AI Community of Practice, the Chief AI Officer Council, and the Chief Data Officer Council, are the scaffolding the federal AI workforce actually uses.
The Disclosure Decision Framework
When an agency builds or acquires an AI system, the default under the 2009 Open Government Directive is disclosure, and the burden falls on anyone arguing for concealment. The following framework, consistent with NIST AI RMF and OMB M-24-10, steps through the decision.
Step 1: Does the system exist? Every AI system operated by, on behalf of, or procured by a federal agency must be listed in the agency AI use case inventory unless it falls within the national security exception in EO 14110 section 11 or is a research-only system not used in operations. 'Every' means every, including commercial off-the-shelf tools like Microsoft Copilot for Microsoft 365 when configured for operational use, chatbots on agency websites, document classification tools behind the firewall, and fraud detection scoring used by program integrity offices. GAO-24-105980 found that DOD, State, and HHS were missing systems from their inventories; the IG follow-up in 2025 closed many of those gaps.
Step 2: What is the system's purpose, and whom does it affect? The purpose drives the rights-impacting and safety-impacting flags under OMB M-24-10. A system that determines eligibility for Social Security Disability Insurance or Supplemental Nutrition Assistance Program benefits is rights-impacting. A system that flags medical images at the VA for clinician review is safety-impacting. A system that routes emails inside an agency is neither. The flags determine which minimum practices apply and which additional documentation must be published.
Step 3: What documentation exists and can be published? Model cards, structured documents describing intended use, training data, evaluation metrics, limitations, and fairness considerations, should be produced for every rights-impacting and safety-impacting system. The USPTO Model Card for Patent Classification, the NLM PubMed model cards, and the Treasury OFAC sanctions screening system card are functional examples. When publishing a model card risks disclosing sensitive training data, the card can be redacted at the dataset-description level while preserving the evaluation and limitations sections.
Step 4: What statutory and executive limits apply? FOIA Exemption 1 covers classified information; Exemption 3 covers information protected by other statutes such as the Trade Secrets Act; Exemption 4 covers commercial information obtained from a person that is confidential under National Archives v. Favish standards and the 2019 Food Marketing Institute v. Argus Leader decision; Exemption 6 covers personal privacy; Exemption 7 covers law enforcement. Export controls under ITAR (22 CFR Parts 120-130) and EAR (15 CFR Parts 730-774) limit release of dual-use technology. The CUI framework under 32 CFR Part 2002 governs unclassified but sensitive information.
Step 5: What is the publication venue and cadence? The federal AI use case inventory at ai.gov/inventory is the baseline. Agency dashboards such as hhs.gov/ai, va.gov/ai, and dhs.gov/ai add detail. Code releases go to code.gov with SPDX license declarations. Datasets go to data.gov with DCAT-US metadata. Model weights go to Hugging Face or agency GitHub repositories with documented licenses (Apache 2.0 is common; the federal CC0 default applies to works of the U.S. government under 17 U.S.C. 105). Cadence should be at least annual and ideally continuous, with change logs that allow external researchers to track model updates.
Step 6: What is the response protocol when the public raises concerns? Every published system should have a named point of contact, a public comment mechanism, and a process for incorporating feedback. The EPA EJScreen documentation, the USPTO model cards, and the VA AI Oversight Committee letters to Congress demonstrate this practice. The GAO and agency OIG audit programs provide independent oversight.
Case Studies: What Goes Right, What Goes Wrong
The IRS ID.me episode is the canonical negative case. In 2021 the IRS quietly contracted with ID.me to require taxpayers accessing online services to authenticate through facial recognition and selfie verification. The arrangement was disclosed only in narrow procurement notices. When journalists at Krebs on Security and Bloomberg reported the change in January 2022, public backlash was immediate. Senator Ron Wyden led a bipartisan congressional response, and within weeks the IRS announced taxpayers could opt out of face capture and interact with a live agent instead. The Treasury Inspector General for Tax Administration issued report 2023-40-034 finding that the IRS had not completed a Privacy Impact Assessment consistent with the E-Government Act of 2002 before deploying the change. The lesson: transparency delayed is trust destroyed. A published use case, a public PIA, and a notice-and-comment window would have surfaced the same concerns during design rather than after launch.
The Michigan Integrated Data Automated System (MIDAS) is the state counterpart. Between 2013 and 2015 the Michigan Unemployment Insurance Agency used MIDAS to auto-adjudicate fraud allegations against claimants, with a false-positive rate exceeding 90 percent and thousands of wrongful determinations. The state did not publish documentation of the algorithm, did not allow claimants to see the evidence against them in a timely way, and did not maintain an audit trail sufficient to reconstruct decisions. The Sixth Circuit Court of Appeals in Cahoo v. SAS Analytics addressed civil rights claims; the settlement exceeded $20 million. The federal lesson is that rights-impacting automated decision systems without published logic and without human review are legally and politically unsustainable.
The Dutch childcare benefits scandal (toeslagenaffaire) drove home the same point in Europe. Between 2013 and 2019 the Belastingdienst used risk classification including a nationality variable to flag childcare benefit claims as potentially fraudulent. Tens of thousands of families were falsely accused, forced to repay benefits, and in some cases lost custody of children. A parliamentary inquiry in 2020 and the resignation of the Rutte III cabinet in January 2021 followed. The Dutch Data Protection Authority fined the tax administration €2.75 million, and the EU cited the case during AI Act negotiations as evidence that automated decision systems in the public sector require mandatory transparency, human oversight, and redress mechanisms.
Positive examples exist too. The USPTO released model cards for its patent classification AI in 2020 and has iterated them with user feedback. The National Library of Medicine's PubMed AI retrieval stack publishes evaluation datasets and baseline results. The Census Bureau's disclosure-avoidance system for the 2020 decennial census, while contested, was documented with unprecedented detail in peer-reviewed publications and public workshops. The General Services Administration's 18F publishes almost all its code at github.com/18F and github.com/GSA. The VA's Algorithmic Assurance Working Group publishes internal guidance for clinical AI and contributes to the Coalition for Health AI. Each of these programs faced criticism, but the criticism sharpened the programs rather than destroying them, precisely because the programs were open enough to absorb feedback without collapsing.
Implementation Playbook for Your Agency
Step A: Inventory. Within 30 days, convene your Chief AI Officer, Chief Data Officer, Senior Agency Official for Privacy, and General Counsel to list every AI system in use, under development, or contracted. Use the OMB M-24-10 inventory template, not an agency-specific variant. Map each system to the rights-impacting and safety-impacting flags. Disclose the inventory at your agency AI landing page and cross-link to ai.gov/inventory.
Step B: Documentation. For every rights-impacting and safety-impacting system, produce a model card following the Mitchell et al. 2019 template, a Privacy Impact Assessment under Section 208 of the E-Government Act, and a system-of-records notice if the system holds records retrievable by personal identifier under the Privacy Act. The VA and USPTO examples are usable templates. Publish them.
Step C: Data. For every model trained on agency data, publish the training dataset through data.gov if lawfully releasable. When not lawfully releasable, publish a dataset card describing what the dataset contains, how it was collected, what demographic groups are represented, and what preprocessing was applied. The National Institutes of Health Bridge2AI program publishes dataset cards even when the raw data is restricted to credentialed researchers.
Step D: Code. Release evaluation harnesses, preprocessing pipelines, and non-sensitive model code on code.gov or GitHub with a clear license. Apply OMB M-16-21, at least 20 percent of custom-developed code must be released as open source. Many agencies exceed this. The IRS Direct File project, 18F's federalist, the login.gov SDKs, and the NASA Earthdata tools are standard examples.
Step E: Participation. Publish notice-and-comment opportunities through regulations.gov when the AI system implements or affects a rule. For non-rule systems, use challenge.gov, agency listening sessions, and the NIST AI Safety Institute Consortium channels. Track comment volumes and responses; report them in the annual AI strategy update.
Step F: Collaboration. Enroll in the Chief AI Officer Council, the Chief Data Officer Council, and domain-specific bodies such as the Coalition for Health AI (CHAI) and the Federal Committee on Statistical Methodology. Use Federal Advisory Committee Act-chartered bodies like the National AI Advisory Committee for structured outside input.
Step G: Monitoring. Publish production performance dashboards for each rights-impacting and safety-impacting system. Include accuracy by demographic subgroup where defensible, error rate trends, and incident reports. The CFPB Consumer Complaint Database is a model for how a federal public dashboard can be both operationally useful and trust-building.
Step H: Review. Fold AI transparency into your annual Federal Information Security Modernization Act (FISMA) report, your Evidence Act learning agenda, your GAO audit responses, and your agency OIG coordination plan. The goal is not to add another compliance burden but to integrate open-government AI into the existing federal accountability architecture. When this works, openness stops being a separate program and becomes the default operating posture for the agency's AI work.
Related Lectures
This lecture connects to: 'Building Government AI Ecosystems' (5.2.1), 'Government AI Venture Creation' (5.2.2), 'Public-Private Innovation at Scale' (5.2.3), 'Community Engagement in Government AI' (5.2.7), 'AI and Democratic Governance' elsewhere in this batch, 'International Standards: EU AI Act and OECD' elsewhere in this batch, 'Rights-Impacting and Safety-Impacting AI Safeguards' elsewhere in this batch, and 'Ethics Boards and Advisory Structures' elsewhere in this batch. Cross-reference the NIST AI RMF 1.0 GOVERN function, OMB M-24-10 sections 5 and 6, and the UK Algorithmic Transparency Recording Standard for international context.
Skill.re