Service Operating Model
- Legacy
- Casework runs on legacy systems and manual review with no AI in the workflow.
- Autonomous
- AI-native delivery compounds: backlogs self-clear and intake routes itself end to end.
AIR scores how ready your agency is to deliver mission outcomes with AI that is embedded, accountable, and defensible to the public, auditors, and oversight.
OMB AI memos, the NIST AI RMF, and FedRAMP authorization now set real expectations, and shadow AI is already in your inboxes and case files whether you have governed it or not.
The same five pillars of AI readiness, framed in the work, systems, and stakes that public-sector and agency leaders actually face.
AI is built into how the agency actually processes cases, claims, and constituent requests, with documented SOPs and reusable assets instead of know-how trapped in a few analysts.
AI changes what the agency delivers and how it justifies its budget, turning freed capacity into faster service, better outcomes, and defensible stewardship of public funds.
AI fluency is broad and owned across the civil-service workforce, with reskilling, redefined position descriptions, and a workforce that reads AI as augmentation rather than RIF risk.
AI use sits inside real policy, authorization, records, and privacy controls aligned to FISMA, the NIST AI RMF, and OMB direction, with QC on outputs that affect the public.
The AI stack is a deliberate, owned, FedRAMP-authorized footprint with named owners, selection criteria, and a review cadence, not an unaccountable sprawl of unauthorized tools.
AIR places Government on a six-tier readiness ladder from 0 to 100, overall and for every pillar. The climb runs from digital but not intelligent, to a compounding, AI-native edge.
AI-native advantage. Compounding intelligence and speed, a durable edge competitors can't copy fast.
Woven through the business. AI shapes the operating model, pricing, and talent, and ROI is proven.
AI in the core, governed. Embedded at named steps with SOPs, policy, and measured gains.
Pockets, not a system. Real use in places, uneven and undocumented.
Experimenting at the edges. Scattered pilots that live in a few people's heads, ungoverned.
Digital, not intelligent. AI is absent or anecdotal, work is hour-priced, the stack sprawls, and no policy exists.
One score tells you that you are behind; five tiers tell you exactly where to start.
The matrix is a 5-by-6 grid: your five pillars of AI readiness scored against the same six tiers, from Legacy to Autonomous. A single overall score tells you roughly where you sit; it hides where you are dangerously behind and where you are quietly ahead. Reading a tier per pillar turns one vague number into five specific, fixable verdicts, so you act on the truth instead of an average.
How Government's regulatory reality maps onto AIR readiness. Each row is a control your governance pillar has to carry.
| Regime | Pillar | What AI readiness requires |
|---|---|---|
| FedRAMP / StateRAMP | P5 | AI services that process federal or state data hold an appropriate FedRAMP or StateRAMP authorization before production use, with the stack owned and inventoried. |
| FISMA (NIST SP 800-53) | P4 | AI systems are categorized and brought under the agency's ATO and continuous-monitoring program with security controls documented and assessed. |
| NIST AI RMF (AI 100-1) | P4 | AI use is mapped, measured, and managed against the Govern, Map, Measure, Manage functions, with documented risk decisions for higher-impact uses. |
| OMB AI memos (M-24-10 / M-24-18) | P4 | Rights- and safety-impacting AI carries the required impact assessments, human oversight, and the agency reports inventory and a designated Chief AI Officer. |
| Privacy Act of 1974 & PIA requirements | P4 | AI uses of records in a system of records are covered by a current SORN and a Privacy Impact Assessment before personal data flows through any model. |
| Section 508 (Rehabilitation Act) | P2 | AI-generated content and AI-driven constituent interfaces meet accessibility standards so public-facing service does not exclude people with disabilities. |
| Public records & FOIA / open-records laws | P1 | AI-assisted decisions and communications are retained, logged, and producible under records-retention schedules and FOIA or state open-records obligations. |
| Federal & state procurement rules (FAR / GSA) | P5 | AI tools are acquired through compliant vehicles with selection criteria, ownership, and spend visibility, not expensed or adopted outside procurement. |
Illustrative mapping for AI-readiness planning, not legal or compliance advice; validate against current federal, state, and local regulation and your authorization requirements with qualified counsel.
Staff paste constituent records, benefit claims, or investigative material into consumer chatbots with no authorized tool or policy, creating an unauthorized disclosure and a privacy violation waiting to surface.
AI screens eligibility, flags fraud, or triages cases and the output becomes the de facto decision, exposing the agency to due-process challenges and bias claims when no official reviews it.
AI-assisted drafts, prompts, and model outputs are not captured under retention schedules, so the agency cannot produce them on a FOIA request or reconstruct how a decision was reached.
AI services without FedRAMP or StateRAMP authorization process government data outside the assessed boundary, breaking the ATO and the agency's FISMA posture.
Unvalidated models produce uneven outcomes across communities or inaccessible interfaces, turning an efficiency project into a civil-rights, Section 508, and public-trust liability.
Concrete first moves you can make before the full diagnostic, one per pillar where it matters most.
Publish a short AI usage policy that names approved tools, bans pasting records or PII into consumer AI, and have every employee and contractor acknowledge it.
Run a 30-day inventory of every AI tool in use, flag anything without FedRAMP or StateRAMP authorization, and route it to procurement and your CAIO for a decision.
Pick one high-volume process like FOIA triage or constituent correspondence, document where AI assists and where a human signs off, and make it a shared standard.
Create the OMB-aligned inventory of AI uses, tag rights- and safety-impacting cases, and assign each an accountable owner and a risk review.
Designate an AI lead with protected time and run one role-specific session for a frontline program team so fluency stops living in two enthusiasts.
Baseline cycle time or backlog on one service line before and after AI so freed capacity becomes a defensible stewardship and budget story, not an anecdote.
The old transformation is finished. The new one is scored.