AIR FOR GOVERNMENT

Public Trust Runs on Whether Your AI Is Governed or Just Happening

AIR scores how ready your agency is to deliver mission outcomes with AI that is embedded, accountable, and defensible to the public, auditors, and oversight.

OMB AI memos, the NIST AI RMF, and FedRAMP authorization now set real expectations, and shadow AI is already in your inboxes and case files whether you have governed it or not.

What AIR measures

Five pillars, read for Government.

The same five pillars of AI readiness, framed in the work, systems, and stakes that public-sector and agency leaders actually face.

P1Service Delivery Operating Model

AI is built into how the agency actually processes cases, claims, and constituent requests, with documented SOPs and reusable assets instead of know-how trapped in a few analysts.

P2Mission Outcomes & Stewardship

AI changes what the agency delivers and how it justifies its budget, turning freed capacity into faster service, better outcomes, and defensible stewardship of public funds.

P3Workforce Capability

AI fluency is broad and owned across the civil-service workforce, with reskilling, redefined position descriptions, and a workforce that reads AI as augmentation rather than RIF risk.

P4Governance, Compliance & Risk

AI use sits inside real policy, authorization, records, and privacy controls aligned to FISMA, the NIST AI RMF, and OMB direction, with QC on outputs that affect the public.

P5Tool Standardization & Authorization

The AI stack is a deliberate, owned, FedRAMP-authorized footprint with named owners, selection criteria, and a review cadence, not an unaccountable sprawl of unauthorized tools.

The AIR rating

Six tiers, Legacy to Autonomous.

AIR places Government on a six-tier readiness ladder from 0 to 100, overall and for every pillar. The climb runs from digital but not intelligent, to a compounding, AI-native edge.

6

Autonomous

85–100

AI-native advantage. Compounding intelligence and speed, a durable edge competitors can't copy fast.

5

Integrated

68–84

Woven through the business. AI shapes the operating model, pricing, and talent, and ROI is proven.

4

Operational

51–67

AI in the core, governed. Embedded at named steps with SOPs, policy, and measured gains.

3

Adopting

34–50

Pockets, not a system. Real use in places, uneven and undocumented.

2

Reactive

17–33

Experimenting at the edges. Scattered pilots that live in a few people's heads, ungoverned.

1

Legacy

0–16

Digital, not intelligent. AI is absent or anecdotal, work is hour-priced, the stack sprawls, and no policy exists.

The point

One score tells you that you are behind; five tiers tell you exactly where to start.

The deep diagnostic

Every pillar, climbed for Government.

The matrix is a 5-by-6 grid: your five pillars of AI readiness scored against the same six tiers, from Legacy to Autonomous. A single overall score tells you roughly where you sit; it hides where you are dangerously behind and where you are quietly ahead. Reading a tier per pillar turns one vague number into five specific, fixable verdicts, so you act on the truth instead of an average.

P1

Service Operating Model

Casework & AdjudicationConstituent ChannelsReusable AssetsProcess OwnershipPerformance MeasurementLegacy System Fit
LegacyAutonomous
Legacy
Casework runs on legacy systems and manual review with no AI in the workflow.
Autonomous
AI-native delivery compounds: backlogs self-clear and intake routes itself end to end.
P2

Service Delivery & Public Value

Constituent OutcomesService DesignProcurement & AcquisitionStewardship of FundsMission Impact
LegacyAutonomous
Legacy
Services and budget justifications are defined exactly as they were pre-AI.
Autonomous
AI-native delivery sets the bar; the agency does more mission per dollar, durably.
P3

Workforce & AI Capability

AI Fluency BreadthRole RedefinitionReskilling PipelineSpecialist RolesWorkforce Sentiment
LegacyAutonomous
Legacy
Staff have no AI skills and no mandate or pathway to build them.
Autonomous
An AI-fluent workforce sets the standard; capability compounds and attracts talent.
P4

Governance, Risk & Compliance

AI Policy & MemosRisk FrameworkAuthorization & SecurityPrivacy & RightsTransparency & RecordsOutput QC
LegacyAutonomous
Legacy
No AI policy exists and shadow use evades FISMA, FedRAMP, and the Privacy Act.
Autonomous
Governance is a built-in advantage; compliance is automated and provably auditable.
P5

Tool Standardization & Stack

Stack FootprintSelection CriteriaOwnership & SpendIntegrationRefresh Cadence
LegacyAutonomous
Legacy
No AI tools are sanctioned and no one owns AI selection or spend.
Autonomous
A defensible, owned platform compounds value and steers spend with discipline.
Governance and compliance

Where the rules bite.

How Government's regulatory reality maps onto AIR readiness. Each row is a control your governance pillar has to carry.

RegimePillarWhat AI readiness requires
FedRAMP / StateRAMPP5AI services that process federal or state data hold an appropriate FedRAMP or StateRAMP authorization before production use, with the stack owned and inventoried.
FISMA (NIST SP 800-53)P4AI systems are categorized and brought under the agency's ATO and continuous-monitoring program with security controls documented and assessed.
NIST AI RMF (AI 100-1)P4AI use is mapped, measured, and managed against the Govern, Map, Measure, Manage functions, with documented risk decisions for higher-impact uses.
OMB AI memos (M-24-10 / M-24-18)P4Rights- and safety-impacting AI carries the required impact assessments, human oversight, and the agency reports inventory and a designated Chief AI Officer.
Privacy Act of 1974 & PIA requirementsP4AI uses of records in a system of records are covered by a current SORN and a Privacy Impact Assessment before personal data flows through any model.
Section 508 (Rehabilitation Act)P2AI-generated content and AI-driven constituent interfaces meet accessibility standards so public-facing service does not exclude people with disabilities.
Public records & FOIA / open-records lawsP1AI-assisted decisions and communications are retained, logged, and producible under records-retention schedules and FOIA or state open-records obligations.
Federal & state procurement rules (FAR / GSA)P5AI tools are acquired through compliant vehicles with selection criteria, ownership, and spend visibility, not expensed or adopted outside procurement.

Illustrative mapping for AI-readiness planning, not legal or compliance advice; validate against current federal, state, and local regulation and your authorization requirements with qualified counsel.

The stakes

What stalling looks like.

Shadow AI in casework and correspondence

Staff paste constituent records, benefit claims, or investigative material into consumer chatbots with no authorized tool or policy, creating an unauthorized disclosure and a privacy violation waiting to surface.

Automated decisions without a human in the loop

AI screens eligibility, flags fraud, or triages cases and the output becomes the de facto decision, exposing the agency to due-process challenges and bias claims when no official reviews it.

Records and FOIA blind spots

AI-assisted drafts, prompts, and model outputs are not captured under retention schedules, so the agency cannot produce them on a FOIA request or reconstruct how a decision was reached.

Unauthorized tools outside the boundary

AI services without FedRAMP or StateRAMP authorization process government data outside the assessed boundary, breaking the ATO and the agency's FISMA posture.

Bias and inequity in public-facing service

Unvalidated models produce uneven outcomes across communities or inaccessible interfaces, turning an efficiency project into a civil-rights, Section 508, and public-trust liability.

Start now

Signature quick wins for Government.

Concrete first moves you can make before the full diagnostic, one per pillar where it matters most.

P4

Ship a one-page acceptable-use policy

Publish a short AI usage policy that names approved tools, bans pasting records or PII into consumer AI, and have every employee and contractor acknowledge it.

Days
P5

Inventory and authorize the stack

Run a 30-day inventory of every AI tool in use, flag anything without FedRAMP or StateRAMP authorization, and route it to procurement and your CAIO for a decision.

Weeks
P1

Turn one workflow into an SOP

Pick one high-volume process like FOIA triage or constituent correspondence, document where AI assists and where a human signs off, and make it a shared standard.

Weeks
P4

Stand up an AI use-case inventory

Create the OMB-aligned inventory of AI uses, tag rights- and safety-impacting cases, and assign each an accountable owner and a risk review.

Weeks
P3

Name an AI capability owner

Designate an AI lead with protected time and run one role-specific session for a frontline program team so fluency stops living in two enthusiasts.

Days
P2

Measure one mission outcome

Baseline cycle time or backlog on one service line before and after AI so freed capacity becomes a defensible stewardship and budget story, not an anecdote.

Weeks

Find out where your organization stands.

The old transformation is finished. The new one is scored.