What is this course about?
Agency AI governance is distinguished from private-sector governance by public accountability: the inventory may be published, the impact assessment may be challenged, and the incident will be reported. This course builds the program with that in mind — a review board with real authority, impact assessment for rights-affecting uses, and transparency reporting.
Who is this course for?
- Agency AI governance leads and responsible AI officers
- CIOs and deputy CIOs
- Program managers deploying AI
- Inspectors general and internal audit staff
What do I need before starting?
- Familiarity with your agency's existing governance structures
- No technical background required
What will I be able to do afterwards?
- Build an AI use-case inventory that captures unapproved deployments
- Stand up a review board with authority that is actually exercised
- Conduct impact assessment for rights- and safety-affecting uses
- Run NIST AI RMF as an agency operating rhythm
- Publish transparency reporting that withstands scrutiny
What does each module cover?
What is in your AI use-case inventory?
50 minThe first deliverable, including the deployments no one told governance about.
Objectives
- Define inventory scope for an agency context
- Discover unapproved and embedded AI use
- Capture the attributes governance actually needs
Topics
Activity. Run discovery in one program area and inventory everything found.
How do you stand up a board with real authority?
50 minMembership, delegation, and the authority to say no in a way that holds.
Objectives
- Define board composition and delegated authority
- Design a review process program staff will use
- Establish escalation for contested decisions
Topics
Activity. Draft the board charter and run a mock review of two real use cases.
How do you assess a rights-affecting use?
55 minImpact assessment for uses that affect eligibility, enforcement, or access to a service.
Objectives
- Identify rights- and safety-affecting uses
- Conduct a structured impact assessment
- Determine mitigations and residual risk
Topics
Activity. Complete an impact assessment for one live rights-affecting use case.
How does NIST AI RMF become an operating rhythm?
45 minTurning the framework into recurring agency activity with named owners.
Objectives
- Translate the four functions into agency activities
- Assign ownership within the agency structure
- Set cadence tied to real triggers
Topics
Activity. Design the operating rhythm with named owners and triggers.
How do you test for bias in an agency system?
50 minBias testing where the affected population is the public and the evidence may be discoverable.
Objectives
- Design bias testing for agency use cases
- Choose comparison groups defensibly
- Document findings knowing they may be disclosed
Topics
Activity. Design and run a bias test for one deployed system.
What should the agency publish?
45 minTransparency reporting that satisfies accountability without creating exploitable detail.
Objectives
- Determine what to publish and at what granularity
- Balance transparency against security concerns
- Design the public inventory page
Topics
Activity. Draft the public AI inventory page for your agency.
How do you handle an AI incident publicly?
45 minIncident response when the after-action review may be requested and reported.
Objectives
- Define what constitutes a reportable AI incident
- Run response and after-action review
- Communicate publicly without compounding the harm
Topics
Activity. Tabletop an AI incident including the public communication.
Assembling the governance program
50 minThe workshop module: inventory, board, assessments, and rhythm assembled.
Objectives
- Assemble the complete program
- Verify coverage of agency obligations
- Plan rollout across program areas
Topics
Activity. Assemble the program and present it to agency leadership.
What is the capstone project?
Agency AI governance program
Produce a complete governance program: use-case inventory with discovery results, board charter with exercised authority, a completed impact assessment for a rights-affecting use, bias test results, the NIST operating rhythm, and a public transparency page.
Deliverable: A governance program with one real impact assessment and a draft public inventory.
How are learners assessed?
- Inventory assessed on whether discovery found unapproved deployments
- Impact assessment reviewed for whether it could conclude against deployment
- Public page reviewed by communications and counsel
What ships with the course?
Facilitator guide
Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
Learner workbook
Exercises, checklists, and the templates each module's activity produces.
Hands-on lab environment
A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
Assessment bank
Scenario questions and rubric criteria mapped to each stated learning outcome.
Source bibliography
Every primary regulation and standard cited on this page, linked and dated.
Which AI agents does this course use?
The hands-on modules run against agents already deployable on the ibl.ai platform for government.
Where does the course material come from?
Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.
- AI Risk Management Framework
NIST
The framework the agency operating rhythm is built from.
- NIST AI 600-1, Generative AI Profile
NIST
Generative-AI-specific risks the impact assessment must address.
- AI Guide for Government
GSA Centers of Excellence
Federal practice guidance for agency AI governance.
- Office of Management and Budget
OMB
Executive branch AI policy direction shaping agency obligations.
Delivery notes
Binding guidance for anyone preparing and delivering this course.
- Module 3's impact assessment must be capable of concluding against deployment. An assessment process that has never stopped anything is a documentation exercise and the audience will recognize it.
- Federal AI policy direction changes with administrations. Verify current OMB direction at each revision rather than citing a specific memo that may be superseded.
- Module 5's documentation-under-disclosure framing is specific to government and important. Findings written knowing they may be published are written differently, and usually better.
- Module 1's discovery will find embedded vendor AI nobody classified as AI. Build the discovery method to catch features shipped inside existing systems.
- Coordinate with GOV-1 — governance and authorization overlap, and the impact assessment should feed the authorization package rather than duplicating it.
Why run AI training on a platform you own?
You own the course, not a licence to it
Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
Model-agnostic delivery
Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
No per-seat training licences
Usage-based or self-hosted, so cost tracks actual use rather than headcount.
Deploy anywhere
Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.
Frequently asked questions
What does the AI Governance Inside a Public Agency course cover?
Agency AI governance is distinguished from private-sector governance by public accountability: the inventory may be published, the impact assessment may be challenged, and the incident will be reported. This course builds the program with that in mind — a review board with real authority, impact assessment for rights-affecting uses, and transparency reporting. It runs 6 hours across 8 modules across 8 modules, at intermediate level, and closes with a capstone: Agency AI governance program.
Who should take AI Governance Inside a Public Agency?
It is written for Agency AI governance leads and responsible AI officers, CIOs and deputy CIOs, Program managers deploying AI, Inspectors general and internal audit staff. Prerequisites: Familiarity with your agency's existing governance structures; No technical background required.
Can we run this course on our own infrastructure?
Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for government teams that cannot send work to a public AI tool.
How do we get access to AI Governance Inside a Public Agency?
Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.
How much does AI training for government cost on ibl.ai?
There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.