# AI Governance Inside a Public Agency

> Government · AI Course · GOV-6
> Source: https://ibl.ai/solutions/government/course/ai-governance-public-agency
> Last updated: 2026-08-25

**Stand up an agency AI governance program — inventory, use-case review board, impact assessment, and public transparency reporting.**

## The Short Answer

**Agency AI governance differs from private-sector governance because the inventory, the impact assessment, and the incident may all become public. ibl.ai supports governance on infrastructure the agency controls, where you own all the code and the data — so an impact assessment can examine the actual system rather than a vendor's description of it.**

On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and pay with no per-seat pricing — so you can deploy anywhere, from your own cloud to a fully air-gapped network.

[Request Access](https://ibl.ai/contact) · [Explore Government](https://ibl.ai/solutions/government)

## Course facts

- **Level:** Intermediate
- **Duration:** 6 hours across 8 modules
- **Format:** Cohort workshop producing governance artifacts
- **Modules:** 8
- **Catalog code:** GOV-6
- **Frameworks covered:** NIST AI RMF, NIST AI 600-1, OMB AI policy, Section 508

## What is this course about?

Agency AI governance is distinguished from private-sector governance by public accountability: the inventory may be published, the impact assessment may be challenged, and the incident will be reported. This course builds the program with that in mind — a review board with real authority, impact assessment for rights-affecting uses, and transparency reporting.

## Who is this course for?

- Agency AI governance leads and responsible AI officers
- CIOs and deputy CIOs
- Program managers deploying AI
- Inspectors general and internal audit staff

### What do I need before starting?

- Familiarity with your agency's existing governance structures
- No technical background required

## What will I be able to do afterwards?

- Build an AI use-case inventory that captures unapproved deployments
- Stand up a review board with authority that is actually exercised
- Conduct impact assessment for rights- and safety-affecting uses
- Run NIST AI RMF as an agency operating rhythm
- Publish transparency reporting that withstands scrutiny

## What does each module cover?

### Module 1 — What is in your AI use-case inventory?

The first deliverable, including the deployments no one told governance about. _(50 min)_

**Objectives**

- Define inventory scope for an agency context
- Discover unapproved and embedded AI use
- Capture the attributes governance actually needs

**Topics:** Inventory scope · Shadow AI discovery · Embedded vendor AI · Attribute capture

**Activity:** Run discovery in one program area and inventory everything found.

### Module 2 — How do you stand up a board with real authority?

Membership, delegation, and the authority to say no in a way that holds. _(50 min)_

**Objectives**

- Define board composition and delegated authority
- Design a review process program staff will use
- Establish escalation for contested decisions

**Topics:** Board composition · Delegated authority · Review process · Escalation

**Activity:** Draft the board charter and run a mock review of two real use cases.

### Module 3 — How do you assess a rights-affecting use?

Impact assessment for uses that affect eligibility, enforcement, or access to a service. _(55 min)_

**Objectives**

- Identify rights- and safety-affecting uses
- Conduct a structured impact assessment
- Determine mitigations and residual risk

**Topics:** Rights-affecting identification · Assessment methodology · Mitigation design · Residual risk

**Activity:** Complete an impact assessment for one live rights-affecting use case.

### Module 4 — How does NIST AI RMF become an operating rhythm?

Turning the framework into recurring agency activity with named owners. _(45 min)_

**Objectives**

- Translate the four functions into agency activities
- Assign ownership within the agency structure
- Set cadence tied to real triggers

**Topics:** Function translation · Agency ownership · Cadence · Trigger conditions

**Activity:** Design the operating rhythm with named owners and triggers.

### Module 5 — How do you test for bias in an agency system?

Bias testing where the affected population is the public and the evidence may be discoverable. _(50 min)_

**Objectives**

- Design bias testing for agency use cases
- Choose comparison groups defensibly
- Document findings knowing they may be disclosed

**Topics:** Bias testing design · Comparison groups · Documentation under disclosure · Remediation

**Activity:** Design and run a bias test for one deployed system.

### Module 6 — What should the agency publish?

Transparency reporting that satisfies accountability without creating exploitable detail. _(45 min)_

**Objectives**

- Determine what to publish and at what granularity
- Balance transparency against security concerns
- Design the public inventory page

**Topics:** Publication scope · Granularity · Security balance · Public inventory

**Activity:** Draft the public AI inventory page for your agency.

### Module 7 — How do you handle an AI incident publicly?

Incident response when the after-action review may be requested and reported. _(45 min)_

**Objectives**

- Define what constitutes a reportable AI incident
- Run response and after-action review
- Communicate publicly without compounding the harm

**Topics:** Incident definition · Response process · After-action review · Public communication

**Activity:** Tabletop an AI incident including the public communication.

### Module 8 — Assembling the governance program

The workshop module: inventory, board, assessments, and rhythm assembled. _(50 min)_

**Objectives**

- Assemble the complete program
- Verify coverage of agency obligations
- Plan rollout across program areas

**Topics:** Program assembly · Coverage verification · Rollout · Sustainment

**Activity:** Assemble the program and present it to agency leadership.

## What is the capstone project?

**Agency AI governance program.** Produce a complete governance program: use-case inventory with discovery results, board charter with exercised authority, a completed impact assessment for a rights-affecting use, bias test results, the NIST operating rhythm, and a public transparency page.

_Deliverable:_ A governance program with one real impact assessment and a draft public inventory.

## How are learners assessed?

- Inventory assessed on whether discovery found unapproved deployments
- Impact assessment reviewed for whether it could conclude against deployment
- Public page reviewed by communications and counsel

## What ships with the course?

- **Facilitator guide.** Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
- **Learner workbook.** Exercises, checklists, and the templates each module's activity produces.
- **Hands-on lab environment.** A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
- **Assessment bank.** Scenario questions and rubric criteria mapped to each stated learning outcome.
- **Source bibliography.** Every primary regulation and standard cited on this page, linked and dated.

## Which AI agents does this course use?

- [Compliance Agent](https://ibl.ai/solutions/government/agent/compliance-agent)
- [Security Agent](https://ibl.ai/solutions/government/agent/security-agent)
- [Knowledge Agent](https://ibl.ai/solutions/government/agent/knowledge-agent)
- [Government Assistant](https://ibl.ai/solutions/government/agent/government-assistant)

## Where does the course material come from?

Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.

- [AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) — NIST. The framework the agency operating rhythm is built from.
- [NIST AI 600-1, Generative AI Profile](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf) — NIST. Generative-AI-specific risks the impact assessment must address.
- [AI Guide for Government](https://coe.gsa.gov/coe/ai-guide-for-government/) — GSA Centers of Excellence. Federal practice guidance for agency AI governance.
- [Office of Management and Budget](https://www.whitehouse.gov/omb/) — OMB. Executive branch AI policy direction shaping agency obligations.

## Delivery notes

Binding guidance for anyone preparing and delivering this course:

- Module 3's impact assessment must be capable of concluding against deployment. An assessment process that has never stopped anything is a documentation exercise and the audience will recognize it.
- Federal AI policy direction changes with administrations. Verify current OMB direction at each revision rather than citing a specific memo that may be superseded.
- Module 5's documentation-under-disclosure framing is specific to government and important. Findings written knowing they may be published are written differently, and usually better.
- Module 1's discovery will find embedded vendor AI nobody classified as AI. Build the discovery method to catch features shipped inside existing systems.
- Coordinate with GOV-1 — governance and authorization overlap, and the impact assessment should feed the authorization package rather than duplicating it.

## Why run AI training on a platform you own?

- **You own the course, not a licence to it.** Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
- **Model-agnostic delivery.** Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
- **No per-seat training licences.** Usage-based or self-hosted, so cost tracks actual use rather than headcount.
- **Deploy anywhere.** Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.

## Frequently asked questions

### What does the AI Governance Inside a Public Agency course cover?

Agency AI governance is distinguished from private-sector governance by public accountability: the inventory may be published, the impact assessment may be challenged, and the incident will be reported. This course builds the program with that in mind — a review board with real authority, impact assessment for rights-affecting uses, and transparency reporting. It runs 6 hours across 8 modules across 8 modules, at intermediate level, and closes with a capstone: Agency AI governance program.

### Who should take AI Governance Inside a Public Agency?

It is written for Agency AI governance leads and responsible AI officers, CIOs and deputy CIOs, Program managers deploying AI, Inspectors general and internal audit staff. Prerequisites: Familiarity with your agency's existing governance structures; No technical background required.

### Can we run this course on our own infrastructure?

Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for government teams that cannot send work to a public AI tool.

### How do we get access to AI Governance Inside a Public Agency?

Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.

### How much does AI training for government cost on ibl.ai?

There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

## More Government courses

- [Getting an AI System Authorized: FedRAMP and NIST 800-53](https://ibl.ai/solutions/government/course/authorizing-ai-fedramp-nist-800-53): The authorization path for AI in a federal or state agency — control selection, boundary definition, and why an LLM complicates the system security plan.
- [Sovereign and Air-Gapped AI for Public Agencies](https://ibl.ai/solutions/government/course/sovereign-air-gapped-ai-public-agencies): Run capable AI with no internet egress — model selection, air-gapped update paths, and the operational realities of a disconnected deployment.
- [Citizen Service Agents: Design, Escalation, and Accessibility](https://ibl.ai/solutions/government/course/citizen-service-agents): Public-facing AI where the user has no alternative provider — plain language, Section 508 conformance, language access, and escalation that never traps a constituent.
- [AI in Public Procurement: Writing an RFP That Gets Real Bids](https://ibl.ai/solutions/government/course/ai-in-public-procurement): Specify AI in a solicitation so you get comparable, honest proposals — required disclosures, evaluation criteria, and contract terms that preserve agency control.
- [Records, FOIA, and AI: Retention When an Agent Writes](https://ibl.ai/solutions/government/course/records-foia-and-ai): What happens to public records law when an AI drafts the memo — retention, prompt logs as records, and responding to a request that reaches an AI system.
- [Legislative and Policy Analysis with AI](https://ibl.ai/solutions/government/course/legislative-policy-analysis-with-ai): Bill tracking, fiscal note support, and comparative policy research — with the verification discipline that keeps a wrong summary out of a member's briefing.
