A19. Attachment Artificial Intelligence (AI) Use Compliance and Risk Management Plan.docx
DOCX document 26 KB Posted
- Attached to
- Scalable Wastewater Surveillance for Routine and Emerging Infectious Disease Pathogens Federal contract opportunity
- Solicitation number
- 75D301-26-R-73493
About this file
This document is an Artificial Intelligence (AI) Use Compliance and Risk Management Plan template designed for contractors who plan to use AI in contract performance when the primary deliverable is not an AI system itself. The template is applicable to the CDC/HHS contract for Scalable Wastewater Surveillance for Routine and Emerging Infectious Disease Pathogens (Solicitation Number 75D301-26-R-73493).
The plan requires contractors to document comprehensive details about their AI usage, including the specific AI tool or system name, whether use is required or optional, and the AI classification type (generative AI, machine learning, computer vision, natural language processing, or other). Contractors must identify ownership and support contacts, provide tool background information including vendor details and hosting environment, and specify what types of data will be processed—distinguishing between public information, government nonpublic information, PII, PHI, and other sensitive data. The template mandates disclosure of whether outputs could materially affect individual rights or benefits (high-impact determination) and requires detailed safeguards including human review procedures, prevention of unauthorized disclosure, and monitoring protocols. Critically, contractors must affirm that all AI use is approved by the Contracting Officer, that government data will not be used for model training without express authorization, and that the plan will be maintained and updated throughout contract performance with notification to the Contracting Officer before any changes or expanded use. The document serves as both a disclosure mechanism and compliance framework to ensure responsible AI governance in federal contracting.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| A19. Request for Proposal IDIQ - updated.pdf | ||
| A19. Request for Proposal IDIQ - updated.pdf | ||
| A19. RFTOP - Task 1 - Issued.pdf | ||
| Scalable Wastewater Questions and Answers - updated.pdf | ||
| Scalable Wastewater Questions and Answers.pdf | ||
| A19. RFTOP - Task 1 - Issued.pdf | ||
| A19. Request for Proposal IDIQ.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Artificial Intelligence (AI) Use Compliance and Risk Management Plan Purpose: Use this when a contractor plans to use, may use, or later proposes to use AI in contract performance, but the primary deliverable is not the development or delivery of an AI system.
1. Background Name of AI tool/system:
Contractor using the AI:
Subcontractor or service provider, if any:
Contract task/function supported:
Describe how AI will be used in contract performance:
Is AI use required to perform the work, or optional?
Required Optional Unknown AI classification:
Generative AI Agentic AI Classical/Predictive Machine Learning Computer Vision Natural Language Processing Reinforcement Learning Other: [Insert] Is this use limited to contractor internal operations?
Yes No
Will the AI touch Government information, systems, identities, networks, or operations?
Yes No Unknown Was the AI system procured to support this particular contract per requirements in the Statement of Work?
2. Who owns and supports this use?
Contractor AI owner:
Contractor technical support contact:
Contractor privacy/security contact:
CDC/HHS program office using or receiving outputs:
Expected users:
Contractor staff only CDC/HHS staff Public users Beneficiaries, patients, applicants, regulated entities, or other external parties Other: [Insert]
3. Tool background Tool or product name:
[Insert] Developer/vendor:
[Insert] Is the AI technology open-source, proprietary, Government-furnished, or other?
☐ Open-source ☐ Proprietary/commercial ☐ Government-furnished ☐ Contractor-developed ☐ Subcontractor-provided ☐ Other: [Insert] If the system uses an LLM or foundation model, what is the primary model?
[Insert] Who provides the LLM/foundation model?
[Insert] What model options are available?
[Insert] Does it require an API key?
☐ Yes ☐ No ☐ Unknown Attach or link, if available:
☐ Model card ☐ System card ☐ Data card ☐ Vendor security documentation ☐ Evaluation summary ☐ Terms of service ☐ Privacy/data retention policy ☐ Audit-log documentation
4. Where is it hosted and authorized?
Hosting environment:
☐ Contractor environment ☐ Commercial SaaS ☐ FedRAMP-authorized cloud ☐ CDC/HHS environment ☐ Local/offline environment ☐ Other: [Insert] Where is the system hosted?
[Insert country/region/cloud/provider] Is the product directly FedRAMP authorized or available through a FedRAMP-authorized instance?
☐ Yes ☐ No ☐ Not applicable ☐ Unknown If no, is it undergoing FedRAMP authorization?
☐ Yes ☐ No ☐ Unknown
5. What data will be used?
Will the AI process, store, transmit, summarize, analyze, or generate Government information?
Yes No Unknown Types of data involved:
Public information Government nonpublic information
PII
PHI
Procurement-sensitive information Proprietary/business confidential information ☐ Other: [Insert] What information will be entered into the AI tool?
[Insert] What outputs will the AI generate?
[Insert] Will prompts, uploads, outputs, logs, or user interactions be stored?
☐ Yes ☐ No ☐ Unknown Retention period:
[Insert] Will Government data, prompts, outputs, or logs be used to train, fine-tune, improve, or benchmark any model?
Yes No Unknown Will any data, prompts, outputs, or logs be shared with other users, tenants, vendors, subcontractors, or third parties?
Yes No Unknown Explain storage, use, retention, deletion, and sharing:
[Insert]
6. Is this high-impact?
Could the AI output materially affect an individual’s or organization’s rights, benefits, services, health, safety, access, eligibility, enforcement status, or other significant interests?
Yes No Unknown Could CDC/HHS personnel rely on the AI output as a principal basis for a decision or action?
Yes No Unknown Is the AI used only for internal drafting, summarization, or administrative support with human review before use?
Yes No High-impact rationale:
[Insert]
7. What safeguards are in place?
How will contractor personnel verify AI outputs before relying on them?
What human review is required before AI-generated content is submitted to CDC/HHS?
How will the contractor prevent unauthorized disclosure of Government information?
How will the contractor prevent misuse, unauthorized use, or corruption of the AI system?
How will the contractor protect privacy, civil rights, and civil liberties?
What internal policies govern this AI use?
8. Monitoring and misuse protection What is monitored?
Accuracy/performance Performance degradation or drift Data leakage signals Abuse/misuse Prompt injection Unauthorized access Other: [Insert] Does CDC/HHS have access to monitoring information, audit logs, or summary reports?
Yes No Upon request Not applicable How are issues detected, escalated, and corrected?
When will CDC/HHS be informed?
What is the standard operating procedure for incidents or unacceptable outputs?
9. Required contractor affirmation The contractor affirms that:
AI will not be used unless approved by the Contracting Officer.
The contractor has disclosed all planned or potential AI use.
The contractor will not enter Government information into unapproved AI tools.
The contractor will not use Government data to train, fine-tune, or improve an AI model unless expressly authorized.
The contractor will maintain and update this AI Use Card throughout contract performance.
The contractor will notify the Contracting Officer and COR before changed, expanded, or new AI use.
The contractor will prevent unlawful discriminatory use or outputs.
The contractor will comply with applicable privacy, security, data rights, records, civil rights, and AI requirements.
File details come from the government source that posted it. Updated .