Attachment 3 - OCIO Data and ICE AI Contract Language.pdf
PDF 256 KB Posted
- Attached to
- Request for Quote - Night Vision Goggles Federal contract opportunity
- Solicitation number
- 192126VSF00000001
- Issued by
- Immigration and Customs Enforcement
About this file
This is a template document containing required contract language for U.S. Immigration and Customs Enforcement (ICE) and the Office of the Chief Information Officer (OCIO) federal contracts.
The document establishes mandatory data ownership and artificial intelligence (AI) governance requirements that must be included in Statements of Objectives (SOO), Statements of Work (SOW), Performance Work Statements (PWS), or as contract addenda. For ICE contracts where OCIO is not the customer, the data ownership language applies to all service requirements exceeding $250,000 (FY23 Simplified Acquisition Threshold) including base plus options, all IT procurements regardless of dollar threshold (excluding micro-purchases and non-IT items), intergovernmental service agreements, inter/intra-agency acquisitions, and letter contracts. For OCIO internal contracts, the language is required for all acquisitions of any size except purchase card transactions. The data ownership requirements establish that all program data generated through contractor activities shall be owned by the Government and made accessible within 24 hours of request with minimum data access capabilities including APIs, downloadable files, or direct database queries; formatted data with clear element identification; machine and human-readable formats; and associated reference data. Enhanced access capabilities through APIs and Change Data Capture techniques are preferred but not required.
The AI use limitations language (approved July 16, 2025) mandates that contractors ensure AI systems comply with all federal, DHS, and ICE AI policies and align with constitutional protections, privacy, civil rights, and civil liberties. Key requirements include: human-in-the-loop oversight and documented AI-generated content for law enforcement decisions; cooperation with federal procedures for notice and appeal regarding determinations impacting individuals; prohibition on using AI as sole evidence for punitive actions or discriminatory decision-making; compliance with AI use case approval and security authorization processes; and adherence to AI Security Control Baseline requirements. Contractors must provide full traceability, auditability, and transparency through documentation of data provenance, third-party model sources, system diagrams, comprehensive AI system explanations, and auditable outputs meeting evidentiary standards. All Government-provided or AI-generated data belongs to the Government; contractors are prohibited from using nonpublic data to train external AI systems or sharing Government data with third parties without authorization. The Government receives appropriate license rights in custom-developed AI models with potential for broad or unlimited rights to certain deliverables. Contractors must prevent vendor lock-in by utilizing industry standards and APIs, ensuring exportable non-proprietary outputs, delivering technical documentation, and supporting knowledge transfer during system transitions with documented exit costs. Security requirements mandate High Impact AI system compliance with OMB and DHS risk management practices, pre-deployment testing and evaluation artifacts, continuous performance and security re-testing before model changes, comprehensive audit and logging of guardrails, models, and system inputs/outputs, and continuous monitoring mechanisms to detect and remediate anomalies, biases, and performance degradation.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Night Vision Goggles RFQ.pdf | ||
| Attachment 1 - Clauses.pdf | ||
| Attachment 2 - Salient Characteristics.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
RFQ 192126VSF00000001
Attachment 3 – OCIO Data & ICE AI Contract Language
Office of the Chief Information Officer (OCIO) / Data Management Unit
Data Ownership Contract Requirements Language
The language/instructions listed on the subsequent pages must be included in their entirety in the Statement of Objective (SOO), Statement of Work (SOW), Performance Work Statement (PWS), or as an attached addendum to the final contract.
1. For ICE Contracts where OCIO is not the customer, this language is required for:
a. All proposed service requirements/procurements (as listed below: i through iv) exceeding the Simplified Acquisition Threshold (SAT: FY23 = $250K) to include Base plus options; regardless, if ICE Data is generated or not.
i. Service Contracts: Stand-alone contracts “C”, Purchase Orders “P”, IDVs and Delivery/Task Orders, or BPAs and Orders/Calls
ii. Intergovernmental Service Agreement (IGSA)
iii. Inter/Intra-agency acquisition (IAA: Assisted or Direct) for contractor services
iv. Letter Contracts
b. All proposed IT requirements/procurements for either commodity or service, with no minimum acquisition threshold, with the exception:
i. Micro-purchases via the Government Purchase Card (PCard)
ii. Not IT procurements (e.g., office supplies, clothing, ammo, furniture, etc.)
2. For OCIO Contracts within OCIO: This language is required for all OCIO acquisitions of any size or type;
regardless, if ICE Data is generated or not, with the exception of P-Card purchases.
NOTE: if there is no SOO, SOW or PWS provided for the procurement/award, the language must be inserted after the CLIN description within Section B of the Award document.
The recommended location within the SOO, SOW or PWS for the insertion of this language/instructions is right after the ICE Office of Professional Responsibility (OPR)/Personal Security Unit (PSU) Security Language and the Information Governance and Privacy (IGP) Language, or as an attached addendum to the final contract.
Waiver of Required Language: The Data Ownership Contract Requirements Language may be omitted, provided there is a waiver based on exigent circumstances up to and including urgent and compelling Mission need, signed off by the Program SES responsible for the acquisition, as well as the CIO or Deputy CIO.
Please contact the OCIO Data Management Unit (ICEOCIODataManagement2@ice.dhs.gov) to request a waiver.
If you have any questions regarding this OCIO/DMU language requirement, please contact the OCIO Data Management Unit (ICEOCIODataManagement2@ice.dhs.gov) or Madeline Ward, Senior Advisor, Office of Acquisition Management (Madeline.Ward@ice.dhs.gov).
OCIO/ Data Management Unit (DMU) - Data Ownership Contract Requirements Language
1. Accessibility of Government-owned Data All stored program data associated with this acquisition shall be owned by the Government. As such, it shall be made accessible to the Government in accordance with the Minimum Data Access Capability described below. This accessibility is required to allow full data transparency, flexibility in performing data analytics, and integration with data from other government programs.
In addition to the Minimum Data Access Capability, the Government prefers, but does not require, that program data be accessible via Enhanced Access Capabilities as described below.
Definition of “program data”: Program Data refers to any data resulting from ICE and DHS organizational activity. Examples of such data include but are not limited to administrative data resulting from human resource, management, and financial actions, as well as operational data resulting from performance of the ICE mission.
Definition of “associated with this acquisition”: Program Data is associated with an acquisition if it is created by DHS organizational activity that is facilitated by the contractor. Examples of how a contractor might facilitate organizational activity follow:
o Program data is stored by contractor personnel o Program data is stored by software that is managed, developed, or used by the contractor o Program data is stored in a repository that is managed, developed, or used by the contractor
2. Minimum Data Access Capability
• The current version of all Program Data is accessible to the Government within 24 hours of request, as well as on any pre-defined schedule as required by the Government.
Data access can occur by various means, provided that Government security requirements are met, and data is accessible in a format that is acceptable to the Government. Examples include but are not limited to APIs that are consumable by the Government, files made available for Government download (e.g., Excel Spreadsheets), or direct database query by federal or contractor personnel.
• The contractor shall format program data accessed by the Government to anticipate the maximum file size of any data to be accessed. File size shall be small enough to assure rapid processing by government applications.
• The contractor shall provide the means for the Government to interpret accessible Program Data as follows:
o Data elements and groupings of data elements shall be clearly identifiable by labels embedded in the data itself, or by a separate schema or file layout which allows such elements and groupings to be identified.
In the case of a relational database schema defined through Data Definition Language (DDL), data elements would be represented as columns, and groupings of data would be represented as tables. In addition, relationships between tables would be described as foreign key relations.
o Labels or names used to identify data elements and groupings of data elements shall be approved by the Government. In addition, each label or name shall be associated with a government approved definition which describes the content of data held therein.
o Program data delivered to the Government shall conform to the Government approved definition for each data element and grouping of data elements.
o All data accessible by the Government shall be both machine readable and human-readable in plain text.
o All reference data associated with Program Data also needs to be accessible to the Government.
Such reference data is required to provide complete understanding of a record.
Reference Data Example: Program data may include a city code which uniquely identifies a city. Reference data associated with a city code may include its name, geographic boundaries, population, median income, etc. This example is provided for clarification of the meaning of reference data and may or may not apply to this specific acquisition. Examples of other reference data codes would include codes representing eye color, gender, country of origin, etc.
3. Enhanced Access Capabilities
The Government prefers that sharing of program data take place via an Application Programming Interface (API) or multiple APIs. APIs allow the Government to efficiently consume data via a widely recognized standard where the data has been completely abstracted from the technology platform that produces it.
In addition, the Government prefers that sharing of program data take place using techniques that enhance efficiency, such as Change Data Capture (CDC). CDC enhances efficiency of data transfer by providing only incremental updates to program data as opposed to providing all program data each time data is shared.
The following language (approved by OPLA on July 16, 2025), shall be added to all ICE contracts:
1. Compliance with Federal Laws and Policies; AI Use Limitations. The Contractor shall ensure any AI system or service provided complies with all applicable federal, Department of Homeland Security (DHS), and U.S. Immigration and Customs Enforcement (ICE) AI Policies, Directives, and Memos, as well as ICE AI governance requirements. The AI solution must align with the U.S. Constitution and all relevant laws and regulations, including privacy, civil rights, and civil liberties. Specifically:
a. The Contractor must stay current and comply with any updates or new AI policy and AI governance requirements issued during the contract term.
b. AI used to support law enforcement decisions or civil actions must include technical and operational safeguards to:
i. Establish human-in-the loop oversight.
ii. Document or label AI-generated content.
c. For AI used in determinations impacting individuals (e.g., risk assessments, identity verification), the Contractor must cooperate with federal, DHS, and ICE procedures for notice and appeal, providing explanations or adjusting outputs upon error findings.
d. The contract prohibits use of AI that violates DHS policy, including:
i. Using AI outputs as sole evidence for punitive or enforcement actions.
ii. Utilizing AI to make or support decisions on improper bases (e.g., predicting future behavior or emotional state leading to discriminatory or unlawful actions).
e. The Contractor must follow AI Use Case approval, Security Authorization, and ICE AI governance and AI risk management processes and requirements before developing, piloting, testing, or deploying AI in ICE environments or using ICE data.
f. The Contractor is responsible for complying with AI Security Control Baseline requirements.
2. Traceability, Auditability, and Transparency. The Contractor shall design, build, document, and operate the AI system or service to be explainable, auditable, and transparent. At a minimum, the Contractor shall:
a. Document the provenance of data used for AI training, fine-tuning, or operation.
b. Ensure data used for AI training, fine tuning, or operation was lawfully obtained and processed.
c. Document the provenance of any third-party AI models used (source, version, etc.).
d. Provide comprehensive system diagrams and inventories that map the AI systems’ API and system connections, data flows, and technical components.
e. Provide comprehensive documentation explaining how the AI system works, including any models and algorithms.
f. Ensure the AI system, where applicable, provides clear explanations or reasoning for its decisions or predictions.
g. Ensure AI outputs are traceable, auditable, meet evidentiary standards, and are explainable to non-technical users. Additionally:
i. Ensure GenAI inputs and their outputs are logged and preserved in line with federal, DHS, and ICE retention policies.
3. Data Rights and Solution Ownership. The contract shall clearly delineate data and intellectual property rights to protect ICE’s interests in the AI solution and associated data. Specifically:
a. All data provided by the Government or generated through the AI system belongs to the Government. The Contractor is prohibited from:
i. Using nonpublic agency data and outputted results to train publicly or commercially available AI algorithms, or any non-ICE systems outside the contract’s scope without ICE’s authorization.
ii. Using Government-furnished data or AI-generated data for purposes outside the contract without ICE authorization.
iii. Sharing, disclosing, or transferring Government data, AI models, or AI-outputs with third parties without ICE’s authorization.
b. The Contractor must grant the Government appropriate license rights in any custom-developed AI models, software, or deliverables. Intellectual Property (IP) rights will be negotiated consistent with federal law and the agency’s mission needs, aiming to avoid vendor lock-in. The Government may require broad or unlimited rights to certain deliverables (including source code or trained model files) for long-term use, maintenance, or integration of the AI solution.
c. ICE maintains ownership over and the Contractor must provide ICE access to:
i. Any derivative outputs of AI developed under the Contract, including data processed using
AI.
ii. Any models trained, fine-tuned, or otherwise developed using ICE data.
4. Prevention Against Vendor Lock-In: To promote a competitive marketplace and long-term sustainability of ICE’s AI capabilities, the Contractor shall:
a. Utilize industry-standards, Application Programming Interfaces (APIs), and protocols wherever possible to ensure interoperability and combability within and between ICE and DHS systems.
b. Ensure inputs and outputs of the AI system are exportable in a non-proprietary, machine-readable format to facilitate integration or transfer of functions to other systems.
c. Where custom components are developed, deliver sufficient technical documentation and access to components (including source code, model weights, or other foundational code) to enable ICE’s long-term use of the AI system.
d. In the case of transitioning the AI system to another contractor or in-house provider, the Contractor must support knowledge transfer and provide all necessary documentation, models, data, derivative outputs, and software to enable sustained system use.
i. The Contract must also document estimated costs and related steps that will be required to exit the Contract.
5. Security, Testing & Evaluation, and Continuous Monitoring: The Contractor shall implement rigorous security and risk management measures for the AI solution, per federal standards, ICE procedures, and Office of Management and Budget (OMB) guidance on AI risks. Key requirements include:
a. If designated as a High Impact AI system, complying with all required AI Risk Management practices (per OMB, DHS, and ICE policy), unless officially granted a waiver.
b. Before deploying the AI system: The Contractor must provide testing and evaluation artifacts and support (including providing requisite access) to enable ICE independent test and evaluation processes to evaluate factors such as, but not limited to:
i. AI system performance, including accuracy and reliability.
ii. Compliance with DHS AI Security Controls.
iii. Resiliency against AI cybersecurity and operational threats, including system misuse/abuse.
iv. Completion of an AI impact assessment and/or other risk assessment procedures, in line with federal, DHS, and ICE policy and practices.
v. Fulfillment of functional, business, and technical requirements.
c. While operating the AI system: The Contractor must re-test system performance, security, resiliency, and abuse/mis-use vulnerabilities before deploying new AI models, fine-tuned models, or other changes to AI systems that require Change Requests.
d. Audit and Logging: Ensure compliance with DHS and ICE AI auditing and logging requirements, including, but not limited to audit and logging the access, usage, and modification of:
i. AI Guardrails deployed in GenAI systems.
ii. Models, including parameters and weights.
iii. AI system inputs and outputs (including prompts).
iv. Additional requirements as determined by federal, DHS, and ICE policy.
e. Continuous Monitoring: The Contractor shall implement continuous monitoring mechanisms to detect and respond to anomalies, biases, or performance degradation in AI systems. Additionally:
i. The Contractor shall establish protocols for the timely remediation of identified issues, including the potential suspension of AI system operations if necessary.
ii. The Contractor shall comply with all continuous monitoring requirements, per federal, DHS, and ICE policy.
File details come from the government source that posted it. Updated .