Section 01
Executive Summary
AI systems developed or validated in military, intelligence, and security settings increasingly shape how governments process information, prioritize cases, identify risks, and coordinate action. In Ukraine and NATO, AI-enabled data fusion has shown operational value for intelligence analysis, battlefield coordination, demining, logistics, and war-crimes evidence processing. The same features that make these systems valuable in conflict — speed, suspicion, fusion, targeting, and decision compression — become dangerous when carried into ordinary civil administration.
Civil governance rests on a different foundation: legality, proportionality, due process, contestability, reversibility, equal treatment, public justification, and accountable human judgment. Systems optimized for wartime or security use do not automatically meet those standards.
Battlefield validation is not civil authorization.
Since this brief was first issued, the pathway it warned about has become more concrete. NATO’s version of Palantir’s Maven Smart System reached full operational capability and classified-network accreditation; a March 9, 2026 Pentagon memo directed that Maven become a program of record by September 30, 2026; DHS has opened a $1 billion, department-wide purchasing agreement with the same vendor; and courts have found or restrained unlawful flows of tax and Medicaid data into immigration enforcement. Confirmed Whether Maven actually became a program of record by the deadline is unverified. Opaque Pentagon officials have also said, as reported by DefenseScoop, that Maven’s U.S. user base doubled this year. Reported Meanwhile, the main U.S. federal AI governance memoranda and the EU AI Act both carve out national-security systems, Confirmed so the hand-off from security to civil use is where scrutiny is weakest. Inferred
Section 02
What Has Changed Since June 2026
The original brief was current to June 1, 2026. The developments below, current to October 7, 2026, bear directly on its argument. Only items that could be traced to an official document or credible reporting are included.
- Reported
Ukraine’s Ministry of Defence reports more than 100 companies using the Palantir-based Brave1 Dataroom to train military AI on real combat data.
The wartime data flywheel is scaling.
- Confirmed
ICE places a ~$45.8 million Palantir order to modernize HSI case management into an “Enterprise Lakehouse” interoperable with CBP, DOJ, and FBI systems.
Cross-domain fusion is now written into procurement requirements.
- Confirmed
NATO’s Maven Smart System reaches full technical operational capability and receives full security accreditation for NATO’s classified network, clearing rollout to all Allied Command Operations subordinate headquarters.
Allied AI command infrastructure is now fully operational.
- Confirmed
Australia’s Federal Court approves an additional A$548.5 million Robodebt settlement (A$475 million in compensation); total costs exceed A$2.4 billion.
Automated administrative harm has a long and costly tail.
- Confirmed
Ukraine’s Defence Minister Mykhailo Fedorov, who launched the Brave1 Dataroom and hosted Palantir in May, is removed in a cabinet reshuffle; Yevhenii Khmara is confirmed as minister on August 19.
Wartime data partnerships outlast the officials who negotiate them; their terms need to be durable and public.
- Confirmed
Federal officials admit CMS shared Medicaid data with ICE beyond a court order; a state attorneys general motion, citing discovery documents, says ICE passed it to Palantir, and an ICE declaration says about six users still held copies.
Purpose limitation and deletion are hard to enforce once data is fused.
- Confirmed
The EU “AI Omnibus” enters into force: Annex III high-risk obligations (which cover law enforcement, migration and border control, and access to public benefits) now apply from December 2, 2027 instead of August 2, 2026.
The main rights-sensitive EU safeguards arrive later than planned.
- Confirmed
The Pentagon names a Maven program director in the CDAO (August 5).
Military AI command infrastructure is becoming permanent.
- Reported
Financial press reports that Maven’s program-of-record designation took effect; no DoD confirmation was located, so whether it did is unverified.
Permanence claims need an official record.
- Confirmed
The UK Information Commissioner publishes audits of police facial recognition in five forces in England and Wales, making 107 recommendations on oversight, record-keeping, image sourcing, and bias.
Even regulated police AI shows governance gaps that audits must catch.
- Confirmed
The D.C. Circuit upholds the block on the IRS–ICE taxpayer-address exchange, finding it “indisputably contravenes” federal tax-privacy law.
Tax data is a live domestic migration pathway.
- Confirmed
Ukraine’s Ministry of Defence announces that it and Brave1 ran standardized trials of AI terminal-guidance modules (September 8).
Battlefield autonomy is advancing quickly.
- Reported
By the Ministry’s account, six of seven guidance modules passed, and successful AI-guided strikes rose tenfold since January; no underlying figures are published.
Performance claims are outrunning independent verification.
- Reported
DefenseScoop reports remarks by Deputy Under Secretary James Mazol (Maven users rose from ~50,000 to 100,000+ in 2026) and CDAO Cameron Stanley (Maven helped strike 13,000 targets in 38 days during Operation Epic Fury); DoD has published no underlying data.
This is the operating logic civil agencies may be pressed to import.
- Confirmed
In a Maine lawsuit, the government acknowledges in a September 18 filing that an HSI agent’s case-management entry on an observer of immigration arrests led to a March 2026 border stop; the court has not ruled.
A real-world analogue of the risk-log problem.
Still unresolved. As of the September 2026 congressional tracker reviewed, no federal statute preempting state AI laws had been enacted; H.R. 5388 remained at the introduced stage. No published Commerce Department evaluation of state AI laws, which EO 14365 required by March 2026, could be located for this revision. Opaque
Section 03
Operational Success Does Not Confer Civil Legitimacy
AI deployed in conflict zones has shown real operational value in data fusion, intelligence analysis, battlefield coordination, evidence processing, and decision support. But a system that proves useful in war, intelligence, or security operations does not thereby become lawful, legitimate, or democratically authorized for immigration enforcement, policing, welfare administration, tax compliance, or other rights-sensitive civil domains.
The central risk is not that military AI exists. It is that systems built or validated for conflict, intelligence fusion, border enforcement, or national-security analysis may migrate into ordinary civil administration without a separate democratic authorization process.
Wartime and security environments reward speed, correlation, anomaly detection, fused visibility, operational prediction, and rapid prioritization across fragmented data streams. Civil governance requires different values: legality, proportionality, notice, due process, contestability, reversibility, equal treatment, public justification, and human accountability. A system can be operationally useful in war and still be democratically unsuitable for welfare eligibility, tax enforcement, immigration case management, policing, or benefits administration.
Even an accurate system can be inappropriate if its purpose, data sources, institutional context, or review procedures conflict with civil-rights protections.
Section 04
Ukraine as a Military-AI Data Flywheel
Ukraine’s wartime use of AI-enabled data fusion shows the operational value of rapidly integrating drone footage, battlefield reports, signals, imagery, logistics data, demining records, and war-crimes evidence. In this setting, speed and integration can save lives, preserve evidence, and improve command decisions.
Brave1 Dataroom. Launched on January 20–21, 2026 by Ukraine’s Ministry of Defence with the Ministry of Digital Transformation, the Armed Forces, the Defence Intelligence Research Institute, and Palantir, the Dataroom is a secure environment, built on Palantir software, where Ukrainian defense developers train, test, and validate models on real combat data. The initial datasets are visual and thermal imagery of aerial targets such as Shahed-type drones, and access requires a mandatory security-compliance procedure. Confirmed By May 2026 then-Defence Minister Mykhailo Fedorov said more than 100 companies were training over 80 detection and interception models, and the Ministry repeated the 100-company figure in June; neither figure has been independently verified. Reported Officials have said the Dataroom may later serve as a channel for sharing battlefield-tested algorithms with allies. Reported The result is a data flywheel: battlefield data improves models, improved models support operations, and operations generate more data.
Palantir’s role. Palantir’s work in Ukraine began after CEO Alex Karp met President Zelenskyy in Kyiv in June 2022. TIME reported in 2024 that the company supplied its software free of charge and that more than half a dozen Ukrainian agencies used it for targeting, war-crimes evidence, demining, refugee resettlement, and anti-corruption work. Reported Palantir and Ukraine’s Ministry of Economy later signed a formal demining partnership. Confirmed In April 2023, Reuters reported that Palantir would help the Prosecutor General’s office pool and analyze evidence related to the more than 78,000 war crimes reported since the invasion, initially without charge. Confirmed
On May 12, 2026, Palantir CEO Alex Karp met Zelenskyy and Fedorov in Kyiv. Confirmed Zelenskyy said they discussed technology “in the context of combat operations and civilian needs”; Fedorov said the existing joint work already includes air-attack analysis, AI processing of large volumes of intelligence data, and the integration of Palantir technology into planning deep-strike operations inside Russia. Reported The Ministry’s own readout says the parties “explored possible areas for further cooperation”; no new agreement was announced. Confirmed Fedorov left office two months later in a cabinet reshuffle. Confirmed
The work is moving quickly. On September 8, 2026, the Ministry of Defence announced that it and Brave1 had run standardized trials of AI terminal-guidance modules against moving ground targets; the Ukrainian outlet The Defender also reported the release. Confirmed By the Ministry’s own account, six of seven manufacturers were recommended for procurement, and a human still makes the decision to strike. Reported The Ministry also reported a tenfold increase since January in successful strikes using AI guidance; it has not published the underlying figures, and the claim has not been independently verified. Reported
No public disclosure of the contractual terms on derivative-model ownership or vendor reuse of Dataroom data could be located. Opaque The concern is not that Ukraine should be denied operational tools during war. It is that wartime validation may later be treated as proof of suitability for civil governance, even though the legal and ethical standards are fundamentally different.
Section 05
NATO, Maven, and the Normalization of AI-Enabled Command Infrastructure
NATO’s adoption of AI-enabled command tools reinforces the normalization of AI as decision-support infrastructure. On March 25, 2025, the NATO Communications and Information Agency and Palantir finalized acquisition of the Maven Smart System NATO for Allied Command Operations, which was expected to begin using it within 30 days. NATO called it one of the fastest procurements in its history, at six months from requirement to acquisition, and SHAPE described it as a sole-source buy. Confirmed
On June 22, 2026, MSS NATO reached full technical operational capability; NATO’s Security Accreditation Board also accredited it for NATO’s classified network, and NATO says the platform supports multiple AI models and will be extended across all ACO subordinate headquarters. Confirmed
In the United States, a March 9, 2026 memorandum from Deputy Secretary of Defense Steve Feinberg directed that Maven become a formal program of record by the end of fiscal year 2026. It moved system administration and oversight from the National Geospatial-Intelligence Agency to a CDAO Maven program office within 30 days, assigned authorizing-official duties to Research and Engineering, and moved future contracting to the Army Enterprise Agreement. Confirmed In August the Pentagon named a Maven program director, and FY2027 budget materials sought more than $1.5 billion to expand access. Confirmed Financial press reported in late August that the program-of-record designation had taken effect. Reported Whether it did is unverified: no official DoD confirmation was located, and DoD officials on September 22 still described the memo as a direction. Opaque On September 22, DefenseScoop reported remarks by two Pentagon officials at a DefenseScoop-hosted conference: Deputy Under Secretary of Defense for Research and Engineering James Mazol said Maven’s user base had grown from about 50,000 in January to more than 100,000, and Chief Digital and AI Officer Cameron Stanley said Maven helped U.S. forces strike 13,000 targets in 38 days during Operation Epic Fury, the 2026 U.S. strike campaign against Iran. DoD has published no data behind either figure, and neither has been independently verified; both rest on this single press account. Reported
This matters because military adoption creates downstream institutional pressure. Once AI-enabled command infrastructure is normal in defense, civilian agencies may seek similar tools for ranking, prioritization, anomaly detection, fraud detection, enforcement targeting, and case management. The same vendor’s platforms now span U.S. targeting, NATO command, Ukraine’s wartime data environment, and DHS-wide enforcement software. Confirmed Shared vendor lineage is not evidence that data moves between these domains, but it lowers the technical and contractual cost of migration. Inferred
A fair objection is that no battlefield-validated model has been shown to have crossed into a civil system. That is correct, and the brief’s claim should be read precisely. The pathways are documented: the same vendor platforms already run in military targeting, allied command, wartime data environments, and civil enforcement. Confirmed The harms of data fusion in civil enforcement are documented, from unlawful tax-data transfers to Medicaid data shared beyond a court order and case-management entries that the government says led to an observer’s border stop. Confirmed No documented instance of a battlefield-validated model being transferred into civil administration was located for this brief. The contract terms, model lineage, and reuse rights that would show such a transfer are not public. Opaque The brief’s claim does not depend on whether a specific battlefield-validated model has crossed into a civil agency. It depends on whether the authorization gap exists and whether it should be closed: the gap is what makes the documented pathways dangerous, and the documented harms show what fusion looks like when it proceeds without authorization.
That migration should not happen through procurement convenience, vendor expansion, emergency carryover, or technological familiarity. Civil use requires its own legal basis, public justification, and accountability framework.
Section 06
Domestic Migration Pathways: Immigration, Policing, Welfare, and Tax
The domestic migration risk is clearest in enforcement domains such as immigration and policing, where AI-enabled data fusion can combine identity records, location signals, law-enforcement databases, prior incidents, financial information, travel records, and case files. In these settings a person may become visible to the state as a risk profile before having any meaningful chance to challenge the underlying data or inference.
Immigration enforcement. Palantir has been an ICE contractor since 2011 and has supported ICE’s Investigative Case Management (ICM) system since 2014; ICE’s FALCON Search & Analysis system ingests DHS, other-agency, and commercial data for investigators. Confirmed In April 2025, ICE added about $30 million to an existing Palantir ICM contract to build ImmigrationOS, covering enforcement targeting and prioritization, near-real-time “self-deportation” tracking, and removal logistics, with a prototype due September 25, 2025 and the contract running at least through September 2027. Confirmed On September 25, 2025, ICE awarded a further ~$29.9 million sole-source order for continued ImmigrationOS licenses and maintenance. Confirmed
The footprint has since grown. In February 2026, DHS signed a five-year, $1 billion blanket purchase agreement for Palantir software across the department. Confirmed WIRED also reported a Palantir tool, ELITE, that maps potential deportation targets using DHS and Department of Health and Human Services data. Reported In June 2026, ICE ordered a ~$45.8 million modernization that merges case management and investigative analytics into an “Enterprise Lakehouse” built to interoperate with CBP, DOJ, and FBI systems. Confirmed Which datasets feed ELITE, and how address-confidence or targeting outputs are validated, has not been publicly documented. Opaque
Tax and health data. Executive Order 14243 (March 2025) directed agencies to remove barriers to interagency data access. Confirmed Two rights-sensitive civil datasets then moved toward enforcement. In Center for Taxpayer Rights v. IRS, a federal district court held in November 2025 that the IRS’s August 2025 disclosure of roughly 47,000 taxpayer addresses to ICE was unlawful, and in September 2026 the D.C. Circuit upheld the block, noting ICE had sought addresses for nearly 1.3 million people through an automated procedure without individual review. Confirmed Separately, federal officials admitted in a California case that CMS had shared Medicaid data with ICE beyond what the court’s order allowed, and the judge paused CMS–ICE data sharing for enforcement. Confirmed A July 2026 motion by more than 20 state attorneys general, citing documents produced in discovery, says ICE then shared that data with Palantir; Palantir told NPR the dataset was purged at the government’s instruction. Reported Palantir’s footprint also extends into tax compliance itself: WIRED reported in March 2026 that the IRS paid Palantir $1.8 million to improve a pilot “Selection and Analytic Platform” to identify the “highest-value” cases for audit, collection, and potential criminal investigation. Confirmed How that tool’s case-selection criteria are validated or disclosed to taxpayers has not been made public. Opaque
Policing. The Los Angeles Police Department ended its LASER program in April 2019, after the Police Commission’s Inspector General found inconsistent criteria for designating “chronic offenders,” weak oversight, and insufficient data to measure effectiveness. Confirmed Systems designed to prioritize risk in this way can embed prior enforcement patterns into future enforcement attention. Inferred Germany offers a constitutional parallel: in February 2023 its Federal Constitutional Court struck down Hesse’s and Hamburg’s laws authorizing automated police data analysis (Hesse’s system was built on the hessenDATA platform) because the powers lacked adequate thresholds. Confirmed In August 2026, the UK Information Commissioner reported audits of facial-recognition use by five police forces in England and Wales, finding a “mixed picture” and making 107 recommendations on senior oversight, records of data sources and sharing, image retention, and accuracy and bias checks. Confirmed
Welfare and tax administration. These domains may seem less coercive than policing or immigration, but automated administrative decisions can still cause severe harm. A person may lose benefits, face repayment demands, be flagged for investigation, wait for support, or be pushed into a burdensome appeal because a system treated anomaly, correlation, missing documentation, or statistical deviation as evidence of risk.
Robodebt · Australia
Income averaging generated unlawful debt notices between 2015 and 2019. The 2023 Royal Commission called the scheme “crude and cruel” and found it was not legal; a further A$548.5 million settlement was approved in June 2026. Confirmed
SyRI · Netherlands
On February 5, 2020, the District Court of The Hague held that the welfare-fraud risk-profiling legislation violated Article 8 of the European Convention on Human Rights for lack of transparency and verifiability. Confirmed
MiDAS · Michigan
From 2013 to 2015 the system automatically accused about 40,000 people of unemployment fraud; a review of 22,000 determinations found 93% did not involve fraud. A $20 million class settlement received final approval in January 2024. Confirmed
None of these three systems was built or validated in a military, intelligence, or security setting, and none would have been caught by a rule aimed only at security-derived systems. They are included because they show what happens when automated administrative decisions are deployed before legal authorization, contestability, and review are in place. That is why this brief argues that authorization has to come first for any AI system in a rights-sensitive domain, with heightened scrutiny when security lineage is present.
Civil harm often appears not as physical force but as delay, denial, debt, investigation, documentation burden, and bureaucratic exhaustion.
Section 07
Domestic Risk Logs and Cross-Domain Fusion
A core danger in military-to-civil translation is building risk profiles from heterogeneous data. Internal or administrative risk logs look technical and neutral, but they can become the infrastructure through which people are classified, prioritized, or targeted.
In this illustration, three sources collected for different purposes are fused into a single score that routes a case to enforcement. The log records that a reviewer touched the case but not what the reviewer judged. Systems built this way can create a surveillance flywheel that bypasses ordinary civil authorization.
A real-world analogue. In a federal lawsuit in Maine, the government acknowledged in a September 18, 2026 filing that an HSI agent’s entry of an observer’s name and vehicle information into Palantir’s ICM system, made during a January 2026 enforcement operation, led to a March 2026 border stop; the plaintiffs say they faced enhanced screening while returning from Canada. The court has not ruled on the claims. DHS’s 2016 privacy assessment shows ICM subject records are published to CBP’s TECS screening platform. Confirmed How derived analytical links are corrected or deleted when a source record is challenged has not been publicly documented for ICE’s new architecture. Opaque
The governance question is not only whether each data source was lawfully collected. It is whether the combined system creates a new decision-making architecture that was never separately authorized, explained, audited, or made contestable.
Section 08
China as a Cautionary Comparison: Data Fusion, Blacklists, and Weak Contestability
China’s public-security and social-governance architecture is a cautionary comparison. Not every democratic deployment resembles it, but it shows where things lead when broad data fusion, weak contestability, administrative consequences, and state access are combined.
Human Rights Watch’s 2019 reverse-engineering of the police app linked to Xinjiang’s Integrated Joint Operations Platform (IJOP) documented a system that aggregates personal, travel, vehicle, phone, and location data, flags ordinary behavior as suspicious, and assigns investigative tasks to officers. Confirmed China’s social credit system, by contrast, is better understood not as a single universal citizen score but as a fragmented set of sectoral databases, administrative blacklists and redlists, and joint sanctions aimed mainly at businesses; local personal-scoring pilots were curtailed or made voluntary and reward-only. Confirmed
The lesson is the institutional pattern: when security platforms, administrative blacklists, identity-linked databases, and weak avenues for challenge converge, the line between delivering civil services and exercising civil control weakens. The EU has drawn this line in law; since February 2025 the AI Act has prohibited social scoring and AI-based prediction of individual criminal offending based solely on profiling. Confirmed
Section 09
Confirmed / Reported / Inferred / Opaque: An Evidentiary Discipline
AI governance debates require evidentiary discipline. This framework separates established facts, claims that have been made on the record but not independently verified, reasonable analytical conclusions, and unknowns hidden by procurement secrecy, classification, vendor confidentiality, or agency non-disclosure.
Publicly documented facts: official records and formal acts, court findings, procurement materials, or credible reporting based on documents or multiple sources. Establishes the factual baseline.
Claims made on the record by an official, agency, or vendor about its own figures, performance, or activities, or carried by a single press outlet, that no one has independently verified. The claim was made; its accuracy is not established.
Reasonable conclusions drawn from known capabilities, institutional incentives, or deployment patterns. Supports risk analysis without overclaiming.
Material facts that are not publicly available because of secrecy, classification, proprietary systems, or agency non-disclosure. Identifies where audit is needed.
Where a figure or capability claim rests only on the claimant’s own statement or on a single press account, the text names who made it and the claim is tagged Reported. Opaque is reserved for material facts that are not publicly available.
Brave1 Dataroom launched January 2026 on Palantir software
Ukrainian MoD release
100+ firms using the Dataroom by mid-2026
Minister’s and MoD statements; not independently verified
80+ models being trained in the Dataroom
Minister’s statement; not independently audited
Ownership of derivative models and vendor reuse terms
No public contract terms located
NATO finalized MSS NATO acquisition March 25, 2025
NCIA/SHAPE release
March 9, 2026 memo moves Maven from NGA to CDAO and toward program-of-record status
Memo as reported by Reuters and DefenseScoop
Financial press reported Maven’s program-of-record designation took effect (August 2026)
Single financial-press report
Maven program-of-record designation completed by Sept. 30, 2026
No DoD release located; officials still described the memo as a direction on Sept. 22
MSS NATO full operational capability and classified accreditation (June 2026)
NATO release
May 12, 2026 Karp meeting with Zelenskyy and Fedorov
Presidential and MoD readouts
Palantir technology used in Ukrainian deep-strike planning
Then-Minister Fedorov’s statement, as reported; not independently verified
New collaboration agreed at the May 12 meeting
No agreement announced; readout says areas were “explored”
ImmigrationOS: ~$30M (April 2025), prototype due Sept. 2025, runs to at least Sept. 2027
Contract justification as reported by WIRED
Data sources and accuracy controls behind ELITE targeting
Not publicly documented
IRS–ICE address sharing was unlawful
District court and D.C. Circuit
Shared vendor platforms lower the cost of military-to-civil migration
Analysis of procurement pattern
Robodebt, SyRI, MiDAS produced wrongful adverse outcomes
Royal Commission, court rulings, settlements
LAPD ended LASER in 2019
LAPD OIG review; Los Angeles Times
LASER-type ranking amplifies historical bias
This brief’s analysis; not an OIG finding
IRS paid Palantir $1.8M to improve a pilot audit-selection platform
Contract documents as reported by WIRED
How the IRS pilot selects cases and whether criteria are disclosed
Criteria not public
Maven helped strike 13,000 targets in 38 days; user base doubled to 100,000+
Officials’ remarks in a single DefenseScoop report; no DoD data published
Ukraine’s MoD and Brave1 ran standardized AI terminal-guidance trials (Sept. 2026)
MoD Ukraine release; The Defender
Six of seven guidance modules passed
MoD Ukraine’s own account; not independently verified
Tenfold rise in successful AI-guided strikes since January 2026
Ministry claim; underlying figures not published
A battlefield-validated model has been transferred into a civil system
Pathways and civil fusion harms are documented; contract terms and model lineage are not public
This framework prevents both underreaction and overclaiming. It lets policymakers act on demonstrated risks while marking clearly where more transparency is required.
Section 10
Error Propagation and the Need for Oversight Cadence
AI systems used in rights-sensitive domains are vulnerable to compounding error. Data-quality problems, model drift, biased feedback loops, incomplete human review, and institutional overreliance can amplify initial mistakes over time.
Et = E0 · ∏i = 1 t max(0, α − β hi)
Equation (1) · governance heuristic
In words: total error at time t equals the initial error multiplied, at each step, by the system’s drift factor (α), reduced by the corrective effect of human oversight at that step (β times hi). Each step’s factor is floored at zero, because oversight can at most eliminate error, not make it negative. With no meaningful review (h = 0), error compounds geometrically as E0 · αt. Because the factors multiply, a single annual audit cannot offset many unreviewed cycles.
Illustrative example. Hypothetical parameters, not an empirical model. The sliders start at α = 1.12, β = 0.35, and h = 0.55, a per-step factor of about 0.93. At those values, error after 16 cycles is about 0.30 with oversight and about 6.1 with none, so unreviewed error ends roughly 20× higher. Changing the parameters shows how quickly the gap moves; a single annual audit cannot offset many unreviewed cycles.
- Per-step factor
- 0.93
- error shrinks
- Error at t=16
- 0.30
- with oversight
- If unreviewed
- 6.1
- h = 0
- Ratio (illustrative)
- 20.4×
- unreviewed ÷ reviewed
Section 11
The Domain-Translation Test
Before any battlefield-validated, security-grade, or enforcement-derived AI system is deployed in civil governance, the responsible agency should apply a five-part domain-translation test. The third column of each card notes where existing law or policy already supplies a partial hook. A system that fails this test should not be deployed in civil administration.
01 · Reversibility
Can the system be withdrawn, disabled, or separated from civil workflows without institutional collapse?
Existing hook (partial): M-25-21 requires agencies to stop using non-compliant high-impact AI; M-25-22 requires anti-lock-in terms.
02 · Contestability
Can affected people and independent overseers challenge the data, inference, ranking, or decision?
Existing hook (partial): M-25-21 remedies and appeals; Colorado SB26-189 adverse-decision notices.
03 · Feedback integrity
Are feedback signals auditable, tamper-resistant, and protected from biased enforcement loops?
Existing hook (partial): M-25-21 ongoing monitoring; NIST AI RMF.
04 · Lawful authorization
Is there explicit legal authority for this civil use, rather than authority inherited from a military or security deployment?
Existing hook (partial): IRC 6103 and the Privacy Act, as the IRS–ICE litigation shows.
05 · Domain separation
Are military, intelligence, enforcement, and civil-benefits systems separated by enforceable technical and legal firewalls?
Existing hook (partial): Privacy Act computer-matching agreements, 5 U.S.C. 552a(o).
Section 12
Minimum Civil Authorization Standard
Before deployment, the responsible agency should publish a civil authorization dossier, available before procurement lock-in, operational deployment, or irreversible integration into agency workflows. The standard puts into practice portability rights, data minimization, purpose limitation, sunset clauses, and vendor accountability.
Much of this content overlaps with documents agencies already produce: M-25-21 AI impact assessments, privacy impact assessments, Privacy Act system-of-records notices, and computer-matching agreements. Confirmed The gap is the trigger. M-25-21 and M-25-22 do not apply to AI used as a component of a national security system, and the EU AI Act excludes systems used exclusively for military, defense, or national security purposes. Confirmed The dossier requirement should therefore attach at the moment a system or its outputs cross from a national-security setting into civil use; under the AI Act’s “exclusively” wording, that crossing should already bring the system back within scope. Inferred
Section 13
Layered Audit Framework: Technical, Operational, and Democratic
Logs can reconstruct actions, but they do not prove judgment. A system may keep a detailed record of what occurred while still obscuring whether officials exercised meaningful independent review. Civil accountability requires three distinct audit layers.
Technical audit
Examines model performance, data quality, security, bias, drift, and robustness.
Does the system function as claimed? Are errors measurable and correctable?
Independent testers with code, model, and data access; agency CAIO
Operational audit
Examines how officials use the system inside real workflows.
Are humans independently reviewing outputs, or merely ratifying them?
Inspectors General; GAO; state auditors
Democratic audit
Examines legality, public authorization, rights impact, and institutional legitimacy.
Should this system be used in this domain at all?
Congress and state legislatures; courts where rights are litigated
A model may be technically functional and still democratically unauthorized.
Section 14
Policy Recommendations
Each recommendation names the actor best placed to act and, where one exists, the framework it can build on. “Agencies” means civil departments and their Chief AI Officers.
- 01
Require a civil authorization dossier before deployment.
Owner OMB (require); agencies (produce)
Build on M-25-21 impact assessments; PIAs; model federal text in Appendix E (E.2); model state bill in Appendix F (F.1)
- 02
Prohibit military-to-civil transfer without separate legal authorization.
Owner Congress; OMB as interim guidance; European Commission and EU Member States
Build on Closes the national-security-system exclusion in M-25-21/M-25-22; clarifies that AI Act Art. 2(3) covers only “exclusively” military, defence, or national-security uses; model federal text in Appendix E (E.1); model state bill in Appendix F (F.1)
- 03
Mandate independent technical, operational, and democratic audits.
Owner Congress (fund and mandate); IGs; GAO
Build on M-25-21 independent review; Section 13
- 04
Establish domain firewalls between military, intelligence, enforcement, and civil-benefits systems.
Owner Congress; agencies
Build on Privacy Act matching rules; IRC 6103
- 05
Require strict data minimization and purpose limitation.
Owner Agencies; procurement officers
Build on Privacy Act; M-25-22 government-data terms
- 06
Guarantee notice, explanation, and appeal rights for affected people.
Owner Agencies; state legislatures; EU Member States
Build on M-25-21 remedies; Colorado SB26-189; AI Act Art. 86 right to explanation
- 07
Require human command primacy for consequential civil decisions.
Owner Agencies
Build on M-25-21 human oversight
- 08
Prohibit opaque risk scores as the sole basis for benefit denial, enforcement action, audit targeting, or other adverse civil decisions.
Owner Congress; state legislatures; EU co-legislators
Build on SyRI and Robodebt lessons; AI Act Art. 5 profiling ban
- 09
Mandate portability rights to prevent vendor lock-in.
Owner Procurement officers; OMB
Build on M-25-22 lock-in protections
- 10
Require sunset clauses and periodic reauthorization.
Owner Congress; state legislatures
Build on No general requirement today
- 11
Require independent red-teaming before deployment in rights-sensitive domains.
Owner Agencies; procurement officers
Build on M-25-21 pre-deployment testing; NIST AI RMF
- 12
Preserve data-sovereignty protections for wartime or emergency datasets.
Owner Ukraine’s MoD and partner governments; vendors by contract
Build on Dataroom terms (not public)
- 13
Require post-action reviews for consequential deployments.
Owner Agencies; IGs
Build on M-25-21 ongoing monitoring
- 14
Publish prohibited-use rules before system integration.
Owner Agencies; procurement officers
Build on EU AI Act Article 5 as a model
- 15
Bring forward, or at least not further delay, safeguards for Annex III public-sector uses (migration, law enforcement, benefits).
Owner European Parliament and Council; European Commission; national market-surveillance authorities
Build on AI Omnibus timeline (December 2, 2027)
Section 15
Conclusion
AI systems validated in war may be useful, powerful, and operationally impressive. That does not make them democratically authorized for civil use. The months since this brief first appeared have made the point less abstract: military AI infrastructure has become more permanent, the same platforms have spread across civil enforcement, and courts have had to stop tax and health data from crossing lines Congress drew.
The lesson is not to reject military AI categorically. It is to preserve the boundary between emergency operational systems and ordinary civil governance. Civil administration requires a higher standard of notice, proportionality, appeal, transparency, and public authorization.
No system built for war, intelligence, security fusion, or enforcement should become part of civil government unless it passes a separate democratic test.
Corrections
Corrections to the June 2026 Edition
The following factual statements in the original June 2026 brief were corrected in this October 7, 2026 revision. Other changes in this revision are listed in the changelog at the end.
- Brave1 Dataroom
- The “100+ firms / 80+ models” figures date from May–June 2026, not the January launch. Sources describe visual and thermal aerial-target datasets, not “intercepts”; access follows a security-compliance procedure. Palantir’s role as platform provider was added.
- May 12, 2026 meeting
- The meeting was with CEO Alex Karp. Deep-strike planning and intelligence processing were described by then-Minister Fedorov as existing areas of cooperation, not a new expansion agreed at the meeting.
- Maven memo
- The March 9, 2026 memo directed that Maven become a program of record by September 30, 2026, moving oversight from NGA to a CDAO program office. It did not move an existing program of record.
- Reuters 2023
- Reuters reported that Palantir would help prosecutors analyze evidence connected to the more than 78,000 reported war crimes, not that processing of all 78,000 incidents had been completed.
- ImmigrationOS
- September 2025 was the prototype deadline, not an extension. The ~$30 million was a modification to an existing ICM contract, followed by a ~$29.9 million continuation award in September 2025.
- Fedorov’s status
- Mykhailo Fedorov was Defence Minister at the time of the January and May 2026 events but left office in July 2026; he is described accordingly.
- Maven program-of-record completion
- Stated as fact in some secondary coverage, but not confirmed by DoD as of this revision; tagged Opaque.
- LAPD LASER
- The Inspector General’s findings concerned inconsistent criteria, oversight, and lack of data on effectiveness. The point about bias amplification is kept as this brief’s own inference and tagged as such.
Sources
References
Sources 1–60 are numbered in order of first citation; later additions follow. URLs were accessed between October 6 and 7, 2026 (UTC). Where a primary source was paywalled or blocked, a secondary report of the same document is listed alongside it. Superscript numbers in the text open the corresponding source.
- 1.Vera Bergengruen, “How Tech Giants Turned Ukraine Into an AI War Lab,” TIME, February 2024.https://time.com/6691662/ai-ukraine-war-palantir/
- 2.Reuters, “Data company Palantir to help Ukraine prosecute alleged Russian war crimes,” Reuters / CNBC, April 22, 2023.https://www.reuters.com/world/europe/data-company-palantir-help-ukraine-prosecute-alleged-russian-war-crimes-2023-04-22/https://www.cnbc.com/2023/04/22/data-company-palantir-to-help-ukraine-prosecute-alleged-russian-war-crimes.html
- 3.NATO Communications and Information Agency, “NATO acquires AI-enabled warfighting system,” NCIA, April 14, 2025 (acquisition finalized March 25, 2025).https://www.ncia.nato.int/newsroom/news/nato-acquires-aienabled-warfighting-system
- 4.NATO Joint Warfare Centre (from SHAPE), “NATO Maven Smart System Achieves Full Technical Operational Capability,” JWC NATO, Published August 12, 2026 (milestone June 22, 2026).https://www.jwc.nato.int/article/maven-achieves-ftoc/
- 5.Brandi Vincent, “DOD components face ‘aggressive’ timeline for Maven Smart System transition,” DefenseScoop, April 15, 2026.https://defensescoop.com/2026/04/15/palantir-maven-smart-system-pentagon-program-transition-feinberg/
- 6.Jon Harper, “More than 100K personnel use Maven Smart System: Pentagon official,” DefenseScoop, September 22, 2026.https://defensescoop.com/2026/09/22/maven-smart-system-ai-james-mazol-cameron-stanley-defensetalks/
- 7.Makena Kelly, “DHS Opens a Billion-Dollar Tab With Palantir,” WIRED, February 19, 2026.https://www.wired.com/story/department-homeland-security-ice-billion-dollar-agreement-palantir/
- 8.Matt Bracken, “Appeals court keeps block on IRS from sharing taxpayer data with ICE,” FedScoop; Center for Taxpayer Rights v. IRS, No. 26-5006 (D.C. Cir. Sept. 8, 2026), September 8, 2026.https://fedscoop.com/irs-ice-data-sharing-appeals-court-block/https://law.justia.com/cases/federal/appellate-courts/cadc/26-5006/26-5006-2026-09-08.html
- 9.Jude Joffe-Block, “ICE shared Medicaid data it wasn’t supposed to have with Palantir,” NPR, July 17, 2026.https://www.npr.org/2026/07/17/nx-s1-5898504/ice-medicaid-palantir-data
- 10.Office of Management and Budget, “M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust,” White House / OMB, April 3, 2025.https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-21-Accelerating-Federal-Use-of-AI-through-Innovation-Governance-and-Public-Trust.pdf
- 11.Office of Management and Budget, “M-25-22, Driving Efficient Acquisition of Artificial Intelligence in Government,” White House / OMB, April 3, 2025.https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-22-Driving-Efficient-Acquisition-of-Artificial-Intelligence-in-Government.pdf
- 12.European Union, “Regulation (EU) 2024/1689 (AI Act), Article 2 (Scope),” EUR-Lex, 2024.https://eur-lex.europa.eu/eli/reg/2024/1689/ojhttps://artificialintelligenceact.eu/article/2/
- 13.Ministry of Defence of Ukraine, “Over 100 Ukrainian companies are already leveraging Brave1 Dataroom to train AI models,” MoD Ukraine; Ukrainska Pravda, June 2026.https://mod.gov.ua/en/news/over-100-ukrainian-companies-are-already-leveraging-brave1-dataroom-to-train-ai-modelshttps://www.pravda.com.ua/eng/news/2026/06/11/8038856/
- 14.Anthony Kimery, “ICE observer lawsuit shows how Palantir records can feed border screening, analytics,” Biometric Update, October 4, 2026.https://www.biometricupdate.com/202610/ice-observer-lawsuit-shows-how-palantir-records-can-feed-border-screening-analytics
- 15.SBS News / AAP, “Robodebt victims share in millions as Australia’s largest-ever class action settlement approved,” SBS, June 23, 2026.https://www.sbs.com.au/news/article/robotdebt-victims-class-action-settlement-approved/sd5arll0g
- 16.The Guardian, “Volodymyr Zelenskyy dismisses Ukraine’s defence minister on eve of Starmer visit,” The Guardian, July 15, 2026.https://www.theguardian.com/world/2026/jul/15/volodymyr-zelenskyy-dismisses-ukraines-popular-defence-minister
- 17.BusinessDay, “Zelensky faces fresh turmoil as Ukraine appoints new defence minister,” BusinessDay, August 19, 2026.https://www.businessday.co.za/world/europe/2026-08-19-zelensky-faces-fresh-turmoil-as-ukraine-appoints-new-defence-minister/
- 18.European Commission, “AI Omnibus enters into force; Regulation (EU) 2026/1744,” European Commission / Official Journal, July 27, 2026.https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-forcehttps://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
- 19.European Commission, “AI Act — application timeline and AI Omnibus,” Shaping Europe’s digital future, Accessed October 6, 2026.https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- 20.European Union, “AI Act Annex III, high-risk systems (public services, law enforcement, migration),” AI Act, 2024.https://artificialintelligenceact.eu/annex/3/
- 21.Brandi Vincent, “Pentagon appoints new Maven Smart System program director in fresh push for C2 integration,” DefenseScoop, August 5, 2026.https://defensescoop.com/2026/08/05/pentagon-appoints-new-maven-smart-system-program-director/
- 22.Patrick Sanders, “Palantir’s Maven Is Now an Official Pentagon Program of Record,” The Motley Fool, August 25, 2026.Secondary financial press; no official DoD announcement of completion located as of October 7, 2026.https://www.fool.com/investing/2026/08/25/palantirs-maven-is-now-an-official-pentagon-progra/
- 23.UK Information Commissioner’s Office, “Facial recognition in policing: earning public trust through strong data protection governance,” ICO, August 2026.https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/08/facial-recognition-in-policing/https://ico.org.uk/media2/uo1cdoxm/police-forces-frt-outcomes-report-202608.pdf
- 24.Olha Zakrevska, “The number of successful strikes using AI guidance has increased tenfold,” The Defender, September 8, 2026.https://thedefender.media/en/2026/09/ai-guided-strikes/
- 25.WIRED, “The IRS Wants Smarter Audits. Palantir Could Help Decide Who Gets Flagged,” WIRED, March 30, 2026.https://www.wired.com/story/documents-reveal-palantir-irs-contract-fraud-clean-energy-credits/
- 26.The White House, “Executive Order 14179, Removing Barriers to American Leadership in Artificial Intelligence,” White House, January 23, 2025.https://www.whitehouse.gov/presidential-actions/2025/01/removing-barriers-to-american-leadership-in-artificial-intelligence/
- 27.The White House, “Executive Order 14243, Stopping Waste, Fraud, and Abuse by Eliminating Information Silos,” Federal Register, Signed March 20, 2025 (published March 25, 2025).https://www.federalregister.gov/documents/2025/03/25/2025-05214/stopping-waste-fraud-and-abuse-by-eliminating-information-silos
- 28.The White House, “Winning the Race: America’s AI Action Plan,” White House, July 23, 2025.https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf
- 29.U.S. District Court for the District of Columbia, “Center for Taxpayer Rights v. IRS, No. 1:25-cv-00457 (D.D.C.),” Civil Rights Litigation Clearinghouse, November 21, 2025.https://clearinghouse.net/case/46138/
- 30.The White House, “Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence,” 90 Fed. Reg. 58499, December 11, 2025.https://www.federalregister.gov/documents/2025/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-intelligence
- 31.Office of Management and Budget, “M-26-04, Increasing Public Trust in Artificial Intelligence Through Unbiased AI Principles,” OMB, December 11, 2025.https://www.whitehouse.gov/wp-content/uploads/2025/12/M-26-04-Increasing-Public-Trust-in-Artificial-Intelligence-Through-Unbiased-AI-Principles-1.pdf
- 32.California Privacy Protection Agency, “California Finalizes Regulations to Strengthen Consumers’ Privacy,” CPPA, September 23, 2025.https://cppa.ca.gov/announcements/2025/20250923.html
- 33.Norton Rose Fulbright, “X.AI sues, DOJ intervenes, enforcement of Colorado’s AI Act suspended,” X.AI LLC v. Weiser, No. 1:26-cv-01515, D. Colo., May 2026.https://www.nortonrosefulbright.com/en-us/knowledge/publications/de3ad9de/xai-sues-doj-intervenes-enforcement-of-colorado-ai-act-suspended
- 34.Goodwin Procter, “Colorado Enacts Law Repealing and Replacing Landmark Colorado AI Act (SB26-189),” Goodwin, June 10, 2026.https://www.goodwinlaw.com/en/insights/publications/2026/06/alerts-technology-fs-colorado-enacts-law-repealing-replacing-landmark-ai-act
- 35.Federal Constitutional Court of Germany, “Legislation in Hesse and Hamburg regarding automated data analysis is unconstitutional,” BVerfG press release No. 18/2023, February 16, 2023.https://www.bundesverfassungsgericht.de/SharedDocs/Pressemitteilungen/EN/2023/bvg23-018.html
- 36.Steptoe LLP, “Federal AI Legislative Tracker,” Steptoe, September 2026.https://www.steptoe.com/a/web/dkVL6BDZnGdLmjjGzB3zCm/steptoe-federal-ai-legislative-tracker_september-2026.pdf
- 37.Ministry of Defence of Ukraine, “Ministry of Defence launches Brave1 Dataroom, a secure environment for training military AI solutions,” MoD Ukraine, January 21, 2026.https://mod.gov.ua/en/news/ministry-of-defence-launches-brave1-dataroom-a-secure-environment-for-training-military-ai-solutions
- 38.Digital State UA, “Ukraine Launches Brave1 Dataroom with Palantir to Train AI Models Using Battlefield Data,” Ministry of Digital Transformation of Ukraine, January 2026.https://digitalstate.gov.ua/news/tech/ukraine-launches-brave1-dataroom-with-palantir-to-train-ai-models-using-battlefield-data
- 39.Meduza, “Palantir CEO visits Kyiv; Ukraine’s defense minister says company’s technology helps plan deep strikes inside Russia,” Meduza (summarizing Defence Minister Fedorov’s Telegram post), May 12, 2026.https://meduza.io/en/news/2026/05/12/palantir-ceo-visits-kyiv-ukraine-s-defense-minister-says-company-s-technology-helps-plan-deep-strikes-inside-russia
- 40.Palantir Technologies, “Palantir and Ministry of Economy of Ukraine Sign Demining Partnership,” Palantir investor news, March 4, 2024.https://investors.palantir.com/news-details/2024/Palantir-and-Ministry-of-Economy-of-Ukraine-Sign-Demining-Partnership/
- 41.Reuters, “Zelenskiy meets Palantir CEO as Ukraine expands use of AI in war,” Reuters, May 12, 2026.https://www.reuters.com/world/europe/zelenskiy-meets-palantir-ceo-ukraine-expands-use-ai-war-2026-05-12/
- 42.Ministry of Defence of Ukraine, “AI and Ukraine’s defence strategy: Mykhailo Fedorov and Palantir Technologies discuss cooperation,” MoD Ukraine, May 12, 2026.https://mod.gov.ua/en/news/ai-and-ukraines-defence-strategy-mykhailo-fedorov-and-palantir-technologies-discuss-cooperation-to-strengthen-security
- 43.Tamara Rozouvan, “NATO agrees sole-source procurement of Palantir’s Maven,” Janes, April 23, 2025.https://www.janes.com/defence-intelligence-insights/defence-news/c4isr/nato-agrees-sole-source-procurement-of-palantirs-maven
- 44.Reuters, “Exclusive: Pentagon to adopt Palantir AI as core US military system, memo says,” Reuters, March 20, 2026.https://www.reuters.com/technology/pentagon-adopt-palantir-ai-as-core-us-military-system-memo-says-2026-03-20/
- 45.DefenseScoop, “Feinberg’s new Maven directive sets AI-enabled decision-making as ‘the cornerstone’ for CJADC2,” DefenseScoop, April 3, 2026.https://defensescoop.com/2026/04/03/palantir-maven-feinberg-directive/
- 46.Caroline Haskins, “ICE Is Paying Palantir $30 Million to Build ‘ImmigrationOS’ Surveillance Platform,” WIRED, April 18, 2025.https://www.wired.com/story/ice-palantir-immigrationos/
- 47.U.S. Department of Homeland Security, “Privacy Impact Assessment DHS/ICE/PIA-032, FALCON Search & Analysis System,” DHS, DHS/ICE/PIA-032.https://www.dhs.gov/publication/dhsicepia-032a-falcon-search-analysis-system-falcon
- 48.U.S. ICE, “Investigative Case Management (ICM) Immigration OS Continued Support,” Award 70CTD022FR000170-P000012 (SAM.gov / GovContractFinder), September 25, 2025.https://govcontractfinder.com/contracts/investigative-case-management-icm-immigration-os-continued-s-70ctd022fr000170-p000012
- 49.Office of the Inspector General, Los Angeles Police Commission, “Review of Selected Los Angeles Police Department Data-Driven Policing Strategies,” LAPD OIG, March 2019.https://www.oig.lacity.org/_files/ugd/b2dd23_21f6fe20f1b84c179abf440d4c049219.pdf
- 50.Los Angeles Times, “LAPD ends another data-driven crime program touted to target violent offenders,” Los Angeles Times, April 12, 2019.https://www.latimes.com/local/lanow/la-me-laser-lapd-crime-data-program-20190412-story.html
- 51.Prime Minister of Australia, “Final report of the Royal Commission into the Robodebt Scheme,” Australian Government; The Guardian, July 7, 2023.https://www.pm.gov.au/media/final-report-royal-commission-robodebt-schemehttps://www.theguardian.com/australia-news/2023/jul/07/robodebt-royal-commission-final-report-recommends-civil-criminal-prosecutions
- 52.District Court of The Hague, “NJCM et al. v. The Netherlands (SyRI), ECLI:NL:RBDHA:2020:1878,” Rechtspraak, February 5, 2020.https://uitspraken.rechtspraak.nl/details?id=ECLI%3ANL%3ARBDHA%3A2020%3A1878
- 53.Benefits Tech Advocacy Hub, “Michigan Unemployment Insurance False Fraud Determinations,” BTAH, Case study.https://btah.org/case-study/michigan-unemployment-insurance-false-fraud-determinations.html
- 54.Michigan Department of Attorney General, “Class Action Settlement Approved in Bauserman v. State of Michigan Unemployment Insurance Agency,” Michigan AG, January 30, 2024.https://www.michigan.gov/ag/news/press-releases/2024/01/30/class-action-settlement-approved-by-court-of-claims
- 55.Human Rights Watch, “China’s Algorithms of Repression: Reverse Engineering a Xinjiang Police Mass Surveillance App,” HRW, May 1, 2019.https://www.hrw.org/report/2019/05/01/chinas-algorithms-repression/reverse-engineering-xinjiang-police-mass
- 56.Vincent Brussee, “China’s social credit score: untangling myth from reality,” MERICS, February 11, 2022.https://merics.org/en/comment/chinas-social-credit-score-untangling-myth-realityhttps://merics.org/en/report/chinas-social-credit-system-2021-fragmentation-towards-integration
- 57.European Union, “AI Act Article 5, Prohibited AI practices,” AI Act, 2024.https://artificialintelligenceact.eu/article/5/
- 58.National Institute of Standards and Technology, “AI Risk Management Framework (AI RMF 1.0),” NIST, 2023.https://www.nist.gov/itl/ai-risk-management-framework
- 59.United States Congress, “Privacy Act of 1974, 5 U.S.C. 552a (including matching agreements),” Cornell LII, As amended.https://www.law.cornell.edu/uscode/text/5/552a
- 60.European Union, “AI Act Article 86, Right to explanation of individual decision-making,” AI Act, 2024.https://artificialintelligenceact.eu/article/86/
- 61.Ministry of Defence of Ukraine, “Ministry of Defence and Brave1 conduct large-scale testing of drones with AI guidance,” MoD Ukraine, September 8, 2026.https://mod.gov.ua/en/news/ministry-of-defence-and-brave1-conduct-large-scale-testing-of-drones-with-ai-guidance
Appendix E
Model Legislative Language
E.1 — No Military-to-Civil Transfer Without Separate Legal Authorization
Section 1. Findings. Congress finds that —
(1) AI systems developed, trained, or validated in military, intelligence, or national-security settings may be operationally effective and democratically unsuitable for civil administration;
(2) the national-security-system carve-outs in OMB M-25-21 and M-25-22, and the “exclusively” military exclusion in EU AI Act Article 2(3), leave the security-to-civil crossing point inadequately governed;
(3) existing law — including the Privacy Act, 5 U.S.C. 552a, and the tax confidentiality protections of 26 U.S.C. 6103 — provides partial protections but does not require separate authorization for a system whose security-domain validation is cited as a basis for civil deployment; and
(4) separate legal authorization is required before any such system enters civil use.
Section 2. Definitions. In this Act —
(a) AI system. Any machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. The term shall be construed consistently with existing federal usage and, where applicable, with definitions adopted by the National Institute of Standards and Technology.
(b) Agency. An executive agency, as defined in 5 U.S.C. 105, for purposes of this Act, and any component thereof.
(c) National-security setting. An element of the intelligence community (50 U.S.C. 3003(4)), the Department of Defense, or a national security system (44 U.S.C. 3552(b)(6)).
(d) Covered system. An AI system, or a model, dataset, or output derived from it, that —
(1) was developed, trained, fine-tuned, or accredited using data, infrastructure, or test results from a national-security setting; and
(2) whose security-domain validation, accreditation, or use was cited or relied upon in —
(A) the agency’s justification for acquiring or deploying it for civil use, including any sole-source justification, authorization to operate, or equivalent record; or
(B) the vendor’s proposal, marketing materials, or other public statements about the system, its model family, or its product line.
Presumption of coverage. An AI system is presumed to be a covered system if the vendor supplies a system of the same product line or model family to a national-security setting. The agency head may rebut the presumption only by a written determination, published before the system is acquired or deployed for civil use, that states the factual basis for finding that the system does not meet paragraph (1) or does not meet paragraph (2), supported by the vendor’s documentation of the system’s training data, fine-tuning, and accreditation history. If the vendor does not provide that documentation, the presumption may not be rebutted. That the system is a commercial product (41 U.S.C. 103) may support such a determination but does not by itself rebut the presumption.
(e) Civil use. Deployment, procurement, or integration into workflows of an agency in a rights-sensitive domain.
(f) Rights-sensitive domain. Any of the following, and case management for any of them —
(1) immigration enforcement;
(2) immigration adjudication, including asylum, refugee, naturalization, visa, and immigration-benefits determinations;
(3) border and port-of-entry screening;
(4) policing;
(5) criminal justice beyond policing, including pretrial release and detention, sentencing, probation and parole supervision, and corrections;
(6) welfare and benefits administration; and
(7) tax administration.
The term does not include (i) internal administrative functions such as payroll, hiring, or facilities management, or (ii) systems used solely for statistical or research purposes that do not produce decisions about identifiable individuals.
(g) Separate legal authorization. A statute or regulation that expressly authorizes civil use of the covered system, or an express written authorization for that use issued by the agency head and published in the Federal Register, together with any Privacy Act system-of-records notice (5 U.S.C. 552a(e)(4)) and computer-matching agreement (5 U.S.C. 552a(o)) required by law. An authorization by the agency head does not by itself constitute separate legal authorization where a statute restricts the collection, use, or disclosure of the data the system relies on, or restricts the use to which the system is put.
(h) Appropriate congressional committees. The committees of the Senate and the House of Representatives with legislative or oversight jurisdiction over the agency concerned.
Section 3. Prohibition. No agency may obligate funds for, deploy, or integrate into civil workflows any covered system unless the agency has obtained separate legal authorization for civil use and published a civil authorization dossier under Section 4. This section does not apply to a system for which the presumption in Section 2(d) has been rebutted by a published determination and that does not otherwise meet Section 2(d).
Section 4. Civil Authorization Dossier. The dossier shall include, at minimum —
(1) system purpose, stated in plain language;
(2) the specific legal authority for civil use;
(3) a data inventory identifying every data source, its collection purpose, and its legal basis;
(4) a model description, including architecture, training-data provenance, known limitations, and validation results;
(5) human-review standards, including when a human must review, what the reviewer must document, and what the reviewer may override;
(6) contestability procedures, including notice to affected persons, appeal timelines, and the mechanism for challenging data, inference, and decision;
(7) audit-access rules, identifying who may inspect the system, at what layer, and under what authority;
(8) vendor obligations, including data-return, deletion, portability, non-reuse, and cooperation with auditors;
(9) data-retention limits, per data class, with a deletion-verification method;
(10) portability rights, describing how data and models transition if the vendor relationship ends;
(11) prohibited uses, enumerated by policy; and
(12) a sunset date, not to exceed three years from publication, after which the authorization expires unless reauthorized.
The dossier shall be reviewed by the agency’s Chief AI Officer and legal counsel, and submitted to the agency’s Inspector General. A summary shall be transmitted to OMB and to the appropriate congressional committees within 30 days of publication. Classified material may be filed in a classified annex, provided that the unclassified portion is sufficient for meaningful public and congressional oversight of the system’s purpose, authority, data sources, and review procedures.
Section 5. Domain Firewalls. The agency shall maintain enforceable technical and legal separation between military, intelligence, enforcement, and civil-benefits systems, including data-minimization, purpose-limitation, and audit-access controls. Nothing in this section prohibits cross-agency coordination that is (1) authorized by statute, (2) documented in a written agreement, and (3) subject to audit.
Section 6. Enforcement.
(a) Limitation on funds. An obligation, option exercise, or modification for a covered system without separate legal authorization and a published dossier is an obligation in excess of available appropriations, prohibited by 31 U.S.C. 1341(a)(1)(A), and reportable under 31 U.S.C. 1351.
(b) Oversight. Within 180 days of enactment, each agency shall report all covered systems, including withdrawn systems, to Congress and to the Comptroller General. The Comptroller General shall review the reports within one year and report findings to Congress. Classified details shall be filed in an annex to the relevant committees, with an unclassified summary.
(c) Complaints and judicial review. Any person, including an individual affected by a covered system or an organization representing such individuals, may file a written complaint with the agency’s Chief AI Officer alleging deployment of a covered system without authorization or dossier. The complaint shall identify the system, or describe it as specifically as the complainant can, state the facts supporting the allegation, and give a means of contacting the complainant. The agency shall respond within 90 days; failure to respond constitutes final agency action. Final agency action to deploy or continue a covered system in violation of this Act is reviewable under 5 U.S.C. 702–706. Relief is declaratory and injunctive only. Fees are available under the Equal Access to Justice Act, 28 U.S.C. 2412. Nothing in this subsection waives sovereign immunity beyond the waiver already provided in 5 U.S.C. 702.
(d) Waiver. The agency head may waive the requirements of this Act for a specific covered system for not more than 180 days upon a written determination that the waiver is necessary to avert an imminent threat to human life. A waiver may be renewed once, for not more than 180 days, upon a new written determination. Within 7 days of issuing or renewing a waiver, the agency head shall transmit the full determination, with any classified material in a classified annex, to the appropriate congressional committees, and shall publish an unclassified summary.
(e) Transition. Notwithstanding Sections 3, 6(a), and 7, a covered system in use on the date of enactment may remain in use for 12 months after that date, during which the agency shall obtain separate legal authorization and publish a dossier under Section 4. Renewals and option exercises under contracts in effect on the date of enactment that occur within that 12-month period fall within this transition. New awards, and material modifications of existing contracts, made after the date of enactment are covered immediately. A covered system for which authorization has not been obtained and a dossier published by the end of the 12-month period shall be withdrawn from civil use.
Section 7. Appropriations. No funds appropriated or otherwise made available to any agency may be obligated or expended for the procurement, deployment, or integration of a covered system unless separate legal authorization has been obtained and the civil authorization dossier has been published.
Section 8. Rule of construction and savings. Nothing in this Act shall be construed to authorize any use of an AI system that is otherwise prohibited by law. Nothing in this Act shall be construed to supersede, limit, or diminish the Privacy Act, 5 U.S.C. 552a, the tax confidentiality protections of 26 U.S.C. 6103, or any other statutory protection for personal data.
Section 9. Condition on grants to states.
(a) Condition. As a condition of receiving funds under a federal grant program that funds state or local administration of a rights-sensitive domain, a recipient shall not deploy, or integrate into the administration of the program, a covered system as used by the recipient unless the recipient has —
(1) identified the state or local legal authority that expressly authorizes that use; and
(2) published a civil authorization dossier for that use containing the elements listed in Section 4.
The recipient shall certify compliance with this subsection to the federal agency administering the program before receiving funds and [annually thereafter] [Alternative: before deploying any new covered system and before any material change in a covered system’s purpose, data sources, or model].
(b) Definitions. In this section —
(1) the term “recipient” means a State, a political subdivision of a State, or an agency or instrumentality of either, that receives funds under a grant program described in subsection (a), directly or as a subrecipient; and
(2) the term “covered system as used by a recipient” means an AI system, or a model, dataset, or output derived from it, that meets Section 2(d)(1) and whose security-domain validation, accreditation, or use was cited or relied upon in the recipient’s justification for acquiring or deploying it, or in the vendor’s proposal, marketing materials, or other public statements about the system, its model family, or its product line. The presumption of coverage in Section 2(d) applies, and may be rebutted only by a written determination of the recipient’s chief executive officer, or that officer’s designee, published before deployment and supported by the vendor documentation that Section 2(d) requires.
(c) Administration. The head of each federal agency administering a program described in subsection (a) shall state the condition in each notice of funding opportunity and include it in each grant agreement entered into or renewed after the date of enactment. After written notice and an opportunity to cure of not less than 90 days, the agency head may withhold, or recover, funds attributable to the use of a covered system in violation of this section. The condition applies only to awards made after the date of enactment.
Section 10. Severability. If any provision of this Act, or the application of any provision, is held invalid, the remainder of the Act and its application to other persons or circumstances shall not be affected.
E.2 — Civil Authorization Dossier Requirement (Executive Branch)
Section 1. Before deploying any AI system in a rights-sensitive civil domain, the agency shall publish a civil authorization dossier. The dossier shall be available before procurement lock-in, operational deployment, or irreversible integration into agency workflows. The dossier documents authorization; it does not substitute for the underlying legal authority.
Section 2. The dossier shall be reviewed by the agency’s Chief AI Officer and legal counsel, and submitted to the agency’s Inspector General. A summary shall be transmitted to OMB within 30 days of publication.
Section 3. The agency shall publish a prohibited-use list for each system covered by this requirement.
Section 4. Each authorization shall include a sunset date not to exceed three years from publication. Reauthorization requires a new dossier and independent review.
Section 5. The agency’s Inspector General is requested to review compliance with this order and to audit covered systems as the Inspector General considers appropriate, and is requested to report findings to the agency head and to Congress in the Inspector General’s next semiannual report.
Notes on cited authorities
These notes flag where a citation is correct but narrower than it might look, and where a drafting choice needs counsel’s attention.
Notes by authority
- 5 U.S.C. 105 defines “Executive agency” as an Executive department, a Government corporation, and an independent establishment, “for the purpose of this title.” It is the right definition for covered federal agencies, and §2(b) incorporates it expressly “for purposes of this Act.” APA review uses the broader “agency” definition in 5 U.S.C. 551(1) and 701(b)(1). Text
- 50 U.S.C. 3003 contains the National Security Act definitions. Paragraph (4) lists the elements of the “intelligence community”; §2(c) cites 3003(4). Text
- 44 U.S.C. 3552(b)(6) defines “national security system”: systems involving intelligence or cryptologic activities, command and control of military forces, equipment integral to a weapons system, or systems critical to military or intelligence missions, plus systems protected as classified. It excludes routine administrative and business applications. The citation is correct. Text
- 41 U.S.C. 103 defines “commercial product.” The citation is correct, but the definition also covers products with “modifications of a type customarily available in the commercial marketplace” and “minor modifications” made to meet Federal Government requirements (§103(3)). A carve-out keyed to commercial products would therefore reach some modified systems. For that reason §2(d) does not exclude commercial products: commercial status may support a determination rebutting the presumption of coverage but does not by itself rebut it, and the lineage and reliance tests do the limiting work. Commercial services are defined separately in 41 U.S.C. 104. Text
- 5 U.S.C. 552a(e)(4) requires a system-of-records notice to be published in the Federal Register. The citation is correct. A SORN gives notice; it does not grant legal authority. §2(g) treats it correctly, as an additional requirement alongside the authorizing statute, regulation, or published agency-head authorization. Text
- 5 U.S.C. 552a(o) requires written computer-matching agreements. The citation is correct, but the requirement applies only to “matching programs” as defined in 552a(a)(8). That definition excludes, among other things, matches made in a criminal or civil law-enforcement investigation of named persons and certain tax-administration matches. It is a partial hook, not a general firewall.
- 31 U.S.C. 1351 is only the Antideficiency Act’s reporting provision. When an officer or employee violates 31 U.S.C. 1341(a) or 1342, the agency head must report to the President and Congress and send a copy to the Comptroller General. It does not prohibit any spending by itself. The operative bar on obligating funds against a funding limitation is 31 U.S.C. 1341(a)(1)(A), read with the purpose statute, 31 U.S.C. 1301(a). The administrative and criminal penalties are in 31 U.S.C. 1349–1350. §6(a) cites 1341(a)(1)(A) as the prohibition and 1351 as the reporting duty. §7’s appropriations limitation is what makes the amount available for an unauthorized covered system zero, so the two sections should stay together. 1351 · 1341
- 5 U.S.C. 702–706 provide APA judicial review. The citation is correct. Section 702 waives sovereign immunity for relief other than money damages, which is what lets APA review do the work the earlier private right of action could not. Section 706 sets the scope of review. 702
- 28 U.S.C. 2412 is the Equal Access to Justice Act provision on costs and fees. The citation is correct. Fee awards under 2412(d) are limited by party net-worth and size thresholds and are not available if the government’s position was “substantially justified.” Text
- 26 U.S.C. 6103 protects the confidentiality of returns and return information. The citation is correct; the D.C. Circuit applied it to the IRS–ICE address exchange (Section 06). Text
- EU AI Act Article 3(1) reads: “’AI system’ means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.” E.1 §2(a) keeps the inference element word for word and leaves out the autonomy and adaptiveness language, so it is somewhat broader than Article 3(1). That is a defensible drafting choice for a gate that turns on lineage and reliance, but it is not an exact match. The existing U.S. statutory definition in 15 U.S.C. 9401(3) is worded differently, and counsel should decide which one §2(a) is meant to be “consistent with.” Text
- EU AI Act Article 2(3) excludes AI systems “where and in so far” as they are placed on the market, put into service, or “used with or without modification exclusively for military, defence or national security purposes.” The exclusion covers defence and national security as well as military use. Recital 24 states that a system built for those purposes that is then used “temporarily or permanently” for civilian, law-enforcement, or public-security purposes “would fall within the scope” of the Regulation. Finding (2)’s shorthand (“military exclusion”) should be read with that wider scope. Art. 2 · Recital 24
- Executive Order 14365 (December 11, 2025). Section 3 directs the Attorney General to set up an AI Litigation Task Force within 30 days to challenge state AI laws. Section 8(b)(iii) provides that the legislative recommendation for a preemptive federal framework “shall not propose preempting otherwise lawful State AI laws relating to … State government procurement and use of AI.” That carve-out limits the legislative proposal only. It does not on its face limit the Task Force’s litigation or the grant conditions in Section 5, and any text relying on it should say so. Text
Points for counsel
- §2(d) presumption. The presumption turns on whether the vendor supplies the same product line or model family to a national-security setting. Neither term is defined. One option is to define them functionally, for example as systems that share a base model, training pipeline, or core software platform, whatever the product name, so that rebranding does not defeat the presumption; another is to leave the terms to OMB guidance. Counsel should also decide whether the rebuttal standard (a published determination supported by vendor documentation) should require independent review.
- Administrability and vendor due process. The presumption burdens the agency’s acquisition decision: it determines what the agency must do before buying or deploying a system. It imposes no sanction, penalty, or debarment on the vendor, which remains free to sell to other customers and to supply the documentation that rebuts the presumption. That structure should not raise a due-process problem for vendors, but counsel should confirm it and should confirm that agencies can administer the product-line test.
- Vendor non-cooperation. If a vendor will not document a system’s training data, fine-tuning, and accreditation history, the presumption cannot be rebutted and the system stays covered. That is deliberate: lineage is usually known only to the vendor, so the burden of producing it sits with the vendor. Counsel may wish to back this with a contract clause requiring the documentation in any new award.
- §6(c) complaints. “Any person” is intentionally broad for filing a complaint, which costs the agency only a response. Judicial review is narrower: a complainant still needs standing to sue under Article III and the APA, which the subsection does not and cannot expand.
- §2(f) border screening. Some border and port-of-entry screening systems may themselves be national security systems under 44 U.S.C. 3552(b)(6). The Act reaches them when a covered system is used in that domain for civil decisions about individuals; counsel should confirm that the interaction with §2(c) is intended.
- §2(g) agency-head authorization. An agency may not authorize itself where a statute restricts the data or the use. Counsel should confirm that Federal Register publication is the right vehicle and whether notice and comment should be required.
- §6(e) transition. The transition overrides §6(a) as well as §§3 and 7, because §6(a) would otherwise treat an option exercise during the window as a prohibited obligation. “Material modification” is not defined; counsel may wish to define it by contrast with the “minor modifications” in 41 U.S.C. 103(3).
- §9 grant condition. Conditions on federal grants to states must be stated unambiguously (Pennhurst State School and Hospital v. Halderman, 451 U.S. 1, 17 (1981)). §9 therefore states the condition and the recipient’s obligations in the section itself, defines “recipient” and “covered system as used by a recipient” on their own terms rather than through §2(b), which reaches only federal agencies, and applies only to awards made after enactment.
- E.2 §5. An executive order cannot direct an Inspector General’s work without raising independence concerns under the Inspector General Act, so §5 requests rather than directs review.
Appendix F
State Version: Model Bill, Introduction, and Talking Points
F.1 — Model State Bill: [State] Civil AI Authorization Act
Section 1. Short title. This Act may be cited as the [State] Civil AI Authorization Act.
Section 2. Findings. The legislature finds that —
(1) state agencies make decisions about benefits, liberty, and livelihoods in which automated error can cause serious and widespread harm, as the record of automated unemployment-insurance fraud determinations shows;
(2) that harm has occurred when automated decisions were deployed before legal authority, public disclosure, and a meaningful right to contest were in place, whatever the system’s origin;
(3) AI systems developed, trained, or validated in military, intelligence, and other national-security settings are offered for civil administration, and validation in those settings does not establish that a system is lawful, accurate, or contestable in civil use;
(4) federal AI governance memoranda apply to federal agencies, not to state agencies; and
(5) a state agency should identify the legal authority for, and publish the data sources, review standards, and appeal procedures of, any AI system before using it to make or support decisions about individuals.
Section 3. Definitions. In this Act —
(a) AI system. Any machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
(b) State agency. Any department, board, commission, authority, or other agency of the executive branch of [State] [, and any political subdivision of [State] and any agency of a political subdivision]. [The term does not include the legislature or the judicial branch.]
(c) Rights-sensitive domain. Any of the following, and case management for any of them —
(1) unemployment insurance, Medicaid, the Supplemental Nutrition Assistance Program, Temporary Assistance for Needy Families, housing assistance, state student aid, and other public benefits;
(2) child welfare and child protective services;
(3) policing, including facial recognition, predictive policing, risk scoring, and case prioritization;
(4) criminal justice beyond policing, including pretrial release and detention, sentencing, probation and parole supervision, and corrections;
(5) participation in immigration enforcement, including any agreement under 8 U.S.C. 1357(g), and the sharing of data for immigration-enforcement purposes;
(6) state tax administration, including audit selection and collection enforcement; and
(7) [other domains the state designates, such as professional or occupational licensing].
(d) Covered system. An AI system that a state agency uses to make, or to materially support, a decision about an identifiable individual in a rights-sensitive domain. The term does not include a system used solely for internal administrative functions such as payroll, hiring, facilities management, or general correspondence, or a system used solely for statistical or research purposes that does not produce decisions about identifiable individuals. That a system is a commercial product does not exclude it.
(e) Materially support. To produce an output, such as a score, ranking, flag, classification, or recommendation, that a decision-maker is required or expected to consider, or that determines which individuals are selected for review, investigation, or action.
(f) National-security setting. An element of the intelligence community (50 U.S.C. 3003(4)), the United States Department of Defense, a national security system (44 U.S.C. 3552(b)(6)), or an equivalent military, intelligence, or defense body of a foreign government.
(g) Security-domain lineage. A covered system has security-domain lineage if —
(1) the system, or a model, dataset, or output from which it is derived, was developed, trained, fine-tuned, or accredited using data, infrastructure, or test results from a national-security setting; or
(2) its validation, accreditation, or use in a national-security setting was cited or relied upon in the state agency’s justification for acquiring or deploying it, or in the vendor’s proposal, marketing materials, or other public statements about the system, its model family, or its product line.
Presumption. A covered system is presumed to have security-domain lineage if the vendor supplies a system of the same product line or model family to a national-security setting. The head of the state agency may rebut the presumption only by a written determination, published in the dossier before deployment, that states the factual basis for finding that neither paragraph (1) nor paragraph (2) applies, supported by the vendor’s documentation of the system’s training data, fine-tuning, and accreditation history. If the vendor does not provide that documentation, the presumption may not be rebutted.
(h) Separate legal authorization. A statute or regulation of [State] that expressly authorizes use of the covered system for the purpose stated in the dossier, or an express written authorization for that use issued by the head of the state agency and published in [the State Register], together with any data-sharing agreement required by law. An authorization by the agency head does not by itself constitute separate legal authorization where a state or federal statute restricts the collection, use, or disclosure of the data the system relies on, or restricts the use to which the system is put.
(i) Dossier. A civil authorization dossier published under Section 5: a short-form dossier for a Tier 1 system or a full dossier for a Tier 2 system.
(j) Heightened-tier system. A covered system that has, or is presumed to have, security-domain lineage.
(k) Department. The [Department of Information Technology], or another state agency the governor designates to maintain the inventory under Section 9.
(l) Adverse decision. A decision about an identifiable individual that —
(1) denies, reduces, suspends, terminates, delays, or seeks recovery of a public benefit, service, payment, or license;
(2) imposes or proposes a penalty, fine, tax assessment, overpayment determination, or collection action;
(3) selects the individual for investigation, audit, fraud review, surveillance, or enforcement action;
(4) initiates, or is considered in, a child-welfare investigation or a decision on removal or placement;
(5) affects the individual’s arrest, detention, pretrial release, sentence, or conditions of probation, parole, or other supervision;
(6) discloses or makes available the individual’s data for law-enforcement or immigration-enforcement purposes; or
(7) otherwise has a comparably significant adverse effect on the individual’s rights, benefits, liberty, or livelihood.
(m) Tier 2 system. A covered system that makes or materially supports an adverse decision, and any heightened-tier system regardless of how it is used. A system whose outputs can lead only to a favorable decision does not materially support an adverse decision if every individual the system does not select for favorable action is processed as though the system had not been used, and the system’s output is neither shown to nor considered by the decision-maker in that processing.
(n) Tier 1 system. A covered system that is not a Tier 2 system.
Section 4. Authorization required.
(a) Authorization and dossier. No state agency may deploy a covered system, or integrate it into the administration of a program, unless the agency has obtained separate legal authorization for that use and has published the dossier required by Section 5 for the system’s tier at least [60] days before deployment.
(b) Contracts. No state agency may enter into a new contract, or materially modify an existing contract, for a covered system unless the contract requires the vendor to provide the information the agency needs to complete the dossier, to disclose any security-domain lineage, and to cooperate with audits under Section 9.
(c) Material changes. A material change in a covered system’s purpose, use, data sources, or model requires a revised dossier before the change takes effect. A change described in Section 5(d) is a material change and is governed by that subsection.
Section 5. Dossier tiers and contents.
(a) Tier determination. Before publishing a dossier, the state agency shall determine whether the covered system is a Tier 1 system or a Tier 2 system, and shall publish that determination in the dossier with a short statement of reasons that describes how the system’s outputs are used in decisions about individuals. An agency that cannot make that determination shall treat the system as a Tier 2 system.
(b) Tier 1: short-form dossier. The dossier for a Tier 1 system shall include, at minimum —
(1) system purpose, stated in plain language;
(2) the specific legal authority for the use;
(3) the categories of data the system uses, and their sources;
(4) the vendor, if any, and the name and version of the product;
(5) a statement of whether the system has, or is presumed to have, security-domain lineage, with the basis for that finding and any rebuttal determination under Section 3(g);
(6) a contact within the agency for questions about the system, and the procedure by which an individual may contest a decision in which the system was used;
(7) prohibited uses, including any use that would make the system a Tier 2 system; and
(8) a sunset date, not to exceed three years from publication, after which the authorization expires unless renewed with a new dossier.
(c) Tier 2: full dossier. The dossier for a Tier 2 system, including every heightened-tier system, shall include, at minimum —
(1) system purpose, stated in plain language;
(2) the specific legal authority for the use;
(3) a data inventory identifying every data source, its collection purpose, and its legal basis;
(4) a model description, including architecture, training-data provenance, known limitations, and validation results;
(5) human-review standards, including when a human must review, what the reviewer must document, and what the reviewer may override;
(6) contestability procedures, including notice to affected persons, appeal timelines, and the mechanism for challenging data, inference, and decision;
(7) audit-access rules, identifying who may inspect the system, at what layer, and under what authority;
(8) vendor obligations, including data-return, deletion, portability, non-reuse, and cooperation with auditors;
(9) data-retention limits, per data class, with a deletion-verification method;
(10) portability rights, describing how data and models transition if the vendor relationship ends;
(11) prohibited uses;
(12) a statement of whether the system has, or is presumed to have, security-domain lineage, with the basis for that finding and any rebuttal determination under Section 3(g); and
(13) a sunset date, not to exceed three years from publication, after which the authorization expires unless renewed with a new dossier.
(d) Escalation. If a change in the use of a Tier 1 system, including a change in how decision-makers use its outputs, would cause it to make or materially support an adverse decision, the change is a material change under Section 4(c). The state agency may not begin the changed use until it has published a full dossier under subsection (c) and [60] days have passed. If the agency finds that a Tier 1 system has, or is presumed to have, security-domain lineage, it shall publish a full dossier and meet Section 6 before continuing to use the system.
(e) Reclassification. The [State Auditor], on its own initiative or at the request of the Department, a member of the legislature, or any person, may determine that a system the state agency classified as Tier 1 is a Tier 2 system. The [State Auditor] shall give the agency written notice of the determination and its reasons, and shall publish it. The agency may continue to use the system for not more than [30] days after receiving the notice, and after that only once it has published a full dossier and, for a heightened-tier system, met Section 6.
(f) Publication. The agency shall publish the dossier on its website and file it with the Department. Information whose disclosure is prohibited by law, or that is a trade secret, may be placed in a confidential annex available to the Attorney General and the [State Auditor], provided that the public portion is sufficient for meaningful public and legislative oversight of the system’s purpose, authority, data sources, and review procedures.
Section 6. Heightened tier. A heightened-tier system is a Tier 2 system and requires a full dossier under Section 5(c), whatever its use. Before deploying a heightened-tier system, and in addition to the requirements of Sections 4 and 5, the state agency shall —
(a) Independent testing. Obtain an evaluation of the system’s accuracy, error rates, and differences in error rates across groups in the population on which it will be used, conducted by an evaluator with no financial interest in the vendor, and publish a summary in the dossier;
(b) Auditor review. Submit the dossier and the evaluation to the [State Auditor], who may review them and report findings to the agency and the legislature within [90] days;
(c) Legislative notice. Transmit the dossier to [the appropriate standing committees of the legislature] at least [60] days before deployment;
(d) Human decision. Ensure that no adverse decision about an individual rests solely on the system’s output, and that a human decision-maker with authority to override the output reviews each adverse decision; and
(e) Shorter sunset. Set a sunset date not more than [two] years from publication.
Section 7. Notice, explanation, and appeal.
(a) Notice. When a covered system makes or materially supports an adverse decision about an individual, the state agency shall give the individual written notice that an AI system was used, a plain-language explanation of the principal factors in the decision, and instructions for appeal.
(b) Appeal. The individual may challenge the data, the inference, and the decision before a human decision-maker under [the state’s existing administrative hearing procedures].
(c) Other rights. Nothing in this section limits any right under [the State Administrative Procedure Act] or federal law.
Section 8. Domain firewalls. Each state agency shall maintain enforceable technical and legal separation between law-enforcement and immigration-enforcement systems and systems used for benefits, child welfare, or tax administration, including data-minimization, purpose-limitation, and audit-access controls. Data collected for benefits, child welfare, or tax administration shall not be used in a covered system for law-enforcement or immigration-enforcement purposes except through coordination that is (1) authorized by statute, (2) documented in a written agreement, and (3) subject to audit.
Section 9. Inventory, oversight, and reporting.
(a) Inventory. Within [180] days after the effective date, the Department shall publish an inventory of covered systems in use by state agencies, with each system’s tier and a link to its dossier, and shall keep it current.
(b) Audit. The [State Auditor] may audit any covered system, including the agency’s tier determination, and shall report to the legislature on state agencies’ compliance with this Act at least once every [two] years.
(c) Annual report. Each state agency shall report annually to the Department and the legislature on the covered systems it uses, any waivers under Section 11, and the number and outcome of complaints and appeals involving covered systems.
Section 10. Enforcement.
(a) Attorney General. The Attorney General may bring an action in [court] for declaratory or injunctive relief to prevent the deployment, or stop the continued use, of a covered system in violation of this Act.
(b) Civil penalties [optional]. [Option A: A court may impose on a state agency that knowingly violates this Act a civil penalty of not more than [$10,000] per violation, to be deposited in [a dedicated fund for independent evaluation under Section 6(a)].] [Option B: A court may impose on a vendor that knowingly provides false or materially incomplete information for a dossier a civil penalty of not more than [$10,000] per violation.]
(c) Complaints and judicial review. Any person, including an individual affected by a covered system or an organization representing such individuals, may file a written complaint with the state agency and the Department alleging use of a covered system in violation of this Act. The complaint shall identify the system, or describe it as specifically as the complainant can, state the facts supporting the allegation, and give a means of contacting the complainant. The agency shall respond in writing within [90] days; failure to respond constitutes final agency action. Final agency action to deploy or continue a covered system in violation of this Act is subject to judicial review under [the State Administrative Procedure Act]. [Relief under this subsection is limited to declaratory and injunctive relief.]
Section 11. Governor’s waiver.
(a) Waiver. The governor may waive Sections 4 through 6 for a specific covered system for not more than [90] days upon a written determination that the waiver is necessary to avert an imminent threat to human life.
(b) One renewal. A waiver may be renewed once, for not more than [90] days, upon a new written determination. No further waiver may be issued for the same system and purpose.
(c) Notice to the legislature. Within [7] days of issuing or renewing a waiver, the governor shall transmit the determination to [the presiding officer of each house of the legislature and the appropriate standing committees] and publish it, withholding only information whose disclosure is prohibited by law.
(d) Limits. A waiver does not suspend Section 7 or authorize any use otherwise prohibited by law.
Section 12. Transition.
(a) Systems in use. Notwithstanding Section 4, a covered system in use on the effective date may remain in use for [12] months after that date, during which the state agency shall obtain separate legal authorization, publish the dossier required by Section 5, and, for a heightened-tier system, meet Section 6.
(b) Existing contracts. Renewals and option exercises under contracts in effect on the effective date that occur within that period fall within this transition. New contracts, and material modifications of existing contracts, made after the effective date are covered immediately.
(c) Withdrawal. A covered system that does not comply with this Act at the end of the transition period shall be withdrawn from use.
Section 13. Savings; relation to federal law.
(a) No new authority. Nothing in this Act authorizes any use of an AI system that is otherwise prohibited by law.
(b) Privacy protections. Nothing in this Act supersedes, limits, or diminishes [the state’s privacy and data-protection laws], the Privacy Act, 5 U.S.C. 552a, the tax confidentiality protections of 26 U.S.C. 6103, or any other protection for personal data.
(c) Federal requirements. Where federal law or a condition of federal funding imposes requirements on the same system, the state agency shall comply with both. A federal dossier may be incorporated by reference but does not satisfy this Act unless the state dossier identifies the state legal authority for the state’s use. A state dossier does not satisfy a federal requirement unless the federal agency administering that requirement accepts it.
(d) Scope. This Act governs state agencies and their contractors. It does not regulate the development or use of AI by private parties acting on their own behalf.
Section 14. Severability. If any provision of this Act, or its application to any person or circumstance, is held invalid, the invalidity does not affect other provisions or applications of the Act that can be given effect without the invalid provision or application.
Section 15. Effective date. This Act takes effect [date]. Section 4(b) applies to contracts entered into or materially modified on or after the effective date.
Introduction to the state version
Why a state version is needed
The federal statute in Appendix E governs federal agencies and attaches conditions to federal grants; it cannot directly govern state administration. Yet the documented harm from automated administration has largely occurred in programs that states run. MiDAS was a Michigan system. Robodebt was Australian, but its American analogues — automated unemployment insurance fraud determinations, Medicaid eligibility terminations, SNAP recertification failures — are administered by state agencies under federal grant conditions. State and local police departments deploy facial recognition, predictive policing, and risk scoring without federal oversight.
MiDAS, Robodebt, and SyRI were not built or validated in security settings, and a rule triggered only by security lineage would not have caught them. They show something else: what happens when automated decisions are deployed before anyone establishes the legal authority, publishes how the system works, or provides a way to contest it. That is why F.1 requires authorization and a published dossier for any AI system used in decisions about individuals in a rights-sensitive domain, and adds a heightened tier when security-domain lineage is present or presumed. The dossier is scaled to the system’s role: a short-form dossier for a system that does not make or materially support an adverse decision, and the full dossier for one that does and for every security-derived system.
How the two versions interact
They are complementary, not duplicative. Four points of interaction matter.
1. Federal systems deployed in state programs. When a federal agency provides a system to a state agency — for example, an eligibility determination tool, a fraud detection platform, or a case management system — the federal statute governs the federal agency’s authorization and dossier. The state statute governs the state agency’s use. A state agency cannot satisfy its own obligation by pointing to the federal dossier; it must produce its own, because the legal authority for state use is different from the legal authority for federal use (F.1 §13(c)).
2. State agencies receiving federal funds. Federal §9 conditions certain grants on the recipient identifying its own legal authority and publishing a dossier for covered systems. The state statute gives the state its own mechanism for meeting that condition. Without a state statute, the state has no mechanism of its own for doing so, and enforcement of the condition is left to the federal grantor.
3. Preemption. Executive Order 14365 (December 2025) sought a federal framework for AI and directed the Attorney General to establish an AI Litigation Task Force to challenge state AI laws. The order also provides that the legislative recommendation it calls for “shall not propose preempting otherwise lawful State AI laws relating to … State government procurement and use of AI.” That carve-out limits only the legislative proposal; by its terms it does not limit the Task Force’s litigation or the grant conditions in Section 5 of the order. A state civil authorization statute is therefore on comparatively strong ground: it regulates the state’s own agencies, not private parties (F.1 §13(d)), and it is the kind of law the order’s legislative carve-out describes.
4. Federal-state information sharing. Where a state agency shares data with a federal agency — or receives federal data — both statutes may apply. The state statute’s domain-firewall provision (F.1 §8) and the federal statute’s matching-agreement provision should be read together. Neither displaces the Privacy Act or 26 U.S.C. 6103.
What the state version covers that the federal version cannot
- State-administered benefits: unemployment insurance, Medicaid, SNAP, TANF, child welfare, state student aid
- State and local policing: facial recognition, predictive policing, risk scoring, case prioritization
- State criminal justice beyond policing: pretrial release, sentencing, probation and parole, corrections
- State tax administration: audit selection and collection enforcement
- State and local case management systems that produce decisions about individuals
The core standard, with a broader trigger
Both versions require separate legal authorization and a published civil authorization dossier before deployment, and both require a sunset. They differ in what triggers the requirement. E.1 applies to systems with security-domain lineage whose security validation was relied upon. F.1, like the executive-branch text in E.2, applies to any AI system used to make or materially support decisions about individuals in a rights-sensitive domain. It then adds a heightened tier — independent testing, state-auditor review, legislative notice, a bar on sole reliance for adverse decisions, and a shorter sunset — when security-domain lineage is present or presumed. F.1 also scales the dossier itself: a covered system that does not make or materially support an adverse decision needs only a short-form dossier, while a system that does, and every heightened-tier system, needs the full dossier (F.1 §5). E.2 has no short form; every system it covers needs the full dossier. The domain-translation test in Section 11 of this brief is the analysis behind the heightened tier; it is not written into either bill as a legal standard.
What the state version does differently
- A broader trigger with a heightened tier, as described above.
- A tiered dossier. Systems that do not make or materially support an adverse decision file a short-form dossier; the state auditor can move a system into the full-dossier tier, and a change in use that makes the system part of adverse decisions requires the full dossier first (F.1 §5(d)–(e)).
- AG enforcement instead of DOJ enforcement. Whether a state attorney general may sue another state agency, rather than represent it, varies by state constitution and statute, so confirm that authority before introduction. Where it exists, the sovereign-immunity and separation-of-powers problems that block federal enforcement do not arise in the same way at the state level.
- Optional civil penalties. Penalties are bracketed in F.1 §10(b). A penalty paid by a state agency comes from state funds and can be circular, so the bill offers a dedicated-fund option and a vendor-only option. The federal version relies on the funds limitation and APA review.
- Governor’s waiver instead of agency-head waiver. At the state level, the governor is the appropriate waiver authority. The waiver is limited to imminent threats to life, may be renewed once, and must be reported to the legislature.
- No private right of action. Standing and exhaustion rules vary widely across state APAs. Complaints, judicial review under the state APA, and AG enforcement are more reliable mechanisms. States with robust APAs may consider adding a private right of action.
How to introduce it
The state version is designed to be introduced as a standalone bill. It does not depend on the federal statute passing. If the federal statute passes later, the state statute will operate alongside it; if the federal statute does not pass, the state statute still provides the authorization gate for state agencies.
Legislator talking points
The 30-second version
“State agencies already use automated systems to decide who gets unemployment benefits, who keeps Medicaid, and who gets flagged for fraud. When Michigan ran one without human review or a real chance to contest, about 40,000 people were automatically accused of fraud. Meanwhile, AI built and tested for war, intelligence, and border enforcement is being offered to civil government, and the federal pathways that could carry it there already exist. Battlefield validation is not civil authorization. This bill requires state agencies to publish the legal authority, data, and appeal process for any AI system before it is used in decisions about people’s benefits, liberty, or livelihoods, with a harder look at systems built for security. It doesn’t ban AI. It requires authorization.”
Why now
- Automated administrative harm has a documented record: Michigan’s MiDAS system automatically accused about 40,000 people of unemployment fraud; 93% of the roughly 22,000 determinations later reviewed did not involve fraud. The state paid $20 million. MiDAS was not a security system. The failure was deployment without human review, transparency, or a meaningful appeal, which is what this bill requires first.
- The pathways from security work into domestic administration already exist at the federal level: the same vendor platforms serve defence, immigration enforcement, and tax and health agencies (Section 06). This brief located no documented case of a battlefield-validated model entering a state agency; the bill puts the gate in place before one does.
- Federal AI governance frameworks — OMB M-25-21 and M-25-22 — apply only to federal agencies, not state agencies, and they carve out national-security systems.
- Executive Order 14365 says the federal preemption legislation it calls for should not propose preempting otherwise lawful state laws on state government procurement and use of AI. That carve-out does not limit the DOJ AI Litigation Task Force or the order’s grant conditions, but it indicates that the federal legislative proposal will not target states’ rules for their own agencies. This is the moment for states to act.
What the bill does
Four things.
1. Creates an authorization gate. No state agency may use an AI system to make or materially support decisions about people in a rights-sensitive domain without separate legal authorization.
2. Requires a public dossier, scaled to the stakes. Before deployment, the agency must publish the system’s purpose, legal authority, data, vendor, appeal path, and sunset date. A system that makes or materially supports an adverse decision — a denial, cut-off, penalty, or selection for investigation — and every security-built system must also publish the full dossier: model description, human-review standards, audit access, retention limits, and the rest.
3. Adds scrutiny for security-built systems. Systems with military, intelligence, or national-security lineage — presumed when the vendor sells the same product line to those customers — need independent testing, state-auditor review, legislative notice, a human decision on every adverse outcome, and a shorter sunset.
4. Provides enforcement. The Attorney General can seek injunctive relief; the state auditor reviews agency compliance; any person can file a complaint and seek judicial review under the state APA. Whether to add civil penalties is left to each state.
What the bill does not do
- It does not ban AI. Agencies can use AI in rights-sensitive domains. They just need authorization first.
- It does not apply to internal administrative functions. Payroll, hiring, facilities management, and general correspondence are excluded.
- It does not apply to statistical or research systems that don’t produce decisions about individuals.
- It does not single out commercial products. A commercial product with no security lineage faces only the base requirements of authorization and a dossier for its tier; commercial status can help an agency rebut the presumption of security lineage but does not do so on its own.
- It does not displace any existing privacy protection. The Privacy Act, state privacy laws, and federal tax confidentiality protections remain in force.
- It does not prevent legitimate interagency coordination. Coordination authorized by statute, documented in writing, and subject to audit is expressly permitted.
The cost question
- Most of the dossier content is already produced: privacy impact assessments, system-of-records notices, procurement justifications, authorizations to operate. The bill adds the trigger and the publication, not the underlying analysis.
- The dossier scales with the stakes. A system that does not make or materially support an adverse decision needs only a short-form dossier; the full dossier is reserved for systems that can contribute to a denial, penalty, or investigation, and for security-built systems.
- Agencies that cannot produce these documents for a rights-sensitive deployment are not ready to deploy.
- The alternative — after-the-fact litigation, wrongful determinations, and settlement costs — is more expensive than the gate. Neither MiDAS nor Robodebt was a security system; both show the cost of automated decisions deployed before legal authority, review, and appeal were secured. Michigan’s MiDAS system automatically accused about 40,000 people of unemployment fraud and ended in a $20 million class settlement; Australia’s Robodebt scheme has cost more than A$2.4 billion.
Objections and answers
“This will slow down modernization.”
The dossier is assembled from documents agencies already produce. The added work is publication and independent review, not new analysis. Systems that cannot contribute to an adverse decision file only a short-form dossier, so the full requirement falls on the systems where errors have the highest human cost.
“The legislature can’t review every AI system.”
The bill doesn’t require legislative review. It requires agency authorization and public disclosure, plus notice to the legislature for security-derived systems. The legislature’s role is oversight, not approval.
“This is anti-innovation.”
The bill is pro-authorization. It creates a clear path for agencies to adopt AI where the legal basis exists. What it prevents is adoption without authorization.
“Federal law already covers this.”
The federal AI governance memoranda (OMB M-25-21 and M-25-22) apply only to federal agencies, not state agencies, and they carve out national-security systems. The crossing point is where both federal and state law are largely silent.
“Vendors will leave the state.”
The bill regulates state agencies, not vendors. Vendors that want to sell to state agencies will comply. Those that can’t produce documentation of their systems’ provenance are the ones the bill is aimed at.
“The AG enforcement provision is unusual.”
The bill pairs attorney-general enforcement with state-auditor review and judicial review under the state APA. Whether the attorney general may sue another state agency, rather than represent it, varies by state constitution and statute, so confirm that authority before introduction.
The one-sentence ask
“No AI system should decide people’s benefits, liberty, or livelihoods in state government until the state has authorized it in public — and no system built for war, intelligence, or enforcement should get there without a harder look.”
What to say if asked about the federal statute
“The federal bill and this bill do different things. The federal bill governs federal agencies and attaches conditions to federal grants. This bill governs our state agencies. They work together. This bill stands on its own.”
A note on sequencing
If you’re introducing both, the state version should go first if the state has a functioning APA and an AG willing to enforce. The federal version is a longer legislative lift. The state version can pass in a single session and produce concrete results before the federal debate concludes.
If you’re introducing only one, introduce the state version. It reaches the state programs where automated-administration harm has actually occurred, and its authorization gate applies whether or not a system came from a security setting.
Revision history
Changelog
This changelog records what changed between the original June 2026 brief and the October 7, 2026 revision, other than the factual corrections listed in Section 16.
Evidence tags
- Fourth tag added. Claims are now tagged Confirmed, Reported, Inferred, or Opaque. Reported covers on-record claims by an official, agency, or vendor, and claims carried by a single press account, that no one has independently verified. Opaque now means only that material facts are not publicly available.
- Retagged as Reported: the Brave1 Dataroom figures of 100+ companies and 80+ models; officials’ statements that the Dataroom may later share algorithms with allies; the May 12 statements about Palantir’s role in deep-strike planning (the meeting itself remains Confirmed); the Ukrainian AI-guidance trial results and the tenfold-increase figure; the Maven 13,000-targets and 100,000-user figures; Palantir’s statement that it purged Medicaid data; WIRED’s report of the ELITE tool (the DHS purchase agreement remains Confirmed); TIME’s 2024 report that Palantir’s software was supplied free and used by more than half a dozen Ukrainian agencies; and the financial-press report that Maven’s program-of-record designation took effect (whether it did remains Opaque). The matching timeline entries were retagged.
- Mixed claims split. Sentences and table rows that combined a documented fact with an inference, an unverified claim, or an unknown now carry a separate tag for each part, including the national-security carve-outs, the IRS audit pilot, the Brave1 launch and its participation figures, and the May 12 meeting.
- Transfer claim. Whether a battlefield-validated model has been transferred into a civil system is no longer tagged. The text and claims table now say plainly that no documented instance was located; the contract terms and lineage that would show a transfer remain Opaque.
Model legislation (Appendices E and F)
- Origin. Appendices E and F were adapted from an outside legal review of the June brief and then revised.
- Fact-check corrections to the review’s text. The talking points said MiDAS cost Michigan $2.4 billion; MiDAS ended in a $20 million settlement, and the A$2.4 billion figure is Australia’s Robodebt. The claim that federal AI guidance “expressly excludes” state agencies now says it applies only to federal agencies. Statements that state attorneys general “routinely” enforce state law against, or sue, state agencies were replaced with hedged language. The Executive Order 14365 passages now say that the Section 8(b)(iii) carve-out limits only the legislative recommendation. The claim that without a state statute the federal grant condition is “unenforceable” now says the state would lack its own certification mechanism.
- E.1 citation corrections. §2(b) incorporates 5 U.S.C. 105 “for purposes of this Act,” because section 105 applies by its terms only “for the purpose of this title”; §2(c) cites 50 U.S.C. 3003(4); §6(a) cites the Antideficiency Act prohibition, 31 U.S.C. 1341(a)(1)(A), with 31 U.S.C. 1351 as the reporting duty.
- E.1 §2(d) reliance test. Reliance may now be shown by the vendor’s proposal, marketing, or other public statements, not only the agency’s acquisition record. A rebuttable presumption of coverage applies when the vendor supplies the same product line or model family to a national-security setting. The separate commercial-product exclusion was removed; commercial status may support rebuttal but does not by itself rebut the presumption. §3’s cross-reference to a Section 2(d) “exclusion” now refers to the rebuttal.
- E.1 §2(f). Rights-sensitive domains now include immigration adjudication, border and port-of-entry screening, and criminal justice beyond policing.
- E.1 §2(g). “Executive authority” is narrowed to an express written authorization by the agency head, published in the Federal Register, which cannot serve alone where a statute restricts the data or use. A definition of “appropriate congressional committees” was added as §2(h).
- E.1 §6(d) and §6(e). The waiver is limited to imminent threats to life (national security removed), may be renewed once, and requires the full determination, with any classified annex, to go to the appropriate committees. The transition now begins “Notwithstanding Sections 3, 6(a), and 7”; §6(a) is included so that option exercises within the window are not treated as prohibited obligations. Renewals and option exercises under existing contracts within the 12-month window fall within the transition; new awards and material modifications are covered immediately.
- E.1 §9. Rewritten to state the grant condition in the section itself and to define “recipient” and “covered system as used by a recipient” on their own terms, because §2(b) reaches only federal agencies.
- E.2 §5. The Inspector General “is requested to review,” rather than directed.
- F.1 model state bill added. Built on E.2’s broader trigger, with a heightened tier for security-domain lineage, optional civil penalties with a drafting note on circularity, and a governor’s waiver limited to imminent threats to life.
- Appendix F framing. MiDAS, Robodebt, and SyRI are now presented as showing why authorization comes first, not as cases a security-lineage rule would have caught. The 30-second pitch no longer says that war- or border-built systems are already appearing in state agencies. The talking point that state agencies are “acquiring AI systems at scale” through procurement without public justification was removed because no source was located for it.
- Recommendations. Recommendations 1 and 2 now point to the model federal text in Appendix E and the model state bill in Appendix F (F.1).
Second-round review fixes
- Bottom line. A one-page summary of five findings and five actions now opens Section 01. It is drawn only from the existing summary and recommendations and carries the same tags.
- Maven program of record. The Executive Summary now says the March 9 memo directed that Maven become a program of record by September 30, 2026, matching Section 05. The financial-press report that the designation took effect is tagged Reported, and whether it did is tagged Opaque, in the text, timeline, and claims table.
- Ukraine trials. The Ministry’s announcement that the trials took place is tagged Confirmed; the six-of-seven result and the tenfold figure are tagged Reported, in the text, timeline, and claims table.
- Maven figures. The Section 02 timeline entry now names James Mazol and Cameron Stanley.
- Medicaid and Maine cases. The wording now follows the sources: officials admitted the over-sharing and the judge paused CMS–ICE sharing; the transfer to Palantir rests on a state attorneys general motion citing discovery documents; and in the Maine case the government acknowledged in a filing that the agent’s entry led to a border stop. No court has ruled on either point.
- Model text. E.1 §6(c) and F.1 §10(c) now say who may complain and what a complaint must contain. E.1 §9 offers a bracketed event-based alternative to annual certification. E.1 §2(d), E.1 §9, and F.1 §3(g) state that the presumption cannot be rebutted without vendor documentation. F.1 §10(b) uses bracketed $10,000 placeholders, and F.1 §13(c) adds that a state dossier does not satisfy a federal requirement unless the federal agency accepts it. New counsel notes cover product-line definitions, vendor non-cooperation, and complaint standing.
- Presumption due process. Counsel notes in Appendix E and F.1 now address whether the product-line presumption is administrable and fair to vendors.
- Text export. The illustrative error-model figures are now a single labeled table in the PDF and Word versions.
Tiered dossier (October 7, 2026)
- F.1 tiered dossier. Responding to the concern that full dossiers for every covered system could overwhelm state agencies, F.1 now scales the dossier to the system’s role. New §3(l) defines “adverse decision,” and new §3(m) and §3(n) define Tier 2 and Tier 1 systems, using the existing §3(e) definition of “materially support.” §5 is restructured: (a) the agency publishes its tier determination with a short statement of reasons and must treat the system as Tier 2 if it cannot decide; (b) a Tier 1 system files a short-form dossier (purpose, legal authority, data categories and sources, vendor, lineage finding, agency contact and contest procedure, prohibited uses, sunset); (c) a Tier 2 system, which includes every heightened-tier system whatever its use, files the existing full dossier; (d) a change in use that makes a Tier 1 system part of adverse decisions is a material change requiring a full dossier [60] days before the changed use; (e) the State Auditor may reclassify a system to Tier 2; (f) the publication and confidential-annex rule is unchanged. A drafting note follows §5.
- Conforming changes. F.1 §3(i), §4(a), §4(c), §6, §9(a), §9(b), and §12(a) now refer to the tiered dossier. §3(g), §7, §10, §11, and §13 are unchanged. E.1 and E.2 are unchanged; the state-version introduction now notes that E.2 has no short form.
- Appendix F prose. The state-version introduction, the list of differences from the federal version, and the talking points (what the bill does, what it does not do, the cost question, and the modernization objection) now describe the two tiers.
- MiDAS wording. The talking points now say MiDAS “automatically accused” about 40,000 people of unemployment fraud, rather than “falsely accused,” matching Section 06 and the sources: the system made the accusations automatically, and a review of about 22,000 determinations found 93% did not involve fraud.
- Tier 1 terminology. The talking points now call the Tier 1 filing a “short-form dossier,” matching F.1 §3(i) and §5(b), instead of a “short-form public notice.”
Presentation and structure
- Byline. The brief now names its author, Alec F., under the title and in the closing note of the web version, on the title page of the PDF and Word versions, and in the Word file’s author property.
- Equation (Section 10). The original described a formula but did not display it, and raw markup leaked into the text. The equation is now displayed, every symbol is defined, and each step’s factor is floored at zero. The interactive figure is labeled an illustrative example with hypothetical parameters, and the 20.4× ratio appears only there.
- Risk-log example (Section 7). Labeled a hypothetical illustration constructed for this brief. It does not depict any real agency system, vendor product, record, or person.
- Harm cases (Section 06). A paragraph now explains that Robodebt, SyRI, and MiDAS were not security-derived and are included to show why authorization comes first.
- Corrections and changelog. Section 16 now lists only factual corrections to the June edition; all other revision notes moved to this changelog.
- Cross-references. Recommendation 3 points to the audit framework in Section 13, not Section 12.
Sources
- Source 61, the Ukrainian Ministry of Defence’s September 8, 2026 release on AI-guidance trials, was added; the trials are now sourced to it as well as to The Defender.
- The Maven strike and user figures are attributed to the officials who gave them, as reported by DefenseScoop.
- Every reference URL was checked against the live page. The SBS, BTAH, DHS privacy impact assessment, LAPD Inspector General, and Brussee entries a reviewer flagged were already correct; one broken link (Goodwin) was fixed. Reuters and Justia pages refuse automated requests, so those URLs could not be loaded in the check.
Verification status
- U.S. Code citations in Appendix E were checked against current law; the notes after the model text record where a citation is narrower than it looks. Legislative counsel should still confirm them, and should verify every cite and bracketed choice in F.1 for the relevant state.
- The EU AI Act Article 3(1) definition was confirmed against the current text.