GovRAMP publishes AI Self-Reporting Addendum for service providers

Original title: AI Self-Reporting Addendum

GovRAMP has published the AI Self-Reporting Addendum to standardize how service providers disclose information about AI-enabled products. The addendum requires disclosure of product architecture, data use practices, governance structures, security controls, identified risks, and system limitations. This gives government agencies greater visibility into AI systems to support due diligence and informed procurement decisions when evaluating cloud services.

What changed

  • GovRAMP published the AI Self-Reporting Addendum as a new disclosure template and requirement for service providers offering AI-enabled products or services.
  • Service providers must now disclose AI product architecture details, including how the AI system is designed and integrated into their services.
  • Disclosure of data use practices is required, specifying how AI systems collect, process, store, and utilize government and user data.
  • Service providers must document their AI governance practices, including organizational structures, policies, and procedures for managing AI systems responsibly.
  • Organizations must disclose security controls, identified risks, and known limitations of their AI-enabled products to support government risk assessment.

What the document requires

GovRAMP requires service providers to disclose key information about AI-enabled products including architecture, data use, governance practices, controls, risks, and limitations.

Who is affected

Service providers offering AI-enabled cloud products and services to U.S. federal, state, and local government agencies participating in the GovRAMP program.

Summary generated by a language model; the official text prevails. Not legal advice.