← Back to Insights
Advisory Brief · Federal AI

AI Deployment Stops at the Authorization Boundary

A client-ready view of what FedRAMP reuse buys a federal AI service, what stays agency work, and why the evidence packet, not the demo, sets the production date.

Date  Jul 2026 Prepared as  Outcome brief ✓ Verified  9 citation clusters checked
Conditional sign-off verdict

It is safe to say yes to a federal AI service only on the near side of the authorization boundary: uses that fit an actively maintained FedRAMP package at or below the right FIPS 199 impact level, with agency-side configuration, monitoring, and evidence owned from day zero, can move now; anything that changes the data class, crosses an impact level, or needs a net-new authorization stays a bounded pilot with a declared route, budget, and expiration.

The deployable line

Reusable evidence

An actively maintained FedRAMP package at or below the agency's FIPS 199 level carries a presumption of adequacy. Reuse cuts duplicated assessment work.

Local risk decision

The agency still authorizes its own system: configuration, identity, integrations, contract terms, and agency-responsible controls, with named owners.

Temporary pilot

A bounded use can run under a temporary authorization with an explicit expiration and a stated plan to convert to full authorization or terminate.

Net-new authorization

No existing package fits the data or impact level. Sponsor capacity and funding become the critical path before any production date.

The sign-off test

Owner

Who makes the agency risk decision, and who owns agency-responsible controls, configuration, and monitoring review after go-live?

Briefing

Is this reuse, a temporary pilot, or a net-new authorization, and which FIPS 199 category or DoD impact level applies?

Proof

Can the packet show boundary, data flows, inherited controls, configuration, model-update process, logging, and incident path?

What leaders should take from it

1
A FedRAMP package is reusable evidence, not deployment approval.

OMB M-24-15 makes an agency presume an actively maintained package adequate at or below its FIPS 199 level, and it preserves the agency head's FISMA responsibility. The agency still authorizes its own system and intended use.

2
Authorization is lifecycle work, not a one-time gate.

NIST's Risk Management Framework runs categorization through continuous monitoring as one process, and the reuse presumption holds only while ongoing requirements stay maintained.

3
Data and mission context decide the boundary.

FIPS 199 categorization and DoD impact levels IL2 through IL6 can make a technically usable AI service unsuitable for the proposed data or identity path.

4
Net-new authorization has a real capacity and funding problem.

GAO reports provider cost estimates of $300,000 to $3.7 million, and agencies describing products delayed or unprocurable when providers would not pursue authorization. These are estimates and reported barriers, not a standard price.

5
The direction of travel is machine-readable evidence.

OMB and FedRAMP 20x point toward automated, continuous authorization evidence. The published five-week figure measures agency review and 80% automation is a goal, so plan from the specific service and route, not a program headline.

Where the evidence stops

Three claims run ahead of the evidence: that a FedRAMP authorization means an agency can deploy the service, that FedRAMP takes a standard number of months end to end, and that authorization is already mostly automated. The defensible claim is narrower: reuse shortens duplicated assessment work, while the agency's own risk decision, configuration, and monitoring still set the production date.

The Deep Dive holds the action map: authorization routes, the day-zero evidence packet, owner map, full claim ledger, and refresh triggers.

Open the Deep Dive
Outcome brief staged from verified Storm Research v2 · 9 citation clusters checked · 0 fabricated · 3 corrected · 2 demoted