Cipher Defense Research
Public-sector AI governance has a distinctive failure mode: policies written to satisfy a directive, filed in a binder, and never operationalized. When an inspector general or oversight body asks how the policy is enforced, the binder is not an answer.
A defensible policy names an owner, defines an approval path employees can actually follow, and specifies what happens when a tool falls outside it. Every clause should map to a mechanism someone can point to under questioning: a review board, a logging requirement, a procurement gate.
Writing policy before inventory produces rules for a hypothetical agency. Discovery first: which AI capabilities are already in use across programs, sanctioned or not, and what data they touch. The policy then governs reality rather than intention.
Decisions, exceptions, and reviews should generate records as a side effect of the process, not as an after-the-fact reconstruction. If defending the policy requires assembling evidence from memory, the policy is not yet defensible.