<?xml version="1.0" encoding="UTF-8"?>
<PerformancePlanOrReport xmlns="urn:ISO:std:iso:17469:tech:xsd:PerformancePlanOrReport" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

 xsi:schemaLocation="urn:ISO:std:iso:17469:tech:xsd:PerformancePlanOrReport http://stratml.us/references/PerformancePlanOrReport20160216.xsd" Type="Strategic_Plan"><Name>ARTIFICIAL INTELLIGENCE ETHICS FRAMEWORK FOR THE INTELLIGENCE COMMUNITY</Name><Description>AI can enhance the intelligence mission, but like other new tools, we must understand how to use this rapidly evolving technology in a way that aligns with our principles to prevent unethical outcomes. -- This is an ethics guide for United States Intelligence Community personnel on how to procure, design, build, use, protect, consume, and manage AI and related data. Answering these questions, in conjunction with your agency-specific procedures and practices, promotes ethical design of AI consistent with the Principles of AI Ethics for the Intelligence Community.

This guide is not a checklist and some of the concepts discussed herein may not apply in all instances. Instead, this guide is a living document intended to provide stakeholders with a reasoned approach to judgment and to assist with the documentation of considerations associated with the AI lifecycle. In doing so, this guide will enable mission through an enhanced understanding of goals between AI practitioners and managers while promoting the ethical use of AI.

This Framework is a living document and we welcome your feedback.</Description><OtherInformation>The use of AI must match the Intelligence Community’s unique mission purposes, authorities, and responsibilities for collecting and using data and AI outputs. AI should:
* Be used when it is an appropriate means to achieve a defined purpose after evaluating the potential risks;
* Be used in a manner consistent with respect for individual rights and liberties of affected individuals, and use data obtained lawfully and consistent with legal obligations and policy requirements;
* Incorporate human judgment and accountability at appropriate stages to address risks across the lifecycle of the AI and inform decisions appropriately;
* Identify, account for, and mitigate potential undesired bias, to the greatest extent practicable without undermining its efficacy and utility;
* Be tested at a level commensurate with foreseeable risks associated with the use of the AI;
* Maintain accountability for iterations, versions, and changes made to the model;
* Document and communicate the purpose, limitation(s), and design outcomes;
* Use explainable and understandable methods, to the extent practicable, so that users, overseers, and the public, as appropriate, understand how and why the AI generated its outputs;
* Be periodically reviewed to ensure the AI continues to further its purpose and identify issues for resolution; and,
* Identify who will be accountable for the AI and its effects at each stage and across its lifecycle, including responsibility for maintaining records created. ^
Identifying and addressing risk is best achieved by involving appropriate stakeholders. As such, consumers, technologists, developers, mission personnel, risk management professionals, civil liberties and privacy officers, and legal counsel should utilize this framework collaboratively, each leveraging their respective experiences, perspectives, and professional skills. 

Agencies should also ensure that individuals involved in the design, development, review, deployment, and use of any AI have sufficient training to address the questions below and the issues presented above.</OtherInformation><StrategicPlanCore><Organization><Name>Office of the Director of National Intelligence</Name><Acronym>ODNI</Acronym><Identifier>_c9be805f-e435-41a3-b2bf-b10c8e5699b8</Identifier><Description/><Stakeholder StakeholderTypeType="Generic_Group"><Name>United States Intelligence Community</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>AI Practitioners</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>AI Managers</Name><Description/></Stakeholder></Organization><Vision><Description>The intelligence mission is enhanced</Description><Identifier>_947c6186-d0e5-11ea-9acb-b941f882ea00</Identifier></Vision><Mission><Description>To guide United States Intelligence Community personnel on how to ethically procure, design, build, use, protect, consume, and manage AI and related data.</Description><Identifier>_947c62a8-d0e5-11ea-9acb-b941f882ea00</Identifier></Mission><Value><Name/><Description/></Value><Goal><Name>Purpose</Name><Description>Determine what goals are to be achieved.</Description><Identifier>_947c6384-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Purpose: Understanding Goals and Risks -- Determine what goals you are trying to achieve to ensure you can design AI that balances desired results with acceptable risk.</OtherInformation><Objective><Name>Goals</Name><Description>Specify the goal to be achieved by creating the AI.</Description><Identifier>_947c6456-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>1.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>What is the goal you are trying to achieve by creating this AI, including components used in AI development? Is there a need to use AI to achieve this goal? Can you use other non-AI related methods to achieve this goal with lower risk? Is AI likely to be effective in achieving this goal?</OtherInformation></Objective><Objective><Name>Methods</Name><Description>Determine the AI system methods that are suitable and preferred for the use case.</Description><Identifier>_947c651e-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>1.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Are there specific AI system methods suitable and preferred for this use case? Does the efficiency and reliability of the AI in this particular use case justify its use for this purpose?</OtherInformation></Objective><Objective><Name>Benefits &amp; Risks</Name><Description>Determine the benefits and risks associated with usage of the AI.</Description><Identifier>_947c65e6-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>1.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>What benefits and risks, including risks to civil liberties and privacy, might exist when this AI is in use? Who will benefit? Who or what will be at risk? What is the scale of each and likelihood of the risks? How can those risks be minimized and the remaining risks adequately mitigated? Do the likely negative impacts outweigh likely positive impacts?</OtherInformation></Objective><Objective><Name>Performance Metrics</Name><Description>Determine what performance metrics best suit the AI.</Description><Identifier>_947c66ae-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>1.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>What performance metrics best suit the AI, such as accuracy, precision, and recall, based on risks determined by mission managers, analysts, and consumers given the potential risks; and how will the accuracy of the information be provided to each of those stakeholders? What impacts could false positive and false negative rates have on system performance, mission goals, and affected targets of the analysis?</OtherInformation></Objective><Objective><Name>Engagement</Name><Description>Engage the AI system developers, users, consumers, and other key stakeholders.</Description><Identifier>_947c6780-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>1.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Have you engaged with the AI system developers, users, consumers, and other key stakeholders to ensure a common understanding of the goal of the AI and related risks of utilizing AI to achieve this goal?</OtherInformation></Objective><Objective><Name>Documentation</Name><Description>Document the goals and risks.</Description><Identifier>_947c6848-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>1.6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>How are you documenting the goals and risks?</OtherInformation></Objective></Goal><Goal><Name>Laws &amp; Policies</Name><Description>Understand governing authorities, legal obligations, information management responsibilities, and risks associated with an AI project.</Description><Identifier>_947c691a-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Legal Obligations and Policy Considerations Governing the AI and the Data -- 
Partnering closely with risk management teams in your agency, including your legal, compliance, records management, classification, and civil liberties and privacy professionals, will help you understand governing authorities, legal obligations, information management responsibilities, and risks associated with an AI project.</OtherInformation><Objective><Name>Data Sources</Name><Description>Identify the authorities, agreements, or contracts govern the collection or acquisition of all sources of the data.</Description><Identifier>_947c69ec-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>2.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>What authorities, agreements, or contracts govern the collection or acquisition of all sources of the data related to the model (training, testing, and operational data)? Who can clarify limitations from the agreements or contracts?</OtherInformation></Objective><Objective><Name>Restrictions</Name><Description>Identify legal or policy restrictions on the use of data.</Description><Identifier>_947c6ac8-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>2.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>What legal or policy restrictions exist on the use of data under this authority/agreement/contract? (For example, data subject to the Privacy Act should be used for a purpose that is compatible with that for which the data was collected).</OtherInformation></Objective><Objective><Name>Data Storage &amp; Sharing</Name><Description>Determine how the data is to be stored, shared, retrieved, accessed, used, retained, disseminated, and dispositioned.</Description><Identifier>_947c6ba4-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>2.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>How must data be stored, shared, retrieved, accessed, used, retained, disseminated, and dispositioned under the authority/agreement/contract, as well as relevant constitutional, statutory, and regulatory provisions?</OtherInformation></Objective><Objective><Name>Authorities &amp; Agreements</Name><Description>Identify authorities or agreements applicable to the AI itself.</Description><Identifier>_947c6c80-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>2.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>What authorities or agreements apply to the AI itself, including the use, modification, storage, retrieval, access, retention, and disposition of the AI? Are there any proposed downstream applications of the AI that are legally restricted from using the underlying data?</OtherInformation></Objective><Objective><Name>Data Combination</Name><Description>Determine whether combining data with other inputs from the AI create new legal, records management, or classification risks.</Description><Identifier>_947c6d5c-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>2.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Does combining data with other inputs from the AI create new legal, records management, or classification risks relating to how the information is maintained and protected?</OtherInformation></Objective></Goal><Goal><Name>Judgment &amp; Accountability</Name><Description>Determine at which point in the process and to what degree a human will be involved in the AI.</Description><Identifier>_947c6e38-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Human Judgment and Accountability -- In the Intelligence Community, the potential purposes and applications of an AI could range from basic business tasks to highly sensitive intelligence analysis. The assessed risk will determine at which point in the process and to what degree a human will be involved in the AI.</OtherInformation><Objective><Name>Decision Making</Name><Description>Determine when human must be involved in the decision process.</Description><Identifier>_947c6f1e-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>3.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Given the purpose of the AI and potential consequences of its use, at what points, if any, are a human required as part of the decision process? If the AI could result in significant consequences such as an action with the potential to deprive individuals of constitutional rights or the potential to interfere with their free exercise of civil liberties, how will you ensure individual human involvement and accountability in decisions that are assisted through the use of AI?</OtherInformation></Objective><Objective><Name>Engagement</Name><Description>Determine where and when humans should be engaged.</Description><Identifier>_947c7004-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>3.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Where and when should the human be engaged? Before the results are used in analysis? Before the outputs are provided for follow-on uses?</OtherInformation></Objective><Objective><Name>Accountability</Name><Description>Identify the accountable human(s).</Description><Identifier>_947c70f4-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>3.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Who should be the accountable human(s)? Do they know that they are designated as the accountable human(s)? What qualifications are required to serve in that role? How is accountability transferred to another human?</OtherInformation></Objective><Objective><Name>Access &amp; Training</Name><Description>Determine the access controls and training requirements for those operating the AI.</Description><Identifier>_947c71da-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>3.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>What are the access controls and training requirements for those operating at different stages in the AI lifecycle?</OtherInformation></Objective><Objective><Name>Reliability &amp; Accuracy</Name><Description>Specify the knowledge required to judge its reliability and accuracy of the AI.</Description><Identifier>_947c72ca-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>3.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>What does the accountable human need to know about the AI to judge its reliability and accuracy?</OtherInformation></Objective><Objective><Name>Biases</Name><Description>Address how introducing an accountable human may produce cognitive biases and/or confirmation bias.</Description><Identifier>_947c7400-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>3.6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>How may introducing an accountable human produce cognitive biases and/or confirmation bias?</OtherInformation></Objective><Objective><Name>Issues &amp; Disputes</Name><Description>Determine who should be engaged for unresolved issues and disputes regarding the AI or its outputs.</Description><Identifier>_947c74fa-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>3.7</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Who should be engaged for unresolved issues and disputes regarding the AI or its outputs?</OtherInformation></Objective></Goal><Goal><Name>Bias &amp; Objectivity</Name><Description>Mitigate undesired bias and ensure objectivity.</Description><Identifier>_947c75ea-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Mitigating Undesired Bias and Ensuring Objectivity -- Ensuring objectivity is a defining characteristic of intelligence analysis. In conducting analysis, Intelligence Community Directive 203  requires that we must perform our functions “with objectivity and with awareness of [our] own assumptions and risks. [We] must employ reasoning techniques and practical mechanisms that reveal and mitigate bias.” For legal, policy, and mission reasons, however, there are certain “biases” that the Intelligence Community intentionally introduces as it designs, develops, and uses AI.
Specifically, we design our models and choose our datasets to screen out irrelevant information, focus on the specific foreign intelligence targets, and appropriately minimize the collection and use of United States person information. In mitigating bias, the Intelligence Community therefore focuses on identifying and minimizing undesired bias. “Undesired bias” is bias that could undermine analytic validity and reliability, harm individuals, or impact civil liberties such as freedom from undue government intrusion on speech, religion, travel, or privacy.
Undesired bias may be introduced through the process of data collection, feature extraction, curating/labeling data, model selection and development, and even in user training. Taking steps to discover bias throughout the lifecycle of an AI, mitigate undesired bias, and to document and communicate known biases and how they were addressed, are critical to long-term reliance on training data sets, to reusing models, and to trusting outputs for follow-on use.</OtherInformation><Objective><Name>Completeness &amp; Representation</Name><Description>Determine how complete and representative the data are.</Description><Identifier>_947c76ee-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>4.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>How complete are the data on which the AI will rely? Are they representative of the intended domain? How relevant is the training and evaluation data to the operational data and context?</OtherInformation></Objective><Objective><Name>Biases &amp; Discrimination</Name><Description>Avoid perpetuating historical biases and discrimination.</Description><Identifier>_947c77e8-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>4.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>How does the AI avoid perpetuating historical biases and discrimination?</OtherInformation></Objective><Objective><Name>Metrics</Name><Description>Determine the metrics to assess the AI’s output.</Description><Identifier>_947c78ec-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>4.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>What are the correct metrics to assess the AI’s output? Is the margin of error one that would be deemed tolerable by those who use the AI? What is the impact of using inaccurate outputs and how well are these errors communicated to the users?</OtherInformation></Objective><Objective><Name>Bias &amp; Accuracy</Name><Description>Address potential tradeoffs between reducing undesired bias and accuracy.</Description><Identifier>_947c7af4-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>4.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>What are the potential tradeoffs between reducing undesired bias and accuracy? To what extent can potential undesired bias be mitigated while maintaining sufficient accuracy?</OtherInformation></Objective><Objective><Name>Training Data</Name><Description>Mitigate bias in the training data.</Description><Identifier>_947c7c0c-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>4.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Do you know or can you learn what types of bias exist in the training data (statistical, contextual, historical, or other)? How can undesired bias be mitigated? What would happen if it is not mitigated? Is the selected testing data appropriately representative of the training data? Based on the purpose of the AI, how much and what kind of bias, if any, are you willing to accept in the data, model, and output? Is the team diverse enough in disciplinary, professional, and other perspectives to minimize any human bias?</OtherInformation></Objective><Objective><Name>Communication</Name><Description>Communicate bias and potential impacts to those who interact with the AI and output data.</Description><Identifier>_947c7d1a-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>4.6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>How will undesired bias and potential impacts of the bias, if any, be communicated to anyone who interacts with the AI and output data?</OtherInformation></Objective></Goal><Goal><Name>Testing</Name><Description>Test systems for accuracy in environments that control for known and reasonably foreseeable risks.</Description><Identifier>_947c7e3c-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Testing Your AI -- Every system must be tested for accuracy in an environment that controls for known and reasonably foreseeable risks prior to being deployed.</OtherInformation><Objective><Name>Performance Metrics</Name><Description>Determine the required level of objective performance for the desired performance metric.</Description><Identifier>_947c7f4a-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>5.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Based on the purpose of the AI and potential risks, what level of objective performance for the desired performance metric, (e.g., precision, recall, accuracy, etc.) do you require?</OtherInformation></Objective><Objective><Name>Bias &amp; Feedback</Name><Description>Evaluate the AI for biased outcomes and inappropriate feedback loops.</Description><Identifier>_947c810c-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>5.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Has the AI been evaluated for potential biased outcomes or if outcomes cause an inappropriate feedback loop? Have you considered applicable methods to make the AI more robust to adversarial attacks?</OtherInformation></Objective><Objective><Name>Testing &amp; Changes</Name><Description>Document the test methodology, results, and changes made based on the test results.</Description><Identifier>_947c833c-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>5.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>How and where will you document the test methodology, results, and changes made based on the test results?</OtherInformation></Objective><Objective><Name>Third Parties</Name><Description>Consider the risks associated with AI created by third parties.</Description><Identifier>_947c845e-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>5.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>If a third party created the AI, what additional risks may be associated with that third party’s assumptions, motives, and methodologies? What limitations might arise from that third party claiming its methodology is proprietary?</OtherInformation></Objective><Objective><Name>Approval</Name><Description>Determine the minimum amount of information necessary to approve an AI for use.</Description><Identifier>_947c8576-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>5.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>What information should you require as part of the acquisition of the analytic? What is the minimum amount of information you must have to approve an AI for use?</OtherInformation></Objective><Objective><Name>Security</Name><Description>Test and mitigate the AI for potential security threats.</Description><Identifier>_947c86a2-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>5.6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Was the AI tested for potential security threats in any/all levels of its stack (e.g. software level, AI framework level, model level, etc.)? Were resulting risks mitigated?</OtherInformation></Objective></Goal><Goal><Name>Builds, Versions &amp; Evolutions</Name><Description>Account for builds, versions, and evolutions of an AI.</Description><Identifier>_947c87c4-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Accounting for Builds, Versions, and Evolutions of an AI -- A successful AI is often refined through numerous iterations, versions, or evolutions, both while it is being trained on training data and after it matures and is applied to mission, analytic, and business data. An existing AI may also be repurposed and require modifications and/or retraining prior to redeployment.</OtherInformation><Objective><Name>Versions &amp; Evolutions</Name><Description>Ensure the version or evolution of AI is designed to achieve the authorized purpose.</Description><Identifier>_947c88e6-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>6.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>As you refine the AI, how does the data you have used, the parameters and weights you have chosen, and the outputs ensure that this version or evolution is designed to achieve the authorized purpose?</OtherInformation></Objective><Objective><Name>Data Drift</Name><Description>Account for natural data drift within the operational environment.</Description><Identifier>_947c8a1c-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>6.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Have you accounted for natural data drift within the operational environment compared to training data?</OtherInformation></Objective><Objective><Name>Repeatability, Auditing &amp; Oversight</Name><Description>Document the provenance of data, outputs of the iteration, and test results to provide for repeatability, auditing, and oversight.</Description><Identifier>_947c8b3e-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>6.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Have you documented provenance of data, outputs of the iteration, and test results (accuracy) in a way that will provide for repeatability, auditing, and oversight? If the AI is continuously modified, are all critical aspects, dependencies, and artifacts version controlled and documented? Will it be clear to anyone auditing the AI or consumers of the AI’s outputs which version was in use at any given moment in time? Will it be clear which iteration of a model drew on which data and produced what outputs?</OtherInformation></Objective><Objective><Name>Versioning</Name><Description>Save documentation on versions of AI and relevant training and test data.</Description><Identifier>_947c8c60-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>6.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Where will you save documentation on versions of AI and relevant training and test data? Have you made that information available to users and consumers of the AI? How will this documentation be retained and made discoverable to ensure compliance with your Agency’s records management responsibilities?</OtherInformation></Objective><Objective><Name>Customers &amp; Missions</Name><Description>Account for changes in the demographics of customers and the needs of the missions.</Description><Identifier>_947c8da0-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>6.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Have you accounted for changes in demographics of your customer for your AI capability (e.g., changing user experience needs) or the changing needs of the mission?</OtherInformation></Objective></Goal><Goal><Name>Purposes, Parameters, Limitations &amp; Outcomes</Name><Description>Document purposes, parameters, limitations, and design outcomes.</Description><Identifier>_947c8ecc-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>7</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Documentation of Purpose, Parameters, Limitations, and Design Outcomes -- 
To ensure your AI is used properly, it is important to communicate (a) what the AI is for, (b) what it is not for, (c) how it was designed, and (d) what its limitations are. Documentation assists not only with proper management of the AI, but also with determining whether the AI is appropriate for new purposes that were not originally envisioned.</OtherInformation><Objective><Name>Documentation</Name><Description>Store the documentation for access by potential consumers of the AI.</Description><Identifier>_947c8fee-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>7.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>How can you store the documentation in a way that is available to all potential consumers of this AI?</OtherInformation></Objective><Objective><Name>Provenance, Usage &amp; Sharability</Name><Description>Document the provenance of the data and its uses and sharability.</Description><Identifier>_947c9138-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>7.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Have you documented where the data came from and its downstream uses and sharability? The downstream uses and sharability of the AI?</OtherInformation></Objective><Objective><Name>Rules</Name><Description>Document rules applicable to the data.</Description><Identifier>_947c926e-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>7.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Have you documented what rules apply to the data as a whole? What rules apply to subsets?</OtherInformation></Objective><Objective><Name>Risks</Name><Description>Document and minimize the risks of using the AI and its output data.</Description><Identifier>_947c939a-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>7.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Have you documented the potential risks of using the AI and its output data, and the steps taken to minimize these risks?</OtherInformation></Objective><Objective><Name>Use Cases</Name><Description>Document use cases for the AI.</Description><Identifier>_947c9534-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>7.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Have you documented use cases for which the AI was and was not specifically designed?</OtherInformation></Objective><Objective><Name>Conclusions &amp; Bias</Name><Description>Document the process for discovering undesired bias and the conclusions.</Description><Identifier>_947c96ba-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>7.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Have you documented the process for discovering undesired bias and the conclusions?</OtherInformation></Objective><Objective><Name>Verification &amp; Validation</Name><Description>Document how to verify and validate the model as well as the frequency with which these checks should be performed.</Description><Identifier>_947c980e-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>7.7</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Have you documented how to verify and validate the model as well as the frequency with which these checks should be performed?</OtherInformation></Objective></Goal><Goal><Name>Transparency</Name><Description>Use methods that are explainable and understandable.</Description><Identifier>_947c9962-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>8</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Transparency: Explainability and Interpretability -- AI can achieve the anticipated outcome despite using inappropriate criteria. Consistent with the Principles of Intelligence Transparency for the Intelligence Community, use methods that are explainable and understandable, to the extent practicable, so that users, overseers, and the public, as appropriate, understand how and why the AI generated its outputs.</OtherInformation><Objective><Name>Explainability &amp; Interpretability</Name><Description>Explain and enable interpretation of how AI makes determinations.</Description><Identifier>_947c9aac-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>8.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Given the purpose of the AI, what level of explainability or interpretability is required for how the AI made its determination? If a third party created the AI, how will you ensure a level of explainability or interpretability? Does this conform with Intelligence Community Directive 203: Analytic Standards?</OtherInformation></Objective><Objective><Name>Outputs</Name><Description>Mark outputs to show that they came from an AI.</Description><Identifier>_947c9bec-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>8.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>How are outputs marked to clearly show that they came from an AI?</OtherInformation></Objective><Objective><Name>Datasets &amp; Tools</Name><Description>Describe the dataset(s) and tools used to make the output.</Description><Identifier>_947c9d4a-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>8.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>How might you respond to an intelligence consumer asking “How do you know this?” How will you describe the dataset(s) and tools used to make the output?</OtherInformation></Objective><Objective><Name>Accuracy &amp; Performance</Name><Description>Assess the accuracy or performance metrics.</Description><Identifier>_947c9e94-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>8.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>How was the accuracy or appropriate performance metrics assessed?</OtherInformation></Objective><Objective><Name>Verification</Name><Description>Independently verify results.</Description><Identifier>_947c9fde-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>8.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>How were the results independently verified?</OtherInformation></Objective><Objective><Name>Errors</Name><Description>Document and explain that machine errors may differ from human errors.</Description><Identifier>_947ca13c-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>8.6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Have you documented and explained that machine errors may differ from human errors?</OtherInformation></Objective></Goal><Goal><Name>Review</Name><Description>At appropriate intervals to ensure AI still meets its purpose and that biases and unintended outcomes are appropriately mitigated.</Description><Identifier>_947ca286-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>9</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Periodic Review -- All AI should be checked at an appropriate documented interval to determine whether it still meets its purpose and that any undesired biases or unintended outcomes are appropriately mitigated.</OtherInformation><Objective><Name>Engagement</Name><Description>Determine how user and peer engagement be integrated into the model development process and periodic performance review.</Description><Identifier>_947ca3d0-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>9.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>How will user and peer engagement be integrated into the model development process and periodic performance review once deployed?</OtherInformation></Objective><Objective><Name>Monitoring</Name><Description>Specify the interval for checking whether the is still accurate, unbiased, explainable.</Description><Identifier>_947ca538-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>9.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Given the purpose of this AI, what is an appropriate interval for checking whether it is still accurate, unbiased, explainable, etc.? What are the checks for this model?</OtherInformation></Objective><Objective><Name>Representation</Name><Description>Determine if the training data remains representative of the operational environment over time.</Description><Identifier>_947ca696-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>9.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>As time passes and conditions change, is the training data still representative of the operational environment?</OtherInformation></Objective><Objective><Name>Performance</Name><Description>Determine how performance metrics will be monitored after the AI is deployed.</Description><Identifier>_947ca880-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>9.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>How will the appropriate performance metrics, such as accuracy, of the AI be monitored after the AI is deployed? How much distributional shift or model drift from baseline performance is acceptable?</OtherInformation></Objective><Objective><Name>Responsibility</Name><Description>Identify those responsible for checking the AI.</Description><Identifier>_947caa88-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>9.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Who is responsible for checking the AI at these intervals?</OtherInformation></Objective><Objective><Name>Accuracy &amp; Precision</Name><Description>Determine how accountable human(s) will address changes in accuracy and precision.</Description><Identifier>_947cabf0-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>9.6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>How will the accountable human(s) address changes in accuracy and precision due to either an adversary’s attempts to disrupt the AI or unrelated changes in</OtherInformation></Objective></Goal><Goal><Name>Stewardship &amp; Accountability</Name><Description>Assign responsibility for the maintenance, monitoring, updating, and decommissioning of the AI.</Description><Identifier>_947cad44-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>10</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Stewardship and Accountability: Training Data, Algorithms, Models, Outputs of the Models, Documentation -- Before the AI is deployed, it must be clear who will have the responsibility for the continued maintenance, monitoring, updating, and decommissioning of the AI.</OtherInformation><Objective><Name>Maintenance, Monitoring &amp; Updating</Name><Description>Identify those responsible for maintaining, re-verifying, monitoring, and updating this AI</Description><Identifier>_947caec0-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>10.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Who will be responsible for maintaining, re-verifying, monitoring, and updating this AI once deployed?</OtherInformation></Objective><Objective><Name>Decisions</Name><Description>Identify those responsible for the decisions of the AI.</Description><Identifier>_947cb028-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>10.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Who is ultimately responsible for the decisions of the AI and is this person aware of the intended uses and limitations of the analytic?</OtherInformation></Objective><Objective><Name>Ethics</Name><Description>Identify those accountable for the ethical considerations.</Description><Identifier>_947cb186-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>10.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Who is accountable for the ethical considerations during all stages of the AI lifecycle?</OtherInformation></Objective><Objective><Name>Responsibility</Name><Description>Identify and empower those who will be responsible in the event the AI no longer meets this ethical framework.</Description><Identifier>_947cb302-d0e5-11ea-9acb-b941f882ea00</Identifier><SequenceIndicator>10.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>If anyone believed that the AI no longer meets this ethical framework, who will be responsible for receiving the concern and as appropriate investigating and remediating the issue? Do they have authority to modify, limit, or stop the use of the AI?</OtherInformation></Objective></Goal></StrategicPlanCore><AdministrativeInformation><StartDate/><EndDate/><PublicationDate>2020-07-28</PublicationDate><Source>https://www.intelligence.gov/artificial-intelligence-ethics-framework-for-the-intelligence-community</Source><Submitter><GivenName>Owen</GivenName><Surname>Ambur</Surname><PhoneNumber/><EmailAddress>Owen.Ambur@verizon.net</EmailAddress></Submitter></AdministrativeInformation></PerformancePlanOrReport>