Bottom line
Agencies must produce actionable AI plans that align with Executive Order 14110, OMB M-24-10, and the NIST AI Risk Management Framework, and those plans must be grounded in verifiable controls, inventories, and evaluation processes rather than narratives123. Microsoftβs documented government-cloud services and Copilot-related capabilities support these federal requirements when deployed in Azure Government and Microsoft 365 Government with appropriate controls and governance456.
Verification note: To reproduce an βAI Action Plan Analysis,β this brief references Microsoft-documented services rather than an application formally named βMicrosoft Discovery App,β and all steps map to primary federal policy and Microsoft technical documentation24.
Policy framing for an AI Action Plan
- EO 14110 directs agencies to advance safe, secure, and trustworthy AI, including governance, standards use, and risk management consistent with federal guidance1.
- OMB M-24-10 requires agencies to establish AI governance structures, maintain public AI use case inventories, implement safeguards for safety-impacting AI, and align risk management to the NIST AI RMF23.
- The NIST AI RMF defines Govern, Map, Measure, and Manage functions, which provide a structure for inventories, risk controls, testing, and continuous monitoring that agencies should reflect in their plans3.
Reference architecture in U.S. Government clouds
- Azure Government is designed for U.S. public sector workloads with compliance attestations and inherits FedRAMP High baselines across its services according to Microsoft documentation, and it maps to DoD Impact Levels per the DoD Cloud Computing SRG where applicable47.
- The FedRAMP Marketplace lists Microsoft Azure Government as authorized, enabling agency ATOs to inherit controls from the baseline authorizations where appropriate8.
- Agencies should constrain AI workloads and data to Azure Government regions and Microsoft 365 Government environments appropriate to their data classification and mission impact levels, consistent with the DoD SRG and agency-specific ATOs76.
Copilot-aligned capability set available to federal teams
- Azure OpenAI Service is available in Azure Government with service documentation that describes connectivity, identity, content filters, and model operations for government tenants5.
- Azure AI Foundry (formerly Azure AI Studio) provides managed tooling for model orchestration, prompt engineering, evaluation, and deployment that can be used with Azure OpenAI Service and other models in supported regions91011.
- Microsoft 365 Copilotβs data, privacy, and compliance documentation describes its use of existing Microsoft 365 security boundaries, tenant isolation, and data residency controls, which agencies must validate against their government cloud environment and service availability matrices before deployment126.
- Power Platform US Government provides low-code services in GCC, GCC High, and DoD environments with specific feature availability and data boundary documentation that agencies must verify when building Copilot-style assistants or custom bots in government clouds13.
- GitHub Enterprise Cloud holds a FedRAMP Moderate authorization per the FedRAMP Marketplace, enabling agencies to use it under ATO for source management and CI/CD, while GitHub Copilot privacy documentation explains data handling and the absence of training on private code for certain SKUs that agencies should assess under AI risk management and data protection policies1415.
Reproducing an AI Action Plan analysis: a step-by-step method
- Establish scope and governance (Govern and Map)
- Identify systems and missions where AI could materially affect safety, rights, or critical operations as defined by OMB M-24-10, and document the agency governance board, roles, and decision authorities for those systems2.
- Align the planβs structure to NIST AI RMF functions and outcomes so each risk control, test, and monitoring activity maps to a defined RMF outcome and measurement3.
- Inventory data and use cases (Map)
- Build an AI-relevant data map using Microsoft Purview to catalog data sources, classifications, lineage, and access policies across Azure Government and Microsoft 365 Government to inform use case feasibility and privacy constraints16.
- Produce the public AI use case inventory and the internal catalog required by OMB M-24-10, capturing purpose, datasets, models/services, human oversight, and impact assessments per the memoβs inventory requirements2.
- Select models and services in-authority (Map)
- Choose Azure OpenAI Service in Azure Government when generative capabilities are required within FedRAMP High and DoD IL-governed environments, and document region, model family, and connectivity patterns from the serviceβs government documentation5.
- Use Azure AI Foundry to assemble evaluation-ready pipelines and prompt flows, explicitly documenting the model version, system prompts, content filters, and tool integrations for traceability911.
- Architect security and compliance (Govern and Manage)
- Constrain deployments to Azure Government services and enforce FedRAMP High control sets with Azure Policy built-in initiatives that map to FedRAMP High to continuously assess configuration compliance417.
- For defense workloads, map data handling and interconnections to the DoD Cloud Computing SRG impact levels and isolation requirements, and record assumptions in the system security plan and AI plan annex7.
- Implement responsible AI safeguards (Measure and Manage)
- Apply Azure AI Content Safety filters and safety system configurations to moderate prompts and outputs for categories such as sexual content, self-harm, hate, and violence, and capture threshold settings and exceptions as part of the AI plan controls18.
- Define human-in-the-loop oversight, output provenance, logging, and fallback behaviors for safety-impacting use cases consistent with OMB M-24-10 safeguards and NIST AI RMF measurement guidance23.
- Evaluate and red-team (Measure)
- Use Azure AI Foundry evaluation capabilities to measure quality, robustness, and safety metrics with offline test sets and scenario-based evaluations, and retain evaluation artifacts and metrics in the technical file for the use case10.
- Implement prompt flow experiments to compare prompting strategies and tool use, and use evaluation runs to inform risk acceptance or iteration decisions documented in governance records11.
- Integrate M365 Copilot where appropriate (Map and Manage)
- Where Microsoft 365 Copilot is in scope, validate data handling, tenant isolation, and plugin/connector exposure against Microsoft 365 Government service descriptions and the Copilot privacy documentation before enabling any users or scenarios126.
- Document user cohorts, information barriers, and sensitivity label policies that constrain Copilot retrieval and actions, and include these controls in the AI Action Planβs safeguards and monitoring sections126.
- Developer platform and CI/CD (Govern and Manage)
- Use GitHub Enterprise Cloudβs FedRAMP Moderate boundary for code and DevSecOps pipelines under an agency ATO and ensure secrets management and environment segregation meet agency policies, noting that Copilot features should be evaluated against the GitHub Copilot privacy controls and agency risk posture before enabling1415.
- Capture software supply chain controls, dependency scanning, and infrastructure-as-code policy tests aligned to FedRAMP High control mappings via Azure Policy and repository checks in the planβs manage function17.
- Monitoring and incident response (Manage)
- Centralize AI application logs, model prompts/responses, safety filter events, and administrative actions into Microsoft Sentinel for Azure Government to support continuous monitoring and incident response within the government boundary19.
- Define operational metrics, drift indicators, and retraining triggers aligned to NIST AI RMF Manage outcomes, and include escalation paths and response playbooks in the plan3.
- Publication and continuous improvement (Govern and Manage)
- Publish required public artifacts such as the AI use case inventory and update cadence per OMB M-24-10, and maintain internal technical files with evaluations, changes, and risk decisions mapped to RMF outcomes23.
- Schedule periodic re-evaluations when models, datasets, or prompts change, and track policy exceptions and mitigations through the governance board with documented approvals23.
Copilot capability specifics for federal use
- Generative model hosting: Azure OpenAI in Azure Government supports government tenants with content filtering and network/identity patterns designed for government clouds, enabling agencies to keep data within Azure Government regions as documented5.
- Orchestration and evaluation: Azure AI Foundry provides prompt flow, evaluation tooling, and deployment scaffolding to build, test, and run Copilot-like assistants or task automations within agency subscriptions91011.
- Productivity copilots: Microsoft 365 Copilot processes user prompts and organization data under Microsoft 365 security and compliance constructs, using existing permissions and policies, and agencies should confirm availability and boundaries in their specific Microsoft 365 Government cloud before production use126.
- Low-code copilots: Power Platform US Government provides service-boundaries and feature availability statements that agencies must consult when planning Copilot-style bots or automations built with Power Platform services in GCC, GCC High, or DoD environments13.
- Developer copilots: GitHub Copilot privacy documentation describes data handling and options for telemetry and suggestions, which agencies should evaluate under OMB M-24-10βs risk management approach and agency policy; GitHub Enterprise Cloudβs FedRAMP authorization does not in itself constitute authorization for all optional features without agency assessment1415.
Mapping to federal requirements
- OMB M-24-10 governance: Steps 1, 2, 5, and 10 establish governance, inventories, safeguards for safety-impacting AI, and public transparency elements required by the memo using documented controls and processes2.
- NIST AI RMF alignment: The Govern/Map/Measure/Manage structure underpins the proposed workflow and provides a traceable mapping from inventories and threat modeling to evaluation metrics and continuous monitoring3.
- Cloud compliance and ATO acceleration: Azure Government FedRAMP High inheritance and DoD SRG mappings, combined with Azure Policy regulatory initiatives, provide authoritative control baselines and compliance assessments to support ATO packages47817.
Gaps, constraints, and what to verify
- Service availability and features for Microsoft 365 Copilot and Power Platform generative capabilities vary across GCC, GCC High, and DoD environments and must be verified against current Microsoft 365 Government and Power Platform US Government service descriptions during planning and prior to deployment613.
- Model availability and versions in Azure OpenAI may differ between commercial Azure and Azure Government regions, and agencies should select models explicitly supported in Azure Government as documented for government tenants5.
- Agencies should treat optional developer-assist features like GitHub Copilot as subject to AI risk management and data protection reviews and should not assume FedRAMP authorization of a platform equates to authorization of all optional features without explicit assessment and ATO documentation1415.
Action checklist for federal teams
- Confirm governance board, CAIO role, and AI policy alignment to OMB M-24-10 and NIST AI RMF; record in plan annexes23.
- Build a data and system inventory relevant to AI using Microsoft Purview, and produce the required AI use case inventory per OMB M-24-10162.
- Choose Azure OpenAI in Azure Government for genAI workloads and orchestrate with Azure AI Foundry; document model, filters, and deployment regions59.
- Enforce FedRAMP High and SRG controls with Azure Policy and SRG mappings; capture control inheritance in ATO artifacts1778.
- Implement content safety, human oversight, logging, and evaluation with Azure AI Content Safety and Azure AI Foundry evaluation flows; retain artifacts1810.
- Validate Microsoft 365 Copilot boundaries and Power Platform feature availability in your government cloud prior to use; configure access controls and labels12613.
- Use GitHub Enterprise Cloud under FedRAMP Moderate for code, and evaluate GitHub Copilot privacy controls under agency policy before enabling1415.
- Centralize monitoring in Microsoft Sentinel for Azure Government and define incident response playbooks for AI-specific events19.
Attribution and verification: All capabilities and policy mappings in this brief are sourced from primary federal policy and Microsoft documentation applicable to U.S. Government environments; where service availability varies by government cloud, agencies should consult current service descriptions during planning and prior to deployment246.
1: Executive Order 14110 β Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence β https://www.federalregister.gov/documents/2023/11/01/2023-24283/safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence 2: OMB M-24-10 β Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence β https://www.whitehouse.gov/wp-content/uploads/2024/03/M-24-10-Advancing-Governance-Innovation-and-Risk-Management-for-Agency-Use-of-Artificial-Intelligence.pdf 3: NIST AI Risk Management Framework 1.0 β https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf 4: Azure Government compliance offerings β https://learn.microsoft.com/azure/azure-government/documentation-government-compliance 7: DoD Cloud Computing Security Requirements Guide v1r4 β https://dl.dod.cyber.mil/wp-content/uploads/cloud/cc-srg_v1r4.pdf 8: FedRAMP Marketplace β Microsoft Azure Government β https://marketplace.fedramp.gov/products/microsoft-azure-government 5: Azure OpenAI Service in Azure Government β https://learn.microsoft.com/azure/ai-services/openai/azure-government 9: What is Azure AI Foundry β https://learn.microsoft.com/azure/ai-studio/what-is-ai-studio 18: Azure AI Content Safety overview β https://learn.microsoft.com/azure/ai-services/content-safety/overview 12: Microsoft 365 Copilot privacy, security, and data residency β https://learn.microsoft.com/microsoft-365-copilot/microsoft-365-copilot-privacy 6: Microsoft 365 US Government service description β https://learn.microsoft.com/office365/servicedescriptions/office-365-platform-service-description/office-365-us-government 14: GitHub Enterprise Cloud β FedRAMP Marketplace listing β https://marketplace.fedramp.gov/products/github-enterprise-cloud 15: About GitHub Copilot and privacy β https://docs.github.com/en/copilot/overview-of-github-copilot/about-github-copilot-and-privacy 16: Microsoft Purview documentation β https://learn.microsoft.com/purview/ 17: Azure Policy built-in initiatives for FedRAMP High β https://learn.microsoft.com/azure/governance/policy/samples/fedramp-high 19: Microsoft Sentinel in Azure Government β https://learn.microsoft.com/azure/sentinel/azure-government 13: Power Platform US Government β https://learn.microsoft.com/power-platform/admin/power-platform-us-government 10: Model evaluation in Azure AI Foundry β https://learn.microsoft.com/azure/ai-studio/concepts/evaluation 11: Prompt flow in Azure AI Foundry β https://learn.microsoft.com/azure/ai-studio/concepts/prompt-flow
References
- Executive Order 14110 β Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence β https://www.federalregister.gov/documents/2023/11/01/2023-24283/safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence β©
- OMB M-24-10 β Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence β https://www.whitehouse.gov/wp-content/uploads/2024/03/M-24-10-Advancing-Governance-Innovation-and-Risk-Management-for-Agency-Use-of-Artificial-Intelligence.pdf β©
- NIST AI Risk Management Framework 1.0 β https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf β©
- Azure Government compliance offerings β https://learn.microsoft.com/azure/azure-government/documentation-government-compliance β©
- Azure OpenAI Service in Azure Government β https://learn.microsoft.com/azure/ai-services/openai/azure-government β©
- Microsoft 365 US Government service description β https://learn.microsoft.com/office365/servicedescriptions/office-365-platform-service-description/office-365-us-government β©
- DoD Cloud Computing Security Requirements Guide v1r4 β https://dl.dod.cyber.mil/wp-content/uploads/cloud/cc-srg_v1r4.pdf β©
- FedRAMP Marketplace β Microsoft Azure Government β https://marketplace.fedramp.gov/products/microsoft-azure-government β©
- What is Azure AI Foundry β https://learn.microsoft.com/azure/ai-studio/what-is-ai-studio β©
- Model evaluation in Azure AI Foundry β https://learn.microsoft.com/azure/ai-studio/concepts/evaluation β©
- Prompt flow in Azure AI Foundry β https://learn.microsoft.com/azure/ai-studio/concepts/prompt-flow β©
- Microsoft 365 Copilot privacy, security, and data residency β https://learn.microsoft.com/microsoft-365-copilot/microsoft-365-copilot-privacy β©
- Power Platform US Government β https://learn.microsoft.com/power-platform/admin/power-platform-us-government β©
- GitHub Enterprise Cloud β FedRAMP Marketplace listing β https://marketplace.fedramp.gov/products/github-enterprise-cloud β©
- About GitHub Copilot and privacy β https://docs.github.com/en/copilot/overview-of-github-copilot/about-github-copilot-and-privacy β©
- Microsoft Purview documentation β https://learn.microsoft.com/purview/ β©
- Azure Policy built-in initiatives for FedRAMP High β https://learn.microsoft.com/azure/governance/policy/samples/fedramp-high β©
- Azure AI Content Safety overview β https://learn.microsoft.com/azure/ai-services/content-safety/overview β©
- Microsoft Sentinel in Azure Government β https://learn.microsoft.com/azure/sentinel/azure-government β©