FederalShield Logo

FederalShield

AI SECURITY ACADEMY

Public-Sector AI Security Checklist

1. Safe Generative AI at Work

Verify Tool Approval Status

Never log into or use a public Generative AI service unless it is officially approved by your agency's IT security/procurement authorities.

Anonymize Public Prompt Input

Scrub all personally identifiable information (PII), agency-sensitive terms, project nicknames, and technical architecture details before submitting prompts to public models.

2. Avoiding Sensitive Data Exposure

Classify Data Before AI Interaction

Understand your data categories (CUI, FOUO, PII, Draft policy documents). Treat public AI input fields as public releases.

Do Not Upload Official Files

Do not upload spreadsheets, source code, internal memos, or citizen datasets to commercial AI tools that retain user input for model retraining.

3. Recognizing AI-Generated Phishing

Be Alert to Hyper-Personalization

Identify emails that mention highly specific agency projects, colleague names, or specific terminology. AI can synthesize personalized lures rapidly.

Validate Out-of-Band

If an email demands urgent financial actions, credential resets, or document transfers, verify the request through an established contact number, not via email reply.

4. Deepfakes & Impersonation Prevention

Challenge Unexpected Communications

Watch for unusual requests from managers or executives on Microsoft Teams, Slack, or telephone. Deepfakes can replicate voices and video in real time.

Use Multi-Factor Authentication

Never bypass established authentication standards based on audio or video validation alone. Follow strict administrative verification paths.

5. AI Tool Approval & Review

Submit Requests Formally

Document the tool name, version, exact business use case, and compliance details (e.g., FedRAMP authorization status) when requesting AI tooling.

Review Privacy Policies

Ensure any tool used allows opting out of data sharing for training purposes (e.g., utilizing API endpoints or enterprise seats rather than consumer tiers).

6. Incident Reporting

Isolate Suspicious Systems

If you suspect credentials or sensitive data were submitted to an unauthorized AI, disconnect the browser session and notify security officers immediately.

Document Leak Details

Log the exact prompt, document uploaded, time of transaction, and the URL of the tool used. This assists forensic teams in assessing breach scopes.

FederalShield LLC is an independent private company and is not affiliated with, endorsed by, or sponsored by any U.S. government agency. This course does not represent official government training or policy.