skills/arckit-us-ai-impact/SKILL.md
[COMMUNITY] Determine whether an AI system is rights-impacting or safety-impacting under OMB M-24-10 and document the minimum risk-management practices, M-25-21 acquisition controls, and public disclosure obligations.
npx skillsauth add tractorjuice/arckit-codex arckit-us-ai-impactInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by qualified US federal counsel, your agency's Senior Agency Official for Privacy (SAOP), CISO, Chief AI Officer (CAIO), and (for FedRAMP matters) the agency PMO and 3PAO before reliance.
Statutory currency: EO 14110 was revoked January 2025; the active AI assurance mandates are OMB M-24-10 (use of AI) and OMB M-25-21 (acquisition of AI). FedRAMP completed the transition to NIST 800-53 Rev 5 baselines in 2024 — Rev 4 references are deprecated. Verify all citations against the current Federal Register, OMB Circulars page, NIST publications, and FedRAMP.gov before relying on this output.
You are an enterprise architect producing an AI Impact Assessment under OMB M-24-10 and OMB M-25-21 for a US federal civilian agency.
$ARGUMENTS
OMB M-24-10 ("Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence", March 2024) is the binding policy framework for federal civilian AI use. It defines two impact categories that trigger heightened oversight:
Appendix I of M-24-10 lists presumed-impacting use cases (those agencies must treat as rights- or safety-impacting unless rebutted). Agencies must implement minimum risk-management practices for each impact category, may not waive them without CAIO documentation, and must publicly inventory AI use cases (federal.ai.gov).
OMB M-25-21 ("Accelerating Federal Use of AI through Innovation, Governance, and Public Trust", April 2025) is the acquisition-side companion: it directs agencies to embed AI risk-management requirements in solicitations, contracts, and vendor evaluations, and requires AI RMF alignment from vendors.
Authoritative anchors:
Read prerequisites:
projects/000-global/ARC-000-PRIN-*.md (architecture principles, if present)$arckit-us-ai-rmf first)NFR-SEC-*, DR-*, INT-*, plus any explicit fairness / non-discrimination requirements.arckit/templates/_partials/RENDERING.mdRead the template:
.arckit/templates-custom/us-ai-impact-template.md (user override).arckit/templates-custom/us-ai-impact-template.md.arckit/templates/us-ai-impact-template.mdUse scripts/bash/create-project.sh --json <project-name> if the project does not yet exist; otherwise locate it.
Use scripts/bash/generate-document-id.sh <PROJECT_ID> AIIA --filename for the artefact filename. The type code for this command is AIIA.
Generate the following sections:
Use the Write tool to save the artefact at the path returned by create-project.sh + generate-document-id.sh.
Emit a short summary to the user — impact verdict (rights-impacting / safety-impacting / both / neither), Appendix I match (Y/N), minimum-practice satisfaction percentage, waiver count, AI Use Case Inventory ID (or "pending"), and CAIO review status. Do not echo the full artefact.
Minimum-practice gaps drive the AI RMF uplift backlog via $arckit-us-ai-rmf. PII-handling AI systems require $arckit-us-privacy-pia. Any residual M-24-10 risks — particularly waiver scenarios — should be entered into $arckit-risk with the next CAIO review date.
After completing this command, consider running:
$arckit-us-ai-rmf -- The minimum-practice gaps surfaced here drive the AI RMF Govern / Map / Measure / Manage uplift backlog.$arckit-us-privacy-pia -- Rights-impacting AI systems handling PII require an E-Gov Act §208 PIA.$arckit-risk -- Residual M-24-10 risks (especially where minimum practices cannot be met) flow into the risk register.tools
Procurement market intelligence — award-value benchmarks, top suppliers, incumbency and concentration, from the UK Tenders MCP
tools
Competitor landscape — rival suppliers, awarded-value market share, head-to-head and concentration, from the UK Tenders MCP
development
[COMMUNITY] Generate a SOCI Act Critical Infrastructure Risk Management Program (CIRMP) governance and evidence pack for Australian critical infrastructure assets.
development
[COMMUNITY] Generate an ASD operational technology cyber security assessment for Australian Government and critical-infrastructure projects with connected OT environments.