Accountingtoday iconAccountingtodaySep 28, 2026 ~4 min source read

TIGTA: IRS must tighten AI risk management for hundreds of use cases

A Treasury Inspector General review found incomplete impact assessments, inconsistent testing documentation and no standardized data-quality processes across sampled high-impact AI applications at the IRS.

IRS's AI risk management needs to be improved

Share this story

Send the public story page.

Useful takeaways from this story.

Taxpayers facing high-impact agency decisions driven by unassessed artificial intelligence models.

Find out how the IRS is deploying hundreds of artificial intelligence use cases.

# What the report says

Administration (TIGTA) reviewed how the Internal Revenue Service manages risk for artificial intelligence (AI) systems and found gaps in documentation and data controls for high-impact use cases. The report notes the IRS had 225 AI use cases as of December 2025 and examined five cases the agency treated as likely to be high impact.

Two of the five sampled cases did not have documented impact assessments. Three did. TIGTA also found testing documentation inconsistent: one of the five cases included extensive testing procedures, while four lacked testing documentation. The IRS had not standardized documentation or established baseline procedures for evaluating data quality before using data in high-impact AI models.

# Why this matters

TIGTA defines high-impact AI as systems whose outputs serve as a principal basis for decisions or actions that have legal, material, binding or significant effects on civil rights, privacy, health, safety or access to critical government resources and services. When AI outputs materially affect taxpayer outcomes, incomplete risk assessments and weak data-quality controls can lead to wrong decisions, missed errors, unfair treatment, or compliance problems.

# Where policy and guidance stand

Budget issued a memorandum (M-25-21) requiring federal agencies to implement minimum risk management practices for high-impact AI by April 2026. The TIGTA report notes that, as of July 2026, the Treasury Department had not issued guidance on minimum risk-management practices. The IRS has developed its own AI governance policy and told TIGTA it is aligning processes with the OMB memo.

# TIGTA recommendations and IRS response

TIGTA made two clear recommendations:

  • Ensure AI impact assessments for high-impact use cases are completed in accordance with OMB Memorandum M-25-21.
  • Develop and implement standard processes for evaluating data quality for use in AI use cases.

The IRS agreed with both recommendations and said it either has or plans to implement corrective actions. Acting chief data and analytics officer Lucia Lykke responded to the report: "We remain committed to continuous improvement and transparency in our AI risk management practices at the IRS."

# Context in broader oversight

The report arrives amid other watchdog findings about IRS security and program weaknesses. Recent TIGTA reviews have flagged cybersecurity deficiencies and labeled the agency's cybersecurity program as not effective for fiscal 2026. Those findings underline that governance, documentation and remediation practices across technology programs are under scrutiny.

# Practical implications for taxpayers and practitioners

Taxpayers whose cases are influenced by AI-driven decisions may be affected if AI outputs are used without full impact assessments or if the underlying data are not vetted consistently. Tax professionals and compliance officers should expect increased documentation and governance requirements as the IRS implements TIGTA's recommendations and aligns with OMB standards.

# What to watch next

  • IRS implementation steps for the two TIGTA recommendations and timelines for completing impact assessments.
  • Treasury Department guidance, if issued, clarifying minimum risk-management practices.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app