# What the report says
Administration (TIGTA) reviewed how the Internal Revenue Service manages risk for artificial intelligence (AI) systems and found gaps in documentation and data controls for high-impact use cases. The report notes the IRS had 225 AI use cases as of December 2025 and examined five cases the agency treated as likely to be high impact.
Two of the five sampled cases did not have documented impact assessments. Three did. TIGTA also found testing documentation inconsistent: one of the five cases included extensive testing procedures, while four lacked testing documentation. The IRS had not standardized documentation or established baseline procedures for evaluating data quality before using data in high-impact AI models.
# Why this matters
TIGTA defines high-impact AI as systems whose outputs serve as a principal basis for decisions or actions that have legal, material, binding or significant effects on civil rights, privacy, health, safety or access to critical government resources and services. When AI outputs materially affect taxpayer outcomes, incomplete risk assessments and weak data-quality controls can lead to wrong decisions, missed errors, unfair treatment, or compliance problems.
# Where policy and guidance stand
Budget issued a memorandum (M-25-21) requiring federal agencies to implement minimum risk management practices for high-impact AI by April 2026. The TIGTA report notes that, as of July 2026, the Treasury Department had not issued guidance on minimum risk-management practices. The IRS has developed its own AI governance policy and told TIGTA it is aligning processes with the OMB memo.
# TIGTA recommendations and IRS response
TIGTA made two clear recommendations:
- Ensure AI impact assessments for high-impact use cases are completed in accordance with OMB Memorandum M-25-21.
- Develop and implement standard processes for evaluating data quality for use in AI use cases.
The IRS agreed with both recommendations and said it either has or plans to implement corrective actions. Acting chief data and analytics officer Lucia Lykke responded to the report: "We remain committed to continuous improvement and transparency in our AI risk management practices at the IRS."
# Context in broader oversight
The report arrives amid other watchdog findings about IRS security and program weaknesses. Recent TIGTA reviews have flagged cybersecurity deficiencies and labeled the agency's cybersecurity program as not effective for fiscal 2026. Those findings underline that governance, documentation and remediation practices across technology programs are under scrutiny.
# Practical implications for taxpayers and practitioners
Taxpayers whose cases are influenced by AI-driven decisions may be affected if AI outputs are used without full impact assessments or if the underlying data are not vetted consistently. Tax professionals and compliance officers should expect increased documentation and governance requirements as the IRS implements TIGTA's recommendations and aligns with OMB standards.
# What to watch next
- IRS implementation steps for the two TIGTA recommendations and timelines for completing impact assessments.
- Treasury Department guidance, if issued, clarifying minimum risk-management practices.