SBA's AI Fraud Pilot Never Classified as High-Impact, OIG Finds
Source
SBA's AI fraud detection pilot didn't include needed safeguards, OIG saysU.S. Small Business Administration / Office of Inspector General
What happened
The SBA's Office of Inspector General published findings that the agency's AI-assisted fraud detection pilot was built on Palantir technology. It screened COVID-19 loan program applicants. It was deployed without being classified as a high-impact use case under OMB Memorandum M-26-04: Increasing Public Trust in AI Through Unbiased AI Principles. That classification gap meant legally required protections never activated. No AI impact assessment was completed. No human oversight mechanism was designed, and affected borrowers had no formal appeals process. The OIG also found that the SBA lacked a functioning AI governance board capable of making or recording such determinations. The findings parallel a similar accountability gap found at another federal agency, where high-impact AI was deployed with no testing records in 80% of cases. The OIG issued six recommendations focused on building the governance infrastructure needed to ensure future AI systems are properly identified, assessed, and controlled.
Why it matters
- ·When no body is responsible for classifying AI systems by risk level, every downstream safeguard required by OMB guidance, including OMB Memorandum M-26-04, fails to trigger. The SBA finding shows this is a governance design failure, not an execution one, and regulators are now naming it explicitly.
- ·Borrowers screened or denied by an AI system with no appeals process face due process exposure that can become a legal and reputational liability. Any AI tool affecting eligibility, benefits, or financial decisions needs a documented path for people to contest outcomes.
- ·Federal contractors deploying AI in government programs, including vendors like Palantir, now face heightened scrutiny over whether their tools were subject to required pre-deployment governance steps. Procurement teams should treat OIG findings as signals of where audit attention is heading next.
Governance controls affected
What to do now
- ☐Review your AI system inventory and confirm that each system has a documented, board- or committee-approved risk classification, specifically identifying which systems qualify as high-impact or high-risk under your applicable framework.
- ☐Verify that your AI governance committee is operational, has defined decision rights for classifying AI use cases, and is recording those determinations in writing.
- ☐For any AI system used in eligibility, fraud screening, benefits, or financial decisions, confirm that a formal process exists for affected individuals to question or appeal AI-influenced outcomes.
- ☐If your organization deploys AI under a federal contract, audit whether the required pre-deployment steps, including impact assessments and oversight mechanisms, were completed and documented before the system went live.
- ☐Ask your procurement and legal teams to review OIG and Government Accountability Office AI-related findings from the past 12 months and map any cited gaps to your own governance controls.
What to watch next
OIG findings at federal agencies are increasingly functioning as enforcement signals: they expose the specific governance steps regulators expect and will audit against. Compliance teams at federal agencies and their contractors should watch for follow-on OIG audits at other agencies using AI in loan, benefits, or grant programs. This pattern is already visible at the IRS and HUD. The OMB's continued issuance of AI governance guidance means the classification framework will only become more detailed and more enforceable over time.
Stay ahead of stories like this
Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.
