Government Track — Certification Specification

Constitutional AI Governance for Government

Federal procurement is the largest AI customer in the world. This specification maps the seven constitutional pillars to NIST AI Risk Management Framework, CISA guidance, FedRAMP alignment, federal acquisition regulation, and state government AI readiness requirements.

← Back to Certification
01 — The Mandate
Why Government Needs Constitutional Governance

The federal government is the largest AI customer in the world. Federal agencies are deploying AI systems for benefits processing, fraud detection, immigration adjudication, healthcare delivery, and national security analysis. Every one of these systems makes decisions that affect real people.

The problem: 68% of enterprises plan to switch AI vendors within 12 months. When an agency switches, what happens to the governance framework? If it was vendor specific, it disappears. If it was constitutional, it persists.

68%
Agencies planning AI vendor transition
63.5%
AI agent incident rate
69%
AI systems sharing credentials

The NIST AI Risk Management Framework provides guidance. CISA provides security direction. FedRAMP provides cloud authorization. But none of these establishes a constitutional standard for AI governance that persists across vendor transitions and agency reorganizations.

That is what Lunara provides.

02 — Regulatory Mapping
Seven Pillars Mapped to Government Requirements
I. Verified Identity NIST AI RMF GOVERN 1.1
Requirement: Every AI system deployed by or procured for a government agency must have a verified identity registered in a public trust registry. Mapped to: NIST AI RMF Govern function (accountability structures), CISA binding operational directives on asset inventory, FedRAMP system categorization (FIPS 199).
II. Declared Governance Framework NIST AI RMF GOVERN 2.1
Requirement: Agencies must declare the governance framework under which each AI system operates. Mapped to: NIST AI RMF Map function, OMB Circular A-123 (internal control), Executive Order 14110 (Safe, Secure, and Trustworthy AI), Federal Data Strategy.
III. Transparency of Contact FOIA, Transparency Act
Requirement: A human contact must be publicly accountable for every AI system. Mapped to: Freedom of Information Act disclosure requirements, Federal Advisory Committee Act transparency, Open Government Data Act, Evidence Act (Foundations for Evidence Based Policymaking).
IV. Data Sovereignty FISMA, FedRAMP
Requirement: Data processed by government AI systems must remain under sovereign control with declared boundaries. Mapped to: FISMA (Federal Information Security Modernization Act), FedRAMP authorization boundaries, CJI Security Policy (for criminal justice systems), HIPAA (for federal health systems).
V. Audit Accessibility GAO, OIG
Requirement: Audit trails must be accessible to GAO, Inspectors General, and authorized oversight bodies. Mapped to: GAO audit authority (GAO Yellow Book), Inspector General Act, OMB Circular A-133 (single audit), agency specific audit requirements.
VI. Revocability FAR, Acquisition
Requirement: Certifications must be revocable when trust is broken or when AI systems are retired. Mapped to: Federal Acquisition Regulation (FAR) termination clauses, Contract Disputes Act, Defense Acquisition Regulation Supplement (DFARS) for DoD systems.
VII. Proportionality EO 14110, Civil Rights
Requirement: Governance requirements must be proportionate to the risk and impact of the AI system. Mapped to: Executive Order 14110 risk based approach, Title VI of the Civil Rights Act (algorithmic discrimination), Section 508 (accessibility), EEOC guidance on AI in employment decisions.
03 — Key Regulatory Frameworks
Full Coverage Across Federal, State, and Defense

NIST AI RMF

America's foundational AI risk management standard. Full Govern, Map, Measure, Manage alignment.

FedRAMP

Cloud authorization boundary mapping. Agency sponsorship and continuous monitoring alignment.

FISMA

Federal information security. System categorization and control baseline mapping.

EO 14110

Safe, Secure, and Trustworthy AI. Risk based requirements and agency inventory.

CISA Guidance

Cybersecurity direction and binding operational directives for AI systems.

FAR / DFARS

Federal and Defense acquisition regulation. Termination and audit clauses.

GAO Authority

Government Accountability Office audit access and Yellow Book compliance.

Civil Rights

Title VI, Section 508, EEOC guidance on algorithmic decision making.

04 — The Procurement Advantage
Vendor Transition Governance Checkpoint

When 68% of agencies are planning to switch AI vendors, the governance question becomes critical: does the governance framework survive the transition?

A vendor specific governance framework disappears when the contract ends. A constitutional governance framework persists because it is tied to the institution, not the vendor.

Agencies that require Lunara certification in their procurement language ensure that every AI vendor they work with operates under the same seven pillars. When they switch vendors, the standard does not change. The implementation changes. The governance persists.

The constitutional governance checkpoint is the procurement innovation that makes vendor transitions safe. It is Lunara's contribution to federal AI readiness.

05 — Certification Process
How Government Certification Works

1. Application: The agency or vendor submits a certification application with system documentation.

2. Identity Verification: Legal entity verification and domain verification through DNS TXT records.

3. Pillar Assessment: Each of the seven pillars is assessed against the relevant regulatory frameworks.

4. Public Registry Entry: Certification is published in the public Shield Registry with full audit trail.

5. Continuous Monitoring: Annual re-verification and revocation triggers for material changes.

6. Revocation: Certifications are publicly revocable when trust is broken.

Founding Pilot for Government AI Programs

Five founding pilot seats for federal, state, or municipal AI programs. Priority processing, founding certification status, and preferred pricing locked for 36 months.

View All Certification Tracks