Federal AI Intelligence
Menu
Snapshot · OMB 2025 inventory · processed Oct 11, 2026
VA · VA-25-2537 · record R2227

Heuristic Behavior Analytics

Department of Veterans Affairs · OIT: Office of Information & Technology

Overview

Development stage
DeployedSource: c) Deployed – The use case is being actively authorized or utilized to support the functions or mission of an agency.
High-impact designation
High-impactSource: a) High-impact
Impact justification
Not reported
Start date
Not reported
Withheld from public reporting
Not reported

Mission

Topic area
Cybersecurity
Operational functions
Risk scoring and triage Derived by keyword rules; see methodology

Problem the AI is intended to solve

Identify anomalous behaviors from established baselines for VA Accounts and Hosts. The output is a Risk score that is provided to CSOC Analysts to more quickly identify accounts and hosts that have been compromised after the initial authentications associated with a computational session

Expected benefits

Quicker identification, response, and mitigation of cybersecurity incidents.

System outputs

Risk scores for Accounts and Hosts, based on a comparison of recent and historic activities.

Technology

AI classification
Classical / predictive MLSource: Classical/Predictive Machine Learning: Models trained on data to make predictions or classifications based on identified patterns or relatio…
System name(s)
Not reported
Custom-developed code
No
Public source code
Not reported

Sourcing

How it was built
Purchased from vendorSource: a) Purchased from a vendor
Vendor (as reported)
Not reported
Vendors (standardized)
None on the standard list

A vendor is the supplier named by the agency. It does not identify the underlying model or AI technology.

Data and privacy

Involves PII
Not reported
Privacy Impact Assessment
Not reported
Authorization to Operate
Not reported
Demographic features
Not reported
Training and evaluation data
Not reported
Federal Data Catalog
Not reported

Governance

0 of 8 minimum-practice questions answered. A blank answer means the agency reported nothing; it does not mean the practice is absent.

Pre-deployment testingNo answer reported
AI impact assessmentNo answer reported
Independent reviewNo answer reported
Ongoing monitoringNo answer reported
Operator trainingNo answer reported
Fail-safeNo answer reported
Appeal processNo answer reported
User and public consultationNo answer reported

Potential impacts and how they were identified

Not reported