How EPA Uses AI and Your Own Compliance Data to Target Facility Inspections

How EPA Uses AI and Your Own Compliance Data to Target Facility Inspections

EPA uses machine-learning models and facility compliance data to target inspections. How the RCRA model works — and how plant managers lower their risk profile.

Your own reports are the tip line now. EPA’s inspection-targeting models run on data analytics built from the submissions your facility already makes — e-Manifests, discharge monitoring reports, emissions inventories, and your public compliance history. Since 2017, EPA has used machine learning to decide which facilities get inspected, and the deployed RCRA model showed a 47% improvement in identifying violations in proof-of-concept. A late report is no longer just a paperwork miss. It is a feature in a risk model that decides whether an inspector shows up at your gate.

Here is what plant managers need to know about how EPA picks its targets — and what actually changed versus what is still marketing.

How does EPA decide which facilities to inspect?

EPA combines its six National Enforcement and Compliance Initiatives, tips and complaints, statutory minimum inspection frequencies, and — since 2017 — machine-learning risk models. The deployed RCRA model, built with the University of Chicago Energy & Environment Lab on roughly 20 years of administrative data, directs inspectors to facilities most likely to have violations.

The scarcity math drives all of it. EPA conducted roughly 8,300 inspections in FY2025 — the second-highest count in eight years — against a regulated universe of hundreds of thousands of facilities. When an agency can physically visit only a small fraction of the facilities it regulates, where those visits go is the entire enforcement question. For decades the answer was a mix of statutory schedules, complaints, and inspector judgment. The model layer does not replace those inputs; it ranks them. A facility that sits inside a NECI category — chemical accident risk, air toxics, PFAS — and also carries a data profile the model flags is at the top of the list.

Does EPA actually use artificial intelligence to pick enforcement targets?

Yes, in one deployed case: AI prioritization of RCRA inspections for Large Quantity Generators, which EPA’s AI inventory says showed a 47% improvement in identifying violations in proof-of-concept. Per EPA’s 2025 AI Use Case Inventory, similar models for Clean Air Act, RMP, and NPDES facilities are in development — not yet deployed.

That deployment gap is the part most coverage skips, and it matters for how you should respond. EPA’s AI Strategy Plan (October 2025) identifies 18 AI use cases across the agency, but enforcement targeting for RCRA Large Quantity Generators is the only high-impact enforcement use case actually running. A Greenberg Traurig assessment from April 2026 concluded EPA’s practical AI adoption is “much more aspirational than real.” Translation for plant managers: you are not up against an all-seeing enforcement machine. You are up against one working model with more on the way — which means the window to clean up your facility’s data profile is open right now, and it will not stay open.

What is the EPA RCRA machine-learning targeting model?

A predictive model developed since 2017 by EPA and the UChicago Energy & Environment Lab, trained on nearly two decades of RCRA administrative data. In a randomized field evaluation against EPA’s existing targeting approach, the model showed a 47% improvement in identifying violations — with no additional inspectors and no additional budget.

That figure is worth sitting with. Same budget, same inspectors, roughly half again more violations identified — purely from choosing targets better. The evaluation was not a modeling exercise on paper; the Lab ran a randomized field trial against EPA’s existing targeting approach. EPA has since made the tool available to regulators nationwide. Combine that efficiency gain with FY2025’s enforcement volume — 2,127 concluded civil cases, the highest in nine years, and more than $1.2 billion in penalties, fines, and court-ordered relief — and the practical takeaway is simple: there are fewer places to hide in the data.

What data does EPA’s inspection-targeting model use?

Administrative data EPA already holds: compliance and violation history, inspection outcomes, and facility self-reported data flowing through systems like RCRAInfo, e-Manifest, and ECHO. That means your own submissions — their timeliness, consistency, and the violations behind them — are the inputs that raise or lower your facility’s risk score.

No drones, no satellite feeds, no new surveillance program. The model’s food supply is the reporting you already do. Your Biennial Report tells EPA what waste you generate and in what volumes. Your e-Manifest records show every hazardous waste shipment. Your discharge monitoring reports, emissions inventories, and TRI submissions round out the picture, and your inspection and violation history sits on top of all of it. This is why data hygiene has quietly become an enforcement issue: a waste code that does not match between your manifest and your RCRAInfo profile, a generator category that drifted from reality, or a reporting gap is exactly the kind of anomaly a model trained on 20 years of violator data learns to notice.

Is EPA building AI models for Clean Air Act and Clean Water Act inspections?

Yes — in development. EPA’s 2025 AI Use Case Inventory lists risk-scoring for Clean Air Act major and synthetic-minor facility inspections, risk-scoring of RMP facilities for elevated accident risk, and identification of high-risk NPDES facilities that fail to submit monitoring reports. None of these is listed as fully deployed yet.

The NPDES use case deserves special attention from plant managers because of what it targets: non-submitters. Not facilities that reported bad numbers — facilities that did not report at all. Silence, in other words, is itself a model feature. If your facility holds an NPDES permit and a DMR slips, you are not flying under the radar; you are matching the exact profile one of these in-development models is being built to find. A manufacturer running combustion sources, chemical processes, and a hazardous waste program sits in multiple model lanes at once — RCRA today, CAA and RMP risk-scoring as those tools come online.

Can I see the compliance data EPA sees about my facility?

Largely yes. EPA’s ECHO database publishes three years of inspection, violation, and enforcement history for over 900,000 regulated facilities — the same administrative record the targeting models draw on. Pulling your own ECHO report is the fastest way to see your facility the way EPA’s screens do.

This is the ten-minute exercise worth doing this week. Search your facility, and read the record like a model would: Are there quarters showing “significant noncompliance” or high-priority violation flags? Late or missing reports? Repeat RCRA findings that were never documented as closed? If the answer to any of those is yes, your facility resembles the facilities the model was trained to flag — regardless of how your program actually runs today. The gap between what your compliance program is and what your public data profile says it is belongs to you to close, and ECHO shows you exactly what needs closing.

What penalties can follow an AI-flagged RCRA inspection?

The same as any inspection: RCRA §3008(g) civil penalties run up to $93,058 per day, per violation at 2025-adjusted levels (40 CFR 19.4), which carry into 2026 because the annual inflation adjustment was canceled. The AI only picks the target — citations and penalties follow the standard enforcement process.

Two clarifications plant managers should have straight. First, the penalty levels: the 2026 inflation adjustment did not happen (no October 2025 CPI data during the lapse in appropriations), so 2025 figures carry forward unchanged — penalties did not go up this year, but $93,058 per day, per violation needs no increase to be ruinous. A violation that ran undetected for 60 days carries a statutory maximum exposure of over $5.5 million before negotiation. Second, the model changes your odds of being inspected, not the rules of the inspection. Once an inspector is on site, it is the standard RCRA checklist: waste determinations, container management, labeling, contingency plans, training records.

What are EPA’s current national enforcement priorities?

Six National Enforcement and Compliance Initiatives for FY2024–2027, as realigned by a March 12, 2025 OECA memo: multi-media border security, drinking water compliance, chemical accident risk reduction under RMP, cleaner air for communities (hazardous air pollutants), PFAS exposure, and coal ash contamination. Facilities inside a NECI category face concentrated inspection attention on top of any model-based targeting.

Think of the NECIs and the models as two overlapping filters. The initiatives say which problems EPA has decided to spend enforcement resources on; the models say which specific facilities within those problem areas look most likely to be violating. An RMP-covered chemical facility is already inside a NECI lane — and RMP accident-risk scoring is one of the models in development on EPA’s AI inventory. If your facility sits at that intersection, assume elevated inspection probability and audit accordingly.

Does a human still decide whether my facility gets inspected or cited?

Yes. EPA’s AI Strategy frames these tools as decision support: models prioritize which facilities inspectors visit, but inspectors conduct the inspection and enforcement staff decide on citations. Greenberg Traurig’s April 2026 assessment likewise found AI is informing targeting, not making enforcement determinations.

No citation is issued by an algorithm. The model puts your facility on a list; a human inspector walks your floor, opens your records, and finds — or does not find — actual violations. That is genuinely good news, and it points at where your effort should go. A facility with a well-run program has nothing to fear from a targeted inspection; the model can only send an inspector to look. What the model does change is the selection odds: inspections are less random than they used to be, so “we’ve never been inspected” is a weaker comfort than it was five years ago. Prepare for the inspection you may now be more likely to get, rather than betting on staying unnoticed.

How can a plant manager lower a facility’s inspection-risk profile?

Behave unlike the facilities the model was trained to flag: file every report on time, clear ECHO noncompliance flags, keep RCRAInfo and e-Manifest data consistent, and close out past violations with documented corrective action. A facility with clean, timely, consistent data gives a risk model very little to work with.

In practice, that is four standing disciplines:

  1. Review your ECHO record quarterly. Identify and resolve “significant noncompliance” or high-priority-violation flags — compliance history is core model input.
  2. Submit every required report on time. DMRs, RCRA Biennial Reports (EPA Form 8700-13A/B), TRI, emissions inventories. The NPDES use case specifically targets non-submitters, so a missed report is a targeting signal, not just a deadline miss.
  3. Keep e-Manifest and RCRAInfo data consistent. Waste codes, generator category, quantities. Inconsistencies between submissions are the anomalies data models surface.
  4. Audit your RCRA program against the common violation set. Waste determinations, open containers, labeling, contingency plans — the items a human inspector actually checks once the model sends them.

None of this is new compliance work. It is the existing work, done with the knowledge that a model is reading the output.

Does self-disclosing violations protect against data-driven enforcement?

It helps substantially. Under EPA’s Audit Policy, violations disclosed through the eDisclosure portal within 21 days of discovery can receive up to 100% gravity-based penalty mitigation (75% without systematic discovery) and a recommendation against criminal referral. In FY2025, EPA received 538 voluntary disclosures covering 957 facilities.

Self-disclosure is the rational response to better targeting. If EPA’s models are getting more efficient at finding violators, the expected cost of “wait and hope” goes up, while the Audit Policy discount for finding and reporting your own violations stays on the table. The mechanics matter: the 21-day clock runs from discovery, systematic discovery (a documented audit program or compliance management system) earns the full 100% gravity-based mitigation, and ad-hoc discovery still earns 75%. A facility that audits itself, finds a violation, corrects it, and discloses inside the window converts a potential enforcement case into a documented good-faith record — which is also exactly the data profile the targeting models score as low-risk.

Do state environmental agencies use EPA’s targeting model too?

EPA has made the RCRA targeting tool available to regulators nationwide, and state agencies were partners in its development. Since most RCRA, CAA, and NPDES inspections in our region are run by authorized state programs — KDHE, MoDNR, ODEQ, TCEQ, NDEE — model-informed targeting can reach facilities through state inspectors, not just EPA regional offices.

This is why “federal enforcement is pulling back” is not the reassurance it sounds like. FY2025’s record numbers largely reflect the prior administration’s case pipeline, and the current federal posture is deregulatory in several program areas — but authorized state programs conduct most routine inspections in Kansas, Missouri, Oklahoma, Texas, and Nebraska regardless of who occupies EPA headquarters. No Midwest state has published its own AI-targeting policy, and if a state agency adopts the model, nothing changes at your gate except the odds: the same state inspector, checking the same items, just directed by a better-informed list. Your data profile feeds that list either way.

The bottom line: fix the data profile while the window is open

Strip away the AI branding and the situation is concrete. One deployed model already directs RCRA inspections at Large Quantity Generators. Three more model lanes — CAA, RMP, NPDES — are in development on EPA’s own inventory. Every one of them runs on data your facility already submits, and most of that record is publicly visible in ECHO today. Humans still make every enforcement decision; the model just decides who gets looked at. The facilities that will regret this shift are the ones whose paperwork profile looks worse than their actual program — late reports, unclosed violations, inconsistent waste data — because those are precisely the signatures a targeting model reads.

That gap between how your facility runs and how it reads is closable, and closing it is standard compliance work: an environmental compliance audit that reconciles your RCRAInfo, e-Manifest, and reporting record, clears the findings behind your ECHO flags, and puts documented corrective action — and, where it makes sense, a 21-day Audit Policy disclosure — on the record before a model-directed inspector does the looking for you. iSi’s environmental compliance team does this work inside manufacturing facilities in 40 states, and our EHS cooperative (EHS COOP) retainer keeps the reporting calendar, data consistency, and corrective-action documentation current year-round for $15,000–$90,000 per year. Against a RCRA exposure of up to $93,058 per day, per violation, the math is not close.

Want to know what EPA’s screens see when they look at your facility? Call us at (316) 264-7050 or schedule a compliance assessment — we will pull your ECHO record with you and walk through what needs to be closed.

Sources