United States — Federal

Federal AI Procurement Rules: What Government Vendors Need to Know

The federal government is the largest AI buyer in the country, and it enforces its own AI rules through procurement memos and contract terms rather than a single AI-specific statute.

OMB M-25-22 in force since Sept. 2025 — a governmentwide contract clause remains only proposedEffective September 30, 2025
A federal contracting officer and technical evaluator assessing AI vendor risk during a procurement review
Photo: Christina @ wocintechchat.com M via Unsplash
Governome Editorial Team8 min readHow we source and review this content.

Three separate rulebooks currently govern a sale of AI to the federal government, and only one of them has actually finished being written. A memo from the Office of Management and Budget sets the baseline terms for most AI contracts today. A second layer, triggered by a different executive order, adds a disclosure requirement that applies only if your product includes a chatbot or generative interface. A third layer — the one contractors most often mistake for already being in force — is a proposed contract clause that GSA hasn't finalized yet. Treating "federal AI procurement rules" as one document is the fastest way to miss which of the three actually applies to your bid.

The memo that actually governs your contract today

The instrument doing the real work right now is OMB Memorandum M-25-22, "Driving Efficient Acquisition of Artificial Intelligence in Government," issued April 3, 2025. It replaced a Biden-era memo, M-24-18, after Executive Order 14179 directed OMB to revise the federal government's AI acquisition guidance within 60 days of taking office — the same executive order that reshaped how agencies use AI internally, covered in more depth in our history of federal AI executive orders.

M-25-22's applicability trigger is worth getting exactly right, because it's the detail vendors most often get wrong: the memo applies to AI systems and services acquired under contracts awarded pursuant to solicitations issued on or after September 30, 2025, plus any option to renew or extend an existing contract's period of performance exercised on or after October 1, 2025. A contract your company signed in early 2025, under a solicitation that went out before that date, isn't automatically covered — but the moment it comes up for renewal, it is.

The memo organizes agency obligations around three themes: keeping the AI marketplace competitive by avoiding vendor lock-in, protecting taxpayer dollars by tracking AI performance and managing risk throughout the contract's life, and requiring cross-functional teams — not just contracting officers working alone — to run AI acquisitions.

What M-25-22 actually puts in your contract

Those three themes translate into specific, negotiable contract terms, not just policy language. Expect intellectual-property and government-data-rights clauses scoped to how the agency actually intends to use your system, rather than a blanket license grab. Expect anti-lock-in provisions too: data portability, model portability, and a vendor knowledge-transfer obligation, all meant to keep an agency from being functionally stuck with one vendor once a system is embedded in its operations.

The bigger fork in the road is whether your system counts as "high-impact AI" — defined as AI whose output serves as a principal basis for decisions or actions with legal, material, binding, or significant effects on things like civil rights, civil liberties, privacy, access to government benefits, health and safety, critical infrastructure, or sensitive and classified information. If it does, the solicitation is supposed to require pre-award demonstrations and red-team testing before the agency ever signs, plus continuous post-award monitoring against quantitative success metrics once the contract is running. If it doesn't, the acquisition can move through a comparatively lighter review. Nothing in the memo makes that classification automatic or self-evident — it's a judgment call the agency and the vendor work out together during solicitation, which is exactly why it's worth raising early rather than discovering it mid-proposal.

A vendor working through the stack

Take Halvorsen Analytics, a fictional mid-size firm bidding on a contract to supply a document-triage tool that helps a federal benefits agency route incoming applications to the right caseworker queue. Halvorsen's system scores documents and assigns a routing category — useful, but it doesn't itself decide whether anyone's benefits get approved or denied, so it's a reasonable candidate for standard review rather than the high-impact track, and Halvorsen's proposal team should say so explicitly rather than waiting for the contracting officer to raise it.

Midway through drafting the proposal, Halvorsen's product team adds a customer-facing chat interface so caseworkers can ask the system natural-language questions about a given file. That single feature pulls the product into a second, separate set of obligations that has nothing to do with high-impact classification: because the interface is powered by a large language model, Halvorsen now needs to be ready to address the Unbiased AI Principles disclosure requirements covered next — regardless of whether the underlying routing decision itself ever gets treated as high-impact. The two tracks run independently. A system can be low-impact under M-25-22 and still owe LLM-specific disclosures, or the reverse.

The ideological-neutrality wrinkle for LLM vendors

A separate track applies specifically to large language models, and it doesn't come from M-25-22 at all. Executive Order 14319, "Preventing Woke AI in the Federal Government," signed July 23, 2025, conditions federal procurement of LLMs on two "Unbiased AI Principles": truth-seeking, meaning the model prioritizes historical accuracy, scientific inquiry, and objectivity, and ideological neutrality, meaning the model functions as a nonpartisan tool that doesn't encode or manipulate outputs toward contested political or social positions. The order directs agencies to write contract terms holding vendors accountable for compliance, including provisions covering certain costs if a contract is terminated over a violation. Like the rest of this stack, the requirement exists because a president signed an order, not because Congress passed a statute — the same structural pattern behind why federal AI policy keeps shifting with the administration, which means a future EO could narrow or drop these terms with the same speed they arrived.

OMB issued the implementing guidance, Memorandum M-26-04, on December 11, 2025. It doesn't name or ban any specific model or vendor. What it actually requires is disclosure: contractors selling LLMs to federal agencies have to provide information about how their models are built, trained, or modified, so the agency can evaluate Unbiased AI Principles compliance itself rather than taking a vendor's word for it. For a company like Halvorsen once its chat feature ships, that means being ready to document training methodology and any fine-tuning or guardrail choices that could bear on neutrality — a materially different ask than the performance-testing paperwork M-25-22 requires for high-impact systems, and one that applies even to an LLM feature bolted onto an otherwise low-impact product.

Still just a draft: GSA's proposed AI safeguarding clause

The piece contractors most often assume is already in force isn't. GSA released a draft contract clause, GSAR 552.239-7001, on March 6, 2026, titled "Basic Safeguarding of Artificial Intelligence Systems," aimed at its own Multiple Award Schedule program rather than federal contracts generally. The initial comment period, originally set to close March 20, was extended to April 3, 2026 after industry pushback. GSA then revised the clause substantially and reissued it on June 17, 2026 under a narrower title — "Basic Safeguarding of Data within Large Language Model Artificial Intelligence Systems (LLMs)" — with a new comment deadline of August 3, 2026.

As of this writing, GSA hasn't finalized either version. The agency has signaled it intends to fold the clause into a future Multiple Award Schedule update, referred to as Refresh 32, at which point current schedule holders would receive it automatically as a mass contract modification rather than something they'd need to opt into. Until that modification actually issues, a GSA Schedule holder isn't bound by the clause's terms, whatever a sales rep or a competitor's marketing might imply. Treat any claim that the clause is "already required" as a signal the person making it hasn't checked GSA's own posted status.

What this means if you're bidding on a federal AI contract

Check the solicitation date against September 30, 2025 before assuming M-25-22 applies — and check it again at renewal, since a contract that started outside the memo's scope can fall inside it the moment it's extended. Ask the contracting officer directly, early in the process, whether your system will be treated as high-impact, because that classification changes the testing and monitoring burden substantially and is far cheaper to plan for during solicitation than to retrofit after award. If your product includes any generative or chat-based interface, assume you'll need to answer Unbiased AI Principles disclosure questions under M-26-04 regardless of how the rest of your system is classified. And if you hold or are pursuing a GSA Schedule contract specifically, track the Refresh 32 timeline separately — it will layer on top of M-25-22's requirements, not replace them, once it actually takes effect.

One more layer worth planning for if you're a subcontractor rather than the prime: none of these obligations stop at the company that signed the contract. A prime contractor bound by M-25-22's data-portability terms or M-26-04's disclosure requirements typically has to flow those same obligations down to any subcontractor whose component actually does the AI work — a common pattern in federal contracting generally, and one that means a smaller AI vendor supplying a component to a larger systems integrator can end up contractually obligated to the same testing and disclosure terms as the prime, even without a direct relationship with the agency. None of this runs through a court or a statute the way the FTC's or EEOC's authority over AI does; it runs through the contract itself, which means reading the actual solicitation and subcontract language matters more here than almost anywhere else in federal AI compliance.

Frequently asked questions

Is there a single federal law or FAR clause that governs AI procurement?
No. There's no government-wide Federal Acquisition Regulation clause specific to AI yet. What currently governs most federal AI contracts is OMB Memorandum M-25-22, which is agency policy guidance, not a FAR clause. GSA has proposed its own clause for its Multiple Award Schedule contracts specifically, but as of this writing it remains in draft and comment status, not yet binding on any contractor.
Does OMB M-25-22 apply to a federal AI contract signed in 2024?
Not automatically. M-25-22 applies to contracts awarded under solicitations issued on or after September 30, 2025, and to option renewals or extensions exercised on or after October 1, 2025. A contract awarded under an earlier solicitation isn't retroactively covered unless it's renewed or extended past that date.
What is 'high-impact AI' under federal procurement guidance, and why does it matter?
It's AI whose output serves as a principal basis for decisions or actions with legal, material, binding, or significant effects — on civil rights, civil liberties, privacy, access to government benefits, health and safety, critical infrastructure, or sensitive and classified information. A system that qualifies faces materially higher scrutiny under M-25-22: pre-award demonstrations, red-team testing, and continuous post-award performance monitoring against quantitative metrics, instead of lighter-touch treatment.
Do the 'Unbiased AI Principles' apply to every AI system sold to the government?
No — they're specific to large language models. Executive Order 14319 and its implementing OMB guidance, M-26-04, condition federal LLM procurement on truth-seeking and ideological-neutrality criteria and require vendors to disclose how their models were built, trained, or modified. A non-generative AI system, such as a computer-vision or predictive-maintenance tool, isn't covered by this specific requirement.
Is GSA's proposed AI contract clause already binding on GSA Schedule holders?
No, not yet as of this writing. GSA first proposed the clause, GSAR 552.239-7001, in March 2026, revised and reissued it for comment in June 2026, and expects to incorporate it into the Multiple Award Schedule through a future Solicitation Refresh — at which point existing schedule holders would receive it as a mass contract modification. Current schedule holders aren't bound by its terms until that modification issues.

Sources & references

  1. Official source
  2. OMB Memorandum M-25-22 — Driving Efficient Acquisition of Artificial Intelligence in Government (Apr. 3, 2025)
  3. Executive Order 14319 — Preventing Woke AI in the Federal Government (Jul. 23, 2025)
  4. The White House — Fact Sheet: President Donald J. Trump Prevents Woke AI in the Federal Government (Jul. 23, 2025)
  5. Executive Order 14179 — Removing Barriers to American Leadership in Artificial Intelligence (Jan. 23, 2025)
  6. GSA — Proposed Government AI System Terms and Conditions (GSAR 552.239-7001 draft)
  7. Federal Register — General Services Acquisition Regulation; Acquisition of Information and Communication Technology; Notice of Listening Sessions and Request for Comments (Jun. 17, 2026)
US federal agency officials discussing AI enforcement policy
Photo: Zoshua Colah via Unsplash
There's no single federal AI law in the US. Here's what federal agencies have actually said about AI, and why existing law already covers more AI use cases than most companies assume.
Governome Editorial Team · 4 min read
Federal policy advisors reviewing a signed executive order on artificial intelligence
Photo: Dylan Gillis via Unsplash
US federal AI policy has never come from a statute. It's come from a sequence of executive orders running from 2019 to 2025 — American AI leadership, then trustworthy government use, then a comprehensive safety order, then that order's rescission and replacement. Here's the full timeline, what each order actually required, and why none of it can outlast a change in administration the way a law would.
Governome Editorial Team · 9 min read
A compliance team mapping an AI product's features to the federal agencies that regulate each one
Photo: Pawel Chu via Unsplash
Teams look for 'the AI regulator' and don't find one, then assume nothing applies. Jurisdiction follows the underlying function — hiring, lending, marketing claims, investment advice, medical use, calling — and a single product can trigger more than one agency at once.
Governome Editorial Team · 7 min read
Congressional and executive branch staff reviewing federal AI policy documents
Photo: Vitaly Gariev via Unsplash
Congress has introduced nearly 400 AI bills and passed none. The reason isn't simple gridlock — it's fragmented committee jurisdiction, a task force that recommended against one big law, and an unresolved fight over federal preemption that's now spilled into the courts.
Governome Editorial Team · 9 min read