Articles

September 30, 2026

AI in Government Contracting: Where Federal Adoption Stands in FY27

Governance is now the challenge, and that is where opportunity sits for agencies closing the gap and the contractors who support them.

Governance is now the challenge, and that is where opportunity sits for agencies closing the gap and the contractors who support them.

Key Findings

  • Federal AI use cases grew 69 percent in one year, to 3,611 across 41 agencies.
  • Agencies already use AI in proposal review and responsibility determinations, and GSA's draft GSAR clause would extend AI governance requirements to contractors.
  • GAO and OMB findings point to five recurring governance gaps: traceability, privacy, vendor concentration, cost governance, and reporting.
  • Programs that reach production build governance in from the start.
  • Contractors who close these gaps now will be ready when requirements arrive.

The Adoption Signal

Federal AI adoption is accelerating, and policy is pushing it forward.

The White House AI Action Plan, released in July 2025, calls on OMB to work with agencies to remove regulations that slow AI adoption and calls for a GSA-managed AI procurement toolbox to speed up procurement. It builds on OMB memos M-25-21 and M-25-22 from April 2025.

The results are showing up in the data. OMB's 2025 Federal Agency AI Use Case Inventory lists 3,611 AI use cases across 41 reporting agencies, up from 2,133 in the 2024 inventory, a 69 percent increase. About half are deployed or in pilot. GAO found the momentum started earlier: federal AI use more than doubled from 2023 to 2024, and generative AI use at selected agencies grew about ninefold.

Policy kept moving in 2026. In June 2026, Executive Order 14409 directed agencies to expand AI-enabled cyber defenses and build a classified process for assessing the cyber capabilities of frontier AI models. Three days later, NSPM-11 set a new framework for AI in defense and intelligence, calling out past policy for fostering "dangerous dependencies on single vendors." Agencies are also implementing OMB M-26-04, which requires new LLM solicitations to include truth-seeking and ideological neutrality principles. DOE's implementation makes compliance material to contract payment and flows the clause down to subcontractors at every tier.

Adoption remains uneven. SBA paused all AI use in 2025, and small business offices interviewed by the GAO reported no current AI use. The open question is whether government guardrails can keep up.

Where the Growth Is

How AI is adopted differs from agency to agency, and that difference matters.

HHS, NASA, VA, DOE, and DOJ lead in total use cases with 447, 425, 367, 340, and 314, respectively, per OMB's 2025 inventory. Volume reveals little about risk. VA (215) and DOJ (114) account for about 74 percent of the 445 high-impact use cases government-wide. Commerce (223) and Interior (247) report zero high-impact use cases despite high volume.

That concentration matters for contractors. Under OMB M-25-22, agencies must, when practicable, disclose in solicitations whether a planned AI use is high-impact and inform vendors of the transparency and documentation requirements they will face. Agencies with the most high-impact AI, like the VA and DOJ, are the ones where those requirements are most likely to reach contractors first.

Deployment varies. About half of reported use cases, 1,818 of 3,611, are deployed or in pilot. NASA reports 425 use cases, with only 47 deployed or in pilot. Many government AI initiatives remain in early development.

For government contractors, the opportunity lies with agencies showing high use-case volume and low deployment. In our view, these agencies are still shaping their AI strategies and vendor relationships, which creates room to influence both.

Note: The inventory excludes Department of Defense use cases and AI used in national security systems or the IC.

AI Is Already Touching Proposal Evaluation

Agencies are developing AI and applying it to contractor evaluations. Contract Acquisition Lifecycle Intelligence (CALI), an automated machine learning tool, reviews proposals against solicitation requirements in four areas: compliance, form compliance, reps and certs compliance, and requirements compliance. It matches solicitation content to proposals, helping evaluators decide faster if a contractor is compliant.

The Army requires automation in its responsibility determinations. Under AFARS 5109.103(b), Army contracting officials must use the Determination of Responsibility Assistant (DORA) bot to help determine whether a prospective contractor is responsible.

Bid protests are testing agency AI use. In Salient CRGT, Inc., B-423640.2, B-423640.4 (January 5, 2026), the protester alleged the agency relied on AI to evaluate quotations. The agency attested human evaluators conducted the assessment. Salient did not respond, so GAO dismissed the AI allegations as abandoned and denied the protest. The case reveals a visibility gap: contractors have limited insight into whether and how AI shaped proposal evaluations, making claims hard to substantiate. Expect more protesters to raise the question, and use debriefings to ask directly how AI supported evaluation.

A September 2026 Court of Federal Claims decision shows what that gap can hide. In TRAX International Corp. v. United States, an Army analyst testing an AI platform called FAST TRACK generated AI evaluations of all three competing proposals during a live source selection and shared them with procurement officials, including the contracting officer. Once the court ordered the evaluations into the record, one offeror's official evaluation contained passages nearly identical, sentence for sentence, to the AI output. The court found TRAX identified no errors traceable to AI and denied the protest, but noted it could not entirely rule out AI's use in the assessments.

For contractors, the rules are already taking shape. GSA's draft clause, GSAR 552.239-7001, would set data ownership, use, and security requirements for contractors processing government data through large language models, and it may be used across GSA's governmentwide vehicles, including the Federal Supply Schedule, GWACs, and OASIS+. Its obligations would flow down to four roles in the AI supply chain: model developers, system operators, system integrators, and service providers. The draft also requires traceable reasoning with source attribution, 30 days' notice before model changes, data export in open formats, and disclosure of every LLM used. Comments closed in August; GSA's next step is either a deviation or formal rulemaking. The rest of this paper shows how contractors can prepare before a final version takes effect.

Assume the agency evaluating your proposal already uses AI and expects its governance standards to be followed.

Adoption Without a Framework

Federal agencies are adopting AI faster than governing it. GovDash analysis of GAO and OMB findings identifies five recurring governance gaps.

On traceability, GAO found in April 2026 that DOD, DHS, GSA, and VA had no policy requiring officials to systematically collect lessons learned from AI acquisitions. OMB M-25-22 calls on agencies to share this knowledge through a GSA-managed repository and set a December 29, 2025 deadline to update AI policies. The cost is concrete: FEMA never documented its damage-assessment model's struggle to distinguish dwelling types. All four agencies agreed with GAO's recommendations, and DHS committed to updating guidance by July 2026.

On privacy, GAO found in March 2026 that OMB's government-wide AI, data, and privacy guidance fully addresses 2 of 10 privacy challenges identified by its expert panel and partially addresses the other eight.

On vendor concentration, federal policy is explicit. NSPM-11 gives defense and intelligence agencies 120 days to update procurement processes to onboard advanced models from multiple vendors and requires contract terms that ensure no company can disable or degrade the systems warfighters depend on. On the civilian side, the market was tested at the end of FY26. GSA says OneGov AI deals reached about 3.5 million federal employees. Promotional $1 offers from leading AI providers began ending or shifting to usage-based pricing.

On cost governance, the Army rejected an AI licensing proposal for its XM-30 combat vehicle fleet priced at about $300,000 per vehicle per year, over $500 million annually in licensing fees alone. Army Project Linchpin officials told GAO that government buyers often underestimate AI costs by overlooking infrastructure needed to sustain capabilities over time. GSA officials said continuous testing judges whether newer model versions justify higher prices. The OneGov transition shows the same dynamic at enterprise scale: as flat promotional pricing shifts to usage-based billing, agencies need usage and cost data to budget renewals.

On reporting, disclosure varies widely. OMB's 2025 inventory, updated April 2026, shows Commerce and Interior reporting high volumes of use cases with none flagged as high-impact, while VA and DOJ flag hundreds. The Consumer Financial Protection Bureau and Federal Maritime Commission reported no AI use. SBA published its first use-case inventory in March 2026, more than five years after the requirement took effect. DOD is entirely outside the public inventory. These differences raise questions about how consistently agencies apply reporting standards.

What documenting lessons learned looks like

GAO highlighted two programs that addressed the six AI acquisition challenges agencies cited most and recorded what they changed: DOD's Maven, run by the National Geospatial-Intelligence Agency, and GSA's USAi, a platform that gives agencies access to several generative AI models.

ChallengeDOD's MavenGSA's USAi
Access to subject matter expertsBuilt cross-functional teams of computer scientists, software engineers, test and evaluation officials, cybersecurity experts, and product managersGSA's chief AI, information, privacy, and cybersecurity officers coordinated closely to reach the right experts
Data rights and IPDeveloped more specific data ownership and data rights terms in later contract actionsWrote a USAi privacy policy and contract language defining data ownership and limiting vendor access to chat data
Acquisition speedUsed Agile approaches with weekly planning meetings and 90-day sprintsPartnered with Anthropic, OpenAI, and Google so agencies can quickly acquire chatbot capabilities and the cloud infrastructure to run them
Requirements definitionAdded increasingly defined AI requirements to follow-on contracts after early ones lacked themReused contract terms that worked in earlier AI acquisitions, such as frameworks defining service expectations
TestingAwarded small contracts to several vendors to test solutions before committing to larger acquisitionsTesting multiple capabilities through a suite of reliability tests before awarding multi-year contracts
Pricing and costStudied costs over time to build a full estimate that includes sustainmentChose usage-based pricing over licensing, with structured pricing so agencies pay less for simple prompts

Both programs appear in the same GAO report, which found that none of the four agencies reviewed require this kind of documentation to be written down and shared. The missing piece is the requirement to pass it on.

Agencies that close this gap will buy AI with fewer repeated mistakes, and contractors who document their own AI work will be easier to buy from.

What AI Done Right Requires

At MeriTalk's July 2026 Shift Happens forum, government and industry leaders examined how agencies can adopt AI quickly without losing control. The post-event brief concluded annual assessments and formal authorizations remain necessary, but periodic reviews cannot keep up with fast AI changes. Controls suitable at deployment may no longer suffice once a tool gains new features or spreads across workflows, so risk management must run continuously. Anish Patel, head of federal at Cloudflare, summed up: "You have to bound the things that you're trying to do. It has to be observable, and then there has to be some … ability to reverse it." Speed and governance work together. The real risk is speed without governance.

The foundation already exists. NIST's AI Risk Management Framework, released in January 2023 and extended with a generative AI profile in July 2024, covers governing, mapping, measuring, and managing AI risk before and after deployment.

As AI takes on more drafting and analysis, human judgment becomes more valuable. Proposal teams must define the problem, supply context, and recognize when an output cannot be trusted. Closing the five gaps requires five capabilities, regardless of which platform a GovCon firm chooses.

CapabilityClosesWhat It Means in Practice
Auditable, traceable outputsTraceability gapEvery AI-assisted draft traces to its source and reasoning, and lessons carry forward to the next pursuit
Privacy and compliance built in by designPrivacy gapPrivacy and documentation requirements are enforced structurally across every user
Platform stability and vendor accountabilityVendor concentration gapWork continues if one AI provider becomes unavailable
Transparent governance over cost and usageCost governance gapUsage and cost stay visible and controlled, with licensing terms known up front
Consistent, verifiable reportingReporting gapAI use and impact are recorded the same way every time, so disclosures hold up to audit

Any AI-enabled GovCon platform is worth measuring against this standard.

The Payoff Is Already Showing Up

Government AI is already producing measurable results in production.

The Army's Office of the Deputy Assistant Secretary (Procurement) built an agentic AI suite with contractor Koniag Government Services to automate procurement work for its contracting workforce. The effort won a 2026 ACT-IAC Innovation Impact Award, recognizing solutions that moved beyond pilot to deliver sustained, measurable value. According to KGS, the suite's three agentic tools and ten automation tools save more than $37 million and 687,000 work hours a year, and other federal customers have adopted them. That is a production result at scale.

ACT-IAC's February 2026 report, Pilots to Production, explains why many pilots never reach production. Across government technology pilots, the report found that programs stall because of gaps in governance, security, stakeholder commitment, and change management, while those that reach production build these in from the start.

Built to This Standard

The gaps agencies work to close tend to become the standards by which contractors are measured. Contractors who close these gaps in their own operations now will be ready when requirements arrive.

Meet Dash, the AI that grows your government revenue. Dash works across GovDash, the AI platform that brings a contractor's data, tools, company knowledge, and operating procedures into one shared context. In Discover, Dash finds and researches relevant opportunities. In Capture, it keeps pursuit records current. In Proposal, it builds compliance matrices, outlines, and drafts. Dash Agents handle recurring work such as pipeline reports, compliance gap reviews, and monthly status report drafts, each running on the customer's GovDash data. Users review and approve each agent before it goes live.

Privacy and compliance built in by design. GovDash is FedRAMP Moderate equivalent, audited by a C3PAO, with NIST SP 800-53 aligned controls. It supports CUI under DFARS 252.204-7012, uses US-based personnel only, and offers a self-hosted deployment option. CUI is tagged at the document level, and Dash receives only content the requesting user is authorized to view. Each agent's tool access is scoped to what the user grants. GovDash uses zero-data-retention models, and customer data is never used to train models.

Platform stability and vendor accountability. GovDash applies the same supply-chain discipline OMB M-25-22 asks of agencies. Model-agnostic routing sends each task to the best-fit model from multiple leading AI providers. New models are adopted only after improving results on production GovCon workloads. If a provider becomes unavailable, traffic fails over automatically across regions and providers. Native integrations with SharePoint, Word, and Salesforce let customers build on systems they already use. Customers can export data in the formats they need, keeping their work portable. GovDash provides model and provider disclosures on request to support compliance obligations.

Transparent governance over cost and usage. Customers consolidate AI subscriptions onto one platform, bringing AI spending under a single contract. Admins can track usage by user and agent and set limits, so AI costs stay visible as adoption grows.

Consistent, verifiable reporting. As a system of record for GovCon, GovDash records work the same way across capture, proposal, and contracts. Every agent run is logged with inputs, tool calls, outputs, and errors. Outputs are written back to the relevant record, maintaining a complete audit trail. Customers receive a changelog every two weeks.

GovDash Customers Are Scaling AI with Governance Built In

GovDash launched Agents on June 17, 2026, for capture research, proposal compliance, and contract work. In ten weeks, customers completed 21,135 agent runs. Runs per weekly active user rose from about 7.4 to 9.6, showing teams now rely on agents in daily work.

GovDash customers are closing the same five gaps inside their own operations.

Traceability. Sumaria Systems unified documents and processes across teams and divisions into one source of institutional knowledge. When a 13-page technical RFI arrived, GovDash produced a first draft in about 90 minutes. SMEs spent 24 hours reviewing, editing, verifying, and validating content for accuracy, compliance, and technical credibility. The team submitted in three days, down from up to two and a half weeks.

Privacy and compliance. Aurex, an aerospace and defense company serving DOD, the Missile Defense Agency, and NASA, evaluated four platforms and eliminated one immediately for lacking GCC High support. GovDash now runs all of Aurex's CRM and proposal workflow.

Vendor concentration. Endurion moved to GovDash after another AI platform failed to deliver promised features. OneZero Solutions chose GovDash as a long-term enterprise platform fitting its existing capture and proposal workflows. "The future felt de-risked for us," said Bob Burnett, Chief Growth Officer. GAP Solutions connected GovDash directly to its existing SharePoint document libraries.

Cost governance. GAP Solutions consolidated four platforms (AI writing, pipeline management, opportunity discovery, and past performance) into one and tripled its pipeline with the same headcount. A cybersecurity SDVOSB serving DOD and the intelligence community reduced reliance on external consultants and estimates $50,000 savings per proposal cycle. Schatz Strategy Group estimates over $75,000 in annual savings. Cape Fox FCG, using GovDash as its primary CRM across 12 federal subsidiaries, saves three to four hours each time its competitive analysis agent runs on a new opportunity.

Reporting. Aurex went from five business units with no shared system to a fully reportable multi-user organization in under six months. Weekly reporting dropped from a full-time job to about 2.5 hours. Endurion pulls pipeline metrics, segmented by prime and sub, directly from GovDash dashboards for investor reporting.

Customers are building these workflows themselves. In the first ten weeks, they created 117 agents addressing five recurring needs: daily opportunity digests scored against capability profiles, bid/no-bid screening, past-performance matching, compliance matrix extraction from Sections L and M, and research briefs automatically posted to new opportunity records.

Source: GovDash product usage data, June 17 to August 30, 2026, and GovDash's published customer case studies.

What to Do Now

Government AI adoption continues to accelerate, and contractor rules are taking shape alongside it. Contractors who win in FY27 will be those who built their AI governance tools from day one. Three steps put you ahead:

  1. Measure your AI tools against the five capabilities. Check that every output traces back to its source, that access controls are maintained, and that your work continues if a provider goes down.
  2. Prepare for GSAR 552.239-7001. Map which of your AI vendors would fall under its four supply chain roles, and confirm you can meet its traceability, change notice, and data export requirements.
  3. Ask about AI in your debriefs. Evaluators may already use AI to review proposals, so ask directly how it supported evaluation.

Meet Dash, the AI that grows your government revenue. Dash works across GovDash to find opportunities, run capture, and build proposals on your company's own data, with the traceability, access controls, and usage visibility this paper describes. Book a demo to score your workflow against the five capabilities.

Recent Articles

More field notes, playbooks, and customer stories from teams winning the work.

Stay ahead with the GovDash monthly intel brief

Your trusted, all-encompassing source for the intel that drives results.