Disclosure for thee but not for me

Gettyimages.com/ MR.Cole_Photographer

Find opportunities — and win them.

Agencies are not disclosing GenAI in procurement and that spells potential trouble, writes attorney David. P.J. Timm.

Federal agencies using generative artificial intelligence to evaluate contractor bids are required to study, manage, and disclose their use of GenAI tools.

However, watchdog reports show agencies are shirking these obligations and incentivizing “Shadow AI” use by government employees. In 2025, the Office of Management and Budget issued memoranda, M-25-21 and M-25-22, requiring agencies to identify their GenAI use cases and determine whether they were “high-impact.”

High-impact means an AI output serving “as a principal basis for decisions or actions that have a legal, material, binding, or significant effects on rights or safety.” If a use case is high impact, the memos require civilian agencies to say so in the solicitation and implement minimum risk management practices.[1] The memos also require agencies to publish an AI use case inventory annually. Civilian agencies aren’t complying with these requirements.

There is no doubt that the evaluation of bids with GenAI tools fits the definition of a “high-impact AI” use case. Evaluators may rely in whole or in part on a GenAI tool to disqualify a contractor’s bid for non-compliance with solicitation requirements. GenAI tools might also help rank proposals, assign strengths, weaknesses, or risks.

Any of these would be high-impact use cases because they directly affect whether a contractor is awarded a contract, i.e., they form the principal basis for decisions that have legal, material, binding, and significant effects on contractors and government spending.

Despite this, more than a year after the memos were created, only a handful of solicitations warn that GenAI tools might be used to evaluate bids and these are all DoD procurements, which are exempted from OMB’s requirements.[2]

In other words, defense agencies that are not required to report GenAI use are occasionally reporting such use anyway, whereas civilian agencies that are required to report GenAI use are not. In 2026, civilian agencies published hundreds of AI use cases, more than 50 of which involved procurement processes or administrative functions and GenAI, agentic AI, or natural language processing.[3] Only one of these was labeled high-impact.[4]

Downgrading procurement use cases is a self-serving tactic that allows agencies to trade transparency for administrative convenience. For instance, the VA boasts that its AI procurement tools enable “automated compliance checks” and “automated drafting and analysis of procurement documents.” But because the VA did not label this as a “high-impact” use case, the VA has not conducted an independent review, had no ongoing monitoring process in place, and did not provide “training for operators of the AI.”

This general approach was criticized in a June 2026 VA inspector general report, which said the agency failed to designate “VA GPT" as a high-impact use case because VA leaders inaccurately “equated use of AI chat tools to using a search engine.”[5]

The IG report said “this analogy is flawed.” Whether intentionally or not, the VA mislabeled its procurement GenAI use cases allowing it to avoid the OMB requirements for oversight.

This problem is not limited to the VA. In May 2026, the Department of Agriculture’s IG released a scathing report explaining that the agency failed to implement adequate governance controls for approved AI use cases and warned that there was an increased risk of shadow AI use due to poor inventory controls.[6] In early July 2026, HHS announced its own IG investigation into its AI governance was underway.[7] Others are bound to follow.

It is one thing to incorrectly label GenAI use cases to avoid administrative hassle. In those cases, at least the use case is publicly disclosed, and the tool itself is running on vetted government systems.

But in other cases, as the USDA report suggests, lax reporting requirements “contribute to instances of Shadow AI” meaning the agency is vulnerable to data leakage through unsanctioned GenAI tools. An environment like this does not inspire confidence that contractor proprietary data will be protected.

The government’s lack of transparency about its own use of GenAI coincides with a push for new, costly, and burdensome disclosure rules for contractors, while agencies are concurrently demanding AI solutions and displaying preference for contractors using GenAI. The government’s mismanagement of GenAI in procurement is undermining trust and is likely to lead to a flurry of unnecessary bid protests.

As agencies shirk their own GenAI-related duties, they are aggressively seeking to impose rules on contractors while simultaneously demanding more AI-related solutions. In June 2026, GSA released a second version of its proposed AI clause, GSAR 552.239-7001, which would create costly and complicated disclosure requirements for contractors using GenAI to perform contracts.[8] The proposed language does not include reciprocal rules for GSA to disclose its own use of GenAI tools.

It is not as if the government is uninterested in GenAI. In fact, civilian agencies are aggressively seeking GenAI solutions from contractors. In June, the principal deputy assistant secretary for the VA’s Office of Information and Technology told contractors at an industry-day event that “AI is becoming an expectation for use of the VA.”[9]

The National Oceanic and Atmospheric Administration recently defended a bid protest challenging award to a contractor whose offer included a 15% price premium.[10] The awardee said it would use Gemini AI to keep documents up to date. The agency said “AI and cloud management are major. . . mission goals” that justified “paying a price premium.”

The protester complained that the evaluation criteria did not mention AI at all. Nevertheless, GAO found a “nexus between the evaluation criteria and NOAA’s consideration of [the awardee’s] intended use of an AI tool.” Contractors competing for awards are thus incentivized to implement GenAI tools into their proposed scopes of work whether they were inclined to do so or not. 

On the evaluation side, the Federal Acquisition Regulation requires independent and documented judgment from human evaluators.[11] In early 2026, a protester alleged, but later abandoned, an argument that an agency “improperly relied upon [GenAI], rather than agency evaluators, to conduct the evaluation.”[12]

If evaluators use Shadow AI, there would be no records for the contractor to make this argument. In the January protest, the AI evaluation argument was discarded due to lack of evidence. More bid protests are likely to come as the ungoverned and undisclosed use of GenAI tools results in errors throughout the procurement process, but if agencies do not comply with the OMB rules it will complicate how contractors prove their allegations.

While no bid protest has gone to the merits on this issue, agencies are playing with fire every time evaluators use GenAI procurement tools without adequate controls and oversight. The government should follow its own rules and correctly label GenAI procurement tools as “high-impact.” Agencies should test their GenAI use cases, train their employees, and manage negative potential impacts. Contractors should demand the bare minimum from the Government.

------

David P.J. Timm is a partner in Burr & Forman’s Washington, D.C. office where he litigates bid protests and claims for contractors. David is the Chair of the Federal Bar Association’s Bid Protest Committee and the Co-Chair of Burr’s AI Committee.

 

[1] Likewise, M-25-22, Section 4(d) says that “When evaluating proposals agencies must, to the greatest extent practicable, test proposed solutions to understand capabilities and limitations of any offered AI system or service.”

[2] OMB M-25-21 and -22 apply to all agencies “except for the Department of Defense. . .”

[3] Based on an independent review of publicly available civilian AI use case inventories. Some notable “not high-impact” procurement related use cases include the Department of Agriculture’s “Procuresight,” the Department of Energy’s “AI for Vendor Compliance,” the General Services Administration’s “Leveraging retrieval augmented generation AI to power outcome-based contracting,” The Department of Health and Human Service’s “Assisting reviews and co-drafting technical evaluation documents,” the Department of Justice’s “Acquisition Support Tool,” the Department of the Treasury’s “AI-assisted POC,” and the Department of Veterans Affairs “VA GPT.”

[4] Department of Veterans Affairs Use Case ID No. VA-25-3573 (claims adjudication and financial decision-making).

[5] Review of Generative Artificial Intelligence Chat Tools for Clinical Use, Report No. 2600182-140, June 11, 2026.

[6] Cybersecurity of Artificial Intelligence Technology at USDA, Report No. 50801-0018-12, May 12, 2026.

[10] TechGlobal, Inc., B-424287, B-424287.2 (June 1, 2026).

[11] FAR 15.308.

[12] Salient CRGT, Inc., B-423640.2, B-423640.4 (January 5, 2026).

NEXT STORY: More satellites will not save us