GOVERNMENT AI IS ENTERING ITS PROCUREMENT ERA: HOW AGENCIES CAN BUY INNOVATION WITHOUT LOSING TRUST
Written By: Chet Hayes, Chief Technology Officer, Vertosoft
A while back I sat in on a meeting where a program office was sorting out an AI tool they had already started using. Good people, smart team, real mission need. But when the conversation turned to the basics, the room went quiet. Who owns the data going into this thing? Can we explain how it reaches a decision if someone challenges it? What happens in year two when the model drifts? Nobody had bad answers. They just did not have the answers yet, because the tool had arrived ahead of the questions.
I have seen that same scene play out more times than I can count over the past two years. And it tells you exactly where government AI actually is right now. The argument about whether agencies should use AI is finished. The hard part has begun, and it is not about the technology. It is about how you buy it, govern it, secure it, and keep it running without spending down the public’s trust in the process.
The demand got ahead of the plumbing
The scale here is real. Federal agencies more than doubled their use of AI between 2023 and 2024, and Congress has put roughly $1.7 billion behind AI efforts across government. That is not a pilot program. That is a buying wave.
The trouble is that the procurement machinery underneath that wave is straining. A recent Government Accountability Office review of AI acquisitions at four major agencies found something I recognized immediately from the field: officials said they were essentially figuring out how to buy AI on their own, without shared institutional memory and without standardized contract language to work from. Every program reinventing the wheel, every program making its own version of the same expensive mistake, and no good system for passing along what they learned.
That gap, between how fast agencies want to move and how ready the buying process is to support them, is the real story of government AI in 2026. It is also where the next round of adoption gets won or lost.
What changed, and what did not
People sometimes ask me what new rule they need to chase. The honest answer is that the foundation has been sitting in plain sight for over a year. The Office of Management and Budget put out two memos back in April 2025 that still set the terms today: M-25-21, on accelerating federal use of AI through innovation, governance, and public trust, and M-25-22, on driving efficient acquisition of AI in government. Those are not fresh headlines. They are the established rules of the road, and the fact that they have been in force this long is the whole point. Acquisition readiness stopped being optional a long time ago.
More recent action, including the June 2026 executive order on advancing AI innovation and security, keeps pushing in the same direction: move fast, but move responsibly. The signal to vendors and agencies alike has been consistent. Nobody is going to reward you for the cleverest model if you cannot show how it gets bought, secured, and governed.
So the question is no longer whether to adopt. It is whether you are ready to buy well. In my experience, that breaks down into three questions, and every agency I talk to is asking some version of all three.
Question one: Is this use case mission-ready?
Before a single dollar moves, an agency needs a real reason to buy. The use cases that hold up are the ones tied to mission outcomes you can actually name. Better service delivery. A more productive workforce. Stronger cybersecurity. A cleaner citizen experience. Faster compliance. The model itself is not the point. What it does for the mission is.
The GAO review put a sharp edge on why this matters. In some cases agencies started with a clear requirement and went looking for a fit. In others, a vendor walked in with a capability that answered no stated need, and the agency took it anyway. One agency wound up with a chatbot feature a vendor had simply tossed in as a bonus, attached to no actual requirement at all.
A mission-ready use case is how you avoid that drift. It forces a plain question up front: what problem are we solving, and how will we know it worked? When a supplier can speak to that in the agency’s own mission terms instead of reciting benchmark scores, they are already in a different conversation than everyone else.
Question two: Is this solution procurement-ready?
This is where a lot of commercial AI products run aground, because the public sector asks for things the private market often does not. A procurement-ready solution has clear answers to a short, unforgiving list of questions.
Who owns the data? Federal guidance now pushes agencies to write contracts so that non-public agency data and the outputs that come from it cannot be used to further train a vendor’s commercial models. “Your data will not train their model” is moving from a courtesy to a contract term.
Can you explain how it behaves? A program office has to be able to defend, in language a reasonable person understands, how the system reaches its results.
Where does it run, and against what security baseline? Cloud and FedRAMP alignment, where it applies, is the price of admission. It is not a selling point.
Can decisions be traced and overruled? Auditability and real human oversight are not nice extras. They are how an agency stands behind what the system does.
Has it been tested for the ways it can fail? Flawed training data, performance that decays over time, outputs you cannot rely on. These are exactly the failure modes that frameworks like the NIST AI Risk Management Framework exist to surface, and buyers are right to ask about them.
Who owns it over its life? Somebody has to monitor it, retrain it, and eventually retire it. If that answer is unclear at purchase, it will be a crisis later.
The GAO findings make the case better than I can. Agency officials told auditors they had a hard time getting the technical experts they needed to evaluate proposals, and a hard time even understanding what the AI was going to cost. The suppliers who win are the ones who make evaluation easier, who show up with procurement-ready documentation instead of leaving an overstretched program office to reverse-engineer it.
Question three: Is the vendor ecosystem ready to support government?
This is the question that separates a strong product from a real public-sector business. And I will be straight about it: this is hard, and even good agencies working with capable vendors get tripped up here.
Selling AI into government takes more than software. It takes partners who understand how agencies actually buy, and most of that work happens in places a commercial vendor has never had to think about.
Start with the marketplaces. Government buyers are leaning hard on the hyperscaler cloud marketplaces to speed up acquisition and draw down enterprise cloud commitments they have already made. For an AI vendor, getting listed on a marketplace is necessary, but it does not get you across the finish line on its own. What actually moves a deal is a channel framework that connects those marketplaces to traditional federal procurement, the mechanics that make multi-party private offers, custom government terms, and dealer-of-record arrangements work in practice.
Then there is the matter of getting onto the right paths to begin with. Emerging technology has to be mapped to the vehicles agencies are allowed to buy through, whether that is a GSA Schedule, the ongoing SEWP transition, or a statewide cooperative contract on the SLED side. A great product on the wrong vehicle is a product the agency cannot buy.
Pricing is its own translation problem. AI often bills on consumption or tokens, and that runs straight into a procurement culture built around predictable, fixed-price line items that an auditor can follow. Somebody has to wrap a usage-based model into a structure a contracting officer can actually award and account for. That work is unglamorous and it is essential.
The GAO review described the systemic version of all this perfectly. The reason agencies keep relearning the same lessons is that there is no shared memory, no common contract language, and no consistent way to capture what works. An ecosystem that supplies that connective tissue does for a vendor what individual agencies have struggled to do for themselves.
I am not going to pretend the path is simple, because it is not. The agencies furthest along will tell you they paid for their lessons the expensive way. The value is not in claiming the road is easy. It is in making a hard road navigable.
Trust is the thing you are actually buying
Underneath all three questions is one word, and it is the word in the title for a reason. Trust. Not the soft version people put on a slide, but the operational kind. Trust that the data is protected. Trust that the system does what it says under real conditions. Trust that an output can be explained to someone who has standing to challenge it. Trust that when the model changes, and it will, somebody is watching.
The reason trust belongs in the buying motion and not bolted on afterward is that a government AI purchase is not a one-time event. The model shifts, the data environment shifts, the mission shifts. An agency that builds oversight, monitoring, and clear accountability into the contract from the start is buying something it can stand behind for years. An agency that treats those as paperwork to clean up later is buying a problem it has not met yet.
Where this leaves us
After more than two decades working on government’s toughest technology problems, here is what I have come to believe. AI adoption in the public sector will not be slowed by a lack of interest. The interest is everywhere. It will be slowed by unclear procurement paths, by trust gaps, and by operational risk that nobody planned for.
The vendors and partners who help agencies answer the mission-ready, procurement-ready, and ecosystem-ready questions clearly are the ones who will scale. The flashiest model will not win government. The one that is easiest to buy responsibly will.