Skip to main content

Learn

AI & Government Contracts

A plain-English guide to artificial intelligence for government contractors — the new federal AI rules, how AI overlaps with the cybersecurity duties you already have, and what to watch when AI shows up in a contract.

Why AI Is Suddenly a Contracting Issue

A few years ago, artificial intelligence — software that can write, summarize, predict, or make decisions on its own — was something most contractors only read about. Today it shows up in everyday work. People use AI to draft proposals, write code, sort résumés, answer help-desk questions, and review documents. At the same time, federal agencies are buying AI products and services of their own, from chatbots to fraud-detection systems.

That creates two separate questions for a government contractor. The first is: what happens when I use AI to do my federal work? The second is: what happens when I sell AI, or AI-powered services, to the government? The answers are different, and this page walks through both. The good news is that the rules are not as strange as they sound. Most of them are extensions of duties you may already have around protecting data and being honest about how you perform a contract.

The New Rules You Should Know

The federal government's approach to AI shifted in 2025. In January 2025, the White House issued Executive Order 14179, "Removing Barriers to American Leadership in Artificial Intelligence." The order's goal is to speed up how quickly the government uses AI while keeping it responsible. An executive order is a written instruction from the President that tells federal agencies how to act.

To carry out that order, the Office of Management and Budget (OMB) — the part of the White House that sets rules for how agencies spend money — released two key memos on April 3, 2025. The first, M-25-21, tells agencies how to use AI responsibly inside their own walls. The second, M-25-22, "Driving Efficient Acquisition of Artificial Intelligence in Government," tells agencies how to buy AI. M-25-22 is the one contractors should watch most closely. Its requirements apply to contracts that come from solicitations issued on or after September 30, 2025, and to options renewed or extended on or after October 1, 2025.

M-25-22 pushes agencies to do several things that affect vendors directly. It tells them to favor AI that is built in the United States, to track how well an AI tool actually performs after it is bought, and to write contracts that protect the government's data and rights. It also tells agencies to bar vendors from using non-public government data to train commercial AI models without the government's clear permission. In short, the government wants to buy more AI — but on its own terms.

Two more developments are worth knowing. In April 2025, Executive Order 14275 directed a broad rewrite of the Federal Acquisition Regulation (FAR) — the rulebook for almost all federal buying. As the FAR is updated, new AI-related clauses are expected to appear in it over time. And on the defense side, the National Defense Authorization Act (NDAA) for Fiscal Year 2026 directs the Department of Defense to build a security framework for AI and machine-learning tools it buys, and to fold that framework into the Defense FAR Supplement (DFARS) and the Cybersecurity Maturity Model Certification (CMMC) program. People sometimes call this idea "CMMC for AI." If you work on defense contracts, expect AI security to become part of the same certification process you already deal with.

When You Use AI in Your Own Work

This is where most contractors will feel AI first — not by selling it, but by using it. And this is exactly where AI runs into the cybersecurity rules you already follow.

Federal contracts protect two main kinds of information. Federal Contract Information (FCI) is information the government gives you, or that you create for the government, that is not meant to be public. Controlled Unclassified Information (CUI) is more sensitive information that has special handling rules. If you handle either one, you have a duty to keep it safe. (Our Cybersecurity 101 page explains both in more detail.)

Here is the trap. Many popular AI tools are public services that run on someone else's computers. When you paste text into one, that text may be stored, reviewed by the company, or even used to train the AI further. If the text you paste is FCI or CUI, you may have just sent protected government information to an outside system that is not approved to hold it. That can break the same safeguarding rules that already apply to your email and your file servers. Security experts call this risk "data leakage," and the government's own AI guidance lists it as a top concern.

The National Institute of Standards and Technology (NIST) — the agency that writes the security standards most federal rules point to — published an AI Risk Management Framework to help organizations use AI safely. It is voluntary, but it is becoming the common language for AI governance. It warns about several risks that matter to contractors: AI tools can leak sensitive data, can "confabulate" (state false things with confidence), and can be tricked by attackers through a method called prompt injection. The lesson is simple. Before you put any government information into an AI tool, make sure the tool is approved to hold that kind of data, and check whether your contract or your customer requires you to disclose that you used AI at all. Agencies are increasingly adding clauses that ask vendors to identify when AI was used to perform the work.

When You Sell or Build AI for the Government

If your company offers AI products, or services that rely on AI, the new acquisition rules shape the deal in ways that may surprise you. Three issues come up again and again.

Data rights and training

Agencies are told to write contracts that clearly state who owns the data and who owns the results. Most importantly, M-25-22 directs agencies to stop vendors from using the government's non-public data to train commercial or public AI models without the government's explicit consent. If your business model depends on learning from customer data, read these terms closely — the default answer from the government is now "no."

Performance and lock-in

The government wants to avoid getting stuck with a tool that does not work or that it cannot leave. So agencies are told to measure how an AI tool actually performs after purchase, and to protect "data portability" — the ability to take their data and move to a different vendor later. Be ready to show real results and to support a clean exit.

Buy American and accountability

M-25-22 favors AI developed and produced in the United States, and it expects agencies to manage AI risk throughout the life of the contract. Government auditors are paying attention too: the Government Accountability Office (GAO) has urged agencies to collect and apply lessons learned from past AI buys. Expect more questions about where your technology comes from and how you keep it safe.

Key Takeaways

  • AI is now a contracting issue two ways: the government is buying more of it, and contractors are using it to do their work.
  • New federal rules in 2025 push agencies to adopt AI quickly but also to manage its risks — and those rules flow down to you.
  • Using a public AI tool with government data can break the same cybersecurity rules you already follow, like the ones protecting CUI and FCI.
  • If you sell or build AI for the government, expect tough terms on who owns the data, who owns the results, and whether your tool can train on government information.
  • When in doubt, treat AI like any other subcontractor: know what it does, write it down, and be ready to disclose it.

What to Do Now

You do not need to be an AI expert to stay out of trouble. A few habits go a long way. Treat any AI tool like a new subcontractor: know what it does, know where your data goes, and write down how you use it. Never paste FCI or CUI into a public AI tool unless it is approved for that information. Check each contract for clauses about AI use, disclosure, and data rights, and ask your contracting officer if anything is unclear. If you build or sell AI, get your data-rights and training terms reviewed before you sign. And if you work in defense, start watching how AI security folds into DFARS and CMMC, because it is coming.

AI can make your work faster and your proposals sharper. The contractors who benefit most will be the ones who use it openly, protect the government's information, and can explain exactly what their tools are doing. That is the same standard that has always applied to good government work — AI just raises the stakes.

When AI Makes or Shapes Decisions

Cybersecurity rules ask whether your data is protected. A second wave of rules asks whether your algorithms are accountable. When an AI system makes or heavily influences a decision about a person, three obligations are converging across federal policy and state privacy law: transparency (telling people an automated system is used), explanation (being able to say why a decision was reached), and a right to contest (a path to human review). A caution worth internalizing: human oversight is not a cure-all — nominal human review often rubber-stamps automated outputs unless the human has real information, time, and authority to override. If a contract requires human oversight of an AI system, build it so the human can actually exercise judgment.

Authoritative References

Where to Go Next

Was this page helpful?