Most writing about US federal AI policy is about direction: executive orders, strategy documents, a general posture toward innovation. For a vendor, almost none of it is actionable, because an executive order binds the executive branch and a strategy binds nobody.

Procurement is the exception. It is where federal AI policy acquires teeth, and the mechanism is straightforward: the rules bind the agency, and the agency binds you through the contract. If you sell AI into federal agencies, the obligations below are already shaping what your buyers are required to ask for.

The two memoranda that matter

InstrumentIssuedAppliesWhat it does
OMB M-25-22
Driving Efficient Acquisition of Artificial Intelligence in Government
3 April 2025 Solicitations issued on or after 30 September 2025, and options renewing or extending a contract Standardises how agencies acquire AI: cross-functional procurement teams, performance validation and pre-award testing for high-impact AI, protection of data and IP rights
OMB M-26-04
Increasing Public Trust in Artificial Intelligence Through Unbiased AI Principles
December 2025 Solicitations and orders for LLMs issued after the memo's date Requires contractual terms addressing two "Unbiased AI Principles"; agencies had to update procurement policies by 11 March 2026

They sit alongside M-25-21, which governs how agencies use AI rather than how they buy it — Chief AI Officers, AI Governance Boards, agency AI strategies. That one shapes your buyer's internal approval path even though it says nothing about vendors.

What M-25-22 changes about the sale

Pre-award testing for high-impact AI

The most consequential shift. For high-impact AI, agencies are directed to validate performance and test before award rather than accepting representations and discovering the truth in production.

Practically, this means a capability claim you cannot demonstrate under someone else's test conditions is a liability rather than a differentiator. Vendors used to selling on benchmark figures should expect to be asked to reproduce them on the buyer's data, for the buyer's task.

Cross-functional evaluation

AI procurements are to be run by teams spanning the programme, contracting, legal, privacy and security functions rather than by a contracting officer alone. Expect the security and privacy questions earlier, and expect them from people who are not persuaded by a demo.

Data and intellectual property

Agencies are directed to protect government data and IP rights in AI contracts. The questions that follow are predictable, and the honest answers are worth preparing before you are asked:

  • Is government data used to train or improve your models — for this customer, or across customers?
  • Who owns outputs, fine-tunes and derived artefacts?
  • What happens to the data, and to anything derived from it, at contract end?
  • Can the agency leave without stranding its data in your system?

What M-26-04 adds for language models

M-26-04 implements Executive Order 14139, Preventing Woke AI in the Federal Government (23 July 2025), which sets out two principles the memo calls the Unbiased AI Principles:

  • Truth-seeking — the memo states that LLMs shall be truthful in responding to prompts seeking factual information or analysis, shall prioritise historical accuracy, scientific inquiry and objectivity, and shall acknowledge uncertainty where reliable information is incomplete or contradictory.
  • Ideological neutrality — LLMs shall be neutral, nonpartisan tools that do not manipulate responses in favour of ideological dogmas, and developers shall not intentionally encode partisan or ideological judgments into outputs unless prompted by or otherwise readily accessible to the end user.

What that means operationally for a vendor:

  1. New solicitations for LLMs carry contractual terms on these principles. Agencies must include them in any solicitation or order for an LLM issued after the memo's date, and may extend the same terms to non-LLM AI models where they judge it appropriate.
  2. Existing contracts get modified. Agencies should modify existing LLM contracts where practicable, and at the latest before exercising an option that extends the period of performance. Renewal is the checkpoint — if you hold a federal LLM contract, the new terms most likely arrive at your next option exercise.
  3. Agencies must be able to assess your compliance. The memo requires agencies to obtain sufficient information from the vendor to determine whether the LLM complies. Which leads to the point most likely to catch resellers out.

The supply-chain problem, named explicitly

M-26-04 acknowledges something most procurement guidance leaves implicit: in federal practice, agencies frequently reach models indirectly, through resellers, integrators and platform operators rather than from the developer. The memo notes that the information available varies with the vendor's position in the software supply chain, with more generally available closer to the original developer.

If you resell or embed someone else's model, your ability to satisfy an agency's information requirement depends on a company that is not party to your contract. That converts an upstream commercial relationship into a procurement dependency. The time to establish what your developer will and will not tell you — and what they will allow you to pass on — is before a solicitation asks.

Reporting routes

Agency policies were required to include a process for agency users of LLMs to report outputs that violate the Unbiased AI Principles. Expect that to generate inbound reports, and expect a contract to be a poor place to discover you have no triage process for them.

A sunset clause worth noting

M-26-04 states that it ceases to have force or effect two years after its issuance unless the Director of OMB provides otherwise. That is unusual and worth tracking: a requirement with an expiry date can lapse, be extended, or be replaced by something different. Build the capability, but do not assume the specific framing is permanent.

What is not in scope

The memo carves out some categories, including AI used incidentally by a contractor for administrative purposes during contract performance — AI a contractor chooses to use, where it is neither directed by nor necessary to fulfil the requirements — and work aimed at evaluating AI generally, such as developing standards or testing methodologies, rather than testing AI for a particular agency application.

These carve-outs are narrower than they may first appear, and scope questions should be settled against the memo and the solicitation rather than against a summary.

A preparation checklist

Ordered by what a solicitation is most likely to test first:

  1. Be able to demonstrate, not just claim. Assume performance will be validated pre-award on the buyer's task, not yours.
  2. Write down your data terms before you are asked. Training use, output ownership, retention, deletion at termination, and exit without lock-in.
  3. Establish what your upstream developer will disclose — and what you may pass to a government customer — if you do not build the model yourself.
  4. Prepare your evidence on the Unbiased AI Principles. What can you actually show about how your model handles factual questions, uncertainty and contested topics? Vague assurance is not evidence.
  5. Build a triage process for reported outputs, since agency users now have a route to report them.
  6. Track your option dates. For existing LLM contracts, renewal is when the new terms most likely arrive.
  7. Read the actual solicitation. Agencies implement these memoranda through their own updated policies, and implementations differ.

The strategic read

Strip away the politics of the framing and the underlying direction is one most AI vendors will meet elsewhere too: buyers increasingly want evidence rather than assurance. Pre-award testing, documentation obligations, data-handling terms and a route to report failures are all versions of the same demand — show us, do not tell us.

Vendors that can produce evidence about how their systems behave — under test, on someone else's data, on questions they did not choose — will find federal procurement easier than vendors who have relied on demos and benchmark claims. That capability is also what enterprise buyers, insurers and state regulators are converging on, so it is rarely wasted effort.

Nothing here is legal advice, and none of it substitutes for reading the memoranda and the specific solicitation in front of you. Where a bid decision turns on scope or on a contractual term, that is a question for counsel experienced in federal procurement.