{"resourceId":"fas-state-ai-contract-provisions-analysis-2026","versions":[{"version":"external-00b9daec92508b706ff611e9b585b52e453f7e71623d602d8c254b0e5ad511eb","resource":{"id":"fas-state-ai-contract-provisions-analysis-2026","title":"Contract analysis raises accountability questions, with methodological and editorial limits","organization":"Federation of American Scientists; Jae Yeon Kim and Aniket Kesari","sector":"State government","geography":"United States; contract analysis covers California, Utah and Florida","publishedAt":"June 8, 2026","publicationDate":"2026-06-08","eventDate":null,"sourceName":"Federation of American Scientists","sourceLabel":"Policy memo reporting ongoing independent research","sourceUrl":"https://fas.org/publication/how-governments-purchase-ai-fair/","evidenceClass":"independent-research","outcomeClass":"cautionary","topics":["governance-procurement","data-security","operating-model"],"finding":"The authors report limited AI-specific accountability language in sampled provisions and advocate risk-based purchasing and updated vendor disclosures. Recommendations are not evaluated interventions.","sledRelevance":"Historical purchasing scrutiny newly added to qualify shared-service expansion and oversight preparation.","evidence":"The methods paragraph identifies 3,771 provisions across 215 contracts in three states and reports 77% as boilerplate. This is a provision-level statistic, not a percentage of unsafe systems or ineffective contracts.","architectureImplications":"Interpretation: require practical access to logs, configuration and export paths needed for independent testing.","governanceImplications":"Interpretation: connect contract obligations to named reviewers and renewal evidence.","securityPrivacyImplications":"Interpretation: evaluate whether promised data and incident controls can be exercised operationally.","caveats":"Ongoing research without a reproducible coding protocol or inter-rater reliability on the page. Broader sample wording is inconsistent; unrelated historical and cost statements also contain apparent errors and were excluded. No causal test of contract reform.","streamIds":["state-government"],"roles":{"sales":"Interpretation: The customer problem is uncertainty about whether an AI purchase preserves enough evidence to judge ongoing performance. Engage procurement, counsel, security and the agency service owner. Ask what happens when the supplier changes the model, which records can be inspected, and what makes renewal defensible. A bounded contract-to-test review could examine one planned purchase and identify missing evidence access. The value hypothesis is a clearer continuation decision, not guaranteed risk reduction or legal compliance. The reported contract sample supports discovery questions, but cannot rank an individual customer's suppliers. Avoid presenting clause prevalence as proof of actual system harm or a quantified commercial opportunity.","engineering":"Interpretation: Translate a proposed assurance obligation into a test that an engineer can run with the access the contract actually permits. Prerequisites include a scoped system boundary, representative test cases and permission to inspect relevant operational evidence. Demonstrate model-version traceability, data deletion behavior, configuration export and rollback where applicable. Compare results with agreed baseline requirements rather than treating a vendor fact sheet as validation. The memo does not establish a preferred cloud or on-premises design, and its contract analysis cannot verify technical enforcement. Include a test for embedded AI added to an existing product, since the service boundary may differ from the original purchase.","delivery":"Interpretation: Pair the contracting officer with an accountable service owner and a technical evaluator before award. Build an obligation register that links each accepted promise to evidence, a review date and an escalation owner. Dependencies include supplier cooperation, counsel review and funded testing capacity. Train operational staff to recognize changes that invalidate prior acceptance. Proposed acceptance criteria: every critical obligation has a runnable verification method or an explicitly accepted limitation, and the first renewal review includes actual performance evidence. These are proposed controls, not results measured in the memo. Risks include boilerplate that cannot be enforced, inaccessible vendor records and treating completed paperwork as successful delivery."},"retrievedAt":"2026-09-11T03:00:56Z","enrichedAt":"2026-09-11T03:02:34Z","enrichmentBasis":"retrieved source","accessibilityWorkforceImplications":"Interpretation: include user testing and evaluator skills in acceptance scope; the memo does not measure accessibility or workload.","procurementImplications":"Interpretation: have procurement counsel assess feasible evidence and change provisions; memo proposals are not jurisdiction-specific legal advice.","operatingModelImplications":"Interpretation: budget time for post-award testing, not merely document collection.","updateExplanation":"URL absent from full archive and targeted search. June analysis newly inspected for provision-level limits and procurement implications; no September findings asserted.","sourceVerification":{"openedUrl":"https://fas.org/publication/how-governments-purchase-ai-fair/","referenceExcerpt":"classifying 3,771 individual contract provisions across 215 contracts.","promptVersion":"sled-research-v3.1","model":null,"basis":"agent-reported inspection"}}}]}