{"resourceId":"gao-ai-acquisition-lessons","versions":[{"version":"legacy/2026-08-30/gao-ai-acquisition-lessons","resource":{"id":"gao-ai-acquisition-lessons","title":"Federal audit finds AI buyers are not systematically capturing procurement lessons","organization":"U.S. Government Accountability Office","sector":"Government procurement and acquisition","geography":"United States","publishedAt":"April 13, 2026","sourceName":"Artificial Intelligence Acquisitions: Agencies Should Collect and Apply Lessons Learned to Improve Future Procurements","sourceLabel":"GAO-26-107859","sourceUrl":"https://www.gao.gov/products/gao-26-107859","evidenceClass":"government-audit","outcomeClass":"cautionary","topics":["infrastructure","data-security","governance-procurement","operating-model"],"finding":"GAO reviewed 13 AI acquisitions and 44 contracts or agreements across Defense, Homeland Security, GSA, and Veterans Affairs. None of the four agencies had policies requiring systematic collection of lessons learned for government-wide reuse.","sledRelevance":"States, localities, districts, and public universities face the same fast-changing market with less contracting capacity. A shared acquisition memory can prevent every entity from rediscovering data-rights, testing, competition, monitoring, and exit problems independently.","evidence":"The performance audit found agencies were missing opportunities to capture practices such as data-rights terms and testing requirements or to avoid recurring mistakes. GAO made four policy recommendations, one to each agency, and all concurred. The sample was intentionally varied but nongeneralizable.","architectureImplications":"Procurement artifacts should identify model, infrastructure, data, integration, testing, monitoring, version-change, and portability responsibilities across the full AI stack rather than buying 'AI' as an undifferentiated capability.","governanceImplications":"Require an acquisition closeout and renewal record covering outcome evidence, failures, contract clauses, vendor performance, data rights, testing, cost behavior, model changes, and exit experience; publish reusable lessons through a statewide, systemwide, or consortium repository.","securityPrivacyImplications":"Contracts should preserve audit and testing rights, define handling of government and constituent data, require change notification and ongoing performance monitoring, and establish deletion, portability, incident response, and termination obligations.","caveats":"The audit covers four federal agencies and a nongeneralizable sample selected partly for maturity and impact; it evaluates acquisition practice rather than the performance of the acquired AI systems and does not establish which contract approach yields the best return."}},{"version":"enrichment/2026-09-05T02:42:45.193Z/gao-ai-acquisition-lessons","resource":{"id":"gao-ai-acquisition-lessons","title":"Federal audit finds AI buyers are not systematically capturing procurement lessons","organization":"U.S. Government Accountability Office","sector":"Government procurement and acquisition","geography":"United States","publishedAt":"April 13, 2026","publicationDate":"2026-04-13","eventDate":null,"sourceName":"Artificial Intelligence Acquisitions: Agencies Should Collect and Apply Lessons Learned to Improve Future Procurements","sourceLabel":"GAO-26-107859","sourceUrl":"https://www.gao.gov/products/gao-26-107859","evidenceClass":"government-audit","outcomeClass":"cautionary","topics":["infrastructure","data-security","governance-procurement","operating-model"],"finding":"GAO reviewed 13 AI acquisitions and 44 contracts or agreements across Defense, Homeland Security, GSA, and Veterans Affairs. None of the four agencies had policies requiring systematic collection of lessons learned for government-wide reuse.","sledRelevance":"States, localities, districts, and public universities face the same fast-changing market with less contracting capacity. A shared acquisition memory can prevent every entity from rediscovering data-rights, testing, competition, monitoring, and exit problems independently.","evidence":"The performance audit found agencies were missing opportunities to capture practices such as data-rights terms and testing requirements or to avoid recurring mistakes. GAO made four policy recommendations, one to each agency, and all concurred. The sample was intentionally varied but nongeneralizable.","architectureImplications":"Procurement artifacts should identify model, infrastructure, data, integration, testing, monitoring, version-change, and portability responsibilities across the full AI stack rather than buying 'AI' as an undifferentiated capability.","governanceImplications":"Require an acquisition closeout and renewal record covering outcome evidence, failures, contract clauses, vendor performance, data rights, testing, cost behavior, model changes, and exit experience; publish reusable lessons through a statewide, systemwide, or consortium repository.","securityPrivacyImplications":"Contracts should preserve audit and testing rights, define handling of government and constituent data, require change notification and ongoing performance monitoring, and establish deletion, portability, incident response, and termination obligations.","caveats":"The audit covers four federal agencies and a nongeneralizable sample selected partly for maturity and impact; it evaluates acquisition practice rather than the performance of the acquired AI systems and does not establish which contract approach yields the best return.","streamIds":["state-government","local-government"],"roles":{"sales":"Interpretation — Problem and stakeholders: Procurement, legal, security, records, and program leaders may repeatedly negotiate AI terms without retaining previous acquisition lessons. Discovery: Where are failed tests, data-rights clauses, supplier changes, renewal decisions, and exit experiences recorded, and does the next buyer consult them? Value hypothesis: Reusing traceable evidence could reduce repeated discovery and expose contractual gaps earlier. Potential engagement: Review a bounded set of completed purchases and build closeout-to-renewal practices within existing procurement tools. Evidence boundary: GAO's 13 acquisitions across four federal agencies support concern about institutional learning. The nongeneralizable audit does not demonstrate procurement savings, poor performance in a particular SLED contract, or a universally superior commercial model.","engineering":"Interpretation — Fit: This resource informs acquisition evidence management rather than AI-model selection. Architecture: Link the existing contract repository to system inventory, test results, data rights, supplier versions, and renewal or termination events. Prerequisites: Executed agreements and technical owners who can explain model, hosting, data, integration, and monitoring responsibilities. Constraints: Cooperative agreements and inherited vendor terms may limit rights; record gaps explicitly. Security: Restrict confidential commercial and constituent information while preserving authorized audit access. Proposed validation: Trace a sample acquisition from requirements through tested controls and exit obligations, then have another buyer retrieve reusable lessons. Confirm that portability, deletion, and change-notice claims have identifiable contractual and technical evidence.","delivery":"Interpretation — Work and dependencies: Add a lessons record to closeout and renewal covering results, failures, useful clauses, supplier conduct, cost behavior, and exit experience. Ownership: Procurement curates reusable material; program and technical owners attest operational facts; counsel approves sharing restrictions. Skills and adoption: Train buyers to distinguish contract promises from tested behavior and make repository review part of solicitation preparation. Governance checkpoints: Review evidence at award, material model changes, renewal, and termination. Proposed acceptance: Sampled records contain source documents, accountable owners, unresolved gaps, and evidence that a later procurement reused or deliberately rejected a lesson. Risks: Missing documentation, inconsistent classification, and an uncurated repository can reproduce the audit's problem despite new paperwork."},"retrievedAt":null,"enrichedAt":"2026-09-05T02:42:45.193Z","enrichmentBasis":"archived evidence"}}]}