{"resourceId":"gao-genai-management","versions":[{"version":"legacy/2026-08-29/gao-genai-management","resource":{"id":"gao-genai-management","title":"Generative AI use grows ninefold while policy and resource controls lag","organization":"U.S. Government Accountability Office","sector":"Government operations","geography":"United States","publishedAt":"July 29, 2025","sourceName":"Generative AI Use and Management at Federal Agencies","sourceLabel":"GAO-25-107653","sourceUrl":"https://www.gao.gov/products/gao-25-107653","evidenceClass":"government-audit","outcomeClass":"cautionary","topics":["knowledge-work","infrastructure","data-security","governance-procurement","accessibility-workforce","operating-model"],"finding":"GAO reviewed 12 agencies and found rapid growth in reported generative AI use alongside recurring difficulties with policy compliance, technical capacity, budget, and keeping appropriate-use rules current.","sledRelevance":"State and local portfolios may scale just as quickly but with fewer specialist resources, making inventories, shared policy patterns, cross-agency collaboration, and clear funding responsibilities essential early controls.","evidence":"Across 11 reviewed inventories, generative AI use cases grew from 32 in 2023 to 282 in 2024. Officials at 10 of 12 agencies said existing policy, including data privacy policy, could impede adoption, and four cited rapid technology change as a barrier to stable practice.","architectureImplications":"Link the AI inventory to owners, environments, data classes, model and vendor versions, technical dependencies, monitoring, and lifecycle state so governance can keep pace with deployment.","governanceImplications":"Use reusable framework mappings and common policy language across agencies, but assign local accountability for use-case approval, funding, outcome measures, and updates when external rules or model behavior change.","securityPrivacyImplications":"Treat privacy, misinformation, national-security-like threats to critical services, and environmental cost as portfolio risks that require defined controls and reporting rather than generic warnings.","caveats":"The review covers federal agencies and reported inventories, not SLED organizations; growth in listed use cases does not prove production adoption, effectiveness, or public value."}},{"version":"enrichment/2026-09-05T02:33:27.019Z/gao-genai-management","resource":{"id":"gao-genai-management","title":"Generative AI use grows ninefold while policy and resource controls lag","organization":"U.S. Government Accountability Office","sector":"Government operations","geography":"United States","publishedAt":"July 29, 2025","publicationDate":"2025-07-29","eventDate":null,"sourceName":"Generative AI Use and Management at Federal Agencies","sourceLabel":"GAO-25-107653","sourceUrl":"https://www.gao.gov/products/gao-25-107653","evidenceClass":"government-audit","outcomeClass":"cautionary","topics":["knowledge-work","infrastructure","data-security","governance-procurement","accessibility-workforce","operating-model"],"finding":"GAO reviewed 12 agencies and found rapid growth in reported generative AI use alongside recurring difficulties with policy compliance, technical capacity, budget, and keeping appropriate-use rules current.","sledRelevance":"State and local portfolios may scale just as quickly but with fewer specialist resources, making inventories, shared policy patterns, cross-agency collaboration, and clear funding responsibilities essential early controls.","evidence":"Across 11 reviewed inventories, generative AI use cases grew from 32 in 2023 to 282 in 2024. Officials at 10 of 12 agencies said existing policy, including data privacy policy, could impede adoption, and four cited rapid technology change as a barrier to stable practice.","architectureImplications":"Link the AI inventory to owners, environments, data classes, model and vendor versions, technical dependencies, monitoring, and lifecycle state so governance can keep pace with deployment.","governanceImplications":"Use reusable framework mappings and common policy language across agencies, but assign local accountability for use-case approval, funding, outcome measures, and updates when external rules or model behavior change.","securityPrivacyImplications":"Treat privacy, misinformation, national-security-like threats to critical services, and environmental cost as portfolio risks that require defined controls and reporting rather than generic warnings.","caveats":"The review covers federal agencies and reported inventories, not SLED organizations; growth in listed use cases does not prove production adoption, effectiveness, or public value.","streamIds":["state-government","local-government"],"roles":{"sales":"Interpretation — Customer problem: AI use-case growth can outrun policy maintenance, technical capacity, and funded controls. Stakeholders: government CIO, portfolio and program leaders, finance, privacy, workforce, and risk teams. Discovery: does the inventory distinguish experiments and operations; who funds control work; which policies are difficult to apply; and how are model changes reviewed? Value hypothesis: shared policy mappings and accountable portfolio management may reduce unmanaged gaps. Potential engagement: reconcile a portfolio sample and assess the operating resources needed for its controls. Unsupported claims: growth from 32 to 282 reported federal use cases is not proof of production adoption, effectiveness, or public value, and the reviewed agencies' barriers cannot be assumed to exist identically in SLED.","engineering":"Interpretation — Fit: strengthen portfolio-to-system traceability using existing inventory and architecture records. Architecture and integration: connect owners, environments, data classes, model/vendor versions, dependencies, monitoring, and lifecycle state to change and approval processes. Prerequisites: shared status definitions, authoritative system records, local policy interpretation, and resources to maintain the mapping. Constraints: rapidly changing features and uneven capacity can make a technically complete inventory stale. Security: link privacy, misinformation, critical-service threats, and other relevant risks to specific controls and reporting, instead of a general assurance field. Proposed validation: trace sampled listed uses into actual configurations, identify unfunded or outdated controls, and rehearse a model/policy change to show who updates the evidence and approves continued use.","delivery":"Interpretation — Work: reconcile records, map reusable policy requirements, assign funding and update responsibilities, and integrate AI changes into existing operating review. Dependencies: agency owners, finance decisions, technical specialists, and current policy interpretation. Ownership: central portfolio staff maintain common definitions; local program owners approve uses and outcomes; IT/risk teams maintain configuration and control evidence. Skills and adoption: train contributors to distinguish inventory presence from operational readiness and to escalate policy ambiguity. Governance checkpoints: intake, funding approval, deployment, and material model or rule changes. Proposed acceptance: sampled entries are current, required controls have owners and resources, and change scenarios produce documented review decisions. Risks include inventory growth masking unsupported services and reusable templates obscuring local accountability or constraints."},"retrievedAt":null,"enrichedAt":"2026-09-05T02:33:27.019Z","enrichmentBasis":"archived evidence"}}]}