Selling AI to federal agencies now carries specific contractual obligations — the GSA AI clause, OMB certification requirements, and NIST AI Risk Management Framework alignment. Using AI inside your own proposal shop carries a different set of risks, starting with CUI handling.
Two separate questions get tangled together constantly: what it takes to sell AI to the government, and what it takes to use AI safely in your own federal contracting work. They have different rules and different failure modes.
I spent eighteen years as a Contracting Specialist and Contracting Officer, and I now advise contractors on both sides of this. These posts cover the clause language, the certification obligations, and the practical questions — including what a CO can and cannot detect in an AI-assisted proposal.
What are the AI clauses and policies contractors must meet?
GSAR 552.239-7001 governs AI on GSA vehicles, OMB policy sets certification requirements before agencies buy AI, and the NIST AI Risk Management Framework is the reference standard evaluators increasingly expect you to map to.
- OMB's AI Use Policy: What Vendors Must Be Ready to Certify Before Selling AI to Federal Agencies — OMB memos M-25-21 and M-25-22 govern how agencies use and buy AI — high-impact classifications, minimum risk-management practices, use-case inventories, and mandatory contract terms.
- The NIST AI Risk Management Framework: A Plain-English Compliance Guide for Federal Contractors — 0 is voluntary on paper and mandatory in practice — agencies cite it in solicitations, score it in evaluations, and expect small contractors to speak its language.
- GSA Revised Its AI Clause for Every Schedule and GWAC: Four Separate Obligations Based on Your Role — GSA revised its proposed AI clause covering all GSA Schedule SINs and GWACs including OASIS+.
- The OneGov AI Agreements: What GSA's Deals With OpenAI, Anthropic, Google, and xAI Mean for Contractors — GSA has signed roughly two dozen OneGov agreements putting frontier AI tools — ChatGPT, Claude, Gemini, Grok — in agency hands at nominal pricing.
- GSA's AI Data-Safeguarding Clause Is Back: What GSAR 552.239-7001 (Version 2) Means for Schedule Holders — 239-7001 on basic safeguarding of Government data inside Large Language Model AI systems. Comments are open, a listening session is set for July 14, 2026, and registration closes July 3.
How do agencies actually buy AI?
Through existing vehicles more often than through new ones. Understanding which SIN or GWAC an agency will use to buy your AI product determines whether you are competitive at all.
- Claude for Government: How Agencies Actually Buy It — and Where Contractors Fit In — Anthropic's Claude is now available to federal agencies through a GSA OneGov agreement, FedRAMP-authorized cloud platforms, and GSA MAS resellers.
- AI Is Reshaping Federal Acquisition: What Contractors Should Actually Do About It — GSA is rewriting solicitation strategies as AI changes proposal design and protests. Here is how contractors should prepare for AI-specific terms, evaluations, and risks.
What are the risks of using AI in your own GovCon work?
CUI leakage is the serious one. Secure software attestation and SSDF/SBOM obligations follow if AI wrote code you deliver. And AI-written proposals have detectable failure patterns that hurt you in evaluation.
- Codex vs. Claude Code for GovCon Proposal Shops: An Honest Comparison for Non-Developers — gov, and draft past-performance write-ups. A practitioner's comparison of where each fits — and a decision table.
- Building a GovCon AI Stack on Claude — Without Leaking CUI or Procurement-Sensitive Data — Capture research, RFP shredding, past-performance libraries, and red-team reviews all run well on Claude — if the deployment matches the data.
- Does AI-Written Code Meet Federal Secure-Software Requirements? SSDF, CISA Attestation, and SBOMs Explained — Federal agencies can only use software whose producer attests to NIST SP 800-218 (SSDF) secure-development practices on CISA's attestation form.
- 8(a) Applications Are Effectively Frozen in 2026 and AI Tools Are Giving You Wrong Advice About GSA Certifications — 8(a) Business Development program applications have not been approved in roughly 325 days as of July 2026.
- Can You Use AI to Write Federal Proposals? What a Contracting Officer Actually Detects — Yes, you can use ChatGPT, Claude, or Gemini on a federal proposal — evaluators cannot prove AI wrote your text.
Frequently Asked Questions
What is the GSA AI clause?
GSAR 552.239-7001 is the clause GSA uses to impose AI-specific terms on Schedule and GWAC contractors, covering disclosure, use limitations, and government rights. Version 2 materially expanded its reach, so contractors who reviewed the original should reread it.
Can I use AI to write federal proposals?
There is no blanket prohibition, but two things matter: never put controlled unclassified information into a tool that is not authorized for it, and understand that generic AI-written proposal prose has recognizable patterns that read as weak to an evaluator. AI is useful for drafting and review, not for producing final narrative unedited.
Do I have to certify anything to sell AI to a federal agency?
OMB policy imposes certification and documentation obligations on agencies acquiring AI, which flow down to vendors as representations and contract terms. What exactly you must certify depends on the use case and risk category, so read the solicitation rather than assuming a general standard.
What is the NIST AI Risk Management Framework?
A voluntary framework published by the National Institute of Standards and Technology for identifying and managing risk in AI systems. It is voluntary in name, but federal solicitations increasingly reference it, which makes mapping your system to it a practical competitive requirement.
How do I use AI in GovCon work without leaking CUI?
Keep controlled unclassified information out of any tool lacking the appropriate authorization, segment your workflows so sensitive material never enters a general-purpose model, and document the boundary. The compliance question is about where the data goes, not about whether AI was involved.
If you are trying to position an AI product for federal buyers, the vehicle question usually comes first — Blackfyre handles GSA Schedule applications end to end, including the SIN strategy for software and AI offerings.