Government Technology Review

Federal Procurement Guidelines for Emerging Technology Acquisitions

New federal rules reshape how agencies buy AI and emerging technology.

Contributing Editor · · 11 min read
Cover illustration for “Federal Procurement Guidelines for Emerging Technology Acquisitions”
GovTech Procurement · August 28, 2026 · 11 min read · 2,566 words

The federal government spends more than $102 billion a year on IT, which makes it the single largest technology buyer on the planet. That spending has climbed roughly 8% year over year since fiscal 2022, and the rules governing how it gets spent have undergone significant changes in recent months.

Here's the part that should catch your attention before anything else: GAO found that agencies have historically poured about 80% of their IT budgets into keeping legacy systems on life support, maintaining aging legacy systems. Every reform discussed below traces back to that one number. Washington looked at a system where four out of every five dollars went to upkeep instead of upgrade, and decided that was no longer acceptable, particularly with AI now in the picture. AI-related contract obligations hit $7.2 billion in 2026, a jump of 966% from 2024. The total potential value of federal AI contracts climbed to $91.8 billion, up 1,912%, and Defense is driving nearly all of it. Whether you're a vendor chasing that money or an agency stakeholder trying to spend it responsibly, the ground under this market has shifted, and it's still moving.

Diagram: Federal IT Spending: Maintenance vs. Modernization. Visualizes: Visualize the stark imbalance in how $102 billion in annual federal IT spending is allocated: 80% goes to maintaining legacy systems, leaving only 20% for new development and…

How the FAR overhaul is rewriting the baseline rules every vendor works under

The Federal Acquisition Regulation is the rulebook that makes sure a contracting officer in Topeka and one in Bethesda are playing by the same set of rules when they buy laptops, cloud storage, or, increasingly, large language models. An April 2025 executive order set off what's now the biggest rewrite of the FAR in its 41-year history, demanding plain language and ordering agencies to strip out requirements that don't earn their keep.

The FAR Council has already pulled more than 500 burdensome provisions, and the total is expected to top 1,000 once the process wraps. Four proposed rules covering more than 20 sections, spread across a combined 1,000-plus pages of formal rulemaking, are working their way through the Federal Register right now. Beyond just deleting clauses, the overhaul is building in regular reviews and sunset provisions so rules don't calcify again, and it's simplifying how bid protests move between agencies.

One change vendors can act on immediately: the micro-purchase threshold jumped from $10,000 to $15,000 for awards made on or after October 1, 2025. That's not a footnote, since it changes how agencies buy low-cost commercial tech without triggering the full procurement machine, and it widens the lane for smaller vendors selling point solutions.

A leaner FAR sounds like good news, and mostly it is, but it also means some of the predictable guardrails vendors have leaned on for years are gone, and nobody's handed out a new map yet. The emerging technology provisions (the ones actually built for AI and cloud) are coming in later releases, so treat what's landed so far as phase one, with the real test still ahead.

What OMB's April 2025 AI memos actually require of agencies and vendors

On April 3, 2025, OMB issued two memos, M-25-21 and M-25-22, replacing the prior administration's AI guidance under a new executive order signed that January. M-25-21 is aimed at agencies, while M-25-22 is aimed at procurement, and it's the one vendors need memorized.

M-25-22 applies to contracts awarded on solicitations issued on or after September 30, 2025, and to contract options exercised on or after October 1, 2025. It requires agencies to pull together cross-functional teams before buying AI, rather than letting a single contracting officer wing it. High-impact AI systems now need performance validation and pre-award testing, meaning a vendor has to show the system works, not just describe how it's supposed to work on a slide deck. Contracts must also bar vendors from using non-public government data to train commercially available AI models without explicit consent, and they have to spell out who owns what IP, how data moves if the government switches vendors, and how the system plays with others long-term. Agencies are also told to favor AI products built and made in the United States.

On the agency side, M-25-21 required every agency to publish an AI Strategy by September 30, 2025, covering current use cases, a maturity assessment, and a plan to get better. Most agencies (DoD and the Intelligence Community excepted) have to keep a public inventory of their AI use cases, updated at least once a year. Here's the one with teeth: any system flagged as high-impact has 365 days to either get its risks mitigated to an acceptable level or get shut down.

What's still missing is the connective tissue. OMB has committed to publishing playbooks for generative AI and AI-based biometrics, and GSA is supposed to build a repository of standard AI contract clauses and negotiated costs for the acquisition workforce to actually use, but neither exists yet in finished form. Add in July 2025's America's AI Action Plan and Executive Order 14319, which directs procured AI models to prioritize truthfulness and ideological neutrality, and you've got a policy stack that's clear on intent but still translating into the actual words that show up in a solicitation. That translation work is happening now, agency by agency, and 2026 is when it's supposed to solidify into something repeatable.

How the "high-impact AI" classification changes what vendors must prove before award

Getting labeled "high-impact" isn't a paperwork inconvenience; it's the line that separates a routine procurement from one where you have to prove your system behaves the way you say it does, before anyone signs anything. Systems tagged "safety-impacting" or "rights-impacting" in an agency's use-case inventory are the leading candidates, though the exact boundary is still being drawn agency by agency, which is its own small headache.

Once a system lands in that bucket, pre-award testing and performance validation become mandatory. You don't get to assert your model's accuracy; you have to demonstrate it, under conditions the agency defines, before the contract is awarded. Remember that 365-day clock from M-25-21? Agencies with existing high-impact systems that can't be brought into compliance in time will need replacements, likely on a compressed schedule. That's either a scramble or an opportunity, depending on which side of the procurement table you're sitting on.

Data rights are quietly becoming a source selection factor. Vendors whose model architecture is proprietary and resistant to interoperability are going to find themselves in longer, harder negotiations, while vendors who design for data portability and government data sovereignty from day one are better positioned in negotiations. There's no governmentwide standard yet for what counts as acceptable evidence; that's exactly what GSA's forthcoming clause and cost repository is supposed to settle, and it's worth watching closely once it drops. Vendors who start documenting their testing methods, model governance, and data handling controls now, before the RFPs even show up, are the ones who'll have answers ready when agencies start asking the questions M-25-22 tells them to ask.

FedRAMP 20x and what the authorization overhaul means for cloud vendors entering the federal market

FedRAMP has long been the front door, and for a lot of cloud vendors, the front door was bolted shut, or at least took a year or two to open. GSA announced FedRAMP 20x on March 24, 2025, aiming to automate compliance checks, let cloud providers lean on commercial security frameworks they already have, and cut down on redundant agency and third-party review.

The numbers back up the claim. By late FY2025, GSA reported average authorization time had fallen to roughly five weeks, a substantial reduction from prior timelines. In July 2025 alone, FedRAMP logged 114 authorizations for the fiscal year, a record high for FY2025, and cleared four new cloud services through the 20x Phase One pilot.

The rollout is happening in stages. Phase 1 focused on pilot authorizations; 26 cloud service providers submitted packages, and the first authorizations came through in July. Phase 2, active now, is expanding into Moderate-impact systems, with roughly 10 pilot authorizations targeted. A government-wide launch is planned for later in 2026, and providers already authorized under the traditional Rev. 5 process are expected to have a transition window, so nobody's being forced to switch overnight.

AI-enabled cloud offerings are getting priority treatment, with some targeted for authorization within two months, which tells you the AI procurement reforms and the cloud security reforms aren't running on parallel tracks; they're converging. For smaller vendors and startups, this is the real headline: a shift from paperwork-heavy assessments toward automation-driven compliance means the cost and time barrier that used to lock out anyone without a compliance department the size of a law firm is finally coming down. One caveat worth repeating: Moderate-impact expansion is still a pilot, so if you're selling into agencies handling Moderate or High sensitivity data, don't assume the five-week timeline applies to you yet.

CMMC 2.0 and the cybersecurity compliance floor now baked into DoD contracts

None of this AI and cloud momentum matters to a DoD contract if the vendor can't clear the cybersecurity bar, and that bar just got a formal shape. CMMC is a DoD cybersecurity requirement that applies across vendor contracts, meaning an AI vendor pitching DoD is subject to it just as much as a hardware supplier is.

The final rule amended the DFARS, and its requirements began showing up in DoD solicitations and contracts on a phased schedule. The old five-tier structure got trimmed down to three levels. lower levels allow self-assessment for basic cyber hygiene, intermediate levels require more rigorous assessment depending on the contract, and the highest level requires a government assessment for the most sensitive work.

Implementation is staged, and the dates matter for planning. Early phases cover select new contracts with self-assessments, while later phases require more rigorous third-party and government assessments for higher-sensitivity contracts.

Here's the part that should make legal counsel sit up: inaccurate self-attestation carries serious legal and contractual consequences that extend well beyond the compliance team. With DoD's total potential AI contract value hitting $90.7 billion in 2026, up 1,605% from 2022, CMMC compliance stops being a compliance department's problem and becomes a revenue problem, since no certification means no access to the fastest-growing part of the federal AI market.

How these regulatory layers interact in practice and where vendors are most likely to be caught unprepared

Diagram: Four Compliance Clocks Running at Different Speeds. Visualizes: Show the timeline misalignment across four concurrent regulatory tracks that a DoD AI-cloud vendor must navigate simultaneously in 2025–2026.

Picture a vendor selling an AI-enabled cloud platform to a DoD component sometime in 2026. That vendor has to satisfy the revised FAR, the AI procurement requirements under M-25-22, a FedRAMP authorization caught mid-transition between Rev. 5 and 20x, and CMMC Level 2 or 3, all running on different clocks with different evidence requirements. None of these frameworks were built with the others in mind, at least not yet, and that's where vendors get tripped up.

Timeline mismatches are the trap nobody talks about enough. FedRAMP 20x Moderate authorizations are still in pilot, CMMC Phase 2's C3PAO assessments don't kick in until November 2026, and meanwhile, M-25-22's solicitation requirements are already live, today, right now. A vendor can be fully compliant on one track and disqualified on another, simply because the tracks don't run at the same speed.

The IP and data rights language in M-25-22 also collides directly with FedRAMP's data boundary rules, which means this isn't a problem you solve with a procurement specialist alone; you need legal and technical teams talking to each other, not working in separate silos. Add in the fact that civilian agencies are writing AI solicitations under M-25-22 without a standard clause library to draw from yet, and you get real inconsistency from agency to agency. A vendor bidding across five agencies should expect to negotiate five sets of terms, not sign one set of boilerplate five times.

There's also a quieter risk buried in CMMC's self-assessment window: the same period that makes compliance easier is the period of highest False Claims Act exposure, because self-attestation without rigor is exactly the kind of thing that draws scrutiny later. The FAR overhaul's removal of 500-plus provisions doesn't actually make life simpler; it redistributes complexity, because now vendors have to track what got deleted and what agency-specific supplement quietly filled the gap. Vendors who start building compliance infrastructure now (documented AI testing regimes, active participation in FedRAMP 20x pilots, SPRS-recorded CMMC self-assessments) are the ones who'll be ready when the solicitation wave actually arrives.

What agency stakeholders and contracting officers need to do differently under the new framework

Contracting officers don't get to run AI procurements the way they ran a laptop refresh contract five years ago. Cross-functional AI acquisition teams are a requirement under M-25-22 now, not a nice-to-have, and that changes the shape of the acquisition process from day one.

The September 30, 2025 AI Strategy deadline has come and gone. Agencies that hit it now face the harder job of turning strategy documents into actual solicitation language people can bid against, while agencies that missed it are working under compressed timelines as mission pressure keeps building, which is not a comfortable place to be.

High-impact AI inventory requirements put contracting officers in a spot they haven't really occupied before: coordinating directly with Chief AI Officers and AI Governance Boards to classify systems correctly. Get the classification wrong, and you're not just risking mission failure; you're triggering that 365-day remediation clock for a system that maybe didn't need it, or missing it for one that did.

FedRAMP 20x is genuinely good news for agency IT leadership. The authorization backlog that used to keep good cloud vendors sitting in a queue is shrinking fast, and procurement teams that update their acquisition strategies to reflect the new timelines can move on cloud modernization projects that used to take years. The FAR's streamlined bid protest process should also cut down on some of the litigation drag that's slowed big tech acquisitions in the past, though agencies shouldn't assume simpler rules mean fewer challenges on high-value AI awards; if anything, bigger dollar amounts tend to invite more scrutiny, not less. Until GSA's AI acquisition guide and clause repository actually ship, agencies are writing their own playbooks in real time, and the intended stopgap (sharing language with peer agencies through the M-25-22 repository mechanism) is the best tool available right now.

How vendors should structure their federal

Structuring a federal go-to-market plan in this environment means accepting that no single compliance milestone gets you across the finish line anymore. A vendor needs a FAR-aware contracts function that tracks which clauses got cut and which agency supplements replaced them, an AI documentation practice that treats testing methodology and model governance as sales collateral rather than an afterthought, a FedRAMP strategy that accounts for both the Rev. 5 legacy path and the 20x pilot track, and, for anyone touching DoD, a CMMC roadmap that starts now rather than in 2027 when Level 3 assessments become mandatory.

None of these tracks move at the same pace, and that's precisely the point worth sitting with. The vendors who treat this as four separate checkboxes to knock out in sequence will keep getting surprised by timeline mismatches; the ones who build one integrated compliance function (legal, technical, and contracts working off the same calendar) are the ones positioned to move fast when the AI solicitation wave that everyone's been bracing for actually crests in 2026. The rules changed, and the vendors who win this market are the ones who stopped waiting for them to settle down and started building for the mess as it actually is.

Sources

  1. files.gao.gov

More in GovTech Procurement