Logo
BlogsArtificial IntelligenceHow to Choose an AI Vendor for Government: A Security and Compliance Checklist

How to Choose an AI Vendor for Government: A Security and Compliance Checklist

An AI vendor for government is a supplier whose system can clear security authorization, whose contract protects agency data and exit rights, and whose delivery record can be independently verified. Evaluate vendors on evidence weight rather than demo quality. The strongest evidence is a contactable production reference in a comparable regulated environment.

Key Takeaways

  • Rank claims by how hard they are to fake. A demo costs a vendor nothing. A public authorization listing and a contactable production reference cost years. Weight them accordingly.
  • Federal policy now agrees. OMB Memorandum M-25-22 directs agencies to tie performance evaluation to mission outcomes rather than vendor-reported metrics, and to run AI procurement through cross-functional acquisition teams.
  • Procurement failure is documented, not theoretical. The GAO’s April 2026 audit of federal AI acquisition (GAO-26-107859) identified six recurring problem areas: requirements definition, pricing opacity, IP rights, testing, timelines, and access to subject-matter expertise.
  • Check the certification scope, not the badge. A SOC 2 or ISO 27001 report covers a defined scope. A vendor can hold a valid certification that excludes the AI product you are buying. Always read the scope section.
  • State rules are moving independently. California Executive Order N-5-26, signed March 30, 2026, directs state agencies to develop AI vendor certification requirements for state contracting.

What makes an AI vendor suitable for government work?

An AI vendor is suitable for government work when three things are simultaneously true: the system can operate inside an authorized security boundary, the contract preserves the agency’s rights to its data and its ability to leave, and the vendor can point to comparable delivered work that someone else will confirm.

Two terms matter for the discussion that follows. Vendor lock-in is a dependency that makes switching suppliers impractical, usually because data, models, or outputs cannot be extracted in usable form. Pre-award testing is evaluating a system’s actual performance on your data and conditions before a contract is signed, rather than accepting the vendor’s own benchmark results.

This is a narrower question than which AI capabilities an agency should deploy, which we cover separately in our overview of AI solutions for public sector organizations. Here the subject is the supplier, not the capability.

Why do government AI procurements go wrong?

They go wrong because procurement capacity has not kept pace with technical complexity, so agencies evaluate what is easy to see rather than what determines success. Demos are easy to see. Data rights, exit paths, and real-world accuracy are not.

The federal record is now documented. The Government Accountability Office published its audit of AI acquisition across federal agencies in April 2026 (GAO-26-107859) and identified six recurring challenge categories: requirements definition, pricing opacity, intellectual property rights, testing, timelines, and access to subject-matter expertise. Note that five of the six are procurement problems rather than technology problems.

Volume makes this urgent at state and local level. The Electronic Privacy Information Center documented roughly 600 state and local government AI contracts in 2023. A 2026 analysis published by the Federation of American Scientists identified more than 1,000 in California, Utah, and Florida alone. A significant share arrive not as standalone AI procurements but as renewals of broader technology contracts that quietly now embed AI features.

That last point deserves attention. Your agency may already be buying AI inside a contract nobody classified as an AI contract.

How should you weigh what an AI vendor tells you?

Weigh every claim by how difficult it would be to fabricate. We call this the Evidence Ladder. The rule is simple: never let a strong Tier 1 claim compensate for a missing Tier 4 or Tier 5 one.

Tier Type of Claim Cost to the Vendor of Producing It What to Ask for Instead or Alongside
Tier 1 (Weakest) Demos, capability decks, marketing claims, benchmark scores the vendor selected Effectively zero; the vendor controls every variable A test on your data, in your conditions, with your success criteria
Tier 2 Self-attestations, security questionnaire responses, written policies Low; nobody independent has checked them The underlying artifact the attestation refers to
Tier 3 Third-party certifications such as SOC 2 Type II or ISO 27001 Moderate; audited, but only within a scope the vendor defines The scope section of the report, confirming the AI product is inside it
Tier 4 Public authorization listings such as FedRAMP or GovRAMP marketplace entries High; independently verifiable and publicly visible The listing itself, plus the authorization level and boundary
Tier 5 (Strongest) Contactable production references in comparable regulated environments Highest; requires having actually delivered Direct contact with the reference, and questions about what went wrong

Tier 3 is where most agencies get caught. A SOC 2 Type II report covers a defined scope of systems and services. A vendor can hold a completely valid report whose scope covers their billing platform and excludes the AI product you are evaluating. The claim is true and irrelevant at the same time. Read the scope section, not the badge on the website.

Federal policy has arrived at the same conclusion. M-25-22 directs agencies to tie performance evaluation to mission outcomes rather than vendor-reported metrics, which is the Evidence Ladder expressed as procurement rule.

What must a government AI contract include?

At minimum: data-use restrictions, government rights to outputs, protection against lock-in, disclosure obligations, and a defined exit path. OMB Memorandum M-25-22, issued April 3, 2025, sets these expectations for federal civilian agencies and is a defensible template for state and local buyers who have no equivalent policy.

Contract Area What M-25-22 Directs What to Write Into Your Contract
Data Use Restrictions preventing vendors from training public AI models on non-public government data An explicit no-training clause covering all agency data, with no exception for "product improvement"
IP and Data Rights Protection of intellectual property and government data ownership Government rights to outputs, embeddings, and fine-tuning artifacts, named individually
Vendor Lock-In Lock-in protections considered across the acquisition lifecycle A written exit path specifying data format, timeline, and cost of extraction
Performance Performance monitoring tied to mission outcomes rather than vendor-reported metrics Agreed metrics, an agreed measurement method, and a remedy if the system misses them
Disclosure AI disclosure provisions and vendor transparency obligations Notification when models, versions, or training approaches change materially
Risk Management Pre-award testing and minimum risk-management practices for high-impact AI Pre-award testing on your data as a condition of award, not a post-award activity

Two scope notes on M-25-22. It applies to AI acquired under solicitations issued on or after September 30, 2025, and it does not apply to the Department of Defense or National Security Systems. It also adds a domestic-preference provision directing agencies to prioritize US-developed AI solutions.

Contract terms only work if someone owns them after signature. Assigning that ownership, and the review cadence behind it, is a governance question rather than a procurement one, which is why agencies increasingly bring AI governance consulting into the process before the solicitation goes out rather than after the award.

What should you ask an AI vendor before award?

Ask questions that require evidence rather than assurance. Each item below should produce a document, a listing, or a contact, not a paragraph of reassurance.

  • Name a comparable production deployment in a regulated environment and give us the reference contact.
  • Show us the scope section of your SOC 2 or ISO report and confirm this product sits inside it.
  • What is your authorization status, at what level, and which environment holds the boundary?
  • Will you run a pre-award test on our data, under our conditions, against criteria we set?
  • If we terminate in year two, what exactly do we get back, in what format, and how long does it take?
  • Who on your team has moved a system through a government security review, and will they be on ours?
  • What happens to accuracy when you change model versions, and how will we be told?

A vendor who answers all seven without deflecting has almost certainly done government work before. That, by itself, is diagnostic.

Do state and local buyers face different requirements?

Yes. State and local agencies are not bound by OMB memoranda, and several states are building their own vendor requirements instead. The direction of travel is toward certification and disclosure rather than deregulation.

California signed Executive Order N-5-26 on March 30, 2026, directing the Department of General Services and the Department of Technology to recommend new vendor certifications for state contracting within 120 days. Under the framework, vendors would attest to and explain their policies on illegal content, harmful model bias, and civil rights and civil liberties protections.

On the security side, GovRAMP, rebranded from StateRAMP in February 2025, serves as the state, local, tribal, and education equivalent of FedRAMP, built on the same NIST SP 800-53 Rev. 5 control set. A joint report from the National Association of State Procurement Officials and NASCIO has recommended that states prioritize bias mitigation, transparency, and accountability in AI procurement.

One structural recommendation worth adopting regardless of jurisdiction: shorter contract terms with built-in revision points after a defined evaluation period. AI systems change faster than a five-year contract cycle, and a shorter term converts a lock-in risk into a scheduled decision. Pair that with AI adoption training for the staff who will operate the system, because an unused deployment fails its next review regardless of how good the contract was.

How JBS helps agencies evaluate and de-risk AI procurement

JBS (Jaffer Business Systems) works with organizations before the solicitation, establishing what the agency actually needs and what evidence a credible supplier should be able to produce. The delivery record behind that is 100+ AI implementations across 46+ enterprise customers in 12+ countries, supported by a team including 30 AI specialists.

The readiness assessment covers data, systems, workflows, security, and governance ownership, which is what turns a vague requirement into a specification a vendor can be measured against. Requirements definition was the first of the six failure categories the GAO identified in federal AI acquisition, and it is the cheapest one to fix.

JBS also meets its own evidence bar. Doculytics, the company’s document-intelligence platform, extracts structured data from forms, applications, and records with 92%+ accuracy. ACE handles high-volume customer-facing engagement. Deployments align to US data-privacy and security standards including CCPA/CPRA, HIPAA, SOC 2, and NIST frameworks, with role-based access, human review, and traceability built into the workflow rather than added at review.

Agencies preparing a solicitation, or reviewing bids already received, can use JBS’s AI governance consulting to define requirements, set pre-award testing criteria, and pressure-test contract terms before award. For the broader capability picture across sectors, see our enterprise AI solutions guide.

Frequently asked questions

What should you look for in an AI vendor for government?

Look for a system that can clear security authorization, contract terms that protect data rights and provide an exit path, and a contactable production reference in a comparable regulated environment. Weight independently verifiable evidence such as authorization listings above demos and self-attestations.

What is OMB M-25-22?

OMB Memorandum M-25-22, issued April 3, 2025, sets federal AI acquisition policy. It applies to AI acquired under solicitations issued on or after September 30, 2025, excluding the Department of Defense and National Security Systems, and covers data use, IP rights, vendor lock-in, performance monitoring, and disclosure.

Is SOC 2 certification enough for a government AI vendor?

No. A SOC 2 report covers a defined scope, and a vendor can hold a valid report that excludes the AI product being evaluated. Always request the scope section and confirm the specific product and environment are inside it before treating the certification as relevant.

How do you avoid vendor lock-in with AI contracts?

Write a specific exit path into the contract: what data returns, in what format, on what timeline, and at what cost. Claim government rights to outputs, embeddings, and fine-tuning artifacts by name. Prefer shorter terms with defined revision points over long contract cycles.

Do state agencies follow federal AI procurement rules?

No. OMB memoranda bind federal executive agencies, not state or local governments. Several states are building their own requirements instead. California Executive Order N-5-26, signed March 30, 2026, directs state agencies to develop AI vendor certification requirements for use in state contracting processes.

Conclusion

Choosing an AI vendor for government is an evidence problem before it is a technology problem. Rank what a supplier tells you by how hard it would be to fabricate, verify certification scope rather than certification badges, and write the exit path into the contract while you still have leverage.

If you have a solicitation in draft or bids on the table, the highest-value hour you can spend is defining what evidence would actually satisfy you. JBS’s AI governance consulting team can work through your requirements, testing criteria, and contract terms with you before the award decision, when changes are still free.

Ready to turn AI readiness
into AI excellence?

Let's empower your people with the skills, confidence, and mindset to lead in an AI-powered world.

Consult an expert