The 2026 Federal AI Procurement Rules Decoded: A Survival Guide for Small Contractors and Subcontractors

Executive Summary

  • The federal AI procurement landscape changed dramatically in 2025 and 2026. Four major instruments now reshape what small primes and subcontractors must do: Executive Order 14275, OMB Memorandum M-25-22, draft clause GSAR 552.239-7001, and FAR Case 2023-008.
  • The FY26 NDAA delivered real cost relief. The certified cost or pricing data threshold rises from $2.5 million to $10 million and the per contract CAS trigger jumps from $2.5 million to $35 million for contracts entered into after June 30, 2026.
  • GSA rewrote draft clause GSAR 552.239-7001 in June 2026. It now reaches only large language models that process government data, but inside that narrower scope it demands eyes off data handling, supply chain attestations, and defined change notice periods. Comments are due August 3, 2026.
  • FAR Case 2023-008 requires a reasonable inquiry into semiconductor supply chains and a 72 hour notification rule. The rule takes effect December 23, 2027.
  • Small contractors who build a documented compliance program in 2026 will be in a far stronger competitive position than those who wait for enforcement. This guide outlines exactly what to do.

1. The 2026 Federal AI Landscape at a Glance

After 15 years working federal cybersecurity and compliance with the Department of State, the Department of Defense, and the Department of Homeland Security, I have watched plenty of regulatory waves come and go. None of them have moved as fast or reached as deep as what is happening with artificial intelligence in federal contracting right now.

In the span of roughly eight months, four major instruments landed on the desks of federal contractors. Executive Order 14275 in April 2025 launched the Revolutionary FAR Overhaul. OMB Memorandum M-25-22 followed days later, rewriting the federal AI acquisition playbook. The FY26 National Defense Authorization Act, enacted in late 2025, restructured the dollar thresholds that determine whether your accounting system gets audited. Executive Order 14365, signed December 11, 2025, created an AI Litigation Task Force at the Department of Justice. Then in March 2026, the General Services Administration dropped draft clause GSAR 552.239-7001, the most prescriptive AI contract clause we have ever seen in federal acquisition.

Layer them all together and you get a federal AI compliance regime that did not exist a year ago. Small primes and subcontractors are at the center of it. The agencies most affected, the Department of Defense, the Department of Homeland Security, the General Services Administration, and the civilian agencies, are the same agencies most small firms rely on for revenue.

I want to be clear up front. I support the policy direction. Protecting federal systems from data poisoning, adversarial tampering, and unauthorized data exposure is exactly the right priority. After spending years inside agencies that handle sensitive national security information, I understand precisely why the government wants tight control over how AI touches its data. The question is not whether AI in federal contracting needs guardrails. The question is whether the guardrails as currently drafted are practical for a 25 person small business with a single GSA Schedule and three subcontracts.

The honest answer in mid 2026 is, not yet.

This guide walks through every major piece of the 2026 federal AI regulatory stack. What each one actually says. Where the gaps are. And what a small contractor needs to do right now to stay competitive without going broke on compliance overhead.

2. The FAR Overhaul: What EO 14275 and the FY26 NDAA Actually Changed

The good news first.

Executive Order 14275, titled Restoring Common Sense to Federal Procurement and signed April 15, 2025, kicked off what the administration is calling the Revolutionary FAR Overhaul. The premise is simple. The FAR had grown so large and so layered that small companies were quietly opting out of federal work to avoid the compliance load. The overhaul is happening in two phases. Phase 1 uses interim class deviations that take effect immediately. Phase 2 involves formal FAR rulemaking to make the changes permanent.

The Department of Defense is running its DFARS overhaul the same way. It issues a class deviation for each revised DFARS Part, with an effective date of February 1, 2026, and follows later with formal notice and comment rulemaking to make the text permanent. Deviations have continued to roll out through 2026. For small contractors, three threshold changes from the FY26 NDAA matter most. They are technically separate from EO 14275, but they form a coordinated reform package.

The Truthful Cost or Pricing Data Act threshold, the statute formerly known as the Truth in Negotiations Act, increases from $2.5 million to $10 million for contracts entered into after June 30, 2026. Note that the $2.5 million figure is itself recent. The threshold sat at $2 million for years and moved to $2.5 million on October 1, 2025 through a routine inflation adjustment. Section 1804 of the FY26 NDAA is what takes it to $10 million.

The per contract Cost Accounting Standards trigger moves from $2.5 million to $35 million under Section 1806(d). And the full CAS coverage threshold doubles from $50 million in annual awards to $100 million under Section 1806(a).

One point of caution on the certified cost or pricing data change. The statutory language runs to certified cost or pricing data generally rather than to defense contracts alone, and several practitioner analyses read it as reaching civilian agency awards as well. Others discuss it strictly in the defense context. DoD is implementing through DFARS class deviations, while the civilian side depends on FAR rulemaking that is still in progress. If your firm holds civilian agency contracts near the threshold, confirm the current state of FAR 15.403-4 with your contracting officer rather than assuming the new number applies.

For a 50 person subcontractor in Northern Virginia or Huntsville, this is genuine relief. The cost of maintaining a CAS compliant accounting system runs into six figures annually once you add up disclosure statements, segregated indirect cost pools, CPA fees, and audit time. A small business that previously had a single $4 million sole source contract was forced to absorb that overhead. Under the new thresholds, that same contract sits well below CAS and below TINA. The cost savings can be redirected toward the AI compliance work this article is about.

KEY THRESHOLDS

Threshold changes for contracts after June 30, 2026

  • Certified cost or pricing data (TINA) threshold: $2.5 million to $10 million
  • Per contract CAS trigger: $2.5 million to $35 million
  • Full CAS coverage: $50 million to $100 million in annual awards
  • None of these changes are retroactive. Contracts entered into on or before June 30, 2026 stay under the old thresholds.

Here is what nobody is telling small contractors loudly enough. None of these threshold changes are retroactive. Contracts entered into before July 1, 2026 stay under the old rules. And the Phase 2 formal FAR rules are still working through the Office of Federal Procurement Policy. If you are negotiating a contract in June 2026, the timing of award matters enormously. A contract executed June 30 is governed by the old thresholds. A contract executed July 1 is not. That single day of difference can determine whether your firm needs to stand up a CAS compliant accounting system or not.

This is also where most small contractors miss a critical point. The cost relief from the FAR overhaul is not a free pass on AI compliance. It is the breathing room the government has signaled it will provide while simultaneously layering on new AI specific obligations. The TINA and CAS changes free up overhead capital. The AI clauses, semiconductor restrictions, and supply chain mandates demand that capital be invested in new compliance infrastructure. The net effect for most small primes and subs is roughly flat. The work just looks different.

3. GSAR 552.239-7001: The Centerpiece of New AI Procurement Rules

This is the piece most contractors are getting wrong right now, because the clause they read about is not the clause currently on the table.

On March 6, 2026, the General Services Administration released a draft clause numbered GSAR 552.239-7001, titled Basic Safeguarding of Artificial Intelligence Systems. It arrived alongside advance notice of Multiple Award Schedule Refresh 31. Industry pushback was immediate. GSA pulled the clause from Refresh 31, extended the comment deadline to April 3, 2026, and went back to work on the text.

On June 17, 2026, GSA published a substantially rewritten version. The new title signals most of what changed: Basic Safeguarding of Data within Large Language Model Artificial Intelligence Systems (LLMs). Comments on the revised clause are due August 3, 2026, and GSA held a public listening session on July 14, 2026. Everything below describes the June version, because that is the text in front of industry today.

If you read the March commentary and never went back, your picture is out of date. The revision narrowed the scope considerably and handed contractors several real protections. It also went deeper on operational requirements inside the narrower scope. Less reach, heavier lift within that reach.

What changed between March and June

The March draft reached AI capabilities generally. The June version applies only where government data is processed by a large language model, and it explicitly carves out LLMs embedded in common commercial products along with LLM functionality that is incidental to the primary purpose of the procurement.

That carve out matters enormously for small firms. The March draft plausibly captured the predictive features in your accounting platform and the anomaly detection in your security tooling. The U.S. Chamber of Commerce made exactly that argument in its public comment. The June version largely answers it.

The flat prohibition on foreign AI also softened into something workable. Rather than an absolute ban, the revised clause asks contractors to maximize use of LLMs developed by entities incorporated in the United States and subject to United States law, with protection against foreign government compulsion of data or operational details. Incidental foreign components such as open source work or published research remain permissible where no security risk or foreign control exists.

Contractors gained protections that were missing in March. The government license narrowed from any lawful government purpose to the purposes defined in the contract. Termination for cause now requires written notice and an opportunity to cure. Decommissioning cost liability is capped at a percentage of contract value that the contracting officer specifies. Trade secrets are exempt from certain disclosure obligations.

What the June clause actually requires

Six obligations carry the weight. They are not the same six that appeared in the March draft.

Obligation 1: Eyes off handling of government data

This is the requirement my federal contracting colleagues find most operationally demanding, and it is new in the June text. Technical controls must prevent human review of government data. That means automated ingestion and response generation without human content review, access controls that stop personnel from viewing the data, encryption in transit, and audit logging that records activity without displaying the underlying content.

Read that carefully against how your vendors actually operate. Many commercial platforms rely on human review for quality assurance, abuse monitoring, or support escalation. If a support engineer can open a ticket and see customer content, that architecture does not satisfy this requirement without changes.

Obligation 2: No training, no marketing, no lingering copies

The government defines its data broadly, covering all data inputs and data outputs plus custom developments, and retains ownership. Contractors may not use that data to train or fine tune models, may not use it for advertising, marketing, or monetization, may not retain it beyond the scope and duration of the contract, and may not transfer, sell, or license it to unauthorized parties. On contract completion or termination, secure deletion is mandatory and must be certified in writing.

Most commercial AI providers train on customer inputs by default and their standard Terms of Service authorize it explicitly. That conflict did not go away in the revision. It is still the single most common blocker I see when a small contractor tries to map an existing vendor relationship onto this clause.

Obligation 3: Supply chain due diligence across four defined roles

The June version replaced the single sweeping Service Provider concept with four defined roles: LLM Developer, System Operator, System Integrator, and Service Provider. Companion clauses attach role specific requirements to each. The framework references NIST AI Risk Management Framework definitions.

Here is the practical improvement for small primes. You now have two compliance pathways rather than one. You can flow the applicable requirements down by contract, or you can obtain written attestations confirming compliance. The attestation route is far more achievable when your counterparty is a large commercial platform that will never sign your paper. Either way, keep the documentation. If covered noncompliance surfaces in your supply chain, you have 72 hours to notify the contracting officer.

Obligation 4: Unbiased AI Principles

Contractors must ensure covered systems are truthful and historically accurate while remaining neutral and nonpartisan. The clause specifically prohibits introducing or embedding partisan or ideological judgments through training data selection, fine tuning, retrieval augmented generation references, system prompts, or other configuration methods.

Note how far that reaches. It is not only about how a model was trained. It covers choices you make at deployment time, including the system prompt you wrote and the documents you put in a retrieval index. Failure to comply with the Unbiased AI Principles is grounds for termination for cause. Document your configuration decisions.

Obligation 5: Change management with defined notice periods

The March draft asked vaguely for notice of material changes. The June version puts clocks on it. Planned material changes require 30 days advance notice, covering things like adding or replacing an LLM, modifying data protection controls, or a change in FedRAMP status. If you identify a change that increases bias, weakens safety guardrails, or degrades performance or truthfulness, you have 7 days. Emergency changes require immediate notice followed by a description of remediation.

Model discontinuation gets its own rule. You owe 30 days advance notice before a model is retired, with concurrent access to the successor model so the government can evaluate it. Anyone who has worked with commercial generative AI knows deprecation notices often arrive with less runway than that.

Obligation 6: Government testing, audit rights, and enforcement

The government reserves the right to run automated benchmark assessments for bias, truthfulness, safety, and unsolicited ideological content, and it may withhold the benchmarks, test data, and methodologies from the contractor. You are being graded on a test you do not get to see.

Consequences run from suspension of the AI system to termination for cause, plus liability for decommissioning costs. The cap on those costs is a percentage of contract value left blank in the draft for the contracting officer to fill in, which makes it a negotiation point rather than a fixed exposure. Before enforcement, the government must disclose the basis for termination and allow an opportunity to cure.

GOVERNANCE INSIGHT

Why this matters for small subcontractors

The obligations cascade by role, not by contract tier. A firm several steps removed from the prime contract can still receive flow down language or an attestation request, even if it has never thought of itself as a government contractor. If you touch an LLM that processes government data in any capacity, expect the request. Decide now whether you can sign an attestation truthfully, because the answer depends on your vendors as much as on you.

Give GSA credit. The June revision is a genuine response to industry comment, and the drafters clearly listened on scope, on foreign sourcing, and on contractor liability. The embedded AI problem that would have swept in half the commercial software market is largely fixed.

The deeper problem survived the rewrite. The clause still treats commercial AI providers as though they were traditional defense subcontractors the government can dictate terms to. They are not. The major providers serve millions of customers across hundreds of industries and will not rewrite standard Terms of Service for the federal market unless that market justifies the engineering. For the largest cloud AI providers it does, and they already offer federal specific tiers. For mid tier providers and most open source deployments it does not.

Add the eyes off architecture requirement and the picture sharpens. A small contractor cannot build automated only data handling on top of a vendor whose support model assumes human access. You either buy the federal tier, at a real premium, or you do not use that tool on the contract. The likely practical outcome is still that small contractors get funneled toward a narrow set of government compliant AI tools at significantly higher cost than the commercial equivalents. That remains the opposite of the marketplace competition the administration has stated as a goal, and it is worth saying so in a comment before August 3.

4. OMB Memorandum M-25-22: The Buy American Foundation

OMB Memorandum M-25-22, titled Driving Efficient Acquisition of Artificial Intelligence in Government, was issued April 3, 2025 and applies to contracts awarded under solicitations issued after December 26, 2025. The memo rescinds and replaces the Biden era M-24-18.

M-25-22 sets the foundation that GSAR 552.239-7001 builds on. Three of its provisions matter most for small contractors.

Section 3c establishes that it is the policy of the United States to buy American and to maximize the use of AI products and services that are developed and produced in the United States. That language did not exist in the prior administration’s AI guidance. It is the basis for the United States developer preference in the GSAR clause and for any future FAR rulemaking on the same topic.

Section 3d requires agencies to establish policies and contract terms ensuring compliance with privacy laws in acquisition, particularly for systems handling personally identifiable information. Senior Agency Officials for Privacy must now be involved in the acquisition process from pre solicitation through award. This raises the documentation bar substantially for any small contractor selling AI capabilities that touch PII.

The memo also requires agencies to revisit data ownership and intellectual property rights in AI procurements. Agencies must restrict vendors from using non public agency data for further training of publicly or commercially available AI without explicit consent. This is where the prohibition on training in GSAR 552.239-7001 traces back to. The GSAR clause is the contract instrument. M-25-22 is the underlying policy. Other agencies will follow with their own acquisition supplements. DoD, DHS, and State will not be far behind.

5. FAR Case 2023-008: The Semiconductor Supply Chain Squeeze

On February 17, 2026, the FAR Council issued a Notice of Proposed Rulemaking to implement Section 5949 of the FY 2023 National Defense Authorization Act. Comments closed April 20, 2026. The rule becomes effective December 23, 2027.

Section 5949 prohibits federal agencies from procuring electronic products or services that include covered semiconductor products or services. Covered means semiconductors designed, manufactured, or sourced by SMIC, YMTC, CXMT, or any other entity owned, controlled by, or otherwise connected to the government of the People’s Republic of China.

The compliance burden flows directly to contractors. The proposed rule would require contractors to:

  • Conduct a reasonable inquiry into their supply chains.
  • Certify at the time of offer that covered semiconductors are not included.
  • Disclose known noncompliant semiconductors and any associated risks.
  • Notify contracting officers within 72 hours if covered semiconductors are discovered during contract performance.

The proposed rule does provide safe harbor protection from civil liability for contractors who make timely, good faith disclosures and remediation efforts. That is a meaningful protection. Good faith disclosure beats discovery during an audit every time.

The challenge for small contractors is the scope of reasonable inquiry. The proposed rule does not precisely define what reasonable means for a 30 person subcontractor selling IT services. What I have seen federal contracting officers expect in practice is a documented supply chain review, vendor certifications, and a tracking process for any new component or product brought into the work. That is achievable, but it requires upfront process investment.

The intersection with AI matters here. Modern AI workloads run on specialized hardware. GPUs, TPUs, and AI accelerators all contain advanced semiconductors. A small contractor running AI inference on commercial cloud platforms inherits the supply chain risk of those platforms. Vendor certifications and contractual flow down language will become essential well before the December 2027 effective date.

GOVERNANCE INSIGHT

The 72 hour notification rule

If covered semiconductors are discovered during contract performance, the contractor has 72 hours to notify the contracting officer. That is not 72 business hours. That is 72 calendar hours, weekends and holidays included. Small contractors need a defined escalation path with named owners and 24/7 contact details before that clock ever starts.

6. Executive Order 14365 and the AI Litigation Task Force

President Trump signed Executive Order 14365, titled Ensuring a National Policy Framework for Artificial Intelligence, on December 11, 2025. The order has received substantially less attention from federal contractors than the GSAR clause, but it matters more than most realize.

Section 3 of EO 14365 directed the Attorney General to establish an AI Litigation Task Force within 30 days. The Task Force’s stated sole responsibility is to challenge state AI laws inconsistent with the federal policy of a minimally burdensome national AI regulation. The Task Force can challenge state laws on grounds of unconstitutional interference with interstate commerce, federal preemption, or other constitutional theories.

Section 4 directed the Secretary of Commerce to publish, within 90 days, an evaluation of state AI laws identifying ones deemed onerous. Section 5 conditioned certain federal funding, including the Broadband Equity Access and Deployment program funds, on states either not enacting conflicting AI laws or agreeing not to enforce them during the funding performance period.

Why does this matter for federal contractors? Three reasons.

First, contractors operating in states with active AI laws (Colorado, California, Illinois, New York, and Texas in certain sectors) face a real possibility that the state law obligations they currently comply with may be challenged or preempted within the next 12 to 24 months. That regulatory instability makes compliance investment decisions harder.

Second, the EO signals where federal AI policy is moving. The administration’s position is that AI regulation should be federal, narrow, and innovation friendly. That posture is consistent with the policy underneath M-25-22 and the GSAR clause. Small contractors should expect future AI rules to follow the same playbook.

Third, the existence of the Task Force creates a litigation environment that will affect commercial AI providers. If a major AI vendor’s standard Terms of Service includes algorithmic bias testing language tied to a state law, and that state law is challenged, the vendor’s terms may shift. Contractors who depend on those vendors should track these developments.

7. How These Rules Stack with Your Existing Federal Obligations

The new AI rules do not replace your existing federal cybersecurity and compliance obligations. They stack on top of them. The list a small federal contractor must now manage in 2026 looks like this.

Compliance Area Foundational Requirement 2026 AI Layer
Cybersecurity NIST 800-171, CMMC 2.0 GSAR 552.239-7001 safeguarding
Supply chain Section 889 telecommunications ban FAR Case 2023-008 semiconductor inquiry
Country of origin Buy American Act OMB M-25-22 United States developer preference
Data handling CUI marking, DFARS 252.204-7012 AI training data restrictions
Incident notification Existing incident reporting rules 72 hour semiconductor notification
Governance framework Contract oversight requirements NIST AI RMF alignment

For small contractors who have spent the past three years getting CMMC and NIST 800-171 in order, the AI rules feel like the next wave of the same flood. The good news is that the underlying compliance infrastructure overlaps considerably. The same documented control environment that supports CMMC also supports AI governance. The data classification work done for CUI maps cleanly onto AI input and output controls. The supply chain risk management work done for Section 889 generalizes neatly to the semiconductor inquiry under FAR Case 2023-008.

A small contractor that has done good CMMC work is roughly halfway to AI compliance already. The remaining half is AI specific. AI inventory, model governance, training data controls, and Service Provider flow downs. None of this is technically difficult. The work simply has to be done, and it has to be documented in a way that an auditor or contracting officer can verify.

8. A Practical 2026 Compliance Path for Small Subcontractors

Here is what I tell every small contractor client.

You do not need to solve everything in 2026. You need to demonstrate that you have a credible, documented program in place and that you are actively moving. Contracting officers and prime contractor compliance teams are looking for evidence of intent and progress, not perfection. The contractors who get caught flat footed are the ones with no documented program at all, not the ones with a program that still has gaps.

The most efficient compliance path for a small contractor in 2026 has five components.

Component 1: AI Inventory

You cannot govern what you do not see. The first step is to inventory every AI capability touching your federal work. That includes obvious generative AI tools used by staff, AI features embedded in commercial business software, AI services consumed through APIs, and AI inside any third party cloud platform involved in contract performance.

For each AI capability, capture the development origin (American or otherwise), the data flows in and out, whether government data could touch the system, and the Service Provider’s standard Terms of Service. This inventory becomes your foundation document. Every other compliance step traces back to it.

Component 2: AI Policy and Governance

Document your AI use policy. Define what is permitted, what is prohibited, who approves new tools, and how exceptions get handled. The policy does not need to be long. A two to three page policy that has actually been signed, distributed, and trained on beats a 40 page policy nobody reads. Tie the policy to the NIST AI RMF functions: Govern, Map, Measure, and Manage. Doing this gives you defensible framework alignment when a contracting officer asks for documentation.

Component 3: Service Provider Flow Downs

Map your supply chain against the four roles the June clause defines: LLM Developer, System Operator, System Integrator, and Service Provider. For each one, get the terms in writing. Where standard Terms of Service conflict with the clause, document the conflict and the workaround. Often the workaround is a federal specific service tier from the vendor, at higher cost. Sometimes it is a contractual amendment.

Remember you have two pathways. Flow the requirements down by contract, or collect a written attestation of compliance. For large commercial platforms that will never sign your paperwork, the attestation route is the realistic one. Verify your existing agreements actually permit the flow downs you would need, and check whether the technical architecture can support eyes off data handling at all. If you are a sub working under a prime, expect the request to reach you regardless of your tier.

Component 4: Supply Chain Documentation

Build a documented supply chain inquiry process now. For each hardware component and AI tool used in federal work, capture the vendor, the country of origin, and any relevant certifications. This is what FAR Case 2023-008 will demand. Building the process before December 2027 is much cheaper than building it under audit pressure in 2028. Vendor certification letters, country of origin documentation, and tier two supplier visibility are the three documents you want in your file.

Component 5: Continuous Monitoring and Notification

Establish defined processes for the 72 hour semiconductor notification, AI model change notification, and AI performance issue escalation. Define who owns the notifications, what the trigger criteria are, and how to document them. A small contractor does not need a dedicated team for this. A named owner and a two page procedure document are sufficient. The point is that when something happens, your firm knows exactly what to do in the first hour, not the first day.

Getting your AI governance in order

Dynamic Comply helps small federal contractors build a real AI governance foundation using the NIST AI RMF and ISO/IEC 42001, before the GSAR clause forces the issue on your next award.

Start the free AI maturity self assessment

9. Six Steps to Take Before 2027

Look, I have built this stuff for federal agencies and for small business clients. Here is the prioritized list.

  1. Inventory every AI capability in your federal work, including embedded AI features inside commercial tools. Do not skip the embedded AI. That is where most audit surprises come from.
  2. Map your LLM supply chain across the four defined roles and review their Terms of Service against the June version of the GSAR clause. Where conflicts exist, document them and the workaround, and decide whether you are pursuing flow downs or attestations.
  3. Document an AI use policy aligned to the NIST AI Risk Management Framework. Sign it, distribute it, train on it. Make it two to three pages, not forty.
  4. Start the supply chain inquiry for FAR Case 2023-008. Begin with your highest spend hardware and IT services vendors. Move to lower spend later.
  5. Train your staff. The single largest source of inadvertent AI exposure in federal work is staff using consumer AI tools for tasks they should not. A 30 minute training a year prevents a six figure incident.
  6. Designate an AI compliance owner inside your organization. It can be a part time role. It cannot be unowned. An unowned compliance program is a failed compliance program.

If you do these six things in 2026, you will be in a defensible posture when the GSAR clause or its FAR equivalent appears in your contracts. You will also be ahead of most of your competition.

10. Where This Leaves You

Federal AI compliance in 2026 is not a mystery. The rules exist. The frameworks exist. The threshold changes from the FY26 NDAA give small contractors real cost relief on other compliance overhead. What is missing for most small primes and subs is a documented program that ties everything together into something an auditor or contracting officer can verify.

The contractors who put that program in place this year will be in a defensible posture when the GSAR clause or its FAR equivalent lands in their contracts. They will be able to respond to prime contractor flow downs. They will pass audits. And they will win competitive awards that require documented AI governance as a threshold criterion.

The contractors who wait for enforcement will spend more, move slower, and lose contracts they should have won. That is the choice, and 2026 is the year to make it.

Talk to Ross about your federal AI compliance program

Every federal contractor has different exposure. Whether you are a 15 person GSA Schedule holder or a 200 person DoD prime, let us talk through what your program should actually look like.

Contact Dynamic Comply

About the author

Ross J. is the founder of Dynamic Comply, an AI governance, compliance, and cybersecurity consulting firm headquartered in Leesburg, Virginia. He brings more than 15 years of federal cybersecurity and compliance experience across the Department of State, the Department of Defense, and the Department of Homeland Security, and holds the CGRC certification along with credentials as a GSDC AI Compliance Lead Implementer and Auditor and Certified Ethical Hacker.

Related articles

  • CMMC 2.0 for Small Federal Subcontractors: A 2026 Implementation Guide
  • Section 889 Compliance: A Field Guide for Small Primes
  • NIST AI RMF Explained for Federal Contractors
  • EU AI Act for US Federal Contractors with European Operations

This article is provided for general informational purposes and reflects the state of the law as of July 2026. It is not legal advice. Federal AI acquisition rules are evolving quickly and draft clauses may change before final rulemaking. Confirm current requirements and consult qualified counsel before making decisions for your organization.

Leave a Reply

Your email address will not be published. Required fields are marked *