The clause is the policy
The world's largest buyer of AI cannot show that its own contracts carry the provisions its own policy requires. That is not an audit failure. It is a diagnosis.
Javad Mushtaq · Founder and Executive Director · 21 May 2026
Reading time 5 min · Published by ImpactLab
Six years into the AI-policy conversation, the world's largest buyer of artificial intelligence cannot demonstrate that its own contracts contain the clauses its own policy documents require. That is the finding underneath the April 2026 audit of United States federal AI procurement, and it is not, properly read, an audit failure. It is a diagnosis.
The problem is not an absence of policy. Federal AI policy exists in volume: executive guidance, agency directives, inventories, risk-management frameworks. The problem is that the policy has not travelled into the contract. Between the office that writes the principle and the office that signs the purchase order, the principle evaporates.
The evidence
The audit examined 44 federal AI contracts. It found that best-practice provisions covering model documentation, audit rights, evaluation-data provenance, and post-deployment monitoring were applied inconsistently across agencies [1]. Not absent everywhere, not present everywhere — inconsistent, which is the harder failure to fix, because it means no agency can point to a peer and copy the answer.
The volume at stake is not marginal. United States federal agencies committed approximately USD 5.6 billion to AI between 2022 and 2024. United Kingdom government AI contracts crossed GBP 573 million by August 2025 [2]. European Union public procurement runs at roughly EUR 2 trillion a year, around 14 percent of EU GDP [3]. Whatever share of that turns into AI over the next five years will be governed by whatever language happens to be in the template.
And the load is doubling while the language is not. Documented federal AI use cases went from 571 in 2023 to 1,110 in 2024, with generative AI use growing ninefold over the same period [4]. The clause library did not double. It did not grow ninefold. In most agencies it did not change at all.
What is actually going on
The mechanism is mundane, which is why it persists.
Policy lives in one office. Procurement lives in another. The AI policy sets principles — human oversight, transparency, documented evaluation. The procurement office writes a Statement of Work using templates that predate the policy, because those templates are what the contracting officer has been trained on, indemnified for, and audited against. The vendor bids using its own master services agreement, which is optimised for the vendor's risk position and says as little as possible about audit rights and evaluation-data provenance.
What ships is the intersection of the three. On the dimensions that matter most for public accountability — model documentation, the right to inspect, the right to know what the system was evaluated on, and the obligation to monitor after deployment — the intersection is almost always the weakest of the three.
No one in this chain is behaving badly. The contracting officer is doing the job as defined. The vendor is doing what vendors do. The policy office wrote a good document. The failure is structural: there is no artefact that carries the policy into the tender. There is no clause library.
Why this matters for capital
The mismatch becomes vivid when you look at who is on both sides of the transaction.
Norway's sovereign wealth fund, at approximately USD 2 trillion under management, holds around 1.3 percent of Nvidia [5]. It is now deploying AI to screen its own portfolio for environmental, social, and governance risk. The asset owner is running AI on the portfolio.
Meanwhile the public buyer — the state that purchases AI systems from companies in that same portfolio — is not yet running a clause library on the contract. Capital has built an AI accountability instrument for the investment side and not for the purchasing side. The same institution, in its capacity as owner, asks harder questions than it asks in its capacity as customer.
That asymmetry is the story. It is also the opening. The disciplines that ESG screening has already developed on the ownership side — documented methodology, defined review, published criteria — translate directly into procurement language. Nobody has done the translation at scale.
What a clause library actually is
It is not a regulation and it is not a standard. It is a versioned, public set of contract provisions, written in the language contracting officers already use, that a ministry or an agency can drop into a Statement of Work without asking permission from anyone.
Each clause does one job. A model-documentation clause specifies what the vendor must supply and in what form. An audit-rights clause specifies who may inspect, on what notice, and under what confidentiality. An evaluation-data clause specifies what the system was tested on and how the buyer verifies it. A post-deployment monitoring clause specifies what is measured, by whom, and what happens when the measurement moves.
The value of a library is that it is boring and reusable. A contracting officer with eleven active tenders and no AI background does not need a philosophy of algorithmic accountability. That officer needs a paragraph that legal will approve and that a vendor will not refuse outright.
The bear case
If the audit bodies and the European Commission report by mid-2028 that clause quality has improved materially through ordinary contracting cycles — templates updated, vendors adjusting, agencies converging — then the clause-library thesis is weakened, and the correct conclusion is that this problem solved itself through professional practice.
That outcome is possible. Procurement communities do learn. We will publish the counter-evidence when it arrives, and we will say plainly that the intervention was not needed.
What we do not accept is the intermediate position: that the gap is known, unaddressed, and expected to close on its own without anyone writing the language down.
What ImpactLab is doing
The Nordic AI Blueprint, first public release in the fourth quarter of 2026, is a clause library and reference document for ministries and agencies operating under the EU AI Act and EEA-equivalent frameworks.
It will be free, open, and versioned. Contributions from public buyers will be named. It will not be a report about procurement. It will be the paragraphs themselves, in the form in which a contracting officer can use them on a Tuesday afternoon.
The clause is the policy. Everything upstream of the clause is preparation.
Bear case · Open · Resolves Q4 2028
If a follow-up federal review before the end of 2028 finds AI-specific clauses in a majority of sampled contracts, the diagnosis was a transition artefact rather than a structural gap.
Footnotes
- [1] FedScoop, "Agencies fall short on documenting AI acquisition best practices, GAO says", April 2026. https://fedscoop.com/agency-ai-procurement-gao-report/ Primary source: US Government Accountability Office, "Artificial Intelligence Acquisitions: Agencies Should Collect and Apply Lessons Learned to Improve Future Procurements", GAO-26-107859, 13 April 2026. https://www.gao.gov/products/gao-26-107859 ↩
- [2] Open Contracting Partnership, analysis of government AI contracting, November 2025. https://www.open-contracting.org/ ↩
- [3] European Commission, public procurement in the EU: figures and policy overview, October 2025. https://single-market-economy.ec.europa.eu/single-market/public-procurement_en ↩
- [4] US Government Accountability Office, "Artificial Intelligence: Generative AI Use and Management at Federal Agencies", GAO-25-107653, 29 July 2025. https://www.gao.gov/products/gao-25-107653 (GAO review of agency use-case inventories at eleven selected agencies) ↩
- [5] CNBC, "Norway wealth fund posts $247 billion profit amid tech, banking boom", 29 January 2026. https://www.cnbc.com/2026/01/29/norway-sovereign-wealth-fund-2025-return-nbim-trillion-oil-stocks-tech-ai-banks-silver.html ↩
Cite this issue as: ImpactLab, The Dispatch, Issue 08, 21 May 2026.
Author
Javad Mushtaq
Founder and Executive Director, ImpactLab. The byline is set inside the publication; ImpactLab is the publisher of record.