Quick answer: Federal agencies procuring agentic AI in 2026 need to evaluate vendors against OMB Memoranda M-25-21, M-25-22 and M-26-04, track GSA's proposed AI safeguarding clause rather than assume it is settled, request agent level documentation and audit trails for autonomous actions, and route the acquisition through a vehicle built for AI buys such as GSA's OneGov agreements or PSI's federal contract vehicles. There is still no FAR clause written specifically for agentic AI, which means agencies are applying high impact AI rules to systems that can act, not just answer.
Agentic AI adoption in government has moved faster than most agencies' acquisition playbooks. In April 2026, OMB published the 2025 Federal Agency AI Use Case Inventory: 3,611 individually reported use cases from 41 agencies, 445 of them flagged as high impact, roughly double the prior year. The policy, security and contracting frameworks are still catching up to that curve. If your agency is evaluating AI agents for casework, procurement review, IT operations or citizen services, here is what needs to happen before you sign.
What Counts as Agentic AI for Procurement Purposes
Agentic AI refers to systems that can plan, take multi step actions, use tools and interact with other systems with limited human intervention. That is a meaningful step beyond generative AI that only produces text or summaries in response to a prompt. For procurement purposes the distinction matters: an agent that can query a database, update a record or trigger a downstream workflow carries different risk exposure than a chatbot that only answers questions, even when both run on the same underlying model.
Most current federal guidance was written for generative AI and large language models, not autonomous agents. Agencies are bridging the gap by treating tool use and system access as high impact characteristics, which pulls agentic deployments into the stricter oversight tier by default.
The 2026 Policy Landscape Agencies Must Procure Against
Before writing a single evaluation criterion, your acquisition team needs to know which frameworks apply. The landscape has shifted substantially over the past 18 months.
1. OMB M-25-21 and M-25-22 (April 3, 2025)
These two memoranda replaced the prior administration's AI guidance, which was rescinded by Executive Order 14148 in January 2025. M-25-21 establishes high impact AI as the trigger for heightened risk management and directs agencies to designate Chief AI Officers with governance and procurement oversight responsibility. M-25-22 covers acquisition specifically, organized around ensuring a competitive AI marketplace, tracking AI performance and managing risk, and promoting cross functional engagement between program, acquisition, legal and technical staff.
2. OMB M-26-04 (December 11, 2025)
Increasing Public Trust in Artificial Intelligence Through Unbiased AI Principles implements Executive Order 14319 and applies to any large language model an agency procures, regardless of deployment method or use case. It requires agencies to contractually obligate vendors to two Unbiased AI Principles, truth seeking and ideological neutrality, to modify existing LLM contracts where practicable, and to stand up a mechanism for end users to report biased or non compliant outputs. Compliance is treated as material to contract eligibility and payment, with express authority to terminate for non compliance.
Agencies had to update internal acquisition policy by March 11, 2026. If your agency has not, that is a gap to close before any new agentic AI buy. The memo carries a two year sunset, so anything you write into a contract on its authority should be reviewed before it expires.
3. GSA's proposed AI safeguarding clause, GSAR 552.239-7001
This clause has moved through two public drafts and is not final. GSA released the first version on March 6, 2026 under Multiple Award Schedule Refresh 31, titled Basic Safeguarding of Artificial Intelligence Systems, with comments open through April 3, 2026. Industry pushed back hard on its breadth, on a prohibition covering foreign AI components including open source material, and on the scope of the rights the government claimed over data inputs, outputs and custom developments. GSA confirmed it would not fold that draft into Refresh 31.
A substantially revised version was published in the Federal Register on June 17, 2026, retitled Basic Safeguarding of Data within Large Language Model Artificial Intelligence Systems. The revised clause narrows the trigger to LLMs that process government data and adds data minimization, eyes off handling and prescriptive limits on human access, along with incident and change notification duties. In place of the blanket domestic sourcing approach, it substitutes United States jurisdictional controls aimed at foreign government control and compelled disclosure. Requirements flow down through the LLM supply chain to developers, operators, integrators and service providers, using actor categories drawn from the NIST AI Risk Management Framework.
GSA held a public listening session on July 14, 2026 and closed comments on August 3, 2026. It is intended for GSA governmentwide vehicles including the Federal Supply Schedule, GWACs and OASIS+. Expect a final version in the coming months, and expect similar language to migrate to other agencies' vehicles regardless of how the rulemaking lands. GSA has also signaled a broader AI acquisition rule favoring firm fixed price structures.
4. NIST CAISI AI Agent Standards Initiative (February 17, 2026)
The Center for AI Standards and Innovation launched the first federal program dedicated specifically to AI agents, organized around industry led standards, community led open protocol work, and foundational security and identity research. It followed a January 2026 Request for Information on AI agent security, which closed March 9, 2026, and runs alongside an NCCoE concept paper on identity and authorization for software and AI agents. No agent specific control set is final yet, so procurement teams cannot point to a finished NIST baseline for autonomy the way they can point to FedRAMP for cloud.
5. GAO-26-107859 (April 13, 2026)
GAO reviewed 13 AI acquisitions and 44 contracts and agreements at DOD, DHS, GSA and VA, and found that none of the four systematically documented lessons learned, because departmental policy did not require it. GAO recommended all four update policy accordingly and all four concurred. The practical signal for your team: there is no mature governmentwide playbook to lean on, so document your own evaluation process carefully. It will be the record you reuse.
The Practical Takeaway: No FAR clause governs AI agents specifically, so agencies are stretching existing high impact AI rules to cover autonomy, tool access and multi agent coordination. Build your RFP language accordingly, and expect to revise it as the NIST work and the GSA clause finalize.
A Five Step Evaluation and Contracting Path
1. Classify the use case before you draft requirements
Determine whether the agentic system touches CUI, FCI or high impact functions such as benefits determinations, security operations or financial transactions. This classification decides which oversight tier and which documentation burden applies from day one, and it is far cheaper to get right before the requirement is written than after a proposal is on the table.
2. Request agent specific documentation, not just a model card
Standard LLM system cards do not capture what an agent can do. Require vendors to provide:
- A full inventory of tools, systems and data sources the agent can access
- Documentation of the guardrails that limit autonomous action scope, and who can change them
- An audit trail that logs intermediary reasoning and action steps, not just final outputs
- Evidence of red teaming aimed at multi step and multi agent failure modes
- Identity and authorization design: what credentials the agent holds, on whose behalf it acts, and how access is revoked
3. Score vendors on human in the loop design, not just model quality
The agentic offerings gaining traction in federal environments are the ones built around human authored rules, a person approving each result and a complete audit trail behind it. GSA's own OneGov agentic offering is marketed on exactly that pattern. Evaluate whether a vendor's architecture makes human override native or bolted on, and ask what the system does when a step fails midway through a chain of actions.
4. Confirm the contract vehicle supports compliant terms
Route through vehicles built for AI acquisition rather than adapting a generic IT services contract after the fact. GSA's OneGov strategy now carries more than 20 agreements, including an agentic AI orchestration offering added in July 2026 that operates in a FedRAMP High and IL 5 and 6 environment with discounted pricing through September 30, 2027. GSA's USAi platform is a reasonable place to test models and workflows before committing to a program of record. One caution: OneGov agreements carry expiration dates and vendor availability has already shifted once in 2026, so confirm current terms with GSA before you design a program around one provider. See PSI's federal contract vehicles for options available to agencies in the National Capital Region.
5. Build sunset and reassessment clauses into the contract
M-26-04 carries a two year sunset, the GSA clause is not final, and NIST's agent specific work is still in development. Write review checkpoints into the contract now, with a defined process for incorporating new requirements, so a compliance update does not force a full new procurement later.
RFP Language: What to Ask Vendors Directly
When drafting solicitation language for agentic AI, agencies are increasingly asking vendors to answer:
- Can you provide a complete list of tools, APIs and systems this agent can invoke autonomously?
- What share of actions require human approval versus autonomous execution, and is that ratio configurable by the agency?
- Is the LLM or its operator subject to foreign government control, or could a foreign government compel disclosure of government data processed by the system?
- How does the system log and expose intermediary reasoning steps for audit purposes, and how long are those logs retained?
- What documentation supports your compliance with the Unbiased AI Principles, and how do you handle a reported non compliant output?
- How do the data handling and disclosure obligations in this contract flow down to your model developer, hosting provider and integrators?
- What is your incident reporting process if the agent takes an unintended or out of scope action, and on what timeline?
Common Procurement Pitfalls to Avoid
Treating agentic AI like a standard software license. The autonomy and system access change the risk profile enough that standard IT procurement templates usually under specify oversight, logging and audit requirements.
Skipping the Chief AI Officer review. M-25-21 makes the role central to high impact AI acquisitions, and M-26-04 puts attestation responsibility there as well. Looping them in late causes rework.
Assuming FedRAMP authorization covers agentic behavior. FedRAMP addresses cloud security. It does not evaluate the specific risks of autonomous multi step action, so agent level review is still needed.
Treating the GSA clause as settled. Neither draft is final. Writing either version verbatim into a solicitation risks locking in language GSA is still revising.
Not budgeting for reassessment. With the NIST work and the GSA clause both still in motion, agencies that do not plan a compliance refresh within 12 to 18 months will likely face a mid contract scramble.
Where this Fits with Broader AI Readiness
Procurement is one piece of a larger readiness question. Agencies that have already mapped their AI readiness and implementation posture, covering data governance, infrastructure and staff capacity, move through agentic evaluations faster, because the hard questions about access and oversight have already been answered internally. If your agency worked through Microsoft Copilot licensing under GCC or GCC High last year, the same governance muscle applies here. See our related guide on Microsoft Copilot for Government licensing and rollout. For a broader look at how enterprises and agencies are approaching agent deployment, our earlier post on agentic AI in the enterprise covers the five step rollout roadmap this procurement guide assumes.
Frequently Asked Questions
Not as of August 2026. Agencies apply the high impact AI framework from OMB M-25-21 and M-25-22, along with GSA's proposed AI safeguarding clause, to cover autonomous agents in the absence of agent specific FAR language. The Revolutionary FAR Overhaul is rewriting large portions of the FAR, but it has not produced a dedicated AI clause.
OMB M-26-04 required agencies to update procurement policies by March 11, 2026 to include contractual requirements addressing the Unbiased AI Principles for LLM procurements. The related M-25-21 and M-25-22 requirements were already in effect from April 2025.
No. FedRAMP addresses cloud security controls but does not specifically evaluate the risks introduced by autonomous, multi step agent actions. Apply additional agent level review even for FedRAMP authorized platforms.
GSA's March 2026 draft clause would have restricted foreign AI components broadly. The revised June 2026 version replaced that with protections against foreign government control and compelled disclosure of government data. The clause is still in rulemaking, with comments closed on August 3, 2026, so track the final rule rather than assuming either draft applies.