AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
VoluntaryFrameworkUS

U.S. General Services Administration AI Strategies and Compliance Plan

Issued by

U.S. General Services Administration

liveEffective 2026-07-29GSA-AICPVerified August 2026
Official document →

The GSA AI Strategies and Compliance Plan establishes a formal internal governance structure for artificial intelligence use across the General Services Administration. It creates an AI Governance Board and a cross-functional oversight committee responsible for reviewing and approving internal AI use requests. The plan applies to GSA operations and sets requirements around privacy controls, security reviews, use-case intake processes, and compliance evidence collection.

Applies To

Public sectorLarge enterpriseAI developerAI deployer

Overview

Published in July 2026, this plan formalizes the GSA's internal approach to AI governance by establishing tiered oversight bodies, including an AI Governance Board that holds ultimate authority over AI adoption decisions within the agency. A cross-functional oversight committee supports the Board by conducting technical, privacy, and security reviews of proposed AI use cases before deployment. The plan aligns with federal AI policy requirements, including Executive Order mandates and OMB guidance on responsible AI use in government. Key provisions address access controls, use-case intake procedures, and the ongoing collection of compliance evidence to support accountability. Although the plan governs internal GSA operations, its structure and documentation standards have direct relevance to vendors, contractors, and enterprises that supply AI-enabled products or services to the GSA. Procurement implications are significant, as supplier conformity with GSA security and privacy expectations is embedded in the compliance framework.

Key Requirements

  • Establish and maintain an AI Governance Board with authority to approve or reject internal AI use cases
  • Operate a cross-functional oversight committee to conduct privacy and security reviews of AI requests before deployment
  • Implement a formal use-case intake process for all proposed AI applications within the agency
  • Apply documented privacy and security controls to all AI systems in use, consistent with federal standards
  • Collect and maintain compliance evidence to support auditability and accountability for each deployed AI system
  • Align AI adoption decisions with applicable federal AI policy, including OMB guidance and relevant Executive Orders

What Your Organization Must Do

  • Map all AI tools currently in use across your organization against the GSA's use-case intake criteria if you supply or seek to supply AI-enabled services to the GSA
  • Update vendor and contractor agreements to include privacy and security control requirements consistent with GSA compliance standards
  • Designate a point of contact responsible for assembling and maintaining compliance evidence packages for each AI system deployed in federal contexts
  • Prepare documentation demonstrating how your AI systems undergo security and privacy review prior to deployment, to satisfy GSA oversight committee expectations
  • Review procurement solicitations from the GSA for new language referencing AI governance conformity requirements, and build response templates accordingly
  • Benchmark your internal AI governance structure against the GSA's two-tier board and committee model to identify gaps that could affect contract eligibility

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Frequently Asked Questions

Does the GSA AI Strategies and Compliance Plan apply to private sector vendors supplying AI tools to the GSA?
The plan governs internal GSA operations, but its privacy and security control requirements are embedded in procurement expectations. Vendors and contractors supplying AI-enabled products or services to the GSA should expect conformity with these standards to affect contract eligibility and solicitation requirements.
What is the role of the GSA AI Governance Board under this plan?
The AI Governance Board holds ultimate authority over AI adoption decisions within the agency. It approves or rejects internal AI use cases, supported by a cross-functional oversight committee that conducts technical, privacy, and security reviews before any deployment proceeds.
When does the GSA AI Strategies and Compliance Plan take effect?
The plan carries an effective date of July 29, 2026, and is currently under draft review. Contractors and suppliers seeking GSA contracts involving AI systems should begin aligning their documentation and governance structures with its requirements ahead of that date.
What compliance evidence do AI suppliers need to maintain to satisfy GSA audit expectations?
The plan requires ongoing collection of compliance evidence for each deployed AI system to support auditability and accountability. Suppliers should maintain documentation covering security and privacy reviews, use-case intake submissions, and access control measures applied prior to deployment.
How does the GSA-AICP align with existing federal AI policy requirements like OMB guidance and Executive Orders?
The plan explicitly references alignment with OMB guidance on responsible AI use in government and applicable Executive Order mandates. It operationalizes those federal-level requirements through its tiered governance structure, use-case intake process, and documented control standards.
What gaps should AI vendors assess in their own governance structures before pursuing GSA contracts?
Vendors should benchmark their internal AI governance against the GSA's two-tier model, which separates board-level decision authority from committee-level technical review. Gaps in formal intake processes, security review documentation, or compliance evidence maintenance are likely to affect contract eligibility under this framework.