RatedWithAI

RatedWithAI

Accessibility scanner

GovernmentSeptember 1, 2026

The AI Questions in a Government Bid Are Scored Before Anyone Looks at Your Demo

State and local AI purchasing standards moved the compliance work upstream, into the solicitation. The vendor that cannot produce an intended-use statement, testing evidence, and a data-use answer inside the response window loses on responsiveness — not on product.

Inventory
Agencies must catalogue the automated systems they run — vendors supply the facts
Pre-award
AI disclosures are scored during evaluation, not negotiated after selection
Ongoing
Model and data changes become reportable events for the life of the contract

Why the Federal Playbook Does Not Transfer

Vendors selling into federal agencies have a well-worn path: get a cloud authorisation, satisfy the security controls, land on a schedule. State and local procurement has no equivalent single gate for AI. Instead, states have been attaching AI-specific requirements to ordinary solicitations — a disclosure section in the RFP, a set of mandatory terms in the resulting contract, and a reporting duty that runs afterwards.

That structure has a consequence worth planning around. There is nothing to certify once and reuse everywhere. Each jurisdiction asks its own version of the same handful of questions, and the differences are in wording rather than substance. A vendor that builds one well-evidenced answer set can respond to most of them; a vendor that treats each RFP as a fresh writing exercise burns weeks per bid and produces inconsistent answers that a diligent evaluator will notice.

The Five Questions Behind Every Variation

1. Is there AI in it, and where exactly?
A feature-level answer, not a product-level one. Name the component, the task it performs, and whether its output reaches a person or only an internal reviewer.
2. What decision does it touch?
Eligibility, benefits, enforcement, employment, and housing are the categories that trigger the heavier requirements. Say plainly whether the system informs one of them.
3. What have you tested, and what did the test show?
Accuracy figures alone rarely suffice. Expect to describe evaluation across subgroups, the dataset used, when it was run, and who ran it.
4. What happens with agency and resident data?
Whether it trains models, whether it leaves the jurisdiction, which subprocessors touch it, and how it is deleted at contract end.
5. What does a human do?
Where review sits in the workflow, what the reviewer sees, and whether they can override. 'A human is in the loop' with no described mechanism reads as a non-answer.

The Bid-Ready Artefact Set

Prepare Before the Next Solicitation
  • A one-page intended-use statement per AI feature, written for a non-technical evaluator
  • A data-flow description naming every subprocessor, storage region, and retention period
  • Evaluation results with dates, dataset description, and subgroup breakdowns where the use case affects individuals
  • A written human-review procedure describing what the reviewer sees and what they can change
  • A model-change notification process you can actually operate at contract scale
Contract Terms to Price In, Not Argue With
  • No training on agency or resident data — assume this is non-negotiable and check your architecture against it
  • Audit and inspection rights covering AI documentation, not just security posture
  • Notice obligations when the underlying model or a foundation-model dependency changes
  • Deletion and return of data at termination, including derived features and embeddings
  • Indemnity for third-party IP claims arising from generated output
Filing Hygiene
  • Claim trade-secret protection at submission using the jurisdiction's stated procedure — not afterwards
  • Segregate proprietary material into clearly marked exhibits so an agency can release the rest
  • Keep answers consistent across jurisdictions; evaluators do compare against public award files
  • Answer the AI-disclosure question 'yes' whenever a feature could plausibly qualify

The Disqualification Is Usually Procedural

Public procurement runs on responsiveness. A bid that omits a required disclosure, or answers it in a way that does not match the form, can be set aside without reaching the merits — and the vendor often never learns that was the reason. This is a different failure mode from private enterprise sales, where an incomplete security questionnaire triggers a follow-up email rather than an elimination.

It is also why the artefact set above is worth building once, in advance. The response window on a public solicitation is short, the questions are known in substance, and the evidence they ask for — subgroup evaluation, data-flow mapping, documented human review — takes longer to produce than the window allows if you start from nothing.

Frequently Asked Questions

Do these rules apply to city and county buyers too?

Increasingly. Large municipalities have adopted their own AI purchasing policies, and smaller ones frequently borrow the state's language wholesale or buy from a state master contract that carries the terms through. Assume the requirements travel down, and read the flow-through clauses in any cooperative-purchasing vehicle you list on.

We use a third-party foundation model. Whose disclosures are these?

Yours, as the contracting party. The agency's counterparty is you, and the disclosure and notice duties land on the entity holding the contract. That makes your upstream provider's terms a compliance dependency: if you cannot get notice of model changes from your provider, you cannot reliably give notice to the agency. Negotiate that visibility upstream before you promise it downstream.

Is a bias audit the same thing as the testing evidence they want?

Related but not identical. A bias audit under an employment-specific law like NYC Local Law 144 is a narrowly scoped, formatted exercise for a defined tool category. Procurement testing evidence is broader and less standardised: it asks what you evaluated, on what data, when, and what the results were, for whatever the system actually does. An audit report is useful supporting material, but it does not by itself answer the general question.

How long do these obligations last after award?

For the contract term and often past it. Reporting duties run continuously, records-retention clauses commonly outlive the engagement, and data-deletion obligations attach at termination. Treat the award as the beginning of the compliance work rather than the end of it, and staff the notification process accordingly.

Related Guides

Build the Answer Set Once

Every jurisdiction asks the same five questions in different words. The vendors that win public-sector AI work are not the ones with the best answers — they are the ones who had answers ready, with dated evidence behind them, on the day the solicitation dropped.

Public-sector buyers also carry digital accessibility obligations that flow through to the software they procure, so the accessibility posture of your interface is scored in the same bid. Fix that before it costs you a responsive submission.