Author: Jessica Tillipman

  • My Family Hates AI

    My Family Hates AI

    My family hates AI. Well, more specifically, my family hates my use of AI.

    While getting ready for work: “Interesting that DOE uses FCA materiality language in its unbiased AI contract guidance, but GSA doesn’t…”

    While commuting: “I want to get back to NSPM-11’s requirement to share AI systems across the national security enterprise and potential provenance concerns…”

    Folding laundry: “But the Princeton-Chicago paper shows that instructing models to be fair doesn’t reliably eliminate biased behavior, so how are contractors supposed to comply with an unbiased AI clause?”  

    On the Peloton: “It’s definitely covered by 18 U.S.C. § 201—you keep getting hung up on an ‘official act,’ but it also covers acts or omissions in violation of official duty.”

    While gardening: “It just seems so odd to me that an agency would use CSO authority to procure janitorial services when you can order them off the GSA Schedule or use simplified acquisition…”

    While doing the dishes:Ok, so if the Chef brings her notebook to the restaurant and takes notes during dinner service, is that commingled document now a ‘Data Output?’”

    And don’t get me started on road trips with my family. This past summer we took a road trip from Virginia to Maine, just after GSA released its revised AI clause. My kids had to listen to me discussing “Government usage context” with Claude and ChatGPT for nearly two weeks in the car. You may be thinking: “poor kids,” but can your elementary school kids explain, with great fluency, the difference between telemetry and “data dust?”

    As a working parent, I’ve become more productive than at any other point in my career, thanks to AI. I am no longer tethered to a desk to write papers, and AI enables me to bring a paper concept to the tool, then spend hours discussing it as I decide whether it is worth turning into a paper. When something moves from “potential working paper” to “actual working paper,” those hours turn into weeks.

    Sometimes an idea hits me out of the blue. For example, this morning I woke up at 5 am thinking about Other Transaction Authority and transparency concerns (as one does). So, I immediately turned to Claude and made sure I captured it. Maybe that becomes a follow-on piece, maybe not. But now that idea is preserved in my AI project. Other times, I read an interesting article, or someone says something on social media that I want to discuss in greater detail, pull background research on, and just think through. So I start discussing it with ChatGPT to help me decide whether it’s worth exploring.  

    Having a brilliant research assistant and sounding board I can fit in my pocket and consult whenever I want has dramatically reduced the friction of thinking through these issues. More importantly, it has helped a government procurement and anti-corruption expert analyze the legal implications of a new technology.

    How I Use AI In My Work

    I was inspired to write this piece because I frequently receive requests from students and early-career researchers for advice about my research, methodologies, and how I communicate complex ideas in a way that everyone can understand. They also often ask how I use AI in my work, so I figured it was time I captured it in writing.

    To be clear, this isn’t a best-practices guide, and I am certainly not suggesting everyone should write this way. Also, although what follows is presented linearly for the sake of organization, my writing process is anything but. I frequently toggle back and forth between different phases as I develop a piece, which ultimately makes the final product stronger and uniquely mine.

    Project Development

    One of the most valuable aspects of AI in legal scholarship is that it reduces friction in the project development phase of the writing process. It lets me develop a piece from anywhere, at any time, and receive feedback immediately. But, and this is probably the most important thing I will say in this entire piece: I bring my paper concepts to AI; I don’t rely on AI to tell me what to write about.

    Project development is the intellectual heart of all my articles. It’s probably the stage of my writing that irritates my family most. When I am developing a paper idea, you will find me talking to a chatbot constantly as I work through where I want to take things. Many of my pieces involve translating technical concepts for a broader audience or weighing in on policy or debate. But my favorite pieces stem from my anger—something has been mischaracterized, someone has overreached, or someone has created a policy that is objectively terrible. As I always tell my students: “write about what pisses you off.” It. Never. Fails.

    AI can be an incredible sounding board as you work through how to translate anger or passion into a piece, especially when you are working on an interdisciplinary piece or something outside your comfort zone. I could not have developed the same level of technical understanding of AI as quickly without using AI for research and feedback. I am not a technologist or an engineer. It took me six months of fighting with ChatGPT (seriously, fighting) to develop my framework for analyzing the risks of organizational conflicts of interest (OCI) embedded in the AI stack. ChatGPT kept defaulting to a traditional OCI analysis and couldn’t see how technology transforms it. And I could never have developed the same understanding of the “informational advantages” that stem from AI data exhaust as quickly without a tool that helped me appreciate the technical differences among types of AI “data,” so I could assess their impact on AI procurement. AI has meaningfully reduced barriers to this type of research. But I want to disabuse you of the notion that “AI assistance” or “reduced friction” means “outsourced thinking” or that using AI is “easy” or “fast.” What happens after I develop and begin drafting the piece has become even more labor-intensive than my pre-AI scholarship.

    Assemble & Write the Piece Yourself

    I distill weeks of research and extensive back-and-forth into a working outline in the tool, then I assemble and write the piece myself. This is critical. When AI, particularly Claude, tries to write polished prose, it often sounds like a bad imitation of Carrie Bradshaw, with each sentence trying to out-pun or out-sass the last. The end result is that all the good ideas you spent weeks developing wind up fighting for their lives, buried under a mountain of weird tics, snappy transitions, and overconfident phrasing. 

    But more importantly, letting AI take the wheel can strip the piece of everything that makes it uniquely yours. I may use an AI tool at different stages of the writing process, but the work still sounds unmistakably like the other articles I’ve written over the past two decades.

    Write So Everyone Can Understand It

    After I graduated from law school, I clerked for Judge Lawrence Margolis at the U.S. Court of Federal Claims. He taught me to write so everyone, including non-lawyers and non-procurement experts, could understand it. That lesson stuck with me, and I adhere to that principle in all my work.

    Long before I started using AI tools, I adopted a writing style that enables someone completely unfamiliar with an issue to understand my work. I learn complex concepts best through analogies, and so that is how I write.

    It’s why my AI tech stack wedding cake came so easily. When I would read other publications’ descriptions of the stack, it reminded me of an abstract painting. But explaining it like food? That I could do. The same with the Chef. Once you understand how the model works through the analogy, other, far more complex ideas start to make sense. AI has also become instrumental to this process as I try to explain complex procurement, anti-corruption, or technology concepts to audiences with little to no familiarity with the subject matter and seek feedback on whether a particular passage is sufficiently accessible to novices. This is a critical step, particularly if your work is interdisciplinary. 

    Stress-Test, Then Stress-Test Again

    If using AI during the project development phase of writing reduces friction, this phase multiplies it. My recent Lawfare article on GSA’s revised AI clause took me, conservatively, over 100 hours to research, develop, write, revise, stress-test, discuss with humans, revise again, present to humans, revise again, discuss with more humans, revise again, reduce to keep the word count within spitting distance of Lawfare’s word budget, submit for review and digest feedback from three editors, revise again, digest feedback from two more editors, and revise again before submitting the final draft.

    Stress-testing is my least favorite stage of my project development. Whenever I write something, I am laser-focused on accuracy, making sure I haven’t overstated anything, that all my claims are supported, and that technical explanations or analogies are airtight. I often joke, “I can’t believe I used to just let my pre-AI articles fly after finishing them!” This stage in my writing involves both AI and human review.

    First, I stress-test the piece with AI by repeatedly subjecting it to adversarial attacks. The stress-test is substantive (“Did I explain this correctly?”), stylistic (“Is it clear?” “Does it flow logically?” “Does it have typos or grammatical errors?”), and accessible (“Would someone unfamiliar with this topic understand this?”). The degree to which I review a piece for errors has probably become unhealthy. I know this because at some point both Claude and ChatGPT tell me to STOP (thankfully, Claude has at least stopped telling me to go to sleep).

    I often hear people say they use AI “just” for copyediting. That’s fine, but to me, one of the most valuable benefits of using AI in the writing process is that it doesn’t just focus on my grammar. I have never fully understood why, if someone has access to a machine that will say, “you didn’t describe that correctly,” “this new case undermines that argument,” or “this paragraph is inconsistent with what you said in a different article last year,” I wouldn’t use it. If I just wanted something to correct my grammar, I would use Grammarly. But I love having a tool that can flag substantive errors, prose that could be misinterpreted, and potentially inconsistent ideas. Sometimes I agree with the suggestions, but most of the time, I don’t. If an AI-suggested edit is correct and strengthens the piece, I accept it, because my goal is always to write the strongest, most accurate piece possible.

    One consequence of accepting this feedback is that your piece will likely carry fingerprints of AI involvement in the research and writing process—particularly sentences that have been stress-tested into oblivion. I am resisting the urge to turn this section into an ancillary rant about AI-detector shaming, but I have a strong aversion to the narrative that has evolved around this issue, which often collapses dramatically different writing processes under an “AI-GENERATED” label. Asking AI to draft an article from a prompt is not the same as using AI to complete tasks traditionally performed by research assistants and editors (e.g., iterative research, substantiation, editing). An AI detector scanning a final draft cannot reconstruct which of these processes has occurred, yet both can trigger a high “AI-Generated” score. 

    Once I finish stress-testing it with machines, I then bring the piece to humans (many humans). They often inspire me to take my work in a different direction or consider ways to improve it. Obtaining human feedback is essential. I received feedback about Buying Blind, my first major AI article, from 14 different people before I even submitted it to the Public Contract Law Journal. My shorter pieces have fewer reviewers, but I never submit a piece to a publisher without another person reading it first.  

    “Good Writing is 90% Good Editing.”

    If stress-testing introduces friction, editing introduces agony. Editing is painful and often requires me to cut prose I have worked so hard on. I agonize over the simplest sentences. I am laughing as I type this, remembering an exchange I had over text with a good friend while I was in the final stages of editing my Lawfare piece, Military AI Policy by Contract: The Limits of Procurement as Governance. After asking for his opinion about whether I should describe something as “procedural protections,” “legal protections,” or “certain protections,” I apologized for my editing insanity. He replied by reminding me that “Good writing is 90% good editing.”

    Like the other phases of my writing, the editing process isn’t linear. Because my articles usually develop over weeks or months, I often introduce new material during editing, swap out paragraphs after receiving feedback, and cut sections as my thinking evolves or new information changes how I want to address something. AI is incredibly helpful during this phase because it provides feedback on my potential edits. The point is that the project is never static until I am 100% satisfied with the piece and I submit the final draft.

    Verify Your Work, Then Verify it Again

    Yes, we all know that AI hallucinates. Yes, we know we need to check our work. But automation bias is real, so you must take time to actually verify things. Sometimes hallucinations are hilariously bad, but sometimes they’re insidious. One time, I asked ChatGPT to help me format some footnotes for one of my publications. The citation it returned changed the title of a GAO report from “Improper Payments and Fraud: How They Are Related but Different” to “Improper Payments and Fraud: How They Are Related but Not the Same.” Thankfully, I caught the error while triple-checking my citations.

    Follow the Rules

    If you are a student, you must (I repeat, you must) comply with your institution’s AI policy. If it is unclear, seek clarification. You may disagree with it, but that’s your rulebook while you are enrolled there. Don’t destroy your career before it has even started.

    As for publications, if they have an AI policy, you must follow it. The last thing you want is for your work to be retracted or for an AI disclaimer to appear at the top of your piece. The challenge is that disclosure rules are evolving in real time, in an environment where the terminology used to describe how people use these tools is wildly inconsistent. Terms such as “AI-edited,” “AI research,” “AI-generated,” and “AI-assisted” are interpreted differently, yet consequential policies increasingly use them without an agreed-upon baseline.

    As terminology and disclosure policies evolve, one theme appears to be emerging more consistently: the human author remains responsible for the work, regardless of the tools used to create it. Kevin Frazier and Alan Rozenshtein call this “absolute authorial accountability” in their excellent article, Large Language Scholarship. One benefit of that approach is that it remains an evergreen benchmark even as technology, expectations, and standards continue to evolve.   

    Have you “Outsourced” Your Thinking?

    AI can remove labor and friction, but I never want it to replace my thinking. Automation bias, cognitive offloading, deskilling, and other concerns are significant, so I think it is important to proactively mitigate these risks. That said, I am uncomfortable developing categorical recommendations about “appropriate” AI use when the research in this space is still evolving. So I am not going to tell you what to do or how you should do it. Instead, I can share some practices I have adopted to ensure AI doesn’t replace my own intellectual labor.

    First, I maintain a diverse research base. I find AI invaluable for research, but I also rely on news articles, government reports, scholarly research, books, and other reputable sources. 

    Second, I talk to humans about my ideas. They provide feedback, offer new perspectives, and often cause me to rethink much of what I have been mulling over as I develop my work. If you are a student or junior scholar, reach out to your professors, practitioners, or experts in the field. I never let students leave a meeting with me about their draft papers without at least 3 names of people they should contact to help them as they develop their work.

    Third, and this is critical, I can explain and defend my work without AI assistance. I also test my ideas as I develop them. All my speaking engagements double as a lab for my working papers. I tested my ideas about GSA’s revised AI clause with at least half a dozen audiences before finalizing it. Each group provided valuable feedback that helped me improve the piece. The beauty of a presentation is that you usually receive at least one question you never anticipate, and you must understand your work well enough to respond to it without turning back to AI to supply the answer.

    This practice also appears in emerging scholarship. Bednar et al.’s fascinating new article, Artificial Intelligence and Human Legal Reasoning, tested whether using generative AI early in a project reduced comprehension and impaired legal reasoning later, when AI was no longer available. The results were surprising, and I encourage you to read the article. In their discussion of best practices, the authors offer a similar heuristic to reduce the risk of cognitive offloading, explaining that if work could not be defended “in a demanding conversation with a skeptical colleague or judge without further preparation . . . [then] . . . the task has likely been delegated rather than assisted, and the professional and developmental costs of that delegation may outweigh its efficiency gains.”

    The Downside of Frictionless AI

    When I first started writing this piece, my 7-year-old asked what it was about. When I told her, she said, “I am going to draw a picture of you using AI.” And this is what she produced. Me, in a hoodie and the plaid Christmas pajama pants my mother-in-law bought for me last Christmas, arguing with Claude.

    On the one hand, it perfectly demonstrates the lesson I teach in all my AI trainings: an output is just the starting point. Always verify and always push back.

    But on the other hand, it highlights something more concerning. Something that I and many others have noticed over the past year. There is a downside to this “frictionless” tool. Yes, it helps us do things we never could before, and yes, it can make many daily tasks easier or more efficient. But for many of us, it has started to play an outsized role in our lives, absorbing much of our downtime. When my 7-year-old can draw a picture like this and knows the tool by name, perhaps it’s time to consider the other potential repercussions of this “frictionless” tool—a topic I will explore in a future blog post.

  • Corrupt Officials Are Like . . . Puppies?

    Corrupt Officials Are Like . . . Puppies?

    Note: Three days ago, we brought home Gryphon, our new 8-week-old golden retriever puppy (that’s him to the right – look at that face!).

    On our 7-hour drive home with him from Charlotte, NC, I thought about a piece I wrote in January 2013, when I was a senior editor of the FCPA Blog. I was inspired to write it while struggling to train our puppy, Annie. Annie crossed over the rainbow bridge a few years ago, but the post has always been one of my favorites.

    Now that we are training, Gryphon, I decided to republish the piece.

    *Thank you to Dick Cassin, founder and former publisher of the FCPA Blog, for allowing me to reshare this.

    Our new puppy, Gryphon

    Corrupt Officials Are Like …….Puppies?

    January 14, 2013

    There’s a very good reason why I recently fell off the blogging bandwagon.

    Annie

    The week before Thanksgiving, I adopted an adorable 8-week old puppy named Annie (that’s her in the picture on the left). If you’ve raised a puppy, you know they dominate your life for the first few months. You spend your days worried about housebreaking, teething, and puppy-proofing and (sleepless) nights worried about crate training (and again about housebreaking — it is always about housebreaking).

    A few weeks ago, after rewarding Annie with a treat for her good behavior, an idea crossed my mind: puppies are a lot like corrupt officials. Bear with me….

    As any new puppy owner knows, housebreaking is often one of the more challenging aspects of puppy training. After a few days in her new home, Annie appeared to be housebroken, but several weeks later started having accidents all over the house. What was I doing wrong? How could I fix this? I was desperate.

    After speaking about the issue with a colleague at school, he passed along a tip that worked well for his (two!) new puppies: “every time your puppy goes to the bathroom in the proper place, reward her with a treat.” That sounded easy enough to me — I assured him I would try it that night after work. He then cautioned me that this could create an expectation of treats, but I dismissed it. What’s the harm in a few extra treats if my carpet is spared?

    That night, I started rewarding Annie with a treat every time she went to the bathroom in the proper place. It soon became evident that my colleague is a genius: she stopped having accidents in the house and responded well to the new reward system. I was thrilled.

    A few days later, my glee turned to dismay. Whereas previously she had graciously accepted her reward with a happy wag of her tail, she now ran over to the treats immediately and impatiently demanded to be rewarded for her good behavior. The next day it got worse as she began faking bathroom breaks to obtain a treat. I had created a monster.

    My decision to start “rewarding” (ok, bribing) Annie to obtain a desired result initially worked, but then slowly backfired. She became pushy and started upping the ante—demanding a greater number of treats in exchange for the same result. The small “grease payments” that I gave Annie (in the form of puppy treats) pushed the deal through, but I almost created a bigger problem in the process.

    Corrupt officials are no different. Today they may ask for a small “grease payment” to expedite the issuance of a license, but tomorrow they will ask for bribes in exchange for zoning approvals. Once officials have flagged individuals or companies as willing to pay bribes, they will certainly demand payments in the future. Moreover, the demands nearly always increase in size. Why should corrupt officials limit their demands to $100 when they can ask for (and probably obtain) $1000? It is never a one-time deal and once companies start paying bribes, it is nearly impossible to stop if they want to continue doing business in a certain locale. The initial success won by the tiny grease payment has given way to a sophisticated and expensive bribery scheme.

    Annie is now almost 16 weeks old and is not only successfully housebroken, but has also stopped demanding treats for her good behavior. It was actually pretty easy to break that bad habit by slowly replacing her puppy “bribes” with praise. Sadly, the same technique is unlikely to appease a corrupt official….

  • What “We Don’t Train on Your Data” Really Means in Your AI Contract: Meet the Chef

    What “We Don’t Train on Your Data” Really Means in Your AI Contract: Meet the Chef

    When I teach AI procurement to government or industry audiences, I always include two slides at the beginning of every presentation. First, I teach the AI tech stack as a wedding cake. That helps people visualize the AI supply chain as tiers, from the foundational infrastructure supporting it (the cake stand) to the governance that surrounds it (the frosting). The cake answers the first question every acquisition professional must ask: what exactly am I buying? They need to understand that they are effectively buying a stack, not just an app.

    But the cake can’t answer the second question: how does the model at the center of that stack actually work? And what does that mean for your intellectual property, your business processes, your compliance obligations, and your procurement risk?

    Answering those questions requires a basic level of AI literacy, so to help explain it, I turn to another food-related analogy: the chef. The chef is the model, and her career illustrates how a model is developed, adapted, and used.

    One caveat before we start. Like the wedding cake, this is not a technical taxonomy, and it will not cover every configuration. Real-world AI deployments are more complex than a single chef, and the vocabulary is much larger than the five terms discussed below. But these are the basics, and they are essential for everyone negotiating AI contracts.

    Culinary school: training

    Before the chef ever cooks for you, she goes to culinary school. She learns knife skills, sauces, techniques, and food safety: a general capability across an enormous range of cooking. That’s training, the process that builds a foundation model’s broad ability, using massive amounts of data, generally before you show up. You usually had no say in her education, and yet you inherit it, good habits and bad, because it shaped everything she does.

    The apprenticeship: fine-tuning

    After school, the chef apprentices at a French restaurant. She’s now specializing—learning a particular cuisine through hands-on work. When she’s finished, she’s not just a chef anymore. She’s a French chef. That’s fine-tuning: taking a generally capable model and adapting it to a specific purpose. Keep in mind that the apprenticeship is training, too. It’s specialized training layered on top of what she learned at culinary school. Now you might be thinking, “Of course, an apprenticeship is training!” If so, great, because remembering this fact is really important during your contract negotiations (more on this below).

    One more thing about this stage, because everything that follows depends on it: what she learns in the apprenticeship isn’t a binder she can return at the end. It’s essentially muscle memory. For all practical purposes, she can no more hand it back than you can forget how to ride a bicycle.

    The recipe book: RAG

    Now she’s cooking at your restaurant, and tonight’s menu includes a dish she hasn’t made since culinary school. She could try to remember it, reaching all the way back to her lessons, reconstructing the recipe from a years-old impression. Sometimes she will get it right. Sometimes she will confidently produce something that looks sort of like the dish but isn’t quite right. That confident invention is a hallucination, and it’s especially likely when a model generates an answer from distant training rather than from a source in front of it.

    So, to reduce that risk, you hand her a recipe book to reference during service. That’s RAG, retrieval-augmented generation. The model doesn’t have to remember—it looks things up in materials placed in front of it, often materials you supplied. And if you’re wondering why a trained specialist needs your book at all, that’s the point. You are not relying only on her memory. You bring the information, and she brings the skills to work with it. This is why RAG exists: as a hedge against the model’s memory. The recipe book helps, but it isn’t a guarantee, so the system can still pull the wrong recipe, and the chef can still misread the right one.

    Standing instructions: configuration

    Before service, the chef gets the restaurant’s standing instructions: the house style, the permitted substitutions, the safety checks she must run. That’s configuration: the system prompts, settings, and standing policies that tell the model how to behave for you specifically. Similar to the recipe book, the instructions are something you handed her. They don’t change who she is. If you take the instruction sheet off the wall, she reverts to the way she used to cook.

    Dinner service: inference

    Next, the orders are placed, each with its own details (say, the allergy at table six), and she cooks[1] the order. Every plate served to diners is inference, the model applying everything above (her schooling, her apprenticeship, the recipe book, the instructions) to produce an output in response to a specific request. This is the only part of the chef’s entire career that you, the AI user, actually see. Everything else happened backstage, and yet it’s your name over the door.

    Once you understand her career, read a common assurance in AI contracting, “we don’t train on your data,” and notice how little it says.

    The AI contract’s promise

    Here’s why the chef is critical to your contracts. Once you understand her career, read a common assurance in AI contracting, “we don’t train on your data,” and notice how little it says.

    Start with the word “train.” Remember that the apprenticeship is training, too, so the promise should extend to fine-tuning as well as to the culinary school. But unless your contract defines the term, its scope is open to interpretation, and in day-to-day performance, the vendor’s reading is applied first, by the party with the least incentive to read it broadly. That’s why careful drafters spell it out: “train, fine-tune, or otherwise improve.” The promise also says nothing about the recipe book: where your supplied materials are stored, who can access them, and whether they are returned to you at the end of the contract. And it says nothing about the records kept while she cooks in your kitchen: the orders, your feedback, what’s sent back, what your kitchen struggles with. The chef doesn’t learn merely by serving dinner, but the vendor who staffed your kitchen can learn a great deal from those records, without ever training anything on them.

    The same goes for the other comforting promise, “we’ll delete your data when the contract ends.” If your data was used for fine-tuning and the vendor keeps the tuned model, deleting the files only removes them; it doesn’t remove what the model learned from them. You can take back the recipes. You cannot reliably make the chef forget what she learned.

    To be clear, this is not a story about vendors tricking anyone. It’s about a literacy imbalance. The vendor understands the chef’s entire career, and most buyers only ever see dinner service, yet given how much depends on understanding what you are agreeing to, both parties should come to the table with a roughly equivalent understanding. Without that basic literacy, you don’t know what you’re buying, what the risks are, or what your protections cover, and that’s true whether you’re a government agency or a company.

    The harder problem: what she learned

    The different parts of the chef behave differently, which is exactly why the vocabulary matters. The materials you supplied, the recipe book and the instructions, can often be segregated, inspected, and returned if the system is built that way and your contract requires it. The things she learned, the schooling and the apprenticeship, are embedded in the chef herself: hard to inspect, and difficult (though not impossible) to unwind. And once that learning happens, “give it back” is essentially off the menu.

    You can take back the recipes. You cannot reliably make the chef forget what she learned.

    That raises a set of questions that get complicated fast. Who has rights to the customization—the version of the chef built for you—and does the vendor keep the underlying chef it arrived with? What is the vendor allowed to do with that custom chef, and with what she learned, after your contract ends? Can it send her across the street to cook your signature dishes for your competitor? Restricting use and claiming ownership are different legal tools, and they raise different problems. These are not hypothetical questions: GSA’s revised draft AI clause is wrestling with all of them right now (I analyzed the earlier draft in Lawfare). I will address those issues in a forthcoming piece. The point is simpler: you cannot even ask these questions unless you know which part of the chef your contract is pointed at. And if you can’t ask them, you don’t know whether the protection you negotiated is real.

    Learn the cake. Learn the chef

    The wedding cake and the chef do different jobs, and you need both. The cake helps you understand what you’re buying. The chef helps you understand how it works. That’s why I begin every AI procurement training with the same advice: learn the cake and learn the chef. If you don’t, you have no idea what you’re negotiating or what you’ve already agreed to in your contracts.


    [1] Yes, I know that technically a “chef” doesn’t cook the dinner, but just go with it (please).  

  • Absolute Discretion Is Not Deregulation: What the Latest Directive Against Anthropic Reveals About Federal AI Governance

    Absolute Discretion Is Not Deregulation: What the Latest Directive Against Anthropic Reveals About Federal AI Governance

    I spent the weekend thinking about the latest government directive regarding Anthropic, and I kept returning to a theme from my recent scholarship.

    For the past year and a half, I’ve researched and written about the federal government’s approach to AI governance. Much of my concern centers on a false binary: the claim that governance and innovation are opposing forces. That oversight is a drag, that safeguards are “blockers,” and that the only way to win the AI race against China is to treat regulation and bureaucratic process as the enemy of AI dominance. It is the underpinning of this administration’s AI policy. Don’t take my word for it. Read some of the statements made repeatedly across this administration:

    • “The United States continues to lead the world in Artificial Intelligence (AI) because of the enormous talent and innovation of our AI industry, and because we refuse to stifle this innovation with overly burdensome regulation.”
    • “It is the policy of the United States to sustain and enhance the United States’ global AI dominance through a minimally burdensome national policy framework for AI.”
    • “To maintain global leadership in AI, America’s private sector must be unencumbered by bureaucratic red tape.”

    I have argued that this is the wrong approach to AI governance. In Buying Blind: Corruption Risk and the Erosion of Oversight in Federal AI Procurement, I argued that governance and innovation are not opposing forces but mutually reinforcing conditions for responsible AI acquisition and deployment. Governance sustains innovation by ensuring fair, transparent markets and by building the institutional trust that adoption depends on. In Governance as a “Blocker”: How the Pentagon’s New AI Strategy Trades Oversight for Speed, I walked through decades of procurement history to show what happens when we treat oversight as the enemy of progress. I pointed to other mature industries that run critical infrastructure, such as aviation, pharmaceuticals, and financial auditing, that long ago reached the opposite conclusion: in high-risk systems, oversight is the condition that enables innovation without destroying trust.

    What I never considered, in any of my work, was that the speed-first administration—the one that treats oversight as the thing standing between America and global AI dominance—would be the one to pull the trigger. According to New York Times reporting, Anthropic received 90 minutes’ notice before the government moved to restrict foreign-national access to its Fable 5 and Mythos 5 models on national security grounds. According to Anthropic, the restriction applies to any foreign national, including its own employees. It was broad enough that the company had to disable both models for all customers to comply. This came on the heels of a supply-chain-risk designation against the same company, announced via tweet, which was later backfilled with a justification and preliminarily blocked by a federal judge, who found serious procedural problems and that Anthropic was likely to succeed on its claim that the government retaliated against it for protected speech.

    There may well be a legitimate national security concern this time, but the way this was done makes it impossible to know and casts even a justified action in the worst possible light. The problem is not that the government exercised discretion; national security demands such latitude. Administration officials reportedly claim the company failed to honor a cybersecurity executive order, but a dispute like that is precisely what a fair process is meant to resolve, not a 90-minute ultimatum. What is striking is the absence of any meaningful process.

    In Governance as a “Blocker,” I discussed my colleague Professor Joshua Schwartz’s description of procurement regulation as a pendulum that swings between the costs of overregulation and underregulation. When rigid rules create inefficiency, policymakers push for discretion; when discretion enables abuse, the system swings back toward constraint. Neither extreme is stable, and across administrations, the government rarely gets the calibration right. But I had been thinking about that pendulum as a swing between too many rules and too few. What happened this week is something else entirely: not too few rules, but no real process. Absolute discretion is not the deregulated end of the pendulum. It is the unstable end—the point where the absence of any constraint produces exactly the abuse that has always swung the pendulum back toward a period of aggressive regulation and oversight.

    We’ve seen this movie before, and we know how it ends. Operation Ill Wind exposed systemic corruption in defense procurement and led to the passage of the Procurement Integrity Act. The pricing, waste, and defense management scandals of the 1980s led to the creation of the Packard Commission. Of course, the actors differ—then it was contractors exploiting lax oversight, now it is the government wielding unchecked discretion. But the lesson holds: extremes never last and ultimately lead to overcorrection. And it is why the deepest irony of this ordeal is that the people who believe they are protecting innovation from governance are governing in ways that have always produced more of the regulation they fear.

    Start with a single firm. Stable, predictable governance is what makes frontier investment rational; arbitrary exclusion makes it a gamble. Nothing chills this incentive faster than knowing your market access can vanish overnight, on a contested basis, and with no meaningful opportunity to respond before it does.

    The administration says it wants to lead the AI race, refuses to stifle innovation, and insists America’s AI leadership relies on a thriving private sector. Then it moves against a leading developer on national security grounds, leaving the company with no choice but to pull its best models for everyone to ensure compliance. That is a strange way to treat the private sector on which American AI leadership depends.

    The damage does not stop at one firm. An administration that governs this way will not avoid the heavy regulation it fears. It is manufacturing the conditions for catastrophe or abuse that, in every cycle I’ve documented, triggers exactly that response. The speed-first camp thinks it is at the pendulum’s deregulated end, but it is standing at the end that swings back hardest.

    In Blacklisting by Tweet is Not a Thing, I asked what kind of business partner the government wants to be. But the concerns raised by this incident are far more significant for the future of frontier AI development. The administration states that America’s leadership in AI depends on unleashing the full potential of its private-sector innovators. Yet within hours, from a midday call to an afternoon directive, it left a leading developer with little choice but to take its best models offline for everyone. Every other frontier developer is watching closely. You cannot unleash an industry on those terms.

  • Fraud in Medicare and Medicaid

    Fraud in Medicare and Medicaid


    In February 2026, I testified before the House Energy and Commerce Subcommittee on Oversight and Investigations at a hearing titled “Common Schemes, Real Harm: Examining Fraud in Medicare and Medicaid.” My written testimony and my opening statement are available below.

    After the hearing, I received Questions for the Record from Representative Earl L. “Buddy” Carter (R-GA) and Representative Debbie Dingell (D-MI). They asked:

    • From a government-contracts perspective, what vulnerabilities in Medicare supplier enrollment allow foreign-controlled shell companies to exploit the system, and how enhanced disclosure or penalties for nondisclosure could help.
    • How to strengthen the integrity of Medicare and Medicaid without jeopardizing access for beneficiaries or overburdening already overworked providers.
    • How the federal government can better support the state and federal agencies responsible for protecting Medicaid.

    My full response, available below, addresses a few recurring themes:

    • One of the most effective responses to foreign-controlled shell companies is to close domestic corporate transparency gaps. The vulnerability begins at company formation, upstream of the Medicare/Medicaid enrollment form.
    • Ownership opacity is a cross-program problem. Procurement, grants, and health programs all turn on knowing who actually owns and controls an entity, and enrollment too often verifies the paperwork rather than the person behind it.
    • Recovering stolen funds depends on preserving dedicated cross-border asset-tracing and recovery capacity, not only front-end controls.
    • Stronger integrity is a matter of better targeting rather than heavier enforcement: classifying conduct accurately, because fraud is distinct from improper payments, waste, and error; matching the tool to the risk; and treating analytics as triage rather than a substitute for human judgment.
    • Effective Medicare and Medicaid oversight depends on stable funding, independent and continuous oversight institutions, and systematic federal-state data sharing.

  • Federal AI Has Outrun Its Governance: The USDA OIG Report

    Federal AI Has Outrun Its Governance: The USDA OIG Report

    I am rooting for the use of AI in government. Every day, I read about a new and exciting government use case. I write about procurement governance and risk because I want federal AI deployment to succeed—so it brings me no joy to write this piece.

    When OMB M-25-21 and M-25-22 were released in April 2025, the governance expectations for agency AI use looked reasonable—Chief Artificial Intelligence Officers (CAIOs), inventories, risk management, Authorizations to Operate (ATOs), generative AI policies, impact assessments, etc. Yet by mid-2025, the administration’s deregulatory posture on AI policy appeared to extend to the federal government’s procurement and deployment of AI. Across multiple policies, programs, and public statements, the administration signaled that agencies were expected to accelerate AI adoption, even as governance structures and technical capacity struggled to keep pace.

    In my article, Buying Blind: Corruption Risk and the Erosion of Oversight in Federal AI Procurement, I warned about exactly this dynamic:

    The deregulatory trajectory has narrowed pathways for implementing [government AI procurement] safeguards. Commercial acquisition preferences direct agencies toward procurement methods least compatible with governance protections, while simultaneous workforce cuts leave fewer acquisition professionals with less AI-specific expertise to implement whatever safeguards remain available.

    M-25-22 articulates principles for responsible AI procurement while the post-AI Action Plan environment removes the regulatory authority and workforce capacity necessary to implement them. Without binding regulations or agency-wide policies, M-25-22’s safeguards exist as aspirations rather than obligations.

    And in my article, Governance as a“Blocker”: How the Pentagon’s New AI Strategy Trades Oversight for Speed, I addressed the broader leadership and adoption dynamic:

    [T]one at the top matters. When leadership frames safeguards as barriers, the organization comes to see compliance as an obstacle rather than a risk-management tool. Adoption metrics measure whether AI capabilities are being used and at what pace, not whether the governance infrastructure underlying those deployments is sound. The practical effect is to shift risk downstream, where it can surface as security incidents, performance failures, bid protests, or mission impact.

    We now have new evidence of what governance failure looks like in practice. On May 12, the United States Department of Agriculture’s Inspector General (IG) released a report, Cybersecurity of Artificial Intelligence Technology at USDA, determining that USDA has not fully implemented cybersecurity and governance controls within AI systems in compliance with federal standards, leaving the agency at risk of data breaches or reputational harm.

    Specifically, the IG found:

    • No security authorization for 89% of AI use cases. OIG found that 73 of 82 operational AI use cases lacked a required system ATO prior to operation and were not recorded in CSAM. An ATO is effectively a security sign-off: someone in charge must review a computer system for risks and approve it before it can run on a federal network. The Federal Information Security Modernization Act (FISMA) and USDA’s own departmental regulations require it for any federal IT system.
    • No generative AI policy, despite widespread GenAI use. USDA missed the December 29, 2025 OMB M-25-21 deadlines to update agency IT policies and to develop a generative AI (GenAI) policy. The Office of the Chief Information Officer (OCIO) told OIG it has not updated or developed any AI policies or procedures.
    • No documented impact reviews for high-impact AI. OIG sampled eight AI use cases against the high-impact criteria: civil rights, access to government resources, public safety, and critical infrastructure. USDA’s own AI inventory separately marks facial-recognition surveillance and AI tools for cover crop mapping, planting date detection, and acreage and crop type validation as high-impact. OIG found OCIO had not performed or documented the required impact reviews.
    • No reliable AI inventory. USDA’s AI inventory relies entirely on an annual self-report data call. OIG examined 82 operational use cases and concluded that the inventory cannot be verified as complete or accurate.

    Beyond these findings, OIG flagged a deeper problem: shadow AI. Shadow AI is the unsanctioned use of AI tools by employees without the formal approval or oversight of the information technology (IT) department. With an inventory built on annual self-reporting and no policy governing GenAI use, USDA cannot know what AI tools its workforce is running on departmental data. The OIG concluded that the methodology itself produces this risk.

    Although shadow AI is a significant concern, it is equally alarming that even sanctioned AI can create major risks when agency-level governance is missing—no generative AI policy, no ATOs, no impact assessments, no reliable inventory.

    The USDA report does not establish that these use cases came through GSA’s AI offerings through its OneGov program. That distinction is important. The report documents an agency-level governance failure, not a OneGov procurement failure. But OneGov is still relevant because it shows the adoption environment in which those failures now operate: AI tools are being made available across government quickly and cheaply, through centralized contracting channels, while responsibility for inventories, ATOs, impact assessments, and internal use policies remains with the ordering or deploying agency.

    OneGov has reached 3.4 million federal users with AI tools at near-zero cost: OpenAI’s ChatGPT Enterprise and Anthropic’s Claude Enterprise at $1 per agency for one year, Google’s Gemini at $0.47 per agency through 2026, xAI’s Grok at $0.42 per agency for eighteen months, and Perplexity at $0.25 per agency for eighteen months. As I wrote in Buying Blind, “below-market pricing drives widespread adoption across the federal government, locking in dependencies before agencies understand costs, develop expertise, establish governance, or build exit strategies.”

    GSA may be thinking about AI governance, but we cannot say the same for USDA. Centralized purchasing does not solve the problem of decentralized governance. Whether USDA employees are using centrally procured tools, agency-procured tools, embedded AI features, or unsanctioned AI accessed off the books, USDA still needs the controls OIG found missing.

    That’s the most critical point: the procurement channel may vary, but the governance obligation does not.

    None of this has produced the kind of high-profile government AI debacle that captures public attention—at least, not that we know of. But the conditions described in this report are exactly the kind that produce one.

    The structural separation between centralized procurement and decentralized governance is the downstream consequence that Buying Blind warned about. USDA, by itself, is what happens when AI adoption outpaces governance and capacity.

    The conditions producing these failures are present across the federal government. Whether other agencies have built governance to match those conditions is a question we will answer only through additional IG evaluations. USDA may be an outlier, or it may be one of the clearest looks so far at agency-wide AI governance. With AI adoption continuing to outrun governance and capacity, USDA is what we can see. The more troubling concern is what we can’t.  

  • The Government Doesn’t Need a Licensing Regime to Reshape Frontier AI

    The Government Doesn’t Need a Licensing Regime to Reshape Frontier AI

    Yesterday, National Economic Council Director Kevin Hassett said the administration is studying an executive order that would require AI models to be vetted “just like an FDA drug” before public release.

    People are underestimating the influence public procurement already has on the frontier AI debate.

    To help understand why, a brief history lesson is instructive. Section 508 of the Rehabilitation Act requires federal agencies to ensure their information and communication technology is accessible to people with disabilities.

    Section 508 did not directly regulate the commercial ICT market—it operated through federal procurement. Vendors seeking federal business typically had to provide accessibility documentation, usually through Accessibility Conformance Reports that explain the extent to which their products conform to federal accessibility standards. These reports became credentials beyond federal procurement: states added similar requirements, enterprise customers requested the same documentation, and vendors found it cheaper to design accessibility into products than to maintain separate federal and commercial lines. In short, federal acquisition policy shaped the commercial baseline beyond its original reach.

    It’s early days, but that same dynamic is emerging for frontier AI.

    On May 1, the Pentagon announced agreements with SpaceX, OpenAI, Google, NVIDIA, Reflection, Microsoft, AWS, and Oracle to deploy advanced AI on classified IL6 and IL7 networks. On May 5, the Center for AI Standards and Innovation (CAISI) announced agreements with Google DeepMind, Microsoft, and xAI covering pre-deployment evaluation, classified-environment testing, and information sharing. Both announcements follow a March 18 partnership announcement between GSA and NIST to “Boost AI Evaluation Science in Federal Procurement.” Under this partnership, CAISI will provide tools and guidance to help GSA evaluate advanced AI models, select and interpret benchmarks, conduct testing in federal workflows, and develop evaluation guidelines and checklists for other agencies to use.

    These announcements are not formally coordinated, but read together, they show the federal government’s growing leverage over companies central to the frontier AI stack. The CAISI agreements are formally voluntary, but leverage operates regardless of whether participation is mandated. The government does not need a freestanding statutory mandate or an executive order. It can achieve much the same effect through procurement by making cooperation on testing, evaluation, classified-environment assessment, documentation, and deployment constraints part of how frontier developers maintain federal market access. For companies seeking sensitive federal AI work, especially classified defense work, this is becoming the new price of admission.

    While stakeholders debate whether the latest developments amount to a licensing regime in disguise, the government is quietly building much the same effect through procurement—and calling it voluntary.

    Students of federal procurement history are well aware of this familiar pattern. The government does not always need to win the underlying legal question to shape behavior. It needs the leverage to be credible enough that regulated parties act on it.

    If CAISI follows the Section 508 path, federal buyers will eventually treat CAISI evaluation, testing artifacts, model documentation, and lawful-use terms as conditions of adoption. Those conditions will travel through prime contractors, cloud marketplaces, subcontractors, regulated enterprise buyers, and product design. Vendors will find it cheaper to build one product line than two, and federal evaluation will become the commercial default. Of course, not every federal requirement will spill over. Vendors may maintain separate model versions for specific usage constraints, but evaluation artifacts, documentation practices, and testing infrastructure are more likely to be standardized across product lines.

    At this stage, though, the infrastructure is still nascent. Unlike Section 508, CAISI currently lacks the statutory backing, FAR integration, and enforcement ecosystem that made Section 508 transformative. Still, the trajectory is what matters. The licensing-authority debate asks whether the executive branch can stop the release of commercial AI models. The procurement question asks what the government can require of any model used in federal work. The government does not need to win the first debate. Procurement is already reshaping the market.

  • From “Dying Donkeys” to DEI Clauses: The False Claims Act Was Never Meant to Police This

    From “Dying Donkeys” to DEI Clauses: The False Claims Act Was Never Meant to Police This

    Congress enacted the False Claims Act (FCA) in 1863 in response to procurement fraud committed against the Union Army during the Civil War. As Fred Albert Shannon’s history of the Union Army recounts:

    For sugar, [the government] often got sand; for coffee, rye; for leather, something no better than brown paper; for sound horses and mules, spavined beasts and dying donkeys; and for serviceable muskets and pistols, the experimental failures of sanguine inventors, or the refuse of shops and foreign armories.

    163 years later, the statute’s core framework remains intact, but the conduct it targets would be unrecognizable to its drafters.

    The FCA has recovered more than $85 billion since the 1986 amendments. The qui tam mechanism, which allows private citizens to file FCA lawsuits on the government’s behalf and collect a share of the recovery, is one of the most effective fraud-detection tools in federal law. The FCA has evolved well beyond “dying donkeys” and now reaches myriad contract compliance obligations, including cybersecurity and labor law. None of what follows is an argument against the FCA or the qui tam provisions.

    In January 2025, Executive Order 14173, “Ending Illegal Discrimination and Restoring Merit-Based Opportunity,” directed agencies to include contract and grant terms requiring counterparties to agree that compliance with federal anti-discrimination laws is material to payment decisions for FCA purposes and to certify that they do not operate programs violating those laws. Last month, the administration took an extra step by requiring a mandatory clause in federal contracts and “contract-like instruments,” positioning the FCA as the enforcement mechanism for determining, among other things, whether a contractor’s mentorship program constitutes disparate treatment under a contractual requirement with no established meaning.

    What distinguishes this application is that the government has aimed the FCA at an underlying compliance obligation too vague to support the weight the statute places on it, extending the statute beyond its intended scope in ways that should concern anyone seeking to protect this important tool.

    The Executive Order

    On March 26, 2026, the President issued Executive Order 14398, “Addressing DEI Discrimination by Federal Contractors.” It directs executive branch agencies and independent establishments subject to the Federal Property and Administrative Services Act (FPASA) to include a mandatory clause in contracts and “contract-like instruments,” including subcontracts and lower-tier subcontracts, prohibiting “racially discriminatory DEI activities.” The order defines this as “disparate treatment based on race or ethnicity” across recruitment, hiring, promotions, vendor agreements, program participation, and resource allocation.

    Much of the clause restates contractual compliance obligations that already exist. Contractors know that their own noncompliance with a contract clause can result in termination, suspension, or debarment, and that submitting claims while knowingly noncompliant with material contract requirements creates FCA exposure. Credible evidence of a violation could also trigger mandatory disclosure obligations.

    On the subcontractor side, primes are already responsible for subcontractor performance and face potential FCA liability when they have knowledge of a subcontractor’s noncompliance. When a subcontractor’s conduct provides credible evidence of a covered violation, including a civil FCA violation, it can trigger the prime’s mandatory disclosure obligations under FAR 52.203-13. What is new is the clause’s reporting threshold for subcontractor conduct that is “known or reasonably knowable” and that “may violate” the clause. Although undefined in the EO, this language appears to set a lower threshold for reporting than the mandatory disclosure “credible evidence” standard. A provision this broad is likely to encourage primes to over-report, an issue that already exists under the mandatory disclosure rule.

    What is also new, and particularly relevant to the FCA, is the clause requiring contractors to acknowledge that compliance is material to the government’s payment decisions, citing 31 U.S.C. § 3729(b)(4). This language attempts to effectively bypass one of the most contentious issues of modern-day FCA litigation by requiring contractors to acknowledge materiality at the time of contract award. In addition, the Attorney General is directed not only to consider FCA actions for violations but to expedite qui tam review, a directive that, if implemented, would dramatically accelerate DOJ’s current practice of extending seal periods well beyond the statutory 60-day window.

    Anti-discrimination obligations have been part of federal contracts since Executive Order 11246 in 1965. They were historically enforced through the Office of Federal Contract Compliance Programs (OFCCP) administrative compliance regime, but the current administration has rescinded EO 11246 and directed the Department of Labor, including OFCCP, to “cease and desist all investigative and enforcement activity” under it. Noncompliance with anti-discrimination requirements has theoretically always posed an FCA risk, but no administration before this one has built an enforcement structure around that theory: mandatory FCA materiality language in contracts and certifications, creation of the Civil Rights Fraud Initiative, and express direction that DOJ consider FCA actions where contractors violate federal civil rights and anti-discrimination laws. These provisions clearly signal that the government expects compliance and will use every available tool to enforce it.

    The Clause’s Falsity Problem

    The FCA does not define one of its core elements: falsity. What is “false” depends on the facts of each case. Yet as an essential element of an FCA violation, the threshold question is always whether the claim is, in fact, false.

    There are two types of falsity in FCA cases: factual and legal. Most people are familiar with factual falsity, such as delivering a product that doesn’t work or billing for services not performed. Legal falsity, in contrast, focuses on the compliance obligations imposed on a contractor by some ancillary statutory, regulatory, or contractual requirement. Legal falsity has expanded the FCA’s reach far past its original factual-falsity roots, and in many domains that expansion has been productive.

    Congress revived the statute in 1986 for the same reason it was enacted in 1863: to address concrete, provable fraud against the government. Modern extensions follow the same principle. Cybersecurity requirements such as CMMC levels and NIST controls provide clear benchmarks. A false certification of compliance with those requirements is a provable misrepresentation. The same applies to federal labor law requirements under the Davis-Bacon Act. Prevailing wages are published, payroll records are auditable, and the certification either aligns with reality or it doesn’t. This is legal falsity working as intended because the underlying obligation provides a clear standard against which a representation can be judged true or false.

    The DEI clause is fundamentally different. “Disparate treatment” is a well-established concept in employment discrimination law, but the clause applies it to categories of conduct where the falsity determination defies straightforward analysis. A mentoring program that recruits from underrepresented groups. Aspirational diversity goals without quotas. Employee resource groups organized around shared backgrounds or identities. Whether any of those constitutes disparate treatment is a genuine legal question, and reasonable compliance officers may answer differently.

    Even DOJ has acknowledged the difficulty of drawing this line. In Fourth Circuit litigation over EO 14173, DOJ “represented at oral argument that there is ‘absolutely’ DEI activity that falls comfortably within the confines of the law.” At the February 2026 Qui Tam Conference, Brenna Jenny, Deputy Assistant Attorney General for DOJ’s Commercial Litigation Branch, stated that enforcement targets practices that resulted in discrimination, “not merely” DEI programs, and that “promoting diversity isn’t inherently unlawful, nor is it a protective talisman.” If the government’s own lawyers concede in federal court that lawful DEI exists, and its lead enforcement official distinguishes between lawful diversity efforts and actionable discrimination, the question of where that line falls for any given program is precisely the kind of interpretive dispute the FCA is poorly suited to resolve.

    In United States ex rel. Lamers v. City of Green Bay, the court found that the FCA does not resolve differences in interpretation arising from a disputed legal question. In United States v. AseraCare, Inc., the court’s position was stronger: a reasonable disagreement about a judgment call, without other evidence of objective falsehood, is not sufficient to establish falsity. To be clear, other circuits have declined to adopt AseraCare’s objective falsity requirement. In United States ex rel. Druding v. Care Alternatives, the Third Circuit rejected a categorical rule that expert disagreement defeats falsity and held that the “objective falsity” framework improperly conflated falsity with scienter. This split, however, does not save the government here. Even circuits that reject AseraCare’s framework still require the government to prove the claim is false. When the underlying obligation is a novel contractual prohibition with no interpretive case law, no agency guidance, and no enforcement history, that proof problem persists regardless of which side of the split the court takes.

    The problem is not that courts cannot interpret the clause. The problem is that the FCA attaches treble damages, per-claim penalties, qui tam bounties, and reputational damage to the resolution of that interpretive question. That is disproportionate when the underlying dispute is about the legal characterization of a business practice under a standard that has never been applied.

    Even If It’s False, Is It Material?

    Even if the government clears the falsity threshold, it still must demonstrate that the falsehood would be capable of influencing the payment decision. In Universal Health Services, Inc. v. United States ex rel. Escobar, Justice Thomas made clear that materiality is “rigorous” and “demanding,” designed to ensure that the FCA is not a “vehicle for punishing garden-variety breaches of contract or regulatory violations.” The opinion also establishes that the government’s own designation of a requirement as material is relevant but not dispositive. The DEI clause does exactly what Escobar warned against, with statutory precision: the contractor “recognizes” that compliance is material to payment decisions “for purposes of” § 3729(b)(4). No appellate court has yet considered whether this kind of contract drafting satisfies Escobar’s materiality standard.

    In United States ex rel. Petratos v. Genentech, the Third Circuit affirmed dismissal where the relator (the whistleblower plaintiff in FCA cases) effectively conceded that CMS consistently reimbursed claims with full knowledge of purported noncompliance, holding that a condition-of-payment label alone does not establish materiality. Declaring a requirement material by contract is not the same as treating it as material in practice. In contrast, United States ex rel. Badr v. Triple Canopy, Inc., shows what a strong legal falsity case looks like. The Fourth Circuit found the Government properly pled materiality where the requirement went to the essence of the contracted service: marksmanship qualifications for base security guards. The court further noted that the contractor’s “elaborate cover-up suggested that the contractor realized the materiality of the marksmanship requirement.”

    Absent overt disregard for the clause’s requirements, such as the compensation-tied-to-demographics and race-restricted program patterns DOJ has flagged, FCA cases alleging DEI violations are unlikely to demonstrate Triple Canopy-level clarity. They are more likely to involve disputed characterizations of HR programs and business practices, not falsified qualification records. The distance between Triple Canopy and a contested mentoring initiative is the distance between fraud and a contract dispute.

    The government’s own conduct since January 2025 may further preclude a finding of materiality the first time this is tested. The administration has signaled this enforcement priority for over fourteen months, stood up the Civil Rights Fraud Initiative in May 2025, and DOJ has reportedly opened investigations into DEI practices at specific companies. But investigations are not the payment-behavior evidence Escobar treats as probative. There appears to be no publicly reported instance of an agency refusing to pay, withholding funds, or imposing a similar penalty for noncompliance with the DEI certification requirement. Implementation of the certification regime was complicated by litigation, which provides the government with a plausible explanation for the thin public record. It is possible that there have been no allegations of noncompliance for the government to respond to, but if there have been, that gap undercuts the government’s claim that these certifications carry demonstrated payment significance in practice.

    The Clause Doesn’t Reach Innocent (Or Even Negligent) Interpretations

    Another essential element of the FCA is its scienter requirement: proof of actual knowledge, deliberate ignorance, or reckless disregard of the truth or falsity of a claim. Given the clause’s objectively fuzzy requirements, United States ex rel. Schutte v. SuperValu Inc. is directly relevant. At issue in SuperValu was the then-popular FCA defense of objective reasonableness. If a defendant had an objectively reasonable interpretation of its legal requirements, it could defeat the knowledge element absent authoritative agency guidance that would have warned it away from the mistaken belief. SCOTUS rejected that defense, clarifying that what matters is the defendant’s belief at the time of submitting the claim, not whether a reasonable interpretation existed afterward. Documented good-faith legal review and genuine restructuring provide a substantial defense, especially if supported by agency guidance. The same indeterminacy that makes falsity difficult to prove makes scienter harder to establish. If reasonable compliance officers disagree about what the clause requires, the government will struggle to show that a contractor knowingly disregarded a standard that no one has been able to define.

    The Law Is Irrelevant When the Threat Is Enough

    The government will face significant doctrinal obstacles if it tries to bring a borderline case alleging a violation of the DEI clause. Yet those obstacles are irrelevant to a contractor’s decision on what to do next quarter. The government just announced another record-breaking year for qui tam filings, now approaching 1,300 per year. Competitors, professional relators, and any employee with access to HR records or training materials are potential whistleblowers. For a company facing a choice between investigation costs, treble damages, per-claim penalties north of $28,000, and debarment exposure on one side, and canceling programs or eliminating policies that could be characterized as “DEI” on the other, the calculus is straightforward. The rational contractor complies regardless of the merits.

    The government bypassed proportional contract administration tools and stacked the most severe civil and administrative remedies against an obligation that reasonable lawyers cannot agree on how to apply. And the compliance pressure is self-reinforcing. Every agency that withholds payment or takes corrective action in response to alleged noncompliance contributes to an enforcement record that the government will use as evidence of materiality in future cases. And every contractor that restructures a DEI program validates the threat, giving the government evidence that the market itself treats the requirement as consequential. The government does not need to win in court today. It needs contractors to act as though it could.

    Using the FCA this way carries costs beyond the immediate policy objective. It dilutes the statute’s deterrent effect against fraud and burdens the qui tam system with cases that belong in contract administration, not fraud litigation. Every borderline DEI case that consumes DOJ resources is one in which actual fraud may not get the attention it deserves.

    The government has used false compliance certifications as the basis for FCA enforcement for decades. What this administration has introduced in the DEI orders is a more aggressive step: writing FCA materiality directly into the contract clause and directing the Attorney General to consider FCA actions. If this approach proves effective, future administrations are almost certain to use it for their own policy priorities.

    Each time the government aims this framework at a standard too ambiguous to support it, it risks producing doctrine that reshapes FCA enforcement well beyond the immediate context. The risk is compounded here because the government has built an enforcement regime that incentivizes qui tam filings but cannot control which cases are filed. It has the authority to dismiss meritless qui tam actions, but the administration is unlikely to dismiss cases alleging the very conduct its own executive order targets. Bad facts make bad law, and the law they make applies to every FCA case that follows, not just DEI cases. But that is a problem for the courts. For contractors, the calculation is simpler. The government does not need to win these cases. It just needs contractors to believe it might.

  • Blacklisting by Tweet Is Not a Thing: What the Federal Contracting Rules Require When Firing a Contractor (Like a Dog)

    Blacklisting by Tweet Is Not a Thing: What the Federal Contracting Rules Require When Firing a Contractor (Like a Dog)

     “I don’t know if it’s murder, but it looks like an attempt to cripple Anthropic. And specifically, my concern is whether Anthropic is being punished for criticizing the government’s contracting position in the press.”

    Those words, spoken by Judge Rita Lin at the March 24 hearing on Anthropic’s motion for a preliminary injunction against the Department of Defense and sixteen other federal agencies, address the question that government contractors and Silicon Valley have been asking for the past month.

    I have described contractor blacklisting as the “corporate death penalty,” a “corporate death sentence,” and the “corporate grim reaper,” but corporate “murder” is a first.

    In late February, the President directed every federal agency to stop using Anthropic’s AI technology. The Secretary of Defense also designated Anthropic a supply chain risk to national security under 10 U.S.C. § 3252 after the company refused to remove usage restrictions from its contracts with the Department. Anthropic filed suit in the Northern District of California alleging that the government’s actions were unlawful. It is separately challenging a covered procurement action under 41 U.S.C. § 4713, which is subject to exclusive review in the D.C. Circuit. I have discussed the underlying policy dispute, including the “all lawful use” directive and the structural gaps in AI procurement governance, in a prior Lawfare piece. Alan Rozenshtein’s Lawfare piece addresses the remedy question from a national security law perspective.

    On March 26, Judge Lin granted Anthropic’s motion for a preliminary injunction, enjoining the president’s social media directive, the secretary’s social media directive, and the Section 3252 supply chain designation. The order is stayed for seven days. The final paragraph of the preliminary injunction order captures in three sentences what this piece explains at length:

    This Order restores the status quo. It does not bar any Defendant from taking any lawful action that would have been available to it on February 27, 2026, prior to the issuances of the Presidential Directive and the Hegseth Directive and entry of the Supply Chain Designation. For example, this Order does not require the Department of War to use Anthropic’s products or services and does not prevent the Department of War from transitioning to other artificial intelligence providers, so long as those actions are consistent with applicable regulations, statutes, and constitutional provisions.

    Everyone expects the government to appeal, so that is probably next. But the question I keep hearing is, what do the federal contracting rules require when the government decides it no longer wants to work with a contractor?

    The procurement system provides detailed, well-established answers to that question, developed by policymakers over decades. Section 3252 required the Secretary to determine, in writing, that less intrusive measures were not reasonably available, and to tell Congress which alternatives were considered and why they were rejected. This piece describes some of those measures.

    The Tools the Government Had But Didn’t Use

    First, the government is not required to contract with Anthropic. Under Perkins v. Lukens Steel, the government enjoys broad discretion to determine with whom it will do business and on what terms. No one disputes that the Executive Branch can decide it no longer wants a particular vendor’s products or services, but it must do so consistent with the law. Beyond this, the federal contracting system offers a range of tools for ending a contractor relationship, and they escalate in severity. With respect to Anthropic, the government skipped to the most extreme one.

    The options available to the government for severing ties with Anthropic depend on the type of contract involved. Based on the public record, Anthropic had FAR-based contracts, including a GSA “OneGov” agreement; deployments through third-party contractors, including Palantir’s Maven Smart System; and a prototype Other Transaction (OT) with the Chief Digital and Artificial Intelligence Office. The tools available to end each relationship differ accordingly.

    We do not know the full picture, but the government had multiple defined processes available to end its relationship with Anthropic and begin removing it from federal systems.

    Termination

    Under Anthropic’s FAR-based agreements, the simplest way for the government to sever its relationship with the company is through a “termination for convenience“ (T4C). If the contract includes a termination for convenience clause, as most FAR-based contracts do, the contracting officer may terminate when doing so is in the government’s interest. The standard is broad, but not limitless, as a termination cannot be an act of bad faith or an abuse of discretion. The contractor is entitled to certain costs when the government exercises its T4C rights, so the parties negotiate a settlement; if they disagree, the disputes process outlined in FAR Part 33 is followed.

    If the concept of “broad government termination rights” sounds vaguely familiar, it is because you may recall that in early 2025, the government, through DOGE, exercised its T4C authority on a sweeping and unprecedented basis, terminating thousands of contracts for convenience across the federal government. The tool is neither obscure nor untested, and the government has shown absolutely no hesitation in deploying it.

    There is little doubt that the government could have demonstrated that terminating its agreements with Anthropic was in the government’s interest. The administration has articulated a policy rationale—it wants AI models free from vendor usage restrictions—and Anthropic declined to comply. Whether or not you agree with the policy, the threshold is not hard to meet. They’ve certainly done it for less.

    With respect to Anthropic’s OT agreement with CDAO, the picture is less certain, as the public record does not disclose the specific terms. Unlike FAR-based contracts, OTs are flexible instruments, so the FAR-based termination process does not automatically apply. But OTs often include FAR-like termination provisions, so the government may well have had a contractual off-ramp for the direct relationship. Beyond the government’s options, Anthropic itself offered to facilitate a transition to another provider.

    Termination addresses the government’s immediate concern: current operational reliance on a vendor it no longer trusts. The government had contractual tools to address that concern without invoking a supply chain exclusion determination. It did not use them.

    Suspension and Debarment

    Termination for convenience is common enough that the FAR has an entire disputes process built around it. What happened last year was jarring, but a T4C in this instance wouldn’t have surprised anyone. The next option on the less-intrusive-measures menu is a significant jump, more like moving from a speeding ticket to a life sentence. But even a life sentence has more process than what the government did here.

    Discretionary suspension and debarment are the federal procurement system’s mechanisms for excluding “nonresponsible” contractors from doing business with the government. Regulated by FAR 9.4, both tools are triggered by evidence of serious misconduct or grossly incompetent performance, but they serve different functions. Suspension is immediate and temporary, designed to protect the government while an investigation or legal proceeding is underway. Debarment is longer-term, typically following a criminal conviction, a civil judgment, or a finding that the contractor’s conduct is serious enough to affect its present responsibility. This is the FAR’s nuclear option. And given its potential consequences (both direct and collateral) it’s no wonder we call it the corporate death penalty.

    Before I continue, I want to stop and address something directly. I am not suggesting that the government should have pursued debarment. On these facts, I do not believe it would survive judicial scrutiny. At issue is a contractual dispute in which a vendor declined to accept the terms the government wanted. That is not the kind of triggering misconduct the system was designed to address. But if we are evaluating less intrusive measures, which Section 3252 requires the Secretary to consider, then understanding what even this most extreme tool requires is essential. Because it shows just how far the government departed from any recognized process.

    Specifically, the debarment process itself recognizes how consequential it can be for a contractor. FAR 9.402(b) establishes the core principle: debarment and suspension may be imposed “only in the public interest for the Government’s protection and not for purposes of punishment.”

    FAR 9.4 implements that principle through a framework that requires notice and an opportunity to respond, though the timing differs depending on the tool used. These determinations are made by a Suspension and Debarment Official (SDO), whose ultimate question is one of present responsibility: can this contractor be trusted to continue doing business with the federal government? In answering this question, the SDO will generally assess present responsibility in light of remedial measures, mitigating factors, and aggravating factors. Suspension and debarment generally preclude new prime contract awards and restrict certain future subcontracts, but they do not, by themselves, require the termination of existing agreements. FAR 9.405-1 expressly permits agencies to continue existing contracts and subcontracts unless the agency head directs otherwise.

    The Subcontractor Problem and Section 3252

    Anthropic’s technology reportedly runs through Palantir’s Maven Smart Systems in classified defense workflows. The government’s direct contractual relationship appears to be with Palantir, not Anthropic. That makes it harder to use ordinary tools for severing the relationship. Directing a prime to remove a deeply integrated supplier mid-performance is indirect and creates commercial and technical risk for the prime. Reuters has reported that removing Claude would require Palantir to replace the model and rebuild parts of its software. As discussed above, debarment would constrain certain future subcontracting, but it would not by itself compel a prime to unwind an existing relationship.

    Section 3252 offers something different. Congress established the original authority in the FY 2011 NDAA to address supply-chain risks in sensitive defense information technology procurements, and the statute defines “supply chain risk” as the “risk that an adversary may sabotage, maliciously introduce unwanted function, or otherwise subvert” a covered system. Applying it to a domestic AI company in a dispute over contract terms pushes the statute well beyond its ordinary adversary-focused framing. Yet the structural difficulty of reaching a deeply embedded supplier through ordinary channels may help explain why the government reached for it.

    Among the covered procurement actions the statute authorizes is the decision to withhold consent for a subcontract with a particular source or to direct a contractor to exclude a particular source from consideration for a subcontract (as implemented by DFARS 239.73). That subcontract-specific authority is best read as prospective. It addresses future subcontracting decisions, not the unwinding of an already-performing subcontract. The government, therefore, could have used a narrower, forward-looking measure while existing arrangements transitioned off on a defined timeline.

    Instead, according to the public record in the Anthropic litigation, it chose a much broader covered procurement action, and the record does not show that narrower alternatives were meaningfully considered. Indeed, Judge Lin noted that the congressional notices required by § 3252(b)(3)(B) did not contain the required discussion of less intrusive measures, and the government conceded that omission at oral argument.

    An Unusual Course of Action . . . Even for Government Procurement

    There is no public record of Section 3252 being used to designate a domestic company as a supply chain risk. No president has ever directed government-wide exclusion of a named contractor by social media post. The government designated Anthropic a supply chain risk to national security and then gave itself six months to keep using Anthropic’s products on classified systems.

    According to Anthropic’s complaint and supporting declarations, the government at one point threatened to both invoke the Defense Production Act to compel Anthropic to provide its services and designate it a supply chain risk, thereby excluding it—contradictory remedies directed at the same company in the same dispute. And as I type this sentence, according to Anthropic’s court filings, the contractor the government branded a national security threat continues to maintain its Top Secret facility security clearance, issued by the same government that currently declares it a threat to the United States government.

    On February 27, the President posted on social media directing every federal agency to “IMMEDIATELY CEASE all use of Anthropic’s technology.” The post characterized Anthropic as a “RADICAL LEFT, WOKE COMPANY” and threatened “major civil and criminal consequences,” without citing a single source of authority for this extraordinary action. Court filings show that Anthropic had contracts or usage with at least 16 federal agencies. Treasury Secretary Bessent posted on X that the department was “terminating all use of Anthropic products.” The Federal Housing Finance Agency and the General Services Administration (GSA) followed. One after another, all on social media, none citing any statutory authority.

    Later that day, Secretary Hegseth posted on social media, directing the Department to “designate Anthropic a Supply-Chain Risk to National Security.” No statute was cited. The Secretary described Anthropic’s stance as “fundamentally incompatible with American principles,” criticized its “defective altruism” and “Silicon Valley ideology,” and declared: “This decision is final.” He also directed that “no contractor, supplier, or partner that does business with the United States military may conduct any commercial activity with Anthropic.”

    On March 3, the joint recommendation and risk analysis materialized, along with the statutory bases, which had appeared in neither of the social media posts. The Secretary signed the Secretarial Determination the same day the recommendations were submitted. The government’s opposition brief characterizes the Secretary’s February 27 social media post as “the beginning” of the decision-making process and argues it was not final agency action.

    So, let’s take them at their word. The Secretary publicly announced the outcome, directed subordinates to produce the justification, and the justification confirmed the predetermined conclusion four days later. The record went from initiation to final determination without the contractor ever having an opportunity to respond before the decision was made.

    None of the Established Processes Were Used

    The government did not terminate Anthropic’s contracts for convenience; it directed every federal agency to stop using Anthropic’s products via social media. It did not initiate suspension or debarment proceedings before an SDO; the decision was made by a political appointee who had already announced the result on social media before any internal process had commenced. At the March 24 hearing, the government’s theory narrowed to speculation that Anthropic might install a “kill switch” or manipulate its software during operations. Anthropic’s counsel denied that the company has any such capability once Claude is deployed, and the government’s lawyer could not confirm otherwise.

    The Secretary’s post also directed that “no contractor, supplier, or partner that does business with the United States military may conduct any commercial activity with Anthropic,” a directive for which the government later conceded there was no statutory basis. At the March 24 hearing, the government’s lawyer further conceded that the statement had “absolutely no legal effect at all.” Judge Lin then pressed the government on what, if anything, prevents the Department from changing its position on how the sentence would operate.

    The Exclusion Without a Name

    Courts have long recognized that a government agency’s conduct can effectively result in a government-wide exclusion without formal debarment proceedings ever being initiated. In Old Dominion Dairy Products, Inc. v. Secretary of Defense, the D.C. Circuit emphasized the severe economic and reputational consequences of effectively excluding a contractor from further government work, including the loss of contracts that would otherwise have been awarded and the effective destruction of the business.

    De facto debarment is notoriously difficult to prove. As Dominique Casimir and Alexandra Barbee-Garrett explain in their piece, The Government’s Just Not That Into You—Is it De Facto Contractor Debarment?, the contractor typically faces “an uphill battle,” where their proposals “simply lose out quietly to those of its competitors, again and again, making it difficult to discern that a de facto debarment is occurring.” Courts generally require either an agency statement that it will not award future contracts or agency conduct demonstrating the same.

    That’s what makes this case so remarkable. De facto debarment cases usually require painstaking reconstruction of a pattern of informal agency conduct, such as repeated nonresponsibility findings, back-channel communications between acquisition professionals, or unexplained refusals to award. This one came with a press release. And the President later stated: “I fired [them] like dogs.”

    The kinds of economic and reputational harm Old Dominion described were already underway before any statutory process had begun.

    What Kind of Business Partner Does the Government Want to Be?

    If the government can brand a contractor a national security threat for refusing to accept contract terms, every federal contract negotiation becomes existential. At the March 24 hearing, Judge Lin pressed the government on precisely this point, asking whether an IT vendor can be designated a supply chain risk because it “is stubborn and insists on certain terms and it asks annoying questions.” She called that “a pretty low bar.”

    The deterrent effect extends beyond Anthropic. It reaches every contractor that might push back on terms it considers unworkable, unsafe, or commercially unreasonable. The procurement system depends on good-faith negotiation between the government and its contractors. Contractors must be able to say no without the government branding them a national security threat—not for protection, but as punishment for driving a hard bargain.

    I have been writing, teaching, and advising on suspension and debarment for nearly two decades. I know what it looks like when the government excludes a contractor. I know what it looks like when the government abuses the process. And I know what it looks like when the government skips the process entirely.

    The corporate death penalty has rules. What happened here followed none of them.

  • U.S. Federal Procurement Anti-Corruption Ecosystem

    U.S. Federal Procurement Anti-Corruption Ecosystem

    Introduction

    This page presents an overview of what I have termed the “Federal Procurement Anti-Corruption Ecosystem” — a layered framework of laws, rules, and normative expectations that shape anti-corruption, integrity, and compliance in U.S. federal procurement. It is the foundation of my Anti-Corruption & Compliance course, which I teach at GW Law School. It is intended as a practical resource for students, practitioners, and policymakers.

    Overview

    The U.S. federal procurement system is mature, complex, and governed by myriad statutory and regulatory requirements. To ensure that U.S. taxpayer dollars are appropriately safeguarded, the Federal Acquisition Regulation (FAR) – the primary regulation applicable to federal executive branch agencies in their acquisition of goods and services – makes clear that the government procurement process demands the highest commitment to ethical and unbiased conduct (FAR 3.101–1).

    To maintain integrity in this regime, entities that do business with the government are subject to a patchwork of requirements, restrictions, and compliance obligations. This framework, which I term the “U.S. Government Procurement Anti-Corruption Ecosystem,” is designed to prevent, detect, and mitigate corruption risks to the fullest extent possible.

    The system recognizes corruption risk as a persistent feature of large spending programs and addresses this risk through oversight and enforcement mechanisms tailored to different categories of misconduct: criminal prosecution for intentional fraud, civil penalties for recklessness, and administrative remedies for noncompliance

    The policies and requirements derive from a diverse composite of criminal and civil laws found in various titles of the United States Code and the Code of Federal Regulations. Moreover, many of the policies that underpin these statutory and regulatory requirements are buttressed by provisions in the FAR that either reiterate the policies or impose additional compliance obligations. This framework relies on multiple overlapping institutions—an intentional redundancy designed to avoid a single point of failure.

    Transparency

    In the United States, most aspects of the procurement process are transparent and readily accessible by the public. For example, the government procurement rules, located in the FAR, are available online at Acquisition.gov to anyone with internet access. Similarly, contract opportunities, requirements, evaluation criteria, and awards can be found in a single online portal – SAM.gov.

    Procurement spending data may be tracked online via a user-friendly website: USASpending.gov. This data can also be found in the Federal Procurement Data System (FPDS). The U.S. government also shares information about contractor misconduct by publishing information related to certain criminal and civil proceedings, administrative agreements, and contractor exclusions (debarment or suspension) at SAM.gov.

    Oversight

    Transparency also bolsters another key component of the U.S. Government Procurement Anti-Corruption Ecosystem: oversight. In addition to traditional sources of accountability, such as the free press and civil society, the United States has developed a variety of sophisticated government oversight tools designed to identify and expose corruption, fraud, waste, and noncompliance.

    Two of those tools are audits and investigations, conducted primarily through agency inspectors general (IGs). IGs are “independent and objective units within each agency whose duty it is to combat waste, fraud, and abuse in the programs and operations of that agency.” IGs fulfill this duty by “conducting audits and investigations relating to the programs and operations of its agency” and by actively referring matters, when warranted, to the U.S. Department of Justice for potential prosecution and agency Suspension and Debarment Officials for possible exclusion from the federal procurement system.

    In addition to the agency IGs who oversee procurements by their respective agencies, in certain circumstances, additional oversight is warranted. For example, given the hundreds of billions of dollars spent by the U.S. Department of Defense (DoD) on an annual basis, the Defense Contract Audit Agency (DCAA) provides audit and financial advisory services to the DoD and other federal entities responsible for acquisition and contract administration. This is in addition to the general oversight provided by the DoD’s Office of Inspector General, and the various criminal investigative services located throughout DoD (i.e., Naval Criminal Investigative Service (NCIS), Air Force Office of Special Investigations (AFOSI), U.S. Army Criminal Investigation Division (CID), etc.).

    Moreover, the U.S. Congress will periodically establish “special” IGs to oversee programs that involve significant government spending. For example, in an effort to oversee billions of dollars spent on reconstruction in Iraq and Afghanistan, Congress established Special Inspectors General for Iraq Reconstruction (SIGIR) and Afghanistan Reconstruction (SIGAR). Similarly, in response to the COVID-19 pandemic, Congress created the Pandemic Response Accountability Committee (PRAC) to oversee and combat fraud, waste, abuse, and mismanagement of pandemic-related programs and funding.

    To improve public access to the reports generated by the U.S. government’s IGs, the Council of the Inspectors General on Integrity and Efficiency (CIGIE) created Oversight.gov – a publicly accessible, text-searchable repository of reports published by federal IGs.

    The U.S. legislative branch provides additional oversight of the U.S. procurement process, generally through relevant committee investigations and hearings, as well as its independent audit agency – the Government Accountability Office (GAO). The GAO is an independent, nonpartisan agency that works for Congress by conducting audits and producing reports on government operations – including government procurement programs and policies. The agency also houses one of the three fora designated to hear bid challenges – a critical government procurement oversight mechanism. The “bid protest” system residing in the GAO is a sophisticated and mature forum that enables contractors to challenge the terms of a solicitation or award of a federal contract. U.S. contractors are also empowered to file challenges at the U.S. Court of Federal Claims (COFC) and at the individual executive branch agency level.

    Ethics Restrictions

    U.S. government service demands that federal employees, including Special Government Employees, place loyalty to the Constitution, the law, and ethical principles above private gain. This “principle” is applicable to federal executive branch employees, including government acquisition professionals, who are also held to additional ethical standards due to their unique positions of trust.

    U.S. government officials are subject to a lengthy list of ethics and integrity restrictions governing their federal work, including including, but not limited to, prohibitions against financial conflicts of interest, prohibitions on the use of nonpublic information in financial transactions, requirements to act impartially in the discharge of duties, and affirmative obligations to disclose waste, fraud, abuse, and corruption to appropriate authorities (5 C.F.R. § 2365.101(b)).

    The ethics rules also prohibit federal employees from misusing their position and government resources (5 C.F.R. § 2365.701 to -.705). This category of restrictions is designed to ensure employees do not use their official positions, including information learned by virtue of the government position, for personal benefit or the benefit of others.

    These ethics rules are designed to ensure that employees do not, for example, exploit the access they have due to their government position to obtain special treatment for themselves, friends, or family. Similarly, they require government employees to conserve and protect government property and prohibit its use for anything other than its authorized purpose. In addition, they require “official time” at work to be used for the performance of official duties –not for personal activities. There are also strict limitations on federal employees’ outside activities – particularly when those activities may conflict with the employees’ government duties (5 C.F.R. § 2365.801 to -.809, 2023). There are numerous other ethics “restrictions” applicable to federal public service, which help to promote integrity in the procurement process (5 C.F.R. §2365).

    In addition to some of the more common ethics restrictions detailed here, there are also some limits on the political activities of federal employees “to ensure that federal programs are administered in a nonpartisan fashion, to protect federal employees from political coercion in the workplace, and to ensure that federal employees are advanced based on merit and not based on political affiliation.” The Hatch Act generally prohibits federal employees from engaging in partisan political activity while on duty, in a federal facility, or using federal property. The extent of the restrictions depends on the type of position the employee holds (i.e., employees in “law enforcement” positions are subject to greater limitations on their political activities). The Office of Special Counsel protects whistleblowers, enforces prohibited personnel practice laws, and administers the Hatch Act, contributing to accountability and integrity in the federal system.

    To ensure federal employees understand their ethical obligations, agencies have designated ethics officials who are tasked with, among other things, implementing the agency ethics program, collecting and reviewing financial disclosure reports, and providing ongoing training and advice to agency employees. The Office of Government Ethics sets executive branch ethics standards and oversees agency ethics programs to prevent conflicts of interest and promote integrity among federal officials.

    Although the United States has a fairly sophisticated ethics regime, the system is not without its flaws. The system famously excludes the president and vice president of the United States from much of its coverage. It also suffers from weak enforcement mechanisms, rendering the system vulnerable to abuse and neglect. Although there have been attempts to address relatively modest “technical” issues in the system, very little has been done to repair some of the system’s more significant weaknesses

    Conflicts of Interest

    Competition is a primary goal of the U.S. procurement system. To help preserve and promote competition, the United States has enacted laws designed to mitigate conflicts of interest. The laws relating to conflicts of interest are both criminal and administrative and are designed to ensure government officials and contractors do not taint procurements with unfair competitive advantages and favoritism toward particular vendors. Federal conflict-of-interest laws fall into two distinct categories: personal conflicts of interest (PCIs) and organizational conflicts of interest (OCIs).

    Personal Conflicts of Interest

    U.S. law attempts to prevent, mitigate, and punish PCIs criminally and administratively. The centerpiece PCI law is found at 18 U.S.C.§ 208 (acts affecting a personal financial interest) – a criminal law. The law prohibits government employees from having personal financial conflicts of interest with their official work. Specifically, the law prohibits federal officials from participating personally and substantially in a particular matter that would have a direct and predictable effect on the financial interests of the official or the official’s (1) spouse or minor child; (2) general partner; (3) organization in which the official serves as an officer, director, trustee, general partner or employee; or (4) persons with whom the official is seeking or has an arrangement for future employment.

    To mitigate potential PCIs, government officials may recuse themselves from the conflicting matter, seek a waiver, or divest the financial interest. The failure to do so could result in a criminal prosecution, civil penalties, and up to five years imprisonment (18 U.S.C. § 216).

    In addition to criminal prohibitions against PCIs, the FAR also contains a specific prohibition designed to prevent PCIs involving contractor employees performing “acquisition functions” (FAR 3.11). This particular provision was created in response to the increased outsourcing of work traditionally performed by government officials. It addresses concerns that when the U.S. government retains contractors to perform acquisition functions (e.g., planning acquisitions, developing statements of work, evaluating contract proposals, developing evaluation criteria, awarding or administering contracts), there is a greater risk that a conflict between a contractor employee’s personal financial interests and the government work it is performing could result in favoritism or bias, ultimately undermining competition.

    The PCIs addressed by 18 U.S.C. § 208 and FAR 3.11 cover a fairly narrow category of conflicts. To address additional scenarios, not covered by these laws, that may still result in favoritism and bias, 5 C.F.R. § 2635.502 requires executive branch officials to maintain impartiality and integrity in the performance of their duties. It mandates that officials recuse themselves from matters that may cause a reasonable person, with knowledge of the relevant facts, to question the government employee’s impartiality. This “impartiality rule” is designed to avoid the appearance of favoritism in government decision-making. “It requires employees to consider these appearance concerns before participating in a particular matter if someone close to that employee is involved as a party to that matter.”

    Organizational Conflicts of Interest

    In recent decades, there has been an increase in organizational conflicts of interest caused by contractors’ competing business interests. This development is the result of consolidation in the information technology and defense industries, as well as the government’s increased reliance on contractors to provide services traditionally performed by public servants.

    The FAR defines an OCI as occurring when, “because of other activities or relationships with other persons, a person is unable or potentially unable to render impartial assistance or advice to the government, or the person’s objectivity in performing the contract work is or might otherwise be impaired, or a person has an unfair competitive advantage” (FAR 2.101). The term “person” includes companies and other contracting entities. The current framework for analyzing whether an OCI exists derives primarily from FAR Subpart 9.5 and decisional precedent from the GAO and the U.S. COFC.

    OCIs are generally separated into three categories:

    1. Impaired objectivity – may arise where a contractor’s outside business relationships create an economic incentive to provide biased advice under a government contract;
    2. Biased ground rules – may occur when, as part of its work under one procurement, the contractor has helped set the procurement’s ground rules, such as writing the statement of work or developing specifications, for another procurement; and
    3. Unequal access to information – may occur when a contractor obtains access to nonpublic information as part of its contract performance which gives it an advantage in a later competition for a government contract.

    FAR 9.504 requires a contracting officer (CO) to “identify and evaluate potential organizational conflicts of interest as early in the acquisition process as possible; and avoid, neutralize, or mitigate significant potential conflicts before contract award.” To fulfill this obligation, COs depend on contractors to disclose, among other things, “any facts that may cause a reasonably prudent perso to question the Contractor’s impartiality because of the appearance or existence of bias” (FAR 9.504). Agencies generally demand this information through solicitation provisions or contract clauses that clearly articulate the government’s expectations with regard to the disclosure of facts and circumstances that would give rise to an actual or potential OCI.

    The law relating to OCIs is currently in flux, as the FAR Council published a new proposed OCI rule in January that will completely overhaul how the federal government handles these potential conflicts. It’s fate is uncertain in light of the Revolutionary FAR Overhaul, which did not integrate any of the proposed rule’s changes into its text.

    Procurement Integrity Act & Post-Government Employment Restrictions

    One of the biggest scandals in U.S. government procurement history occurred in 1988, when an investigation revealed that DoD employees had accepted bribes from contractors in exchange for confidential procurement information that helped the contractors secure new contract awards. Known as “Operation Ill Wind,” the scandal ultimately resulted in the prosecution of more than 60 contractors, consultants, and government officials and a recovery of more than $622 million in fines, restitution, and forfeitures (Federal Bureau of Investigation, no date). In response to the scandal, Congress moved quickly by enacting the Procurement Integrity Act (PIA) (41 U.S.C. §§ 2101–07; FAR 3.104).

    The PIA attempts to promote competition in two ways: by prohibiting the disclosure and receipt of confidential procurement information and by placing restrictions on post-government employment. With respect to the protection of confidential procurement information, the PIA prohibits the disclosure and receipt of nonpublic contractor bid or proposal information or source selection information before the award of a related federal agency procurement contract. This provision recognizes that the disclosure or receipt of such information could provide a prospective bidder or offeror with an unfair competitive advantage.

    The PIA’s post-employment restrictions impose reporting and disqualification requirements on government acquisition officials engaging in employment discussions and negotiations. Its “compensation ban” prohibits government officials who are involved in certain procurement functions from accepting compensation from covered contractors for one year after performing those functions. The PIA’s provisions are construed quite broadly, imposing restrictions that may not be obvious to covered individuals. For example, a requirement to recuse from participation in a procurement can be triggered even if the employee is not engaged in formal employment discussions. Mere contact with a bidder or offeror about possible employment may necessitate that the employee affirmatively reject the possibility of employment or be disqualified from further personal and substantial participation in the relevant procurement.

    The post-employment restrictions found in the PIA are buttressed by criminal “revolving door” restrictions found at 18 U.S.C. § 207, which imposes limits on the type of work former federal employees may perform for their new employers for specific periods of time. The restrictions range from a single year to lifetime bans and may include limitations on the employee’s ability to appear before or communicate with their former agency. The statutory requirements are often bolstered by Executive Orders, which provide additional “revolving door” restrictions.

    Post-employment issues often arise in the context of bid protests, where disappointed bidders or offerors allege that their competitor has an “unfair competitive advantage” stemming from their hiring of a former Government employee.

    Encouraging Disclosures of Fraud, Waste, and Corruption

    Corruption is notoriously difficult to detect given that most corrupt transactions or agreements are executed covertly with the proverbial wink and a nod. To help root out and mitigate these illegal activities, the U.S. government has aggressively embraced a disclosure model. Whether by incentivizing voluntary disclosures, threatening debarment for failure to comply with mandatory disclosure obligations, or mandating government employee disclosures, disclosures have become a centerpiece of the U.S. government’s efforts to combat corruption.

    Mandatory Disclosures

    FAR 52.203–13 imposes a mandatory disclosure obligation on government contractors if they hold a contract expected to exceed $6 million with a performance period of 120 days or more (FAR 3.1004). FAR 52.203–13 requires contractors to make their disclosure in writing to the relevant agency Office of the Inspector General (OIG) and send a copy to the CO. The disclosure must contain information about certain violations of the law that a contractor’s principal, employee, agent, or subcontractor has committed in connection with the award, performance, or closeout of its government contract or any subcontract thereunder. The conduct that triggers disclosure includes:

    • A violation of Federal criminal law involving fraud, conflict of interest, bribery, or gratuity violations found in Title 18 of the United States Code
    • A violation of the civil False Claims Act
    • A significant overpayment.

    Voluntary Disclosures

    Even where the mandatory disclosure obligation is not applicable, the U.S. government has spent the last several decades encouraging companies to voluntarily disclose misconduct to the government. In an effort to incentivize disclosure, the government has detailed the type of “credit” companies will receive for their disclosures and cooperation.

    The DOJ Criminal Division’s “Corporate Enforcement and Voluntary Self-Disclosure Policy” outlines the incentives available to corporations that discover and disclose potential criminal violations to the Justice Department (DOJ Justice Manual, 9–47.12). In short, the policy states that if a company voluntarily self-discloses, fully cooperates, and timely and appropriately remediates the violation, there is a presumption that the DOJ will decline to take enforcement action against the company absent certain “aggravating circumstances involving the seriousness of the offense or the nature of the offender” (DOJ Justice Manual, 9–47.12). Even if a company does not meet the strict criteria necessary for a declination, the policy offers a sliding scale of benefits (e.g., discounts from the U.S. Sentencing Guidelines fine range) to companies depending on the extent of their cooperation, seriousness of the misconduct, and the timing of their disclosure.

    Government Employee Disclosures

    The U.S. government emphasizes the important role government employees play in detecting and reporting misconduct – particularly in the procurement system. For example, the Standards of Ethical Conduct applicable to executive branch government employees require the disclosure of “waste, fraud, abuse, and corruption to appropriate authorities.” The FAR also imposes more targeted obligations on acquisition professionals. For example, FAR 3.104 requires government employees to report possible violations of the Procurement Integrity Act. FAR 3.302 requires employees to report suspected gratuities given to an officer, official, or employee of the government in an effort to obtain a contract or favorable treatment under a contract to the Contracting Offier or other designated official. Similarly, FAR 3.303 requires agencies to report suspected collusion to the DOJ Antitrust Division. There are numerous other examples of reporting obligations scattered throughout the FAR, emphasizing the importance the government places on these disclosures

    Whistleblowing Protections & Rewards

    The U.S. government recognizes that individuals who disclose wrongdoing often face backlash from their employers and colleagues. In an effort to incentivize whistleblowing and protect individuals who bring wrongdoing to light, the United States has enacted an extensive system of whistleblower rewards and protections.

    Government Whistleblower Protections

    The Whistleblower Protection Act protects “any disclosure of information” by federal government employees that they “reasonably believe . . . evidences an activity constituting a violation of law, rules, or regulations, or mismanagement, gross waste of funds, abuse of authority or a substantial and specific danger to public health and safety” (National Whistleblower Center). It prohibits retaliation in response to such disclosures, such as terminations, disciplinary or corrective action, transfers, details or reassignments, poor evaluations, or pay cuts.

    Notably, the Whistleblower Protection Act does not protect disclosures that reflect only a disagreement with policy, information required to be kept secret by Executive Orders in the interest of the national defense or conduct of foreign affairs, or if disclosure is prohibited by law (5 U.S.C. § 2302(b)). Most federal employees are covered by this law, though it specifically exempts whistleblowers from the intelligence community and the FBI from its coverage.

    Employees who work in a classified environment are covered by separate whistleblower protection statutes (e.g., intelligence community employees are covered by the Intelligence Community Whistleblower Protection Act of 1998, the Intelligence Authorization Act for Fiscal Year 2014, and Presidential Directive 19). Depending on the employee’s position, there may be limits relating to whom they may disclose the information. In general, civilian employees may disclose information to anyone, including nongovernmental audiences, unless the information is classified or specifically prohibited by law from release. If the information is classified or specifically prohibited by law from release, it may only be shared with the relevant agency OIG, the Office of Special Counsel, or a designated agency official.

    Contractor Whistleblower Protections

    Recognizing that government contractor employees play an important role in ensuring that federal funds are utilized honestly, efficiently, and with accountability, Congress enacted additional statutory protections for employees of contractors from retaliation (41 U.S.C. § 4712; 10 U.S.C. § 4701). Employees of a contractor, subcontractor, grantee, or subgrantee or personal services contractor are protected against retaliation (including discharge, demotion, or discrimination) for disclosing information about:

    • Violations of law, rule, or regulation related to a federal contract (including the competition for or negotiation of a contract) or grant
    • Gross mismanagement of a federal contract or grant
    • Gross waste of federal funds
    • Abuse of authority relating to a federal contract or grant
    • Substantial and specific danger to public health or safety.

    The disclosure must be made to an authorized individual or entity:

    • A Member of Congress or a representative of a committee of Congress
    • An Inspector General
    • The Government Accountability Office
    • A federal employee responsible for contract or grant oversight or management at the relevant agency
    • An authorized official of the Department of Justice or other law enforcement agency
    • A court or grand jury
    • A management official or other employee of the contractor, subcontractor, or grantee who has the responsibility to investigate, discover, or address misconduct (41 U.S.C. § 4712).

    Disclosures to an individual or entity not included in this list are not protected.

    Whistleblower Rewards

    To further incentivize individuals to disclose wrongdoing and compensate them for the potential loss of income, many whistleblower programs in the United States also offer financial rewards. Studies have shown that whistleblower reward programs increase the likelihood that individuals will come forward and expose wrongdoing.

    The most prominent whistleblower rewards statute in the United States is the False Claims Act, which is used to combat procurement fraud. If a case is successful, whistleblowers receive a 15–30 percent share of the recoveries. The United States has numerous other successful whistleblower reward programs, including several new programs that have been created in the past few years:

    Fraud

    Federal integrity failures operate on a spectrum, and federal law addresses them through distinct legal regimes that turn on different scienter requirements and decision-making forums, ranging from criminal prosecution to civil and administrative remedies. Public labeling, particularly by government officials, should use labels that track those legal distinctions, because terminology can shape the enforcement pathway, the consequences that follow, and the resulting public impression.

    Criminal Fraud

    Criminal fraud and false-statement offenses are punitive and require proof beyond a reasonable doubt that the defendant acted with a culpable mental state, not merely that information was inaccurate. Core federal fraud statutes, including mail fraud, wire fraud, and major fraud against the United States (18 U.S.C. §§ 1341, 1343, 1031), generally require proof of an intent to defraud. In government contracting matters, prosecutors also frequently rely on related Title 18 offenses, including knowingly presenting a false, fictitious, or fraudulent claim (18 U.S.C. § 287), making a materially false statement knowingly and willfully (18 U.S.C. § 1001), and conspiracy to commit an offense or to impair lawful government functions through deceit (18 U.S.C. § 371). Consistent with that emphasis on intent and willfulness, the Government Accountability Office describes fraud as obtaining a thing of value through willful misrepresentation and emphasizes that whether conduct constitutes “fraud” is ultimately determined through the judicial or other adjudicative process. These offenses are typically felonies punishable by significant fines and imprisonment.

    Civil False Claims Act

    Civil False Claims Act liability targets fraud against the government through a lower scienter threshold and civil remedies. Enacted in 1863 in response to allegations of fraud against the Union Army during the U.S. Civil War, the FCA is a statute that has become one of the world’s most consequential anti-fraud enforcement tools. The FCA imposes liability when a person acts “knowingly,” a standard that includes actual knowledge, deliberate ignorance, and reckless disregard, and does not require proof of specific intent to defraud. The statute creates civil liability for, among other things, knowingly presenting (or causing to be presented) a false claim for payment, knowingly making or using a false record or statement material to a false claim, conspiring to violate the Act, and knowingly concealing or improperly avoiding an obligation to pay the government (31 U.S.C. §§ 3729–3733). The FCA is not intended to cover honest mistakes or incorrect claims submitted through mere negligence. A defendant found liable faces treble damages plus substantial per-claim civil penalties.

    The FCA is also strengthened by a distinctive whistleblower mechanism. Its qui tam provisions allow private citizens (relators) to file suit on the government’s behalf and receive a share of the recovery, typically 15–25 percent if the government intervenes and 25–30 percent if it declines. By deputizing private enforcement in this way, the FCA has become an exceptionally powerful tool, with annual recoveries often exceeding one billion dollars.

    Administrative False Claims Act

    Administrative remedies address smaller-dollar false-claim and false-statement matters through agency adjudication rather than federal court litigation. Formerly known as the Program Fraud Civil Remedies Act (PFCRA) and now known as the Administrative False Claims Act (or “baby False Claims Act”), this regime authorizes agencies to pursue certain matters through administrative proceedings, generally limited to claims not exceeding $1,000,000 (inflation-adjusted), with judicial review and judicial enforcement in federal court. It is designed, in part, to provide agencies a pathway when the Department of Justice elects not to pursue FCA remedies. The National Defense Authorization Act for FY25 included enhancements intended to encourage agencies to use this tool more frequently.

    Corruption

    The U.S. federal government has several laws designed to deter and punish illegal bribes and gratuities. These laws are designed to ensure that government officials do not accept anything of value in exchange for influencing a government official’s judgment or an official act, including the award of a government contract. Notably, the laws are defined broadly to encompass both large (i.e., wire transfers of large sums of money, bags full of cash) and small (i.e., gifts and hospitality) schemes. “Anything viewed as valuable by the public official, whether tangible or intangible, could potentially trigger liability if viewed as an attempt to improperly influence a government official to obtain a contract or favorable treatment” (Tillipman, 2014).

    Domestic Corruption

    The “centerpiece” of federal public corruption law, 18 U.S.C. § 201, prohibits two offenses: bribery and gratuities. Applicable to the demand and supply side of the illegal transaction, the statute punishes “both sides of a corrupt transaction.”

    FAR 3.101–2 reinforces the prohibition against gratuities in the procurement context by prohibiting government employees from soliciting or accepting, directly or indirectly, any gratuity, gift, favor, entertainment, loan, or anything of monetary value from anyone who (a) has or is seeking to obtain government business with the employee’s agency, (b) conducts activities that are regulated by the employee’s agency, or (c) has interests that may be substantially affected by the performance or nonperformance of the employee’s official duties.

    In addition to the bribery and illegal gratuities statute located at 18 U.S.C.§ 201, the federal government has many other statutes that it can use to prosecute public corruption (or what Professor Randall Eliason refers to as “bribery by another name”). Statutes such as Honest Services Fraud (18 U.S.C. § 1346.), the Hobbs Act (18 U.S.C. § 1951), and federal pro- grams bribery (18 U.S.C. § 666) similarly punish corrupt activities, though their application differs depending on the facts of a particular matter. For example, because 18 U.S.C. § 201 is limited to federal public officials, Honest Services Fraud and the Hobbs Act are often used in the prosecution of state corruption cases.

    In addition to bribes, the U.S. federal government also prohibits “kickbacks” via the Anti- Kickback Act of 1986 (41 U.S.C. Chapter 87). The statute prohibits “subcontractors from making payments and contractors from accepting payments for the purpose of improperly obtaining or rewarding favorable treatment in connection with a prime contract or a subcontract relating to a prime contract” (FAR 3.502–2). “Kickbacks” are defined broadly to include “any money, fee, commission, credit, gift, gratuity, thing of value, or compensation of any kind” (FAR 3.502–1). Contractors are also prohibited from directly or indirectly including “the amount of any kickback in the contract price charged by a subcontractor to a prime contractor or a higher tier subcontractor or in the contract price charged by a prime contractor to the United States” (FAR 3.50–2).

    Foreign Corruption

    U.S. law also prohibits the bribery of foreign public officials through the Foreign Corrupt Practices Act (FCPA). The FCPA makes it illegal to corruptly offer or provide money or anything else of value to officials of foreign governments, foreign political parties, or public international organizations with the intent to obtain or retain business (15 U.S.C. §§ 78dd-1, et seq.). The law also requires issuers – companies whose securities are listed in the United States – to maintain accurate books and records and strong internal controls. Known globally for its broad application and robust enforcement, the FCPA has transformed the global anti-corruption compliance landscape and helped bolster anti-corruption enforcement efforts around the world. Although violations of this law do not directly impact the U.S. procurement system, companies that do business with the U.S. government should be aware of the FCPA’s prohibitions and government compliance expectations given the potential consequences for violations of the law, such as debarment.

    Collusion

    Enacted in 1890, the Sherman Act prohibits any agreement among competitors to fix prices, rig bids, or engage in other anti-competitive activity (5 U.S.C.§1). The Sherman Act covers a variety of anti-competitive schemes, which are prosecuted by the DOJ Antitrust Division, including (but not limited to):

    • Price Fixing: An agreement among competitors to restrict price competition, such as raising, fixing, or maintaining the price at which their goods or services are sold.
    • Bid Rigging: An agreement among some or all the bidders which predetermines the winning bidder and limits or eliminates competition among co-conspirators.
    • Market Allocation: Competitors agree to divide markets among themselves, including cus- tomer segments, geographic segments or product categories

    Given that procurement systems are uniquely vulnerable to collusive misconduct, the DOJ launched the Procurement Collusion Strike Force (PCSF) in 2019 to combat antitrust crimes and related government procurement schemes at the federal, state, and local levels. The PCSF aims to deter and detect collusive behavior, enhance coordination and capacity among law enforcement partners, and educate key stakeholders to raise awareness of anti-competitive conspiracies and their consequences

    Pre-Qualification & Exclusion

    Pre-Qualification (Responsibility Determination)

    In the United States, COs are required to determine whether a contractor is “responsible” prior to the award of the contract (FAR 9.103). Determination of contractor qualification requires consideration of whether the firm: (1) can be expected to complete the contract work on time and in a satisfactory manner; (2) is organized in such a way that doing business with it will promote various social and economic goals; and (3) satisfies other special standards of eligibility imposed by statutes and regulations.

    Contracting Officers make this determination by reviewing information available in various federal government procurement systems, including the Federal Awardee Performance and Integrity Information System (FAPIIS) (available at SAM.gov) and the Contractor Performance Assessment Reporting System (CPARS) (CPARS.gov), as well as other sources, such as contractor-supplied information and pre-award survey reports (FAR 9.105–1(c)).

    Prospective contractors must be able to demonstrate the following to be determined respon- sible: (1) adequate financial resources to perform the contract; (2) the ability to comply with the delivery or performance schedule; (3) a satisfactory performance record; (4) a satisfactory record of integrity and business ethics; (5) the necessary organization, controls, skills, and experience; (6) the necessary equipment and facilities; and (7) be otherwise qualified and eligible to receive an award (FAR 9.104–1).

    Exclusion (Suspension & Debarment)

    The United States has a mature debarment regime, designed to protect the U.S. government from contractors that are corrupt, incompetent, or otherwise non-responsible. FAR 9.4 provides the framework for discretionary suspension and debarment in the U.S. procurement system and is grounded in the concept of “protection” rather than “punishment.”

    As noted in FAR 9.402: “The serious nature of debarment and suspension requires that these sanctions be imposed only in the public interest for the Government’s protection and not for the purposes of punishment.” The punishment/protection distinction is one of the most frequently misunderstood aspects of the U.S. debarment regime – often leading to confusion and misunderstanding about how or why certain exclusion decisions are made when a contractor’s misconduct is discovered. The confusion likely stems from the mistaken belief that debarment is an extension of the government’s criminal justice system, designed to punish bad actors. Although this is certainly the case in some countries, in the United States, debarment is a “business decision,” intended to protect taxpayer dollars, not punish misconduct.

    Suspension & Debarment Officials (SDOs) may be found in most federal executive branch agencies, with some agencies having more than one (e.g., Department of Defense and the Department of Homeland Security). Although they are required to comply with the policies and procedures detailed in FAR 9.4, agencies are responsible for establishing their own methods and procedures for coordinating suspension and debarment actions, which has led to some severe inconsistencies in agencies’ approaches to debarment. Because two or more agencies may have an interest in a particular contractor’s exclusion, the Interagency Suspension and Debarment Committee (ISDC) can coordinate suspension or debarment proceedings among interested agencies (known as the “lead agency” process).

    SDOs are tasked with determining whether a contractor that has engaged in misconduct is presently responsible and, therefore, still eligible to receive government contracts. To determine a contractor’s present responsibility, SDOs must employ a two-step analysis. First, SDOs must determine whether, pursuant to FAR 9.4, there is cause for suspension or debarment, which generally includes fraud, crimes, very poor performance, violation of certain contract terms or laws, a knowing failure to disclose evidence of fraud or corruption, or “any other cause so serious or compelling a nature that it affects the present responsibility of the contrac- tor or subcontractor.”

    If an SDO establishes there is cause, they must then determine whether exclusion is still necessary to protect the government’s interest. In making this assessment, an SDO will consider a multitude of “mitigating factors” to determine whether the contractor poses a threat to the government’s interests, including cooperation, disciplinary action against responsible employees, compliance enhancements, and other remedial measures.

    Contractor Compliance

    Over the last several decades, there has been an emerging global consensus on the importance of corporate ethics and compliance programs to help companies prevent, detect, and mitigate mis- conduct. The consensus has derived from increased global efforts to combat corruption. Since the late 1990s, dozens of countries have made multilateral commitments to combat corruption and enacted anti-corruption legislation to fight bribery and foster a new era of corporate compliance. Driven primarily by U.S. anti-corruption enforcement efforts, many large multinational companies have responded by investing heavily in sophisticated compliance programs and robust internal controls. As anti-corruption enforcement efforts and compliance expectations have grown, government anti-bribery enforcement agencies, nongovernmental organizations, and civil society organizations have begun publishing compliance guidance to assist companies with the design and implementation of internal ethics and compliance programs.

    Notably, the development of rigorous internal compliance programs has been particularly pronounced in the defense industry, especially among large U.S. government contractors. This is because, similar to other heavily regulated industries, government contractors face increased enforcement risks. Since 2008, all U.S. government contractors have been legally required to have a written code of business ethics and conduct and to make a copy of the code available to each employee engaged in the performance of the contracts (FAR 52.203–13). The rule also requires contractors to exercise due diligence to prevent and detect criminal conduct and promote an organizational culture that encourages ethical conduct and a commitment to compliance with the law.

    Companies seeking guidance regarding compliance best practices can access a wealth of information on the internet. The Defense Industry Initiative and International Forum on Business Ethical Conduct have developed compliance “toolkits” and regularly host ethics and compliance events for contractors. In addition, governments, NGOs, and public organizations have also published guidance to assist companies seeking information about compliance best practices. The DOJ’s “Evaluation of Corporate Compliance Programs” document is also a critical resource for contractors and compliance professionals.

Subscribe