Skip to content

5 signs your agency’s AI governance is already failing and how to fix it

The Government Accountability Office (GAO) didn't speculate about federal AI risk this year. It documented it, agency by agency, with names and dates. The pattern across its recent reports is consistent: agencies are adopting AI faster than they can govern it. And, citizens' own comfort with AI hasn't caught up either. According to Pew Research Center, half of U.S. adults now say the increased use of AI in daily life makes them feel more concerned than excited, up from 37% when Pew first asked in 2021. Just 10% of U.S. citizens say they're more excited than concerned.

The issue compounded because of the impressive speed of AI adoption organically within government. Federal AI use cases nearly doubled from 571 to 1,110 across 11 selected agencies in a single year, and generative AI use grew ninefold in that same window (GAO-25-107653, July 2025). This pace of growth exceeds any policy team's ability to keep up, and GAO's findings show exactly where the gaps are opening.

Therefore, it's a good time to pause and take stock, to consider if your agency already has a potential problem, and what can be done today to ameliorate the situation. It helps to know the signs, so here are five key indicators your agency's AI governance is already behind, based on GAO findings and citizen feelings on the current state of AI:

1. Adoption is outpacing policy. Most federal agencies adoption of AI has outstripped its oversight, according to both a NextGov survey and E&Y’s research. Executive guidance has also been a moving target: EO 14110 was rescinded in January 2025, replaced by OMB M-25-21 and M-25-22 that April, then updated again by M-26-04 in December 2025. If your policy hasn't caught up with the last guidance change, it's already behind the next one.

2. Oversight is fragmented. The Atlantic Council noted fragmentation between federal and state AI policies. GAO identified 94 AI-related requirements that are government-wide (or have government-wide implications), spanning statutes, executive orders, and guidance, including 10 separate executive branch oversight and advisory groups sharing a role in implementation (GAO-25-107933, September 2025). When no single person owns the whole outcome for AI, gaps between teams can go unnoticed. This, in part, is why 30% of federal CDOs now also serve as CAIO, up from essentially none a few years earlier.

3. The workforce gap is showing. Brookings pulled historical USAJobs postings data for several years across seven technical job series and found AI-specific job listings grew from zero in 2016 to about 8% of all technical postings by 2024. The job need nearly doubling from 184 to 318 postings, which is just a small symptom of the problem. For government, highly qualified technical candidates are always hard to find as they are in such demand by the public sector. GAO's AI Accountability Framework lays out clear practices for governance, data, performance, and monitoring across the AI lifecycle. But a severe shortage of federal staff with AI expertise limits how well agencies can actually apply it (GAO-23-106811, May 2023 testimony). A framework nobody has the capacity to run becomes a document on a shelf, not a practice in production.

4. Risk assessments are an afterthought. GAO reviews have repeatedly found agencies moving high-impact AI into production faster than they can assess or manage its risks, with risk review too often happening after deployment rather than before it. That gap tracks with how people describe their own experience of AI. In the Pew Research survey of the U.S. public and AI experts, only 17% of the general public thought AI would have a mostly positive impact on the country over the next 20 years, compared with 56% of AI experts. And it's not just optimism that's missing: almost half or more of both groups said they have little or no control over how AI is used in their lives, and more than half said they want more control than they currently have. People aren't necessarily against AI — they're reacting to the sense that no one is managing it carefully on their behalf. That's the same gap GAO keeps finding inside agencies — assessment that arrives after the decision, not before it.

5. Procurement is outrunning the guardrails. Cost pressures and budget management always presents additional complexity in the Public Sectors, but perhaps it is even more true with AI projects. There are no prior historical presidencies. Agencies more than doubled their use of AI acquiring it through a mix of agency-directed and vendor-driven approaches, sometimes with industry introducing capabilities before agencies had set their own requirements (GAO-26-107859, April 2026). GAO recommended agencies systematically collect and apply lessons learned across procurements; still, most aren't able to do so yet. Contracts are closing faster than governance can catch up.

What best-in-class looks like

None of this means governance is impossible at scale. Rather, governance has to be built as a control point, not bolted on after the fact. GAO's four-principle model (governance, data, performance, monitoring) gives agencies a lifecycle to design around rather than a checklist to catch up on later. The agencies GAO cites favorably are the ones that governed before they were asked to.

That's also the thesis worth bringing back to your leadership: data governance is the control point for everything downstream: bias, breaches, compliance, and public trust. Framing it that way changes the conversation. It's not "IT problem," it's "risk control point." It's not "compliance checkbox," it's "trust enabler." It's not "cost center," it's "audit-readiness investment."

Public unease about AI itself is already widespread — half of Americans say they're more concerned than excited about its growing presence in daily life, per Pew's research — and every agency that governs well before a GAO review, rather than after one, is one more reason for that unease to ease.

If you're accountable for how your agency scales AI responsibly, the next GAO report is coming whether you're ready or not. The choice is whether your agency is called out as the good example or as the finding.

Sources:

  1. Nextgov/FCW, "Survey: More than half of federal agencies now planning agentic AI pilots" (May 2026)
  2. https://www.ey.com/en_us/newsroom/2026/04/federal-government-agencies-efficiency-efforts-face-significant-barriers
  3. https://www.brookings.edu/articles/assessing-the-state-of-ai-adoption-across-the-federal-government/
  4. https://www.deloitte.com/us/en/Industries/government-public/perspectives/federal-cdo-survey-2026.html
  5. https://www.pewresearch.org/short-reads/2026/03/12/key-findings-about-how-americans-view-artificial-intelligence/
  6. GAO-25-107653 (July 2025) • GAO-25-107933 (September 2025) • GAO-23-106811 (May 2023 testimony) • GAO-26-107859 (April 2026)

Keep up with the latest from Collibra

I would like to get updates about the latest Collibra content, events and more.

There has been an error, please try again

By submitting this form, I acknowledge that I may be contacted directly about my interest in Collibra's products and services. Please read Collibra's Privacy Policy.

Thanks for signing up

You'll begin receiving educational materials and invitations to network with our community soon.