In This Article
Key Takeaways
- GAO report GAO-26-107681, published March 26, 2026, found that OMB's government-wide AI guidance fully addresses only 2 of 10 privacy challenges a GAO-convened expert panel identified.
- The two challenges OMB's guidance does address: building AI-skilled workforce capacity, and scaling AI systems with privacy protections in place.
- The eight it does not fully address include clear evaluation and audit protocols, isolating sensitive data from training sets, standardized performance metrics, and updated privacy impact assessment practices specific to AI.
- GAO made two recommendations to OMB: specify known privacy risks agencies should weigh in their AI policies, and issue additional guidance or facilitate information-sharing on the eight unaddressed challenges. OMB declined to comment on the draft report.
What GAO actually did
On March 26, 2026, the Government Accountability Office published GAO-26-107681, "Artificial Intelligence: OMB Action Needed to Address Privacy-Related Gaps in Federal Guidance". Rather than auditing a single agency's AI system, GAO convened a panel of privacy and AI experts and asked a narrower question: as federal agencies adopt AI faster, does the government's central guidance actually cover the privacy risks that come with it? The panel identified 10 distinct privacy challenges agencies face when deploying AI, from data exposure in training sets to unclear consent processes for the public.
GAO then checked those 10 challenges against OMB's existing AI policy — primarily the framework built around OMB Memorandum M-25-21, which already requires agencies to run pre-deployment testing, impact assessments, and ongoing monitoring for AI systems it classifies as high-impact.
Two covered, eight not
The finding that matters: OMB's guidance fully addresses just 2 of the 10 challenges the panel identified — building the workforce skills agencies need to implement AI responsibly, and scaling AI deployment while keeping privacy protections in place. The other eight are only partially addressed or not addressed at all, per ExecutiveGov's coverage of the report. Those gaps include the absence of clear protocols for evaluating and auditing AI systems that handle sensitive information, no standard method for isolating sensitive data out of training sets, no standardized performance metrics tied to privacy protection, unclear public consent processes, and privacy impact assessment practices that were not written with AI's specific risks in mind.
Why this is a real gap, not a paperwork complaint
M-25-21 already requires agencies to complete an AI impact assessment before deploying high-impact AI. GAO's point is that the template for that assessment, and the guidance behind it, was not built to catch the privacy failure modes specific to AI — like a model memorizing and later surfacing sensitive records it was trained on. An agency can be fully compliant with the letter of M-25-21 and still miss that risk, because the guidance doesn't name it.
What GAO recommended
GAO made two recommendations directly to OMB: specify the known privacy risks agencies should be weighing when they write AI policy, and either issue additional guidance or facilitate information-sharing across agencies on the eight unaddressed challenges — including evaluation methods, data-separation techniques, and technical safeguards. OMB declined to comment on the draft report, which means, as of this writing, the gap GAO identified is still open rather than resolved by a follow-up memo.
What this means if you're building or buying AI for an agency
For a program office or contracting team, the practical takeaway is not to wait for OMB to close these gaps before acting. If a system touches personal data and is anywhere near GAO's definition of high-impact, the privacy impact assessment and data-handling design should be built to the strictest reasonable standard now, not to the minimum M-25-21 currently spells out — because GAO has already told OMB, in writing, that the current spec is incomplete. Teams building AI systems that combine strong data governance (CUI handling, Privacy Act compliance) with AI-specific risk assessment from day one are the ones that won't need to retrofit when OMB eventually tightens the guidance; see Precision Federal's data governance capability page for how that design work fits into an ATO package.
Sources: GAO — GAO-26-107681, published March 26, 2026; ExecutiveGov — GAO calls on OMB to address privacy challenges. Analysis and framing by Precision AI Academy.
Common questions
Does this report mean federal agencies are violating privacy law with their AI use? No. GAO's finding is that OMB's central guidance doesn't fully address 8 of 10 identified privacy challenges, not that any specific agency system is non-compliant with existing law.
What is a 'high-impact' AI use case under M-25-21? AI whose output serves as a principal basis for a decision or action with a legal, material, binding, or significant effect on rights, safety, or access to government services or benefits.
Has OMB responded to GAO's recommendations? OMB declined to comment on the draft report, per GAO's published findings. No public follow-up guidance addressing the eight gaps has been issued as of this report's publication.