GAO Says OMB's AI Guidance Only Covers 2 of 10 Privacy Risks Agencies Actually Face

GAO Says OMB's AI Guidance Only Covers 2 of 10 Privacy Risks Agencies Actually Face

In This Article

  1. What GAO actually did
  2. Two covered, eight not
  3. What GAO recommended
  4. What this means if you're building or buying AI for an agency

Key Takeaways

What GAO actually did

On March 26, 2026, the Government Accountability Office published GAO-26-107681, "Artificial Intelligence: OMB Action Needed to Address Privacy-Related Gaps in Federal Guidance". Rather than auditing a single agency's AI system, GAO convened a panel of privacy and AI experts and asked a narrower question: as federal agencies adopt AI faster, does the government's central guidance actually cover the privacy risks that come with it? The panel identified 10 distinct privacy challenges agencies face when deploying AI, from data exposure in training sets to unclear consent processes for the public.

GAO then checked those 10 challenges against OMB's existing AI policy — primarily the framework built around OMB Memorandum M-25-21, which already requires agencies to run pre-deployment testing, impact assessments, and ongoing monitoring for AI systems it classifies as high-impact.

Two covered, eight not

The finding that matters: OMB's guidance fully addresses just 2 of the 10 challenges the panel identified — building the workforce skills agencies need to implement AI responsibly, and scaling AI deployment while keeping privacy protections in place. The other eight are only partially addressed or not addressed at all, per ExecutiveGov's coverage of the report. Those gaps include the absence of clear protocols for evaluating and auditing AI systems that handle sensitive information, no standard method for isolating sensitive data out of training sets, no standardized performance metrics tied to privacy protection, unclear public consent processes, and privacy impact assessment practices that were not written with AI's specific risks in mind.

Why this is a real gap, not a paperwork complaint

M-25-21 already requires agencies to complete an AI impact assessment before deploying high-impact AI. GAO's point is that the template for that assessment, and the guidance behind it, was not built to catch the privacy failure modes specific to AI — like a model memorizing and later surfacing sensitive records it was trained on. An agency can be fully compliant with the letter of M-25-21 and still miss that risk, because the guidance doesn't name it.

What GAO recommended

GAO made two recommendations directly to OMB: specify the known privacy risks agencies should be weighing when they write AI policy, and either issue additional guidance or facilitate information-sharing across agencies on the eight unaddressed challenges — including evaluation methods, data-separation techniques, and technical safeguards. OMB declined to comment on the draft report, which means, as of this writing, the gap GAO identified is still open rather than resolved by a follow-up memo.

What this means if you're building or buying AI for an agency

For a program office or contracting team, the practical takeaway is not to wait for OMB to close these gaps before acting. If a system touches personal data and is anywhere near GAO's definition of high-impact, the privacy impact assessment and data-handling design should be built to the strictest reasonable standard now, not to the minimum M-25-21 currently spells out — because GAO has already told OMB, in writing, that the current spec is incomplete. Teams building AI systems that combine strong data governance (CUI handling, Privacy Act compliance) with AI-specific risk assessment from day one are the ones that won't need to retrofit when OMB eventually tightens the guidance; see Precision Federal's data governance capability page for how that design work fits into an ATO package.

Sources: GAO — GAO-26-107681, published March 26, 2026; ExecutiveGov — GAO calls on OMB to address privacy challenges. Analysis and framing by Precision AI Academy.

Common questions

Does this report mean federal agencies are violating privacy law with their AI use? No. GAO's finding is that OMB's central guidance doesn't fully address 8 of 10 identified privacy challenges, not that any specific agency system is non-compliant with existing law.

What is a 'high-impact' AI use case under M-25-21? AI whose output serves as a principal basis for a decision or action with a legal, material, binding, or significant effect on rights, safety, or access to government services or benefits.

Has OMB responded to GAO's recommendations? OMB declined to comment on the draft report, per GAO's published findings. No public follow-up guidance addressing the eight gaps has been issued as of this report's publication.

About Precision AI Academy

Precision AI Academy publishes practical AI news, plain-language analysis, and free courses for builders and working professionals. It is a sister site of Precision Federal, a federal software and AI firm. We verify the numbers, cite the primary sources, and skip the hype.