Back Download thesis (PDF)
MSc Thesis · Oxford Internet Institute · Submitted August 2026

Procurement and Process:
what AI procurement rules did—and what repealing them didn't.

An interrupted time series analysis of federal AI contracting after the 2024 OMB AI procurement memoranda—tracing how a pair of White House memoranda, their enforcement, and their 2025 repeal shaped how civilian agencies acquire artificial intelligence.

The 2024 memoranda imposed substantial new governance and acquisition requirements on federal AI use—requirements a compliance-cost account would predict to slow contracting. The data reject that prediction. Once the requirements became enforceable on 1 December 2024, civilian AI contracting accelerated sharply and specifically; when the framework was partially repealed in April 2025, no robust AI-specific reversal followed.

Enforcing the rules moved federal AI acquisition. Repealing them did not move it back.

Status
Submitted · MSc Social Science of the Internet · 11,568 words
Method
Interrupted time series · OLS, Newey–West HAC & GLS AR(1)
Data
USAspending.gov · SAM.gov · OMB AI Use Case Inventory · FY2016–FY2026
Sample
63.4M transactions screened · 6,730 civilian AI transactions · 1,929 awards · 120-month series
Read
Full thesis (PDF) ↓
The question

Does procurement regulation change what government acquires?

Public procurement has quietly become one of the principal instruments of AI governance in the United States. In the span of roughly thirteen months, the federal government stood up and then partially dismantled a substantial compliance regime for public-sector AI through procurement instruments alone—OMB memoranda and acquisition guidance, not statute. M-24-10 (March 2024) established internal governance structures and risk-management practices; M-24-18 (September 2024) translated them into acquisition requirements; both became enforceable on 1 December 2024; and M-25-21/22 (April 2025) rescinded them in favour of an acceleratory posture.

Despite procurement's growing regulatory importance, there is limited empirical evidence on whether it actually moves acquisition. This thesis tests that question directly, at three points: the memoranda's release dates, their shared enforcement deadline, and their repeal. The findings, in order: the two releases are too institutionally entangled to separate; enforcement produced a sharp, AI-specific acceleration; and the repeal produced no robust AI-specific reversal.

Acceleration at enforcement
+5.2 /mo
additional AI contract actions per month after 1 Dec 2024 (p = .002), against a pre-policy trend below one—robust across all three estimators
Nine months after the break
+45%
AI contract actions above the extrapolated pre-policy trend; new awards run +149% above it
AI hidden below the prime tier
$2.3B
in subawards to named AI vendors sitting beneath 539 prime contracts that do not themselves read as AI
After the April 2025 repeal
Null
no robust AI-specific reversal—AI's share of civilian IT contracting shows no break that survives across estimators
Civilian AI contract actions and obligations by month · Oct 2021 – Jan 2026
Period
Hover the chart
AI contract actions
AI obligations ($M)
AI contract actions (count)
AI obligations ($M)
Enforcement (solid)
Other policy dates (dashed)
The chart displays the recent window of the series. The estimation baseline runs FY2016–FY2025 (120 monthly observations), extended to January 2026 for the repeal test; the full series, figures, and estimation appear in the thesis.
Finding

Enforcement left a mark; repeal did not. After the 1 December 2024 deadline, civilian AI contracting accelerated by roughly 5.2 contract actions and 3.5 new awards per month against pre-policy trends below one—robust across all three estimators, and specific to AI: the AI share of new civilian IT awards climbed at the same moment. Because new awards and total actions break together and in matching proportion, the acceleration reflects new procurement decisions rather than the re-papering of existing contracts. After the April 2025 repeal, AI contracting declined—but so did civilian contracting broadly, and AI's share of civilian IT shows no robust break. The decline was a government-wide contraction, not a reversal specific to AI.

Who supplies it, and who buys it

Top vendors by total AI obligations

The market the record shows is a mix of direct AI-native supply and intermediated passthrough. Palantir dominates the vendor distribution outright, ahead of integrators such as Booz Allen and Accenture and high-volume resellers such as Four Points and ThunderCat that intermediate many smaller acquisitions—not the small-firm ecosystem the innovation-policy literature envisions procurement cultivating.

Purchasing agencies since enforcement

By number of contract actions. The General Services Administration is the largest single buyer, but accounts for roughly a fifth of activity; AI acquisition is distributed widely across Health & Human Services, Homeland Security, Treasury, NASA, and dozens of further agencies.
The repeal

Repeal without reversal

In April 2025, M-25-21 and M-25-22 rescinded the Biden-era framework and reoriented federal AI policy from risk management toward acceleration. This furnishes the symmetric test the design was built to support: if operationalising the requirements moved contracting, did rescinding them move it back?

It did not. Civilian AI contracting declined after the repeal, but civilian contracting declined broadly across 2025, and the decisive test—the AI share of civilian IT, which holds the wider contracting environment constant—shows no repeal break that survives across estimators. Nor did the activity migrate out of view: AI acquired through resellers declined alongside directly named AI rather than absorbing it, consistent with a real, economy-wide contraction rather than a recording artefact.

The asymmetry is itself the finding. Enforcement produced robust, AI-specific trend changes; wholesale repeal produced none. One reading the thesis develops is that the repeal was in any case partial: M-25-21 retained the Chief AI Officer role and the high-impact AI category—precisely the administrative capacity that enables acquisition. The infrastructure the framework installed persisted beyond the framework itself, and federal purchasing behaviour tracked the operationalisation of governance requirements far more closely than their removal.

The blind spot

The record misses much of what it is meant to register

The contract record under-captures federal AI acquisition through three structural channels. Omission: a substantial share of the AI use cases the government itself declares cannot be matched to any civilian prime contract at all. Labelling: declared AI frequently carries contract descriptions in which no identifiable AI language appears, invisible to any text-based method however carefully tuned. Tier: real AI work flows to AI vendors as subawards beneath prime contracts that do not read as AI—at least 1,868 subawards under 539 distinct primes, on the order of $2.3 billion, to vendors including Palantir, C3.ai, Databricks, and Clearview.

The sharpest illustration is the governmentwide OneGov arrangement, live from spring 2025, which negotiates near-free enterprise access to commercial AI tools by treating the federal government as a single buyer. By GSA's own account it has reached roughly 3.4 million users and avoided approximately $1.15 billion in cost—yet in the contract record it surfaces only as a handful of one-dollar subscription line items. The mechanism that defines the instrument, collapsing price toward zero, is precisely the mechanism that removes the reportable obligation making procurement visible.

The consequence is double-sided: the same record failures blind external accountability and internal oversight simultaneously. On the evidence here, no instrument the government currently operates can reliably tell it which of its contracts involve AI—a gap that sits prior to the concerns about capture and capability that dominate the critical literature.

Method

Interrupted time series on the civilian contracting universe

The analysis screens 63.4 million prime transactions from USAspending.gov (FY2016–FY2026), supplemented with Other Transaction Authority agreements from SAM.gov and cross-validated against the OMB AI Use Case Inventory. AI-related activity is identified through a tiered lexicon—full-phrase and bounded-acronym matches, the capability vocabulary the memoranda regulate, and named vendors and products with corroboration requirements—refined by documented exclusion screens and a manual review pass. Defence and intelligence agencies are excluded throughout: the memoranda govern civilian agencies, and defence contracting is a structurally distinct procurement regime.

Design
Segmented regression · level and slope terms at each intervention · fiscal-year seasonality controls, with full month fixed effects as robustness
Outcomes
AI contract actions · new AI prime awards · AI share of civilian IT (within-series normalisation against a ~2.17M-action IT base)
Interventions
M-24-10 (Mar 2024) · M-24-18 (Sep 2024) · 1 Dec 2024 enforcement deadline (headline break) · M-25-21/22 repeal (Apr 2025)
Inference
OLS, Newey–West HAC, and GLS AR(1); a break is treated as robust only where it holds across all three
Baseline
FY2016–FY2025 (120 months), extended to Jan 2026 for the repeal test; FY2026 truncated for reporting lag
Validation
Placebo breaks at six non-event dates · monthly event study · bent and quadratic counterfactuals · alternative filter widths · subaward-augmented universe

The chart above presents the descriptive series with intervention markers; the thesis develops the estimation, the announcement-versus-enforcement timing tests, the robustness battery, and the measurement-visibility analysis in full, with the complete filtration code in Appendix B.

Implication

Procurement can mobilise; it cannot yet verify

The thesis hypothesised that enforcement would slow contracting, with risk-management practices, impact assessments, and CAIO review functioning as compliance burdens. The data rejected that reading. Drawing on the institutional literature on rules as coordination—North's account of institutions reducing transaction costs, and the policy-uncertainty findings of Baker, Bloom, and Davis—the more consistent interpretation is that the memoranda functioned as legitimising infrastructure. For agencies reluctant to act while the terms of acceptable acquisition remained undefined, the framework supplied those terms and built the administrative capacity that converted an ambiguous reputational gamble into an authorised category of purchase. The memoranda did not instruct agencies to buy artificial intelligence; they made buying it an ordinary administrative act.

The comparison across policy levers is the broader contribution. The governance lever and the acquisition lever are both legible in the contract record and estimable within it; the price-and-access lever is neither. OneGov plausibly moves more AI into government than either memorandum, yet it is the instrument the record is least able to see. The levers that govern by rule leave a trace; the lever that governs by price does not.

The resulting tension frames the conclusion: procurement is a governance lever that can move purchasing behaviour, measurably and specifically, but one the state operates partly blind. An instrument whose effects cannot be verified, applied to a market the government can only partially see, is a strong tool for mobilisation and a weak one for comprehensive regulation. If procurement is to function as AI regulation, the challenge is not only to govern what the state buys, but to make what it buys governable.