The GovAI Stack: FedRAMP-Authorized LLM Services and the Procurement Mechanics That Actually Move
The US federal AI stack has clarified around a specific set of FedRAMP-authorized services. What agency CIOs are actually procuring, and how the mechanics work.
The US federal AI conversation between roughly 2023 and mid-2025 was dominated by pilots, by executive orders, and by a lot of policy language that did not translate cleanly into procurement action. That has shifted meaningfully in the last twelve months. The specific set of FedRAMP-authorized large-language-model services available to federal agencies has clarified, the procurement vehicles agencies are actually using to buy them have consolidated, and the internal mechanics of getting a use case from approved to in-production have become clear enough to describe. The GovAI stack, in other words, is real.
The first observation is that FedRAMP High authorization for the specific commercial LLM services has moved from aspirational to actual for the major hyperscaler-hosted offerings, and the Department of Defense Impact Level authorizations for the analogous classified environments have followed a similar path. That authorization work is what has unblocked the procurement action that trailed it. Agencies that were waiting for authorization certainty before committing to a specific vendor pathway now have that certainty for a defined set of services, and the procurement pipelines have started to move accordingly.
The second observation is about vehicles. The specific procurement vehicles agencies are actually using are narrower than the general acquisition catalog suggests. The GSA schedules, specifically the ones that carry AI-relevant IT services, are handling a meaningful share. The specific government-wide acquisition contracts run by NASA, NIH, and the Department of Defense are handling the rest, with the specific vehicle chosen depending on the agency's existing procurement relationships and on the specific labor category the acquisition requires. The organizations that have gotten AI work under contract quickly have almost all done so through vehicles their contracting offices already knew how to run, rather than through the AI-specific vehicles that generated initial press attention.
The third observation is about the authorization-to-operate process, which is where public-sector AI adoption tends to stall. The specific agencies that have moved from pilot to production have done so by treating the authorization process as a design constraint on the pilot rather than as a gate at the end of the pilot. The specific security controls, data-handling boundaries, logging requirements, and human-in-the-loop attestations that the authorizing official will require have been baked into the pilot architecture from the start. Agencies that ran a pilot on a clean architecture and then tried to retrofit the authorization posture at the end have, in almost every case, taken meaningfully longer to reach production than agencies that started with the authorizing official in the room.
The fourth observation is about the specific use cases that are actually moving. Document processing, particularly for the specific document types that dominate the workload of large civilian agencies, has produced the clearest set of authorized productions. Constituent-service inquiry handling, with careful scoping of the specific query types the model is allowed to handle, has followed. Analytical work against unclassified public data has generally cleared authorization more quickly than work involving personally identifiable information or law-enforcement data, which is where the process still takes longer for reasons that are appropriate to the underlying data sensitivity.
The fifth observation is about the state level. The specific state agencies that have moved fastest on AI adoption have generally done so by piggybacking on the federal authorization work rather than by running parallel state-level authorization for the same commercial services. That practice has produced the fastest state-level production deployments, and it is worth naming because it suggests a pattern for the next wave of state-level agency adoption that does not require every state to rebuild the security review from scratch.
For a federal agency CIO, the working guidance is that the current AI portfolio should be inventoried against the specific FedRAMP-authorized services, the specific procurement vehicles the contracting office actually operates well, and the specific authorization pathway that fits the use case. Portfolios that carry a general AI strategy without those three specifics have almost always taken longer to move to production than portfolios that started with them.
For a state or local government CIO, the parallel guidance is that the federal authorization work is a real resource that can be used, through the specific mechanisms that state procurement offices have historically used to consume federal certifications. Agencies that are running parallel authorization work for services that already carry federal authorization are, in most cases, absorbing cost and time that a settled reciprocity practice would remove.
For a non-profit or an NGO working with federal agency partners on AI use cases, the practical implication is that the technical stack the partner agency can actually consume is narrower than the general commercial market. Grant proposals and program designs that assume the agency can use any commercial AI service are, in current authorization conditions, working from a broader set of options than actually exists.