When AI Helps Write the Proposal: Governance, Disclosure and Data Risk in U.S. Human Services Procurement

A human services provider can have a carefully governed artificial intelligence environment inside its organization and still know surprisingly little about the AI being used around the edges of a proposal. A consultant may use generative AI to restructure a Medicaid managed care response. A grant writer may summarize a large evidence pack. A business-development employee may test whether an RFP narrative addresses every evaluation criterion. A subcontractor may use AI to refine material that ultimately becomes part of the prime provider’s submission.

None of those activities necessarily means that AI “wrote the proposal.” Each can nevertheless create questions about accuracy, privacy, disclosure, proprietary information and organizational accountability. These emerging issues sit naturally within the Innovation, Pilots & Emerging Models Knowledge Hub, because procurement is becoming one of the places where organizations first discover that their formal AI policies do not always match the technology being used across their wider professional ecosystem.

The U.S. environment makes this particularly complex. There is no single procurement system governing Medicaid agencies, counties, managed care organizations, behavioral health authorities, health systems, grantmakers and federal agencies. AI disclosure requirements may therefore emerge through individual RFPs, state or local procurement rules, contracting policies, grant conditions or purchaser-specific due diligence rather than through one nationally uniform declaration. At the federal level, current policy increasingly addresses how agencies acquire and govern AI, but that should not be confused with a universal rule requiring every offeror to disclose every use of generative AI during proposal preparation.

The central governance challenge is therefore not simply whether AI was used. It is whether the organization understands how it was used, what information entered the system, whether the resulting content was independently verified, whether the use complied with applicable requirements and whether the final proposal remains an evidence-based representation that the provider is prepared to deliver.

AI-assisted proposal writing is becoming an operational governance issue

Generative AI entered many organizations first as an individual productivity tool. Staff experimented with summaries, outlines, editing and research. That model is already being overtaken by AI embedded within document software, search platforms, meeting tools, customer relationship systems, analytics products and specialist operational applications.

Proposal development sits directly inside this transition. Competitive RFPs can require hundreds of pages of specifications, attachments, policies, data requests and narrative responses. AI can help teams navigate that information more efficiently, particularly when used for document comparison, structural review, editing and evidence organization. That makes AI and automation relevant not only to service delivery but also to the corporate infrastructure surrounding HCBS, LTSS, IDD, behavioral health and other community-based services.

The governance risk appears when organizations regard proposal writing as separate from their wider information and technology environment. A narrative response may contain staffing structures, financial assumptions, workforce data, service-user examples, incident learning, quality findings, proprietary operating models or information about proposed partners. What looks like an ordinary writing task can therefore involve information that the organization would normally expect to control carefully.

Providers consequently need to move beyond a binary rule of “AI allowed” or “AI prohibited.” The more useful questions concern purpose, information sensitivity, account configuration, human oversight and consequences. Using AI to reduce repetition in a publicly available capability statement presents a very different risk from uploading identifiable behavioral-health case records into an uncontrolled system.

The United States does not have one equivalent AI disclosure rule for human services proposals

One of the most important distinctions for U.S. providers is jurisdiction. A Medicaid agency in one state, a county behavioral health authority in another and a national health plan can all procure community-based services through materially different rules and contract structures.

Federal AI policy should therefore be interpreted carefully. Office of Management and Budget guidance issued in 2025 strengthened the federal framework for agencies acquiring and using AI, including attention to competition, data, interoperability, privacy and responsible procurement. That framework is significant for organizations selling AI products or AI-enabled services to federal agencies. It does not, by itself, create a blanket national declaration requiring every human services organization to identify generative AI used to polish an ordinary proposal.

Federal acquisition rules also protect contractor proposal and source-selection information from unauthorized disclosure during federal procurements. That reinforces a wider principle relevant to generative AI: proposal information itself can have sensitivity and commercial value. An organization should therefore think about where draft material is processed rather than assuming that information becomes low risk simply because it belongs to a business-development function.

State and local practice can develop differently. A solicitation may expressly ask whether AI was used. Another may contain restrictions relating to confidential information, cybersecurity, subcontractors or automated decision-making without asking anything about proposal drafting. A third may say nothing about AI at all. Managed care organizations and health systems may apply their own vendor-assurance requirements.

This makes provider contracting and procurement compliance a question of reading the actual solicitation rather than importing a generic organizational answer. If an RFP asks for the tool used, its purpose and the sections affected, the provider should answer those questions accurately. If it asks about security architecture, data retention or model training, additional information may be necessary. If it asks only whether AI was used, a lengthy technical explanation may create complexity without improving transparency.

Disclosure should be accurate without becoming performative

Organizations can respond to emerging AI questions in two unhelpful ways. One is to minimize legitimate AI use because they fear that disclosure will disadvantage the proposal. The other is to provide an elaborate statement about encryption, enterprise controls, model training, human review and cybersecurity regardless of what the purchaser actually asked.

A more mature approach is proportionate disclosure. The response should accurately describe material AI use and provide the assurance requested by the purchaser. It should not characterize AI as the independent author of organizational claims when it was supporting human drafting, but nor should it describe substantive drafting assistance as mere spell-checking if that would be misleading.

For example, a provider may accurately state that a generative AI tool supported structuring, editorial refinement and comparison against RFP requirements while all factual claims were derived from organizational evidence and independently verified before submission. That description establishes both the role of AI and the continuing human accountability behind the proposal.

The distinction matters because proposal language can become operationally consequential. A statement about 24-hour response capacity, DSP training, behavioral support expertise, network adequacy, quality performance or implementation timing may influence evaluation and later become part of contractual expectations. Generative fluency cannot establish whether the provider actually possesses that capability.

Organizations seeking stronger evidence discipline can use the Regulatory Readiness Gap Analyzer to examine whether claims about organizational controls are supported by underlying evidence. The same principle applies beyond formal regulation: polished language should never become a substitute for demonstrable capability.

Scenario: a Medicaid proposal exposes a contractor AI governance gap

A multi-state HCBS provider is responding to a state procurement for community-based disability services. Its employees have access to an organization-approved generative AI workspace governed through corporate technology and information-security policies. The proposal team also engages an experienced external specialist to strengthen several operational narratives.

The consultant uses a separately licensed generative AI account to compare draft responses with the RFP questions, restructure lengthy passages and improve clarity. The underlying evidence comes from the provider’s service models, workforce information, quality reports and operational leaders. Identifiable participant records are not required for the work, and all final narratives are reviewed by the provider before submission.

Late in the process, the procurement team notices an AI disclosure question. Its standard organizational statement says that generative AI is used only through the provider’s approved corporate environment. That is true of employees but does not accurately describe the consultant’s work.

The mature response is not to conceal the external use or automatically conclude that the proposal has been compromised. The provider establishes what tool was used, for what purpose, what information was processed and what privacy settings applied. It then answers the solicitation accurately and verifies that the final content remains supported by organizational evidence.

The more important learning occurs afterward. The provider realizes that its AI policy governed employees but did not adequately address consultants, proposal specialists, agencies and other external contributors. Future engagement terms are amended so material AI use is discussed at project initiation rather than discovered immediately before an RFP deadline.

The organization remains accountable for claims produced through an AI-assisted workflow

Generative AI changes the mechanics of drafting; it does not transfer responsibility for the submission. Whether the proposal is prepared by employees, consultants or a mixed team, the offeror remains responsible for the accuracy and deliverability of the representations it makes.

This has particular significance in Medicaid and human services contracting. Proposal narratives may describe staffing ratios, transition arrangements, incident controls, person-centered planning, clinical oversight, network capacity, data reporting, quality-improvement processes and commitments to people and families. Some promises may directly influence pricing and operating models after award.

A strong evidence chain therefore works backward from the final claim. Where did the statement originate? Who knows whether it is current? Is it supported across every site covered by the proposal, or only one program? Has an operational leader agreed that the commitment can be delivered? Is a percentage supported by reliable data? Does a case study remain faithful to the underlying experience?

This connects directly with translating practice into evidence. AI may improve the articulation of an evidence base, but it cannot manufacture the evidence itself. A sophisticated proposal process preserves that distinction even when AI-supported drafting becomes routine.

Human verification needs to test substance, not merely grammar

The phrase “human review” is increasingly attached to AI governance, but it can mean almost anything. Reading a generated paragraph for obvious mistakes is not the same as verifying its factual basis, operational feasibility and contractual implications.

For proposal development, meaningful verification may require several forms of expertise. Operations leaders may validate service-delivery claims. Finance teams may check pricing assumptions. Workforce leaders may confirm recruitment or training statements. Quality teams may examine performance evidence. Clinical specialists may review health or behavioral claims. Compliance or legal teams may need to consider statements carrying particular regulatory or contractual significance.

The provider does not need an elaborate approval structure around every AI-assisted sentence. It does need assurance proportionate to the significance of the claim. A mature process distinguishes between editorial assistance and content whose inaccuracy could materially affect the procurement or subsequent service.

This is a broader risk ownership and assurance issue. The person pressing “submit” cannot personally verify every specialist assertion in a large human services proposal. Accountability therefore depends on clear review responsibilities and an evidence trail showing where important claims were validated.

Personal, business and enterprise AI environments should not be treated as equivalent

The contractor question becomes more complicated because similar generative AI capabilities can be accessed through different account types. A personal subscription, business workspace and enterprise deployment may provide comparable drafting functionality while operating under different contractual, administrative, privacy and governance arrangements.

Organizations should therefore avoid using “paid AI” as a synonym for “enterprise AI.” Equally, they should not assume that every personal account operates with identical privacy settings. Some consumer AI services provide controls over whether submitted content can be used for model improvement, while business environments may apply different default contractual treatment. Those distinctions matter, but they do not remove the need to consider what information is being processed.

For a provider assessing contractor use, relevant questions may include:

  • whether submitted information can be used to train or improve provider models;
  • whether the account is individually or organizationally administered;
  • what retention and deletion controls apply;
  • what security and authentication arrangements protect access;
  • whether confidential or personal information is involved;
  • what contractual terms govern the service; and
  • whether the proposed use is compatible with the provider’s own risk and privacy requirements.

NIST’s AI Risk Management Framework offers a useful conceptual discipline here because it treats AI risk management through governance, context, measurement and active management rather than relying on a single product label. Its Generative AI Profile similarly recognizes that generative systems can introduce distinct risks across areas such as information integrity, privacy, security and human reliance.

For provider leadership teams, the Digital Transformation, AI and Cybersecurity Readiness Assessment offers a practical way to examine whether AI adoption, data governance, cybersecurity, workforce capability and supplier assurance are developing as one governance system rather than as separate technology projects.

Data minimization is often the strongest first control

Account security matters, but it should not become justification for processing information that the proposal task does not require. Human services organizations routinely hold information about disability, health, behavioral support, substance use, safeguarding, housing, family circumstances and other highly personal aspects of people’s lives.

The stronger question is therefore often: does this information need to enter the AI environment at all?

A proposal writer refining a case study may need to understand the support challenge, intervention, outcome and evidence of change. They rarely need a participant’s full name, date of birth, exact address, Medicaid identifier or complete clinical history. Removing unnecessary detail before AI-assisted processing can reduce privacy exposure regardless of account type.

This connects with minimum necessary standards and access controls. HIPAA’s precise applicability depends on the organizations, information and activities involved, and not every human services provider or proposal record falls within the same legal structure. The operational principle nevertheless remains valuable: sensitive information should not be processed merely because it happens to be available.

That principle becomes especially important when external contributors are involved. Contractors may legitimately need access to organizational evidence while having no reason to see identifiable participant-level records. Designing the evidence flow around the task rather than giving broad access reduces both conventional confidentiality risk and emerging AI risk.

HIPAA matters, but it is not the whole privacy framework

U.S. organizations can fall into a common governance trap by treating every AI privacy question as a HIPAA question. HIPAA is highly relevant where protected health information is handled by covered entities and business associates, but community-based care and human services operate across a much wider information environment. Disability services, housing programs, behavioral health providers, county-funded services, grant-funded organizations, workforce systems and contractors may handle sensitive information under different legal, contractual and organizational requirements.

The practical implication is that a proposal team should not assume that information is safe to process through generative AI simply because a particular record falls outside HIPAA. Confidentiality obligations may arise through state law, contractual provisions, professional duties, Medicaid requirements, organizational policy or other privacy frameworks. Information may also be commercially sensitive even when it contains no personal data at all.

Where HIPAA does apply, organizations need to consider whether the AI service is being used in a way that involves protected health information and whether the required contractual and security arrangements are in place. That analysis should not be improvised by a proposal writer immediately before an RFP deadline. It belongs within broader privacy, confidentiality and data-protection governance.

The distinction becomes even more important in behavioral health and substance use services, where information may be subject to additional confidentiality protections. A proposal narrative may need to demonstrate experience supporting people with serious mental illness, substance use disorder or complex co-occurring needs without exposing identifiable histories to tools that do not need that level of detail.

A case study can be valuable evidence without becoming an unnecessary privacy exposure

Human services proposals often depend on case studies because they show how policy and service models translate into real outcomes. The strongest examples can demonstrate coordination, crisis prevention, community inclusion, workforce responsiveness, supported decision-making or improved stability more convincingly than generic statements of capability.

The same detail that makes a case study persuasive can also make a person identifiable. Removing a name does not necessarily anonymize a narrative if it still contains a rare diagnosis, exact age, distinctive family circumstances, a named hospital, a specific county, unusual behavioral history and a precise sequence of events.

This creates an important difference between pseudonymization and genuine de-identification. Calling someone “Member A” or “Person B” may reduce obvious identification while leaving enough contextual information for colleagues, family members or local professionals to recognize them.

Scenario: reducing a powerful case study to the evidence actually needed

A behavioral health provider is preparing a county RFP response and wants to demonstrate how its community team prevented an unnecessary emergency department presentation. The source material includes a detailed chronology involving psychiatric symptoms, medication changes, family conflict, prior hospitalization, police contact and the person’s housing situation.

The bid team wants to use generative AI to turn the chronology into a concise 600-word example. Rather than uploading the original case record, the team first identifies the evidence required by the RFP: recognition of deterioration, rapid engagement, clinical consultation, family coordination, revised safety planning, follow-up and the resulting stabilization.

Names, dates, locations, precise diagnoses and other details that do not advance the procurement response are removed before the text reaches the AI tool. The generated narrative is then compared with the original source by an authorized reviewer to ensure that the intervention and outcome remain accurate.

The result is not simply a safer AI workflow. It is often a better proposal. Removing unnecessary detail forces the team to distinguish between information that is interesting and evidence that actually demonstrates capability.

This is one reason case studies and qualitative evidence should be governed with the same discipline as quantitative performance claims. A compelling story still needs provenance, proportionality and an appropriate privacy boundary.

Proposal information can be commercially sensitive even when no personal data is involved

Privacy is only one part of the risk. Competitive proposals can contain information that organizations would not willingly share outside the procurement process: staffing models, pricing assumptions, proprietary workflows, implementation plans, market strategy, technology architecture, quality weaknesses, subcontractor arrangements and performance data.

Generative AI governance therefore needs to consider confidentiality and intellectual property as well as personal information. Uploading a draft pricing strategy may create no HIPAA issue while still exposing commercially sensitive material. The same applies to an internal corrective-action report used to strengthen a quality response or a proprietary service design developed over many years.

For larger providers, the relevant control may already exist elsewhere in the organization. Information-security classifications, confidentiality policies, document handling rules or vendor-assurance processes can often be extended to AI rather than replaced by a completely separate framework.

This is where data governance and information accountability become more useful than generic instructions to “be careful with AI.” A mature organization defines categories of information, identifies who may process them, determines which environments are acceptable and knows when additional approval is required.

The proposal team should distinguish AI used to write the response from AI proposed as part of the service

Another important U.S. procurement distinction is between using AI during proposal preparation and proposing an AI-enabled capability within the contract itself. These are not the same governance question.

A provider may use generative AI to improve the structure of an RFP narrative while proposing a completely conventional HCBS service. In that situation, the purchaser’s concern is primarily about the integrity, privacy and transparency of the proposal-development process.

By contrast, a bidder may propose predictive analytics to identify people at risk of hospitalization, automated scheduling to allocate DSP capacity, conversational AI to support member navigation, computer vision to monitor safety, or machine learning to prioritize referrals. Those uses affect service delivery directly and may influence people’s access, rights, privacy or outcomes.

The due-diligence threshold should therefore be considerably higher. Purchasers may reasonably want to understand what data the technology uses, what decision it supports, how bias is assessed, whether people are informed, how human review operates, what happens when the system is wrong and how subcontracted technology vendors are governed.

This distinction matters for technology-enabled care. Disclosure that AI helped edit a proposal does not provide assurance about an AI-enabled service model, and assurance about the proposed technology does not necessarily describe how the proposal itself was drafted.

State Medicaid agencies and managed care organizations may ask different questions

Variation becomes especially visible when Medicaid services are procured or administered through managed care. A state Medicaid agency may establish procurement requirements for an MCO or service network while the health plan develops its own subcontractor standards, cybersecurity requirements, data-sharing agreements and provider reporting expectations.

A provider could therefore encounter AI governance in several places. A state RFP may ask an MCO how it governs artificial intelligence. The resulting managed care contract may create expectations around subcontractors or technology vendors. The MCO may then pass additional requirements into provider agreements, vendor questionnaires or security assessments.

That does not mean every HCBS provider will face identical AI provisions. Some states retain substantial fee-for-service structures. Others use managed LTSS extensively. Behavioral health may be carved into separate arrangements. County systems may add another layer of procurement and administration.

The transferable principle is that provider teams should trace the origin of the requirement. Is it federal law, state regulation, Medicaid contract language, a health-plan policy, a procurement question or an organizational preference? That distinction helps prevent a purchaser-specific requirement from being treated as universal while ensuring that genuine contractual obligations are not dismissed as optional.

The Governance Maturity Assessment can help organizations test whether responsibilities for external requirements, technology oversight and delegated accountability are sufficiently clear across executive, operational and compliance functions. AI procurement governance becomes difficult when nobody knows who owns the final interpretation.

Scenario: an MCO requires more assurance than the original state solicitation

An IDD provider successfully joins a Medicaid managed care network after responding to a competitive procurement. The state solicitation contained no question about generative AI. Six months later, the MCO updates its vendor-risk process and asks network providers to disclose material AI systems used in administrative or service functions.

The provider initially assumes the requirement concerns only clinical technology. During review, leaders recognize that AI is also being used in recruitment, document drafting and quality analysis. The organization distinguishes those internal productivity uses from technology affecting member-facing decisions and gives the MCO a proportionate account of each category.

For proposal drafting, the organization records the tools used and confirms human validation. For quality analytics, it performs a deeper review because generated summaries may influence management decisions. For a proposed member-facing digital assistant, it requires formal privacy, accessibility, bias and escalation review before deployment.

The organization has not adopted one control for every AI use. It has created graduated assurance based on consequence. That is more sustainable than attempting to classify all generative technology as either harmless or prohibited.

Contractor and subcontractor AI use should become part of normal supplier governance

Health and human services organizations depend extensively on third parties. Proposal consultants are only one example. Providers may use billing vendors, software companies, staffing agencies, clinical specialists, auditors, marketing firms, data analysts and outsourced administrative services. Each can introduce AI into the provider’s operating environment without the provider purchasing an AI product directly.

The governance response should therefore connect with existing provider risk management and assurance. Organizations can require contractors to disclose material AI use where it affects confidential information, formal deliverables or services performed on the provider’s behalf. Higher-risk arrangements can then receive additional review.

A practical contractor standard might distinguish among:

  • low-risk productivity use involving public or nonsensitive material;
  • use involving confidential organizational information;
  • use involving identifiable personal, health or behavioral information;
  • AI that contributes materially to formal advice, analysis or contractual deliverables; and
  • AI embedded directly within services delivered to people.

Those categories allow the organization to scale controls rather than imposing enterprise procurement requirements on every freelance editor or treating a high-impact technology vendor like an ordinary administrative contractor.

Contract language may also need to evolve. Confidentiality and data-processing provisions written before generative AI became commonplace may not explain whether contractors can use external AI services, whether organizational data may be retained by technology providers, or whether the client expects notification before material AI use.

Standard AI declarations can provide consistency but also create false assurance

Large organizations often create standard answers to recurring procurement questions. That is sensible. Business-development teams cannot repeatedly rebuild responses to cybersecurity, diversity, business continuity, privacy and AI questions from first principles.

The risk appears when a standard statement describes an organizational environment more narrowly than the actual proposal process. A declaration might say that only centrally approved enterprise AI is used, while an external consultant or subcontractor uses a different environment. Another statement might say that AI is used only for proofreading even though teams also use it to restructure substantive draft narratives.

The issue is not that the underlying use is necessarily inappropriate. The problem is that the standard statement has become detached from practice.

This is a familiar assurance challenge. Policies, templates and procurement libraries are representations of organizational controls. They remain reliable only when the organization periodically tests whether reality still matches the wording.

For proposal teams, a simple pre-submission question can close much of the gap: has anyone materially contributing to this response used generative AI in a way that affects the declaration we are about to make? That includes external contributors where their work forms part of the provider’s submission.

Purchaser due diligence should focus on consequence and evidence

Procurement teams also need to avoid turning AI disclosure into a ritual. Asking whether AI was used may produce transparency, but the answer is useful only if the purchaser knows what risk it is trying to assess.

A bidder that used ChatGPT or another generative system to improve readability presents a different assurance question from a bidder that generated staffing projections, interpreted regulatory requirements, calculated financial assumptions or designed an automated service decision through AI.

Purchasers can therefore make due diligence more proportionate by examining consequence. Relevant follow-up questions may concern the reliability of factual claims, sensitive data handling, proprietary information, human review or the role of AI in the proposed service itself.

This aligns with advanced procurement and contract operations. Strong procurement does not collect information simply because it is fashionable. It uses disclosure to identify where additional assurance could materially affect contract risk, service quality or public trust.

AI-assisted writing raises an evidence question as much as a technology question

Generative AI can make weak evidence sound convincing. That may be the most important procurement risk of all.

A model can transform an uncertain internal statement into polished, confident prose. It can connect fragmented facts into a coherent narrative and produce language that sounds authoritative even where the evidence is incomplete. The resulting paragraph may be grammatically excellent and operationally indefensible.

This creates a particular risk for organizations with large proposal libraries. Content can be reused, summarized, adapted and improved over multiple procurement cycles until the original provenance becomes difficult to identify. AI can accelerate that process.

Strong providers therefore need to preserve the relationship between proposal claims and source evidence. This does not require a citation after every sentence. It does require enough traceability that significant commitments, metrics and examples can be validated.

The Quality Dashboard Builder can support organizations in strengthening the quality and performance architecture from which proposal claims are drawn. Reliable procurement evidence ultimately depends on reliable operational evidence; no drafting technology can compensate for weak underlying data.

Boards should care about the governance boundary, not individual prompts

AI-assisted proposal writing would rarely justify routine board review by itself. The governance significance lies in what it reveals about the organization’s wider control environment.

Board and executive leaders should be interested when contractor technology use sits outside established governance, when confidential information can move into external systems without clear rules, when organizational declarations cannot be verified or when AI-supported outputs increasingly influence consequential decisions.

The relevant assurance is therefore thematic. Leaders need confidence that AI use is governed according to risk, that privacy and security responsibilities are clear, that significant supplier risks are visible and that human accountability remains intact. They do not need a register of every prompt used to shorten a proposal paragraph.

This connects with board governance and accountability. The board-level question is whether the organization understands its dependence on AI-enabled workflows and whether controls still operate when technology is used by people outside the formal workforce.

That is an increasingly important distinction in a sector where external expertise, delegated functions and subcontracted delivery are common. AI governance that stops at the employee boundary will become progressively less credible as technology adoption spreads across the wider provider ecosystem.

A contractor AI standard should be proportionate to the information and the consequence

The emerging governance gap is unlikely to be solved by requiring every external consultant, proposal specialist or agency to use exactly the same technology environment as the provider. That may be impractical, particularly for independent professionals and smaller firms. A stronger approach is to establish minimum expectations that follow the sensitivity of the information and the consequence of the work.

For proposal development, those expectations can be relatively simple. External contributors can be asked to disclose material use of generative AI, avoid processing identifiable or unnecessarily sensitive information through unapproved systems, maintain appropriate account and privacy settings, and ensure that AI-assisted content is independently reviewed before it becomes part of a formal submission.

Higher-risk activity should trigger stronger controls. If a consultant is handling protected health information, analyzing confidential incident records, processing employee information or using AI to produce financial, legal, regulatory or clinical analysis, the organization may need additional privacy, security, contractual or professional review. The threshold should be driven by risk rather than by whether the individual happens to be an employee.

This approach fits naturally with policies, procedures and operational controls. A provider does not need a separate policy for every possible AI tool. It needs sufficiently clear rules to distinguish ordinary productivity assistance from activity that could materially affect confidentiality, rights, contractual commitments or service quality.

Contract terms may need to catch up with AI-enabled professional work

Consultancy and subcontracting agreements written only a few years ago may contain detailed confidentiality and data-protection provisions without mentioning generative AI. That does not necessarily mean AI use falls outside those obligations, but explicit language can remove uncertainty.

A future agreement might require contractors to notify the organization before using generative AI materially in a formal deliverable, prohibit identifiable participant information from being entered into unapproved AI services, require compliance with relevant confidentiality obligations and make clear that the contractor remains responsible for the accuracy and professional quality of the work.

The objective should not be to create a hidden technology audit of every external professional. It is to prevent a situation in which the organization makes a procurement or governance statement without knowing whether the contractors contributing to the work operated within the assumptions behind that statement.

Contractor controls also need to remain adaptable. An organization may decide that AI-assisted editing of nonsensitive proposal material is acceptable while requiring explicit authorization for processing participant-level information. It may permit a consultant’s business-grade environment for one task while requiring access to the provider’s own systems for another. Those distinctions are signs of mature governance rather than inconsistency.

Scenario: a one-page AI clause changes the next procurement

After discovering during one RFP that an external proposal specialist had used a different generative AI environment from internal staff, a regional human services provider updates its standard consulting agreement. The change is deliberately short.

Contractors are asked to disclose material AI use connected with client deliverables. They may use generative AI for low-risk drafting and editorial support, but identifiable participant or employee information cannot be processed through an external AI service without prior approval. Contractors remain responsible for validating their work and must comply with existing confidentiality and information-security requirements.

Several months later, the provider engages a specialist to support a Medicaid managed care proposal. At project initiation, the consultant confirms that generative AI may be used to compare drafts against RFP requirements and refine lengthy narrative sections. No participant-level data is required. The provider records the arrangement and agrees how factual claims will be verified.

When the MCO subsequently asks about AI use in proposal preparation, the team already knows the answer. There is no last-minute investigation, no attempt to fit external activity into an inaccurate corporate statement and no need to treat ordinary drafting assistance as a governance incident.

The improvement is small but significant. AI governance has moved from retrospective discovery into normal project mobilization.

Organizations should distinguish assurance from technological prestige

The market is increasingly filled with labels such as enterprise AI, secure AI, private AI and responsible AI. These can describe meaningful differences in product architecture and contractual protection, but they can also create false confidence if governance relies on the label alone.

An enterprise environment may provide stronger administrative controls, organizational identity management, contractual data protections and centrally governed settings. Those are valuable capabilities. They do not guarantee that users will enter appropriate information, recognize hallucinated output, preserve confidentiality or challenge inaccurate recommendations.

Conversely, an individually licensed tool may be configured with restrictive model-improvement settings and used only with nonsensitive information. That does not make it equivalent to an enterprise environment, but neither should account category alone determine whether a low-risk use is acceptable.

The mature assurance question is therefore broader: what data is involved, what controls apply, what contractual environment governs the technology, what decision is being supported, what could go wrong and who checks the output?

This is consistent with the direction of broader U.S. AI risk management. NIST’s AI Risk Management Framework remains voluntary and is itself evolving, but its core emphasis on governing, mapping, measuring and managing risk provides a useful discipline. The framework encourages organizations to understand AI within its actual context rather than treating technology adoption as a binary compliance exercise.

Federal AI procurement policy is important but should not be overstated

Federal acquisition policy is also evolving. OMB Memorandum M-25-22, issued in April 2025, provides current federal guidance for agencies acquiring artificial intelligence and replaced the earlier M-24-18 approach. It emphasizes efficient and responsible acquisition, competition, interoperability, data considerations and the protection of privacy and government information.

That policy matters to providers and technology companies pursuing federal opportunities, particularly where the procurement itself involves an AI system or AI-enabled service. It should not be interpreted as a universal rule governing how every Medicaid provider, county contractor or nonprofit organization drafts a proposal.

The distinction is important because federal policy can easily be overextended in sector commentary. A state Medicaid agency may draw on federal AI principles without adopting the same procurement mechanics. A county may develop its own disclosure question. An MCO may impose vendor requirements through contract rather than public procurement law. A private health system may use entirely different assurance criteria.

For providers, the practical rule remains the same: read the actual solicitation, contract and applicable jurisdictional requirements. National frameworks can inform governance, but they do not remove state, payer or purchaser variation.

AI disclosure should not become an unstated evaluation penalty

As AI disclosure questions become more common, purchasers will also need to consider how suppliers interpret them. If bidders believe that admitting legitimate AI use will reduce their score, organizations may be incentivized to describe substantive assistance as ordinary software functionality or avoid disclosure altogether.

That would undermine the purpose of transparency. A more effective procurement environment distinguishes between responsible AI assistance and risks that genuinely require additional due diligence.

A provider that uses generative AI to tighten prose, organize evidence or compare a response with an RFP requirement is not presenting the same risk as an organization relying on AI to invent performance information or make consequential eligibility, staffing or clinical decisions. Procurement teams can preserve that distinction by explaining why disclosure is requested and how the information will be used.

This becomes particularly important where smaller providers, community-based organizations and specialist contractors compete with national organizations. AI can help smaller teams reduce administrative burden and improve proposal quality. Governance should protect procurement integrity without creating a technological compliance barrier that only organizations with large enterprise platforms can navigate.

The strongest control is still the evidence behind the proposal

Much of the discussion around generative AI focuses on hallucination, but proposal risk is not limited to obviously false information. AI can also make weak, dated or incomplete organizational evidence sound more authoritative than it really is.

A provider might have an old workforce statistic, a case study from one program or a policy that has not been fully implemented across its network. Generative AI can integrate those fragments into confident prose without understanding whether the evidence is representative. That can produce a narrative that sounds stronger than the underlying capability.

Strong proposal governance therefore preserves source ownership. Significant claims should be traceable to current organizational evidence and reviewed by people able to judge their operational accuracy. Where evidence is uncertain, the response should be qualified or strengthened rather than rhetorically polished into certainty.

The Quality Improvement Action Plan Builder can support organizations where proposal preparation exposes a genuine operational gap. A mature provider does not use AI to conceal weak evidence; it treats the weakness as information that may require remediation, clearer qualification or future improvement.

AI literacy is becoming part of proposal and leadership capability

Governance cannot sit entirely with technology teams because many consequential decisions about AI occur within ordinary operational work. Proposal leads decide what evidence to upload. Consultants decide how to structure prompts. Quality staff decide whether a generated summary accurately reflects an incident trend. Managers decide whether an AI-assisted narrative represents what actually happens in services.

Those responsibilities require a level of AI literacy that goes beyond knowing how to use a chatbot. Staff and contractors need to understand that generated text can be plausible and wrong, that privacy settings vary between environments, that de-identification may be incomplete and that confidential organizational material carries risk even where HIPAA does not apply.

They also need to understand when AI use is low risk. Overly cautious governance can create unnecessary administrative barriers and encourage people to hide routine technology use. Effective training should therefore help users distinguish between ordinary assistance and situations requiring escalation.

This links with trust, transparency and ethical data use. The strongest organizations will not rely solely on technical restriction. They will develop enough organizational understanding for people to recognize the implications of what they are doing.

Boards need visibility of the control environment rather than every use case

For boards and executive teams, the appropriate level of oversight is strategic. A governing body does not need to know that a proposal manager used AI to shorten a paragraph. It does need confidence that the organization has established boundaries around sensitive information, understands significant external dependencies and can make accurate representations to purchasers.

Useful assurance may include recurring themes from privacy reviews, cyber incidents involving AI-enabled tools, significant exceptions to approved technology, contractor compliance issues, high-impact AI use cases and areas where organizational policy no longer reflects operational practice.

Leaders should also ask whether governance reaches beyond direct employees. If consultants, subcontractors and technology vendors contribute materially to formal deliverables or services, the organization needs enough visibility to understand where delegated activity creates risk.

This is where governance maturity and organizational readiness become meaningful. Mature governance is not demonstrated by having the longest AI policy. It is demonstrated when responsibilities, escalation routes and assurance remain clear as technology use expands into new parts of the organization.

The future challenge will be AI that no longer looks like AI

Today, AI disclosure often assumes that users deliberately open a named generative platform. That distinction is likely to become less useful. AI functionality is increasingly embedded within word processors, search engines, transcription tools, analytics platforms, customer-service systems and enterprise applications.

Proposal teams may soon use AI-supported functions without considering them separate from ordinary software. Documents may be summarized automatically. Draft language may be suggested inside the application. Search systems may synthesize information rather than simply retrieve it. Procurement platforms themselves may increasingly use AI to help evaluators analyze responses.

The governance question will therefore shift from “Did anyone use AI?” toward more consequential questions: did AI materially influence a claim, analysis, calculation, recommendation or decision? What information did the function process? Could the output affect a person, contract or public decision? Was meaningful human review retained?

This evolution fits the wider challenge of scaling emerging models. Governance designed around individual products can become obsolete quickly. Governance designed around information, consequence, accountability and evidence is more durable.

Proposal governance can become an early test of organizational AI maturity

AI-assisted proposal development may appear peripheral to service delivery, but it provides a useful test of whether an organization is ready for more consequential AI adoption. Proposal teams operate across strategy, operations, finance, quality, workforce, data and external partnerships. Weak governance becomes visible quickly because information crosses those boundaries under deadline pressure.

An organization that can answer basic questions about proposal AI use is developing capabilities it will need elsewhere. It knows which technologies are being used, distinguishes account and contractual environments, minimizes sensitive information, verifies outputs and understands who is accountable for external contributors.

Those disciplines become even more important when AI begins to influence scheduling, quality intelligence, risk identification, workforce analytics or member navigation. The technology changes; the governance principles remain recognizable.

For provider executives, the opportunity is therefore larger than creating another procurement declaration. AI-assisted proposal work can reveal gaps in supplier governance, information classification, evidence traceability and organizational accountability before those gaps affect a higher-risk use case.

Scenario: proposal governance becomes a pathway to broader AI assurance

A national provider initially develops an AI protocol because several government and health-plan RFPs begin asking about generative AI. The first version focuses narrowly on proposal drafting, confidentiality and human verification.

Within a year, leaders realize the same questions apply elsewhere. Recruitment teams use AI-assisted screening tools. Quality staff use automated summaries to identify patterns in incidents. Operations teams experiment with workforce forecasting. A technology vendor introduces an AI-supported member communication feature.

Rather than creating separate governance systems for each function, the provider develops a common risk framework. Low-impact productivity uses remain decentralized within defined boundaries. Uses involving personal data, consequential decisions, automated recommendations or service delivery require progressively stronger review. Contractor and vendor use is brought into the same architecture.

The original procurement question has therefore acted as an early warning. It revealed that the organization needed to govern AI according to information and consequence rather than according to department or employment status.

The outcome is not more control for its own sake. It is a clearer route for responsible experimentation, because teams know when they can proceed, when they need advice and when stronger assurance is justified.

Conclusion

Generative AI is becoming part of the infrastructure through which U.S. health and human services organizations prepare proposals, analyze information and coordinate complex work. That does not make every AI-assisted RFP response a high-risk activity. It does mean that providers, payers and public purchasers need a more sophisticated vocabulary than simply asking whether AI was used.

The strongest governance distinguishes assistance from authority. AI can help structure evidence, improve clarity and review complex requirements, but the provider remains responsible for every claim it submits and every commitment it ultimately delivers. Privacy, confidentiality and data minimization still matter. So do account configuration, contractor governance, human verification and the quality of the evidence behind the prose.

The federal landscape adds useful direction but not national uniformity. OMB policy increasingly shapes federal acquisition of AI, NIST provides evolving voluntary risk-management frameworks, and state Medicaid agencies, counties, MCOs and other purchasers may establish their own requirements. Providers therefore need controls that are strong enough to withstand variation without pretending that one disclosure rule applies everywhere.

The next stage of maturity will be less about policing individual prompts and more about governing information, consequence and accountability across the provider ecosystem. Organizations that build that capability now will be better positioned to use AI productively while preserving procurement integrity, public trust and the rights and interests of the people their services exist to support.