CDW Government’s Asim Iqbal and Aaron Chapman delivered a stark message at the AWS Summit Washington, D.C. in July 2026: federal agencies are losing control of artificial intelligence not because pilots fail, but because early successes invite a cascade of uncoordinated follow-ons. Their prescription is a single, mandatory intake process for every AI use case—combined with risk-based governance and a hard 90-day cycle to move from concept to measurable mission outcomes.

What the panel actually proposed

The core idea is deceptively simple. Instead of letting program offices separately procure chatbots, document analyzers, or agentic tools, every AI initiative must enter through one front door. That intake captures the mission problem, expected outcome, business owner, user population, data profile, and risk factors. A designated governance board then triages it into one of four risk tiers:

Risk Tier Typical Example Governance Approach
Tier 1: Low Internal drafting or meeting summarization Approved environment, basic data controls, lightweight registration
Tier 2: Moderate Workflow automation or code assistance connected to agency repositories Security/privacy review, named owner, monitoring requirements
Tier 3: High Systems influencing benefits, enforcement, or critical operations Enhanced testing, human oversight, impact assessment, continuous monitoring
Tier 4: Restricted Uses that can’t meet legal, security, or mission safeguards Denied, redesigned, or deferred

The panel stressed that the intake process must avoid becoming a bureaucratic essay contest. Its goal is routing—not stalling—and every deployment gets a renewal checkpoint where the agency asks: Is it still solving the problem? Are metrics holding? Has the risk profile changed?

Framed as a 90-day enterprise AI program, the playbook breaks into three phases:
- Days 1–30 (Control & Visibility): Name executive sponsors, run an AI discovery sprint to inventory all active pilots and embedded AI features, launch the single intake form, define interim data-use rules, pick 2–4 priority use cases with clear mission value, and baseline current performance.
- Days 31–60 (Guardrails & Patterns): Build reusable architecture patterns, identity standards, logging requirements, vendor due-diligence templates, contract language for model changes, evaluation templates, and a shared AI sandbox with defined boundaries.
- Days 61–90 (Measurable Results): Move at least one use case to a controlled production release, measure outcomes against the baseline (processing time, backlog reduction, accuracy, cost avoidance), and institutionalize a renewal discipline where every AI asset is periodically re-validated or retired.

What it means for you—whether you work in government or not

If you manage IT in a federal agency, this framework directly responds to OMB directives that call for accelerated AI adoption while preserving privacy, civil rights, and accountability. It gives you a concrete, timeline-driven way to show progress and avoid the audit nightmare of “shadow AI” embedded in SaaS tools your teams may already be using without approval.

But the lessons travel well beyond government. Large enterprises face the same pilot-to-production gap. A university might struggle with a dozen department-level chatbots; a manufacturer may have fragmented quality-inspection models. The one-front-door model works because it forces a single portfolio view and ties governance to business outcomes, not just technology.

For IT architects and security teams, the model clarifies where shared investments pay off. Rather than letting each project build its own identity plumbing or logging pipeline, you create approved patterns and a secure sandbox. That reduces the temptation for teams to bypass official channels because they can get a working environment faster through the front door than around it.

Vendors serving government or regulated industries should also take note. The panel explicitly called for contract language that addresses model changes, subprocessor visibility, data deletion, and incident notification. If you sell AI tools, expect procurement to ask tougher, lifecycle-oriented questions—not just at award but at every renewal.

How we got here

The federal AI story has moved rapidly from “can we?” to “we must.” Generative AI lowered the barrier to prototyping so much that one person with a cloud account can build a convincing demo in an afternoon. Over the last two years, agencies have launched hundreds of pilots for knowledge retrieval, customer support, document classification, software development, and scientific research. But that speed masked the hard work of scaling: identity integration, records obligations, model updates, and changing mission needs.

The OMB’s current guidance reinforces the push for disciplined scaling. It emphasizes avoiding duplicative spending, designating accountable AI leaders, and maintaining public AI use case inventories. Yet without a structured intake and renewal process, those inventories tend to become stale lists rather than active governance tools.

Congress, too, is watching. Multiple legislative proposals in 2025–2026 have sought quarterly agency AI reports and centralized oversight. The CDW panel’s 90-day blueprint reads like a practical answer to those pressures: a way to demonstrate control without piling on process.

What to do now—a practical starting checklist

You don’t need a cabinet-level mandate to begin. Agency or enterprise IT leaders can initiate several steps this quarter:

  1. Name an AI governance lead—even if the role is part-time—and clarify decision rights for high-risk uses.
  2. Run a two-week discovery sprint to catalog every AI pilot, embedded feature (think Copilot in Office, Salesforce Einstein, or AWS AI services), and planned purchase. Include contractor-managed environments.
  3. Create a one-page intake form with the 10 fields the panel recommended: mission problem, expected outcome, business owner, user population, AI function, data profile, decision role, technology path, initial risk factors, and success measures.
  4. Adopt risk tiers immediately, applying lighter controls to Tier 1 uses and reserving heavy scrutiny for Tier 3. Publish the criteria so teams can self-assess before they submit.
  5. Pick one low-risk use case and one high-impact use case and run them through the intake-to-renewal cycle within 90 days. Use the low-risk project to debug the process; use the high-impact project to demonstrate mission value.
  6. Draft contract addenda for AI transparency, even if you can’t amend all existing agreements right away. Address model update notifications, data residency, subprocessor changes, and audit rights.
  7. Set up a shared sandbox with pre-approved data sets, identity controls, and logging. This alone can cut weeks from pilot setup and prevent shadow IT.
  8. Decide on renewal cadences now. Low-risk tools might renew every 12 months; high-risk ones every 6. Tie renewal to the original business case metrics.

For teams using Microsoft platforms, many of these controls map directly to Azure Policy, Purview compliance portals, and Entra ID governance features. The technical building blocks exist; the missing piece is the organizational workflow that connects them to mission decisions.

Outlook

The CDW-articulated model will gain traction as agencies look for ways to satisfy OMB reporting requirements without grinding innovation to a halt. The next 12 months will likely see a handful of civilian and defense agencies publicly adopt a one-front-door approach and publish results. Watch for announcements from the General Services Administration or Department of Veterans Affairs, both of which have active AI portfolios.

On the vendor side, expect cloud providers to embed more of these governance patterns into their AI platforms. AWS already offers AI service cards and guardrail configurations; Microsoft is expanding its responsible AI tooling within Azure AI Studio. The agencies that succeed won’t just buy better tools—they’ll operationalize the panel’s insight that governance, done right, is the fastest path to enterprise AI results.