If you have ever shortened a form because nobody was finishing the long one, you probably told everybody it was a win.
Say the old version runs to forty questions and half come back empty — which means the data is useless, which means nobody reads it, which means the people filling it in are right to treat it as theater. So you cut it to twelve. Completion jumps to ninety percent, the number goes on a slide, and the slide goes over very well.
What doesn't go on the slide is how the twelve got chosen. You keep the questions people were already answering and cut the ones they weren't. That sounds neutral. It isn't. The questions that come back blank are almost never the easy ones — they are the ones where answering honestly costs something, or where nobody in the building knows the answer. That isn't shortening a form. It is no longer asking about the parts of the work that are hardest to defend, then reporting the resulting silence as a success metric.
The U.S. government has just done a version of the same thing, at national scale, to the only public list of what artificial intelligence it runs on you. The case for the shorter form is a real one, and it gets a fair hearing further down (it is better than you'd expect). It is also not the whole story, and the whole story is sitting in a public spreadsheet almost nobody has counted.
Where this list came from, and why nobody can just cancel it
Every federal agency has to keep a public list of the ways it uses AI. The idea arrived in an order telling every agency to write down what AI it uses (Executive Order 13960, signed December 3, 2020, in the final weeks of the first Trump administration) and survived the change of party. Two years later Congress put it in statute through the Advancing American AI Act, signed December 23, 2022, requiring each agency to "prepare and maintain an inventory of the artificial intelligence use cases of the agency, including current and planned uses" and to publish it.
That last part is the hinge of this entire article. Congress made the list mandatory. Then it left the shape of the list to the budget office: agencies must make their inventories public "in a manner determined by the Director" of the Office of Management and Budget.
So the existence of the list is law. The questions on it are administrative discretion. To change what the public learns, nobody has to repeal anything; you change the form. That is not a scandal — it is how delegated authority works — but it means the interesting action happens where there is no vote and no headline.
Which brings us to April 14, 2026, when OMB published the completed 2025 inventory as a machine-readable GitHub repository. Credit where it is due: a raw CSV rather than a PDF is a real act of transparency, and everything below I know only because they published it that way.
The number that moved, and the number that moved it
The headline everyone ran was that federal AI use cases more than doubled. Whether that is true depends entirely on which number you subtract from.
The 2025 inventory contains 3,611 individually reported AI use cases. Nextgov/FCW put the increase at 105 percent, measuring against a 2024 figure of 1,757, and Global Government Forum ran it under a headline saying the count had more than doubled. Both are accurate reports of a real comparison.
But 1,757 was a December 2024 snapshot — a partial-year view of a list still being assembled. OMB's own 2024 repository, updated afterward, closed the year at 2,133 use cases and 351 rights- or safety-impacting ones, "as of January 23, 2025." Measure 3,611 against 2,133 and the growth is 69.3 percent. Enormous — but not a doubling.
That is the figure the serious analysts use. Brookings, in an April 15, 2026 assessment by fellow Valerie Wirtschafter, reports 41 agencies documenting more than 3,600 use cases, 69% above the total number reported in 2024. FedScoop called it a nearly 70 percent rise; so did the Center for Democracy and Technology. Same file, two stories, and the difference is a choice of denominator.
Then there is the agency count, which is stranger. Press coverage says 56 agencies. Brookings says 41. That looks like a contradiction, and I went looking for one. There isn't. Both numbers are OMB's, on adjacent lines of its own README: 56 counts total agency submissions of any kind — individually reported use cases, a consolidated commercial filing, or a written confirmation that the agency uses no AI at all. The 41 counts agencies that submitted individually reported use cases. I loaded the spreadsheet and counted distinct agency names myself: 41.
So "56 agencies reported AI use" is not what the 56 means. Fifteen of those 56 filed no individual use cases whatsoever, two affirmatively reported using no AI, and one — the Equal Employment Opportunity Commission — says its inventory is forthcoming. Fifty-six is a headcount of paperwork received: an honest number that becomes a dishonest sentence the moment it is read aloud as a measure of adoption.
Sixty-two columns, then thirty-six
I did not want to quote anybody's summary of what changed between the two editions, so I did the boring version and counted the columns. Last year's consolidated inventory published 2,133 rows across 62 columns per use case. This year's individually reported inventory publishes 3,611 rows across 36. Twenty-six fields gone — a 41.9 percent cut in what the public is told per system.
I counted published columns, which is not the same as saying OMB deleted twenty-six questions: ten of the 2024 columns were "if other, please explain" follow-ups. Strip those out and last year still carried 52 substantive fields to this year's 36.
OMB does not hide the change. In its own README it says it reduced the number of questions to streamline burdensome agency reporting requirements, while maintaining what it calls essential data fields for public accountability. Homeland Security describes it from the receiving end: the 2025 focus was on streamlining, resulting in fewer data fields overall.
So which questions stopped being asked? Three, quoted exactly as the 2024 form put them, because they are the three a person on the receiving end of a government decision would care about:
"How is the agency providing reasonable and timely notice regarding the use of AI when people interact with an AI-enabled service as a result of this AI use case?"
"What steps has the agency taken to detect and mitigate significant disparities in the model's performance across demographic groups for this AI use case?"
"…is there an established mechanism for individuals to opt-out from the AI functionality in favor of a human alternative?"
None has a counterpart among the 36 columns of the 2025 file. Two nearby survivors — fields for an appeal process and for public consultation — apply only to use cases flagged high-impact, which is 445 rows out of 3,611. For the other 3,166, the questions about notice, about demographic disparities, and about your right to ask for a human are simply not on the form anymore.
The bucket for software everyone already runs
The second structural change is subtler and, in fairness, harder to argue with.
OMB created a new category of "consolidated reporting" for common commercial off-the-shelf tools. The reasoning in the reporting instructions is plainly stated and, honestly, correct: "it is impracticable to require individualized reporting for all instances of AI that rely on commercial-off-the-shelf products or services."
Consider the alternative. Every office that turns on an AI assistant inside its word processor files a use case, and you drown the list in autocomplete. The guidance names twenty listed tasks eligible for collective treatment — generating first drafts of documents, summarizing the key points of a lengthy report, generating code — and an agency answers yes or no once instead of once per bureau. The consolidated file runs to 900 rows with 468 affirmative answers, from the 46 agency submissions OMB records.
And here is the strongest fact in OMB's favor, which I would be a poor guide if I skipped: a high-impact use case is not eligible for the consolidated format. Whatever else consolidated reporting does, it is not a hiding place for the systems that decide things about you.
But scale disappears into it. At an event this year, OMB's deputy director for management Eric Ueland noted that in 2025 more than three-quarters of CFO Act agencies reported deploying at least one major AI chatbot to at least 10,000 employees. Ten thousand people using a general-purpose model on federal work, all day. In the consolidated file that is a "Y" in a cell. (One letter. Ten thousand people.)
Which is why the growth number is so slippery. The Center for Democracy and Technology reads the same 69 percent rise as an undercount, arguing that consolidated reporting of commercial products, while it may help usability, also risks obscuring the total increased use of AI in government. Brookings pushes the other way: self-reported, inconsistent, and blind to AI deployed through DOGE. One says the number is too small; the other says it is too noisy to trust either way.
A word on vendors, and then the caveat that kills every vendor argument you will read this year. Counting product names across both published files: Copilot appears in 213 rows and Microsoft products of any kind in 293; ChatGPT or OpenAI in 98; Google in 65 and Gemini in 35; Claude or Anthropic in 32; Palantir in 28; Grok or xAI in 6. Interesting — and nearly useless, because the vendor field is blank in 2,821 of the 3,611 individually reported rows. Every count there is a floor, not a share, and turning them into market share is arithmetic with a missing denominator.
The seven questions that survived — and the 215 rows that leave them blank
So did the survivors get answered?
Of the 3,611 use cases, 445 are flagged high-impact. I counted them directly out of the file OMB published as a spreadsheet and got exactly 445, matching OMB's stated total. Two controls, before you take a stranger's count: the same method applied to the 2024 file returns 351 rights- or safety-impacting cases, precisely the number OMB states in its own 2024 README, and my Homeland Security subtotals match the figures CDT published independently.
"High-impact" is not a vibe. The memo governing all of this, M-25-21, reserves the label for AI whose output is a principal basis for decisions with legal, material, binding, or significant effect on your civil rights, your access to education, housing, credit, employment or critical government services, or on human health and safety.
Those 445 are concentrated: Veterans Affairs holds 215, Justice 114, Homeland Security 55, Energy 29 — four departments accounting for 413 of them, the remaining 32 scattered across ten more agencies.
For high-impact systems, M-25-21 requires minimum risk management practices: pre-deployment testing, a completed AI impact assessment, independent review, ongoing monitoring, staff training, a failsafe, and an appeal route for the person affected. Those seven became columns in the 2025 inventory. The memo also says that where risk cannot be mitigated, agencies "must cease the use of the AI," and gave them 365 days from issuance to document implementation. It issued April 3, 2025, so the 365-day mark was April 3, 2026. The files went up April 14 — eleven days after.
So I counted the seven fields. Across all 445 high-impact use cases, the pre-deployment testing field is blank in 318, says "In-progress" in 82, and says "Yes" in 45. Narrow to the 227 marked as actually deployed and it is 102 blank, 81 in progress, 44 yes.
Then it gets specific. All 215 of the Department of Veterans Affairs' high-impact rows leave every one of the seven fields blank — testing, impact assessment, independent review, monitoring, training, failsafe, appeal process — plus the field where an agency explains why it designated the system high-impact in the first place. Not "no." Not "in progress." Empty.
These are not obscure back-office tools. In that all-blank set, agencies named systems including "Automated Claims Processing," "Disability Benefits Document Classifier," "Summarization of Clinical Data," and one called "Claims Adjudication and Financial Decision-Making." Government Executive picked three names out of that same block in April — the clinical-summarization one plus two others; I found all three again in the raw CSV, which is how corroboration is supposed to work.
Justice is different in shape and not much better in substance: DOJ answered every one of the seven questions with the words "In-progress" or nothing at all — that answer, or a prefixed variant of it, in all seven fields for 73 of its 114 high-impact cases, blank for the other 41. Homeland Security is the outlier that answered: 32 "Yes" on pre-deployment testing, 28 with training established, 28 with monitoring established.
Now the caveat, and I want it in bold because it matters more than the finding. A blank field is a reporting fact, not a compliance finding. An agency could have done every bit of the testing, written the impact assessment, stood up the appeal process, and simply not carried it into a spreadsheet whose format changed this year. Nothing here proves anybody broke a rule. Even CDT, the most critical voice in this debate, frames it as inconsistent reporting and insufficient detail about high-impact use cases rather than a finding of non-compliance. That is the ceiling, and I am staying under it.
But hold the shape of it. The form got shorter so the important questions would get answered. On the largest single block of high-impact AI in the federal government, they came back empty anyway.
The summary and the file disagree elsewhere too: OMB reports 1,818 use cases as deployed or piloted, and the published file records a development stage for only 1,480. A reader counting it cannot reproduce 1,818 (I tried).
And a live argument rather than a bookkeeping note: a third box on the form, "presumed high-impact, but determined not high-impact," now holds 110 use cases, 49 of them at Homeland Security. DHS explains the mechanism on its own site — a use case can be presumed high-impact without satisfying the definition. CDT reads that box as a way an agency could underplay or obscure the riskiness of a system. DHS reads it as honest triage. Both readings fit the same spreadsheet, which is the problem with a self-designated risk label.
The strongest argument against everything I have just written
I promised this, and I meant it.
The old form did not work either. In December 2023 the Government Accountability Office found incomplete and inaccurate data across agency inventories: of the 20 agencies that submitted one, five provided comprehensive information for each reported use case and the other 15 did not — disclosures FedScoop summarized as not "fully comprehensive and accurate." That was the long form. Sixty-two columns did not produce sixty-two columns of truth.
It was worse before that. A peer-reviewed study of the early inventories by Christie Lawrence, Isaac Cui and Stanford's Daniel E. Ho found that nearly half of agencies failed to publicly issue AI use case inventories — even where they had demonstrable machine learning use cases — and that even compliant efforts were inconsistent. FedScoop puts the instrument's history bluntly: the early editions were rife with inconsistency, delays, and sometimes even errors. Three administrations of both parties have improved this list and it is still imperfect. Treating 2024 as a lost golden age would be nonsense.
And the burden is real. The R Street Institute made this case to Congress in June 2025: agencies "have a responsibility to identify and remove barriers to further responsible AI adoption and application, where practicable," and should streamline paperwork attached to federal AI deployments. Adam Thierer, who gave that testimony, is not a straw man and I will not flatten him into one — the same document calls for "providing meaningful public transparency into the Federal Government's use of AI." He wants both. So do I.
Together that is a strong case: a form nobody can complete produces exactly the blank fields I just spent a thousand words describing, and a short form answered honestly beats a long one abandoned halfway. Here is where it stops working for me. If the trade was fewer questions, better answers, the answers should have gotten better. Instead the government's biggest holder of high-impact AI returned all seven surviving fields blank on all 215 of its systems, and only 45 use cases out of 445 government-wide answered "Yes" to the most basic question there is: did you test this before you turned it on? You can defend cutting twenty-six columns. It is harder to defend cutting twenty-six columns and getting silence on the seven you kept.
And a whole category of AI the form never reached. Before you read a single row you have to read the exclusion list: AI used as a component of a National Security System or within the Intelligence Community is out of scope, as are — in OMB's own 2026 wording — "Department of War use cases." Whatever the federal government's most consequential AI is, it is not in this file and never was.
Ottawa publishes a hundred answers about one system, and publishes them first
The most useful comparison here is not Brussels or Beijing. It is the country immediately to the north, which answered the same problem with the opposite instinct (and which runs a veterans' benefits department too).
Canada's Directive on Automated Decision-Making, administered by the Treasury Board of Canada Secretariat, starts from a narrower question. Clause 5.1 applies it to any automated decision system in production used to make an administrative decision or a related assessment about a client. Not all AI. Decisions about people. Then it does four things the U.S. inventory does not.
It moves disclosure before deployment. Clause 6.1.1 requires completing, approving and publishing the results of an Algorithmic Impact Assessment "in an accessible format on the Open Government Portal prior to the production of any automated decision system." Not an annual return the following spring — a published assessment before the thing runs.
It takes the tier out of the department's hands. Clause 6.1.2 requires applying the relevant requirements "as determined by the algorithmic impact assessment." The score assigns your obligations; you do not pick them. Set that against the American design, where M-25-21 lets an agency's Chief AI Officer waive one or more of the minimum practices for a specific application by written determination, recertified annually. Both systems have an escape hatch. Only one is opened by the party being regulated.
It requires outside eyes, in public: clause 6.3.7 obliges departments to have qualified experts review the system and the assessment, and to publish "the complete review or a plain language summary" before production.
And it writes notice, explanation and recourse into the rule rather than the questionnaire — notice that a decision will be made or assisted by an automated system, "a meaningful explanation to clients of how and why the decision was made," and recourse that is "timely, effective, and easy to access." Those are the three American questions that fell off the form between 2024 and 2025, asked in Canada not as a survey item but as a standing duty.
In practice? Veterans Affairs Canada published an assessment for its disability-benefit automation naming the respondent who filled it in (Daniel Andrews, listed as Architect), giving the project phase as design, recording an impact level of 2 with a raw impact score of 55 and a mitigation score of 30, then listing what a level-2 result triggers — starting with peer review and publication of the findings. Level 2 is a middling score, not a maximum, and the system was still on the drawing board.
Two countries, the same mission, the same kind of decision — whether a veteran's disability claim is granted. One published a scored, named assessment of a system still in design, at a level that obliges it to publish an expert review before it runs. The other published 215 high-impact rows with every risk box empty.
The register is live: Canada's Open Government Portal holds thirty-nine published assessments across ten departments, most from immigration and social-benefits agencies, with new records still landing in August 2026. Thirty-two ship a machine-readable file alongside the PDF; I counted the answered fields in each, and the median published assessment fills in about a hundred of them for a single system — against 36 columns per American use case, and the seven high-impact fields 215 U.S. Veterans Affairs rows leave blank. The questionnaire is built in the open as a public software project, which is part of why counting it is possible at all, and the OECD's policy observatory records the Directive as a Treasury Board instrument accompanied by the Algorithmic Impact Assessment.
Now the honesty check, because this section would be propaganda without it. Thirty-nine Canadian assessments against 3,611 American use cases is not evidence that Canada discloses more; the two registers count different things. Clause 5.2 excludes systems used solely for research and experimentation and those in test environments, the scope reaches only decisions about a client, and clause 8.3.4 lets agents of Parliament skip publication altogether. Most of what the American inventory counts would never enter the Canadian register. Canada is not finished either: systems built before June 24, 2025 had until June 24, 2026 to comply with the current requirements, a deadline that passed this summer.
So the defensible claim is narrow: Canada asks far more per system, and asks before deployment rather than after. That is the whole comparison — and it is the exact axis on which the American inventory just moved backwards.
The inventory in 2030
The trend lines here are unusually easy to draw.
The consolidated bucket eats the list. Twenty eligible commercial tasks becomes thirty, then forty, because the reasoning that justified twenty — AI is now ambient in ordinary software — gets truer every quarter. By 2029 the drafting, summarizing, translating, coding and scheduling that fill most of an office day are all collectively reported. The individually reported inventory stops being a census of federal AI and becomes a list of the unusual federal AI. The growth rate flattens, somebody writes a story about adoption plateauing, and it hasn't plateaued. The counting changed.
Meanwhile the high-impact label stays self-assigned, the third box absorbs the pressure, and a waiver sits available by written determination. Which direction does 110 travel?
Then picture 2029. A veteran's claim is denied. Her representative asks which systems touched the file and gets a straight answer, because the inventory is public and searchable — genuinely better than 2020. She looks up the row. Development stage: deployed. Vendor: blank. Pre-deployment testing: blank. Appeal process: blank. High-impact justification: blank. Every question she would want to ask has a column, every column is empty, and no rule was broken.
Now the likelier version, because it is cheap and somebody will do it. Somebody builds a diff tool comparing each year's schema against the last and publishing what got deleted. The first run makes news, because "twenty-six columns disappeared" is a better story than "3,611 use cases." After that, deleting a column from a public federal questionnaire gets noticed within hours instead of never. That is a game worth playing, and it is winnable.
What the people who count this for a living say
The striking thing about this dispute is that it does not divide the way you would expect.
From the center, Brookings' Wirtschafter tracks an unambiguous expansion — participation up from 21 agencies in 2023 to 41 in 2025, large agencies increasing their share of reported use cases from 69 percent to 76 — while insisting the inventories are self-reported, never fully consistent, and hard to compare over time. Her caution is methodological, not ideological.
From the civil-liberties side, CDT's agency-level findings and my independent counts landed on the same numbers, which was the most reassuring thing that happened during this research. Where we differ, we differ narrowly: CDT counts 315 DOJ use cases to the 314 in OMB's individually reported file, and describes DOJ's risk-management reporting as containing no information — where I would say DOJ answered every one of those questions with "In-progress" or nothing at all. Same emptiness; I want its exact shape on the record.
From the free-market right, R Street's Thierer told Congress that agencies must remove barriers to responsible AI adoption and streamline the paperwork attached to federal AI deployments — and, in the same testimony, that they should provide meaningful public transparency into the government's use of AI. He is not on the other side of this argument. He is describing a trade nobody has yet made honestly.
And from the academy, the Stanford work led by Ho establishes the fact everyone else's numbers rest on: these inventories have always undercounted. That cuts both ways. This year's rise is partly better counting rather than pure growth — and the current total is still a floor.
So what does this mean for you?
More than you'd think, because for once the primary source is a spreadsheet anybody can open.
Go look up your own agency. The inventory is a public CSV on GitHub, not a PDF and not a FOIA request. Search it for the department handling your benefits, your taxes, your immigration status, or your employer's regulator, and read the use case names. They are in plain English, and will tell you more in ten minutes than a year of coverage will.
When you see a growth figure, ask which baseline. 105 percent and 69 percent describe the same file — one measured against a partial December 2024 snapshot of 1,757, the other against OMB's final 2024 total of 2,133. Neither is a lie; only one is a comparison.
Do not read "56 agencies" as "56 agencies using AI." It counts submissions, and 15 of them contained no individual use cases at all — two of those agencies affirmatively reporting they use none.
If you have a claim in front of a federal agency, ask whether an AI system was involved, and which one. The inventory gives you the vocabulary for a specific question instead of a general one. Ask for the use case name, ask whether it is designated high-impact, and if it is presumed high-impact but was determined not to be, ask why.
If you work inside an agency, bring two questions to your next AI governance meeting. Has our Chief AI Officer waived any minimum practice, and when was that waiver last recertified? And why are our risk-management fields blank — is the work not done, or did nobody carry it into the new format? Only one of those is a compliance problem.
Ignore vendor market-share claims built on this file, including mine. Four out of five individually reported rows name no vendor at all.
Remember what is missing entirely. National security systems, the Intelligence Community, and what OMB now calls "Department of War use cases" sit outside this inventory. Whatever you conclude from the file, conclude it about the civilian government only.
The lesson, as I see it
Shortening a form can be the right call, and the people arguing for it here are not villains — they are looking at fifteen agencies filing incomplete data and concluding, reasonably, that the instrument was too heavy to lift.
But the test for whether the trade worked is not the completion rate. It is whether the questions you kept now get answered. Sixty-two columns became thirty-six on the promise that the survivors were essential. Then 215 of the government's 445 high-impact systems — every high-impact system at the department that serves veterans — came back with all seven of those fields empty, and only 45 use cases in the entire federal government said "Yes" to having been tested before deployment. That is not a burden problem. A blank is not heavy.
What Canada suggests is that the real variable was never the length of the form. It is when you ask, and who decides how much you have to answer. Ask before the system runs and the answers shape the system; ask in an annual return the following spring and the answers describe something already in service. Let a score assign the obligations and the tier is a finding; let the agency assign them and it is a negotiation.
Congress made this list mandatory and left its shape to the budget office — a reasonable delegation in 2022, and the crux of everything now. A future administration could restore the notice question, the disparities question and the opt-out question tomorrow, without asking anyone. It could also cut ten more columns the same way. Neither would require a vote.
So the durable protection is not the form. It is that the file is public, machine-readable, and counted by strangers — which, for all my complaints, this government chose to do and did not have to. The rows are blank. The spreadsheet is not.
Go count something. It is a badly underrated afternoon.
A public spreadsheet nobody counts is just a rumor with better formatting. Counting it — slowly, with the caveats attached — is most of what the HAIA Foundation does, and it goes out weekly from over here. Bring somebody who works for a federal agency; they will know which column went missing.






