top of page

The 50-State AI Ownership Fight That Contracts Will Decide

Google News surfaced a sharp conflict spanning 50 states: governments can deploy artificial intelligence without truly controlling what happens after the contract begins.

The question sounds simple. Who owns an AI system once a state agency starts using it? Yet ownership can refer to several different assets. Those include software, model weights, government data, generated outputs, audit records, employee feedback, and improvements made during deployment.

A state rarely buys all those assets as one transferable package. It usually licenses a vendor’s service while retaining rights to some data and accepting limits on everything else. The public agency can remain accountable for decisions even when the vendor controls the machinery behind them.

That imbalance is the central issue. States want faster services, lower administrative burdens, and better access to information. Vendors want to protect intellectual property, reusable models, and commercial methods.

Both positions can be legitimate. The conflict begins when a contract leaves the state responsible for an AI system it cannot inspect, test, transfer, or reconstruct.

The Google News Headline Points to a Contract Problem

The ownership of government AI is usually decided before deployment, inside procurement language that few residents ever see.

A state can purchase servers and own the physical equipment. Most modern AI arrangements work differently. Agencies commonly acquire cloud subscriptions, application programming interfaces, analytics platforms, or managed services.

An application programming interface, or API, lets one system request functions from another system. The agency sends data or instructions, while the vendor operates the underlying model and infrastructure.

That arrangement separates operational use from legal ownership. A department can use an AI assistant every day without owning its model weights, source code, training process, or supporting infrastructure.

Model weights are the learned numerical parameters that shape a model’s responses. They are often among a vendor’s most closely protected assets.

The agency may still own information supplied by residents. However, its contract must explain whether the vendor can retain that information, create embeddings from it, or use it for product development.

Embeddings are numerical representations that help AI systems compare and retrieve related information. They can preserve meaningful patterns from source material even when the original documents are stored elsewhere.

Generated material creates another layer. An AI system might summarize a case file, rank benefit applications, flag suspected fraud, or recommend an inspection. The contract must establish whether the agency can export those outputs in a usable form.

Access alone is not ownership. An agency can view results through a dashboard while lacking the right or technical ability to retrieve the underlying records.

That distinction becomes critical when a contract expires. The vendor might return source documents but omit prompts, intermediate calculations, confidence scores, model versions, or human corrections.

Without those records, the next provider cannot reproduce the old system’s work. Auditors also struggle to determine why a past decision occurred.

These are not theoretical administrative details. The Electronic Privacy Information Center found 621 AI contracts with a possible market reach exceeding $720 million. Its research covered records from 27 states and the District of Columbia.

The systems identified by EPIC touched education, health care, policing, and public benefits. In such settings, incomplete ownership terms can affect a person’s access to essential services.

A contract therefore needs a detailed asset map. It should distinguish agency inputs, vendor materials, jointly created configurations, system outputs, logs, evaluations, and post-deployment improvements.

The map should also identify who can use each asset, for which purposes, and for how long. A broad declaration that “the state owns its data” does not answer those questions.

States also need deletion terms that cover backups, derived artifacts, and subcontractors. Otherwise, a vendor can delete the visible database while related material remains throughout its service chain.

The headline distributed through Google News captures a national problem, but the decisive language remains local. Every procurement office can define ownership differently.

Deployment Makes States Accountable Without Giving Them Full Control

A public agency cannot outsource its responsibility to residents, even when every technical component belongs to a contractor.

Government accountability follows the public function. If an AI system influences benefits, employment, licensing, education, health care, or policing, residents will challenge the agency using it.

The vendor may have designed the model. A systems integrator may have connected it to agency databases. A cloud company may store the records. Yet the state still makes, communicates, or enforces the resulting decision.

This division creates an accountability gap. The agency carries the legal and political consequences, while key evidence can remain inside a vendor-controlled system.

Consider a benefits agency using AI to prioritize applications for review. A resident denied assistance might ask what data affected the decision and how an error can be corrected.

The agency needs more than a final score. It needs the relevant input fields, applicable model version, processing history, decision rules, and records of human review.

If the contract promises only access to a current dashboard, the agency may lack the evidence needed for an appeal. A software update can also change the system before investigators examine the earlier decision.

Model versioning records which system configuration produced a particular result. It serves a role similar to keeping the exact regulation and case file used in a traditional decision.

State public-records laws add another complication. Government documents are often subject to disclosure, retention, and preservation duties. Vendor claims involving trade secrets can restrict access to technical material.

Trade-secret protection serves a real commercial purpose. A state should not obtain unrestricted publication rights to every proprietary model merely because it purchased a subscription.

However, confidentiality cannot become a blanket substitute for accountability. Contracts can create controlled access for auditors, regulators, courts, and authorized researchers without publishing proprietary code to everyone.

The balance requires planning. Agencies should define which materials must remain available during investigations and after termination. They should also establish how long those materials must be retained.

Colorado’s AI consumer law illustrates the growing focus on deployers, meaning organizations that use high-risk systems. Its framework requires impact assessments, risk management, consumer notices, and opportunities to appeal certain consequential decisions.

Such duties increase the importance of documentation. A deployer cannot conduct a meaningful assessment if the developer withholds performance data or system limitations.

The same problem appears when an agency discovers discriminatory outcomes. It needs authority to test the system, obtain relevant records, and require corrective action.

A vendor’s standard service agreement might restrict reverse engineering, benchmarking, or publication of test results. Those restrictions can collide with a government’s oversight duties.

States must negotiate testing rights before deployment. They should cover independent evaluations, demographic performance analysis, security reviews, and investigations prompted by resident complaints.

The contract should also state what happens when testing identifies harm. Options include correction deadlines, suspended use, additional human review, reimbursement, and termination without punitive exit costs.

Human oversight does not solve every problem. A worker cannot meaningfully review an AI recommendation without enough context to question it.

An interface that displays a score and an “approve” button can turn human review into ceremony. Agencies need explanations, uncertainty indicators, and permission to reject automated recommendations.

The state therefore owns the public responsibility, regardless of who owns the software. That reality should shape every technical and contractual right it requests.

The Real Opponents Are Public Control and Vendor Dependence

The central contest is not one state against another; it is public control against dependence on systems that agencies cannot move or inspect.

Vendors need reusable products to serve many customers. Building a separate model, infrastructure stack, and operating process for every state would raise costs and slow deployment.

States also benefit from shared commercial platforms. A mature vendor can provide security teams, frequent updates, specialized engineers, and tested integrations that one agency cannot maintain alone.

The danger is not private participation itself. It is vendor lock-in, which occurs when switching providers becomes technically, legally, or financially impractical.

AI can deepen that lock-in because the system changes through use. Agencies add prompts, policy documents, workflows, labels, corrections, and evaluation results.

Those additions can become part of the deployed service. If they cannot be exported, the state loses accumulated operational knowledge when it leaves.

A conventional database migration usually focuses on tables, files, and schemas. An AI migration may also require embeddings, retrieval settings, safety rules, prompt templates, evaluation sets, and model-specific integrations.

A retrieval system searches approved information before a model generates its answer. Its usefulness depends on document processing, access controls, ranking settings, and feedback collected over time.

Ownership language must cover those components separately. Otherwise, a vendor can return the original documents while keeping the configuration that made them useful.

This challenge resembles the difference between owning books and owning a working catalog. The content remains technically available, but practical access collapses when the organizing system disappears.

Teams already managing large document collections understand that distinction. A searchable knowledge base depends on structure, permissions, and retrieval quality, not merely file possession.

The federal government has started addressing the same procurement issue. An April 2026 GAO review examined AI acquisitions across several major agencies.

Officials at all five selected agencies identified data ownership and intellectual property rights as challenges. GAO highlighted the need for portability, clear licenses, pricing transparency, and protections against vendor lock-in.

Portability means more than downloading a spreadsheet. The state needs data in documented formats, along with the relationships and metadata needed to reuse it.

Model portability is harder. A proprietary model may not transfer to another cloud or vendor. In that case, the contract should preserve the state-created layers surrounding it.

Those layers can include prompts, evaluation cases, business rules, system instructions, workflow definitions, and performance histories. Keeping them reduces the cost of replacing the core model.

States should also avoid treating every improvement as vendor property. An agency employee might spend months correcting outputs and developing specialized instructions.

A fair contract can distinguish between improvements to the vendor’s general product and configurations created for the agency. It can also license jointly developed work to both parties.

Data use requires similar precision. Government information used to operate a service should not automatically become training material for a vendor’s general model.

A prohibition on training must define training broadly enough to matter. It should address fine-tuning, evaluation, product analytics, synthetic-data creation, and human review.

Fine-tuning adapts a model using additional examples. Even when vendors do not retrain a foundation model, they can still derive commercial value from agency interactions.

The contract should identify approved purposes instead of relying only on vague restrictions. It should specify whether data can support security, service improvement, abuse detection, or new product development.

Subcontractors need the same boundaries. A state’s primary provider may rely on a cloud host, model developer, monitoring company, and human review service.

Each participant can create another copy, log, or derived artifact. Ownership protections weaken if they apply only to the vendor named on the cover page.

States can respond through standard clauses and cooperative purchasing. Shared language reduces negotiation costs and prevents agencies from solving the same problem independently.

However, standardization should set a minimum, not erase differences among use cases. A writing assistant for public communications poses different risks from a system influencing Medicaid eligibility.

The ownership question should track consequences. Higher-risk deployments require stronger audit access, longer retention, clearer appeal records, and faster suspension rights.

Fifty States Are Building Rules at Different Speeds

The state-by-state patchwork reflects different institutions, budgets, laws, and risk tolerances rather than 50 complete ownership frameworks.

The phrase “50 states, 50 different ways” can suggest that every state has settled its approach. The available evidence shows a less orderly picture.

Some states have centralized AI policies or designated oversight officials. Others rely on existing privacy, cybersecurity, procurement, and public-records rules.

Many are still developing contract language. The National Conference of State Legislatures reported that a 2024 survey found only 9 percent of respondents had preferred AI procurement terms.

Another 62 percent were developing such language, while 29 percent had not started. Those figures describe a transition, not a mature national system.

NCSL’s government AI overview also documented growing attention to inventories, assessments, employee guidance, and procurement standards.

Inventories answer a basic question: where is AI being used? A government cannot control systems it has not identified.

Even a strong central policy can miss tools purchased through individual agencies. AI features can also arrive through ordinary software updates without a new procurement process.

A customer-service platform may add automated summaries. A human-resources system may introduce candidate ranking. A case-management product may add predictive recommendations.

The state might never issue a solicitation labeled “artificial intelligence.” Ownership and oversight terms must therefore apply when AI enters through upgrades, subcontractors, or embedded features.

Contracts should require notice before a vendor activates a material AI feature. Agencies then need the right to assess it, reject it, or negotiate additional safeguards.

A material feature is one that changes data use, decision influence, risk, or operating costs. Minor interface improvements would not require the same review.

State structures also affect who can impose those terms. A centralized technology office can establish shared requirements across agencies. A decentralized state may depend on individual departments and procurement officers.

Budget capacity matters too. Large states can hire specialized lawyers, security professionals, and data scientists. Smaller jurisdictions may rely more heavily on vendor documentation.

That disparity strengthens the case for shared public resources. Model clauses, evaluation templates, and incident definitions can help without forcing every state into an identical policy.

The National Association of State Procurement Officials says successful purchasing requires collaboration among procurement, technology, legal, privacy, and program teams. Its procurement guidance also emphasizes monitoring after award.

That cross-functional approach is essential because no single office sees the entire risk. Procurement understands contract leverage, while program staff understand the decisions being supported.

Technology teams assess architecture and portability. Privacy officers examine data use. Civil-rights specialists evaluate whether the system can produce unequal outcomes.

State attorneys interpret records laws and due-process requirements. Security teams determine whether logs, integrations, and model access create new attack paths.

The process becomes slower when every question arrives late. It becomes faster when agencies establish ownership requirements before vendors submit proposals.

Clear requirements can also help vendors. Companies can price the requested rights accurately and avoid months of uncertain negotiation.

The current patchwork is therefore both a risk and a testing ground. States are discovering which clauses work through pilots, disputes, audits, and contract renewals.

Yet experimentation has limits when residents bear the consequences. A failed chatbot is inconvenient. An opaque eligibility system can deny food, medical support, or housing assistance.

States need a common floor for consequential uses. That floor should include traceable outputs, audit access, data portability, incident reporting, and enforceable exit rights.

Above that floor, states can adapt governance to local laws and institutions. Uniformity is less important than ensuring that no deployment leaves accountability without evidence.

What Ownership Language Still Cannot Guarantee

Strong contracts create leverage, but they do not make an AI system accurate, fair, secure, or understandable.

A state can own every generated record and still deploy a poor system. It can obtain source code without having employees who can evaluate it.

Technical capacity remains a major constraint. GAO found that federal acquisition teams faced difficulty accessing data scientists and cybersecurity experts. State and local agencies often face tighter staffing limits.

Vendor documentation can help, but it is not independent evidence. Performance claims should be tested using the agency’s population, data quality, workflow, and operating conditions.

A model that performs well in a laboratory can fail after deployment. Policies change, resident behavior shifts, source data deteriorates, and vendors update underlying models.

This process is often called model drift. It describes declining or changing performance as the relationship between data and real-world outcomes evolves.

Generative systems add another form of change. A vendor can replace a foundation model while keeping the same product name and interface.

The new model might respond differently to identical prompts. Without version records and change notices, the agency cannot connect altered behavior to the update.

Contracts should require advance notice for significant changes. They should also give agencies time to test updates before high-risk production use.

Yet testing has limits. Rare failures can escape benchmarks, while social harms may not appear in aggregate accuracy scores.

An overall accuracy rate can hide large differences among demographic groups. It can also obscure whether errors fall mostly on people already facing barriers.

Ownership does not resolve those measurement choices. Agencies must decide which outcomes matter and which error rates are acceptable.

Public transparency creates another tradeoff. Residents deserve meaningful information about systems that affect them. Vendors reasonably seek protection for proprietary methods and security-sensitive details.

Publishing source code is not always necessary or sufficient. A more useful disclosure may identify the system’s purpose, data categories, decision role, known limits, vendor, and appeal process.

Agencies should publish enough information for affected people to understand the system’s role. Independent reviewers also need controlled access to deeper technical evidence.

The lack of a visible contract does not prove abuse. Likewise, the existence of a contract does not prove responsible deployment.

EPIC’s research raised concerns about decisions moving into private systems without adequate public input. That criticism should not be generalized into a claim that every contracted AI system is unlawful or harmful.

Many tools perform lower-risk administrative work. They can summarize internal documents, route service requests, detect duplicate records, or help employees find policies.

The risk changes when AI determines facts, ranks people, recommends enforcement, or shapes access to public services. Ownership safeguards should increase with that influence.

The primary keyword creates its own caution. A headline seen through Google News is a discovery point, not the complete evidentiary record.

Aggregation can compress a complicated issue into one provocative question. Readers should follow the underlying reporting and examine official contracts, laws, audits, and agency policies.

Search visibility also does not establish national consensus. The available evidence supports a fragmented procurement landscape, not a literal set of 50 finalized ownership models.

The most defensible conclusion is narrower. State governments are deploying AI under different legal and administrative systems, while many ownership rules remain unsettled.

Contracts can close part of that gap. They cannot replace capable staff, continuing oversight, public notice, or a process for correcting harmful decisions.

Three Signals Will Show Who Really Controls State AI

Control becomes visible during model changes, public challenges, and contract exits, not during a polished product demonstration.

The first signal is the spread of standard AI contract clauses. States should publish or share language covering government data, generated outputs, audit logs, training restrictions, portability, and deletion.

Standard clauses would show that ownership has moved from broad policy into enforceable procurement. Their absence would leave agencies negotiating critical rights one contract at a time.

The second signal is how states handle vendor and model changes. Agencies need inventories that identify embedded AI features, deployed versions, updates, and responsible officials.

Watch for requirements that vendors provide advance notice of material changes. Also watch whether agencies can test updates before those changes reach residents.

If states document these transitions, they strengthen the claim that public institutions remain in control. Silent changes would weaken it.

The third signal is what happens at renewal or termination. A genuine exit test should determine whether an agency can retrieve records and move essential workflows elsewhere.

The test should include prompts, configurations, evaluations, logs, and documentation. Exporting only source documents would not recreate the operational system.

States should also verify deletion after migration. That process must cover active databases, backups, derived artifacts, and relevant subcontractors.

These signals matter more than declarations that a state “owns its data.” Ownership becomes meaningful only when the agency can inspect, govern, transfer, and preserve what it needs.

Residents should watch for public AI inventories, impact assessments, contract summaries, and appeal procedures. Journalists can compare those documents with purchasing records and system behavior.

Government buyers should ask vendors to demonstrate portability before award. A sample export can expose missing fields and proprietary dependencies before they become expensive.

Technology teams should maintain agency-controlled evaluation sets. These are collections of representative cases used to test performance across versions and providers.

Program leaders should define the records needed to explain individual outcomes. Legal teams can then connect those records to retention, disclosure, and appeal requirements.

Vendors also have an opportunity. Companies that offer credible audit access and usable exits can distinguish themselves from providers built around dependency.

Google News will continue surfacing stories about state AI policies, launches, and disputes. The decisive evidence will remain inside contracts and operating records.

The next question for every agency is practical: can it explain a past output, test a new model, and leave its provider without losing institutional memory?

If the answer is no, the state does not control the deployment in the ways that matter. It merely has permission to use it.

Public officials, vendors, and residents should demand a clearer answer before consequential systems scale. Follow the contracts behind the next Google News headline, then ask who can audit, transfer, and stop the system.

Get started for free

A local first AI Assistant w/ Personal Knowledge Management

For better AI experience,

remio only supports Windows 10+ (x64) and M-Chip Macs currently.

​Add Search Bar in Your Brain

Just Ask remio

Remember Everything

Organize Nothing

bottom of page