A new federal watchdog report offers a timely warning for operations racing to adopt generative AI: deploying powerful chat tools without classifying their risk or building oversight around them can create exactly the kind of exposure regulators look for.
The Department of Veterans Affairs Office of Inspector General (OIG) reviewed the VA’s use of general-purpose AI chat tools between October 2025 and February 2026 and found broad, largely ungoverned adoption. Two authorized tools, VA GPT and Microsoft 365 Copilot Chat, drew heavy engagement, with more than 15,000 active users across the agency’s AI-focused internal channels. Staff used the tools to draft clinical notes and summarize patient care, yet the agency did not centrally curate or evaluate the prompts feeding those outputs. Of 135 prompts found in an internal sharing app, 79 were clinical.
The central finding has direct parallels for the ARM industry. Under a 2025 Office of Management and Budget memo, federal agencies must identify high-impact AI uses and apply controls such as pre-deployment testing and human oversight. The VA classified one narrow tool, Ambient AI Scribe, as high-impact and built safeguards around it. It did not extend the same scrutiny to the general-purpose chat tools, even though staff were using them for nearly identical documentation work. VA leaders compared the chat tools to search engines, an analogy the OIG rejected, noting that generative AI synthesizes and transforms source material into new content rather than simply returning links.
For collectors, the substitution is easy to make. Swap clinical notes for account notes, dispute responses, or consumer-facing messages, and the governance gap looks familiar. The report also flagged that the VA had no way to tag or trace AI-generated records, leaving it unable to detect error patterns or investigate incidents after the fact. Research cited in the review found a 1.5% hallucination rate in AI clinical documentation, with 44% of those errors deemed major.
The OIG made three recommendations: define permissible uses and oversight, evaluate whether high-impact safeguards should apply, and fold AI risk monitoring into existing safety programs. The VA concurred and set an April 2027 target.




