Flash Briefs

Blog post hero imageFlash Brief
Compliance & Risk

Fewer than 1% of HHS’s AI uses are ‘high impact.’ It stands out.

HHS has classified fewer than 1% of its nearly 450 AI use cases as 'high-impact' requiring enhanced risk management oversight—a stark contrast to DHS (23%), DOJ (36%), and VA (59%). This classification gap signals inconsistent AI governance implementation across federal agencies and creates immediate compliance uncertainty for contractors developing AI solutions. Contractors must prepare for potential reclassification waves, agency-specific AI risk frameworks, and heightened scrutiny on existing HHS AI deployments. The discrepancy represents both a compliance risk and a strategic opportunity for firms that can navigate multi-agency AI governance requirements.

Cabrillo Club·February 23, 2026
Blog post hero imageFlash Brief
Compliance & Risk

Regional Ocean Partnerships Reauthorization Act of 2026

The Regional Ocean Partnerships Reauthorization Act of 2026 extends federal funding and program authority for collaborative ocean research and coastal management initiatives across multiple regional partnerships. This legislation sustains multi-year contracting pipelines for environmental monitoring, oceanographic data collection, and marine science services primarily through NOAA and DOC, with cross-agency collaboration from EPA, DOI, USGS, and Navy. Contractors holding positions on OASIS+, POLARIS, GSA MAS, and SeaPort-NxG should immediately review their capture pipelines for affected agencies and prepare for recompete cycles and new task order releases tied to continued appropriations. This is a program continuation event—not a new market—but it confirms budget stability and signals upcoming solicitation activity in FY2027-2031.

Cabrillo Club·February 22, 2026
Blog post hero imageFlash Brief
Compliance & Risk

Export-Import Bank Reauthorization Act of 2026

The Export-Import Bank Reauthorization Act of 2026 extends the authorization of the Ex-Im Bank, ensuring continued access to export credit financing, loan guarantees, and insurance programs for U.S. exporters. This 10-year reauthorization provides critical certainty for defense, aerospace, infrastructure, and manufacturing contractors pursuing international sales, particularly those in long-cycle capital equipment and project finance deals. Contractors with ITAR-controlled products, heavy equipment exports, or international infrastructure projects should immediately assess their export finance strategies and pipeline opportunities that depend on Ex-Im Bank support. The reauthorization maintains a vital competitive tool against foreign export credit agencies while reinforcing compliance requirements under ITAR, EAR, and trade agreement frameworks.

Cabrillo Club·February 22, 2026
Blog post hero imageFlash Brief
Compliance & Risk

Make Housing Affordable and Defend Democracy Act

The Make Housing Affordable and Defend Democracy Act has been referred to House Armed Services, Homeland Security, and Judiciary committees, signaling potential reallocation of $175 billion in federal funding from immigration enforcement to housing and democratic infrastructure. Defense, homeland security, and facilities management contractors should monitor committee markups closely, as this legislation could redirect ICE, CBP, and border security appropriations toward housing construction, property management, and legal services contracts. The bill's cross-committee referral indicates complex procurement implications across DOD, DHS, DOJ, HUD, and GSA. Contractors in affected NAICS codes should prepare capture strategies for both potential new housing opportunities and possible immigration enforcement contract reductions.

Cabrillo Club·February 22, 2026
Blog post hero imageFlash Brief
Compliance & Risk

Stop Censoring Military Families Act

The Stop Censoring Military Families Act (H.R. 5527), introduced September 19, 2025, by Reps. Raskin and Houlahan, mandates restoration of books removed from Department of Defense Education Activity (DoDEA) schools following prior administration policy changes. A federal judge has already ruled that DOD must cease censoring classroom and library materials on race and gender, creating immediate compliance obligations for DoDEA and contractors supporting military education infrastructure. Contractors providing education services, curriculum development, library management, and social services to military families should prepare for expanded scope requirements and potential contract modifications across OASIS+, Alliant 3, and DoDEA-specific vehicles.

Cabrillo Club·February 22, 2026
Blog post hero imageFlash Brief
Compliance & Risk

Submission for OMB Review; Federal Acquisition Regulation Part 27 Requirements

The Regulatory Secretariat Division has submitted a routine request to OMB for a three-year extension of existing information collection requirements under FAR Part 27, which governs patents, data rights, and copyrights in federal contracting. This is a standard administrative renewal—not a regulatory change—and contractors should expect no immediate modifications to their intellectual property compliance obligations. The current approval expires February 28, 2026, and the proposed extension would maintain existing reporting requirements through 2029. Contractors in technology development, R&D, software, and manufacturing sectors should continue operating under current FAR Part 27 provisions while monitoring for the final OMB approval.

Cabrillo Club·February 21, 2026
Blog post hero imageFlash Brief
Compliance & Risk

House Democrats question DHS, ICE use of surveillance tech

House Democrats are demanding comprehensive oversight of DHS and ICE's procurement and deployment of surveillance technologies, specifically targeting data collection systems from vendors Penlink and Paragon. Lawmakers have set a March 5 deadline for DHS to brief Congress on acquisition processes, legal justifications, data handling procedures, and oversight mechanisms. This scrutiny signals potential procurement restrictions, enhanced compliance requirements, and policy changes that will directly impact contractors providing surveillance, biometrics, location tracking, and investigative support services across DHS components. Contractors in this space must immediately review their privacy frameworks, prepare for heightened acquisition scrutiny, and anticipate new compliance surfaces in upcoming solicitations.

Cabrillo Club·February 20, 2026
Blog post hero imageFlash Brief
Compliance & Risk

GSA reveals first round of awards for Alliant 3 contract

GSA has announced the first 43 awardees for Alliant 3, the unrestricted enterprise-level GWAC replacing Alliant 2, with 33 additional awards coming in subsequent phases for a total of 76 contract holders. This no-ceiling IT services vehicle covers cybersecurity, cloud services, data solutions, systems engineering, and digital transformation—representing the primary procurement pathway for complex federal IT initiatives across all civilian and defense agencies. After a year-long delay due to bid protests, Alliant 3 is now operational for task order competitions, fundamentally reshaping the competitive landscape for IT services contractors. Non-awardees must immediately pivot to teaming strategies, while awardees must activate capture operations across all federal agencies authorized to use this vehicle.

Cabrillo Club·February 20, 2026
Blog post hero imageFlash Brief
Compliance & Risk

How commercial drones make the Pentagon’s ‘Blue UAS Select’ list

The Defense Department has operationalized its Drone Dominance Program with the launch of the Blue List UAS website, cataloging 54 approved commercial drone models (29 with 'select' operational status) that meet NDAA Section 848 supply chain security requirements. The Defense Contract Management Agency now provides a streamlined procurement pathway for military units to acquire compliant drones without lengthy waiver processes, building on 2020's Blue UAS initiative and eliminating drones with components from security-risk countries. This policy shift creates immediate market access for approved vendors while closing the door on non-compliant competitors, fundamentally restructuring the $2B+ DOD commercial drone acquisition landscape.

Cabrillo Club·February 20, 2026
Blog post hero imageFlash Brief
Compliance & Risk

How to make Tech Force work

OPM has launched the U.S. Tech Force program to place 1,000 technology fellows annually into federal agencies starting September 2025 for one- or two-year terms, supervised by private sector managers. This initiative creates immediate opportunities for technology contractors to support federal digital transformation, particularly in workforce augmentation, technical program management, and modernization consulting. Contractors with active positions on OASIS+, CIO-SP4, and GSA Schedule 70 should prepare capture strategies now, as agencies will require implementation support, integration services, and technical oversight frameworks to operationalize this program successfully.

Cabrillo Club·February 20, 2026
Blog post hero imageFlash Brief
Compliance & Risk

Federal CIO Greg Barbaccia tapped for two leadership roles at GSA

Federal CIO Greg Barbaccia has been appointed as acting director of GSA's Technology Transformation Services (TTS) while maintaining his White House OMB role, replacing Thomas Shedd who transitions to fraud prevention. This dual-hat leadership consolidates federal IT policy and GSA's digital service delivery under one executive, potentially accelerating technology modernization initiatives and altering contractor engagement models for critical platforms like Login.gov, SAM.gov, and cloud.gov. Contractors in IT services, digital transformation, and identity management should monitor for policy shifts in FedRAMP authorization timelines, digital service standards, and GSA Schedule modernization efforts.

Cabrillo Club·February 19, 2026
Blog post hero imageFlash Brief
Compliance & Risk

SpaceX and Blue Origin abruptly shift priorities amid US Golden Dome push

A December 2025 White House executive order mandates a missile shield prototype by 2028 under the Golden Dome initiative, with lunar return by 2028 and permanent moon presence elements by 2030. This directive is forcing SpaceX, Blue Origin, and the broader aerospace industrial base to rapidly pivot toward lunar development and space defense systems, creating immediate contracting opportunities across DOD, Space Force, NASA, and the Missile Defense Agency. Contractors in aerospace manufacturing, launch services, missile defense, and systems engineering must immediately assess their ITAR/CMMC posture and position for upcoming solicitations across NASA SEWP, Space Enterprise Consortium, and R2C2 vehicles. This represents the most significant space policy shift since the establishment of Space Force, with billions in contract value at stake through 2030.

Cabrillo Club·February 19, 2026
Blog post hero imageFlash Brief
Compliance & Risk

Airbus open to two-fighter option for FCAS to keep program alive

Airbus has publicly endorsed a 'two-fighter solution' for the stalled Future Combat Air System (FCAS), Europe's sixth-generation fighter program jointly developed by France, Germany, and Spain. The proposal would split the program into two separate aircraft designs to resolve disputes over work share, technology transfer, and program leadership that have paralyzed development. This fracture in Europe's flagship defense collaboration signals potential realignment of transatlantic defense partnerships, creates new market entry points for U.S. contractors with complementary technologies, and may accelerate Foreign Military Sales opportunities as European nations reassess their air superiority roadmaps.

Cabrillo Club·February 19, 2026
Blog post hero imageFlash Brief
Compliance & Risk

BAE says its Eurofighter pipeline is filled until first GCAP assembly

BAE Systems has secured Eurofighter Typhoon production through the mid-2030s with orders from Spain, Italy, Germany, and Turkey, planning to scale from 14 to 20 aircraft annually by mid-2028 with potential for 30/year. This production bridge extends until the UK-Italy-Japan GCAP sixth-generation fighter begins assembly targeting 2035 entry into service. U.S. defense contractors face intensified competition in international fighter markets and allied interoperability requirements, particularly as European defense industrial capacity expands and ITAR/EAR compliance surfaces become critical for firms pursuing Foreign Military Sales and Direct Commercial Sales opportunities in advanced air systems.

Cabrillo Club·February 19, 2026
Blog post hero imageFlash Brief
Compliance & Risk

HHS’s reported AI uses soar, including pilots to address staff ‘shortage’

HHS reported a 65% increase in AI use cases in 2025, deploying tools like ChatGPT and Copilot to address critical staffing shortages following significant workforce reductions. This strategic pivot toward automation fundamentally alters HHS's procurement posture—traditional labor-hour contracts face compression while AI-enabled service delivery models gain traction. Contractors in IT services, BPO, administrative support, and legal services must immediately reassess pipeline positioning and technical capabilities, as HHS's $2M AI caregiving initiative signals broader adoption across all operating divisions including FDA, CDC, CMS, and NIH.

Cabrillo Club·February 19, 2026
Blog post hero imageFlash Brief
Compliance & Risk

Interior Department finding momentum with modernization

The Department of Interior is executing a comprehensive modernization of its contracting and procurement infrastructure, deploying robotic process automation (RPA) and evaluating generative AI and blockchain technologies for acquisition workflows. Following an IG audit that identified $40 million in misclassified IT purchases across FY2022-2024, DOI is centralizing IT infrastructure and tightening FITARA compliance controls. Contractors serving DOI—particularly those in IT modernization, cloud services, and emerging tech—should anticipate stricter procurement classification reviews, updated technical requirements in upcoming solicitations, and potential consolidation of contract vehicles as the agency standardizes its technology stack.

Cabrillo Club·February 18, 2026
Blog post hero imageFlash Brief
Compliance & Risk

FAA, DOD data silos were partly to blame for last year’s DCA crash

The NTSB's final report on the DCA midair collision identifies systemic failures in data sharing and safety management between FAA and DOD, with specific emphasis on incompatible safety reporting systems and inadequate risk assessment processes. The FAA's Aviation Safety Information Analysis and Sharing (ASIAS) program had zero integration with Army Safety Management systems, creating dangerous blind spots. Contractors supporting aviation safety systems, data analytics, and inter-agency information sharing should anticipate new compliance requirements for safety data collection, enhanced oversight protocols, and mandated cross-agency data integration standards—particularly those holding OASIS+, ASTRO, and GSA Schedule 70 vehicles supporting FAA and DOD aviation programs.

Cabrillo Club·February 18, 2026
Blog post hero imageFlash Brief
Compliance & Risk

Australia prepares for next batch of ‘Ghost Bat’ warplane buddy drones

Australia's Royal Australian Air Force has contracted Boeing Defence Australia for seven additional MQ-28A Ghost Bat collaborative combat aircraft in a AUS$754 million (US$534 million) third tranche, bringing the total fleet to 18 units with 10 operational aircraft planned by 2028. This expansion signals accelerating international demand for unmanned collaborative combat systems and validates the CCA concept as a cornerstone of allied long-range deterrence strategies. U.S. defense contractors with capabilities in autonomous systems, AI-enabled mission planning, sensor fusion, and secure datalink technologies should immediately assess positioning for Foreign Military Sales (FMS) and Direct Commercial Sales (DCS) opportunities as allied nations replicate Australia's CCA integration model.

Cabrillo Club·February 17, 2026
Blog post hero imageFlash Brief
Compliance & Risk

Federal Register: Federal Acquisition Regulation: Prohibition on Certain Semiconductor Products and Services

The FAR Council is proposing amendments to prohibit federal agencies from procuring products or services containing covered semiconductor products or services, effective December 23, 2027. This implements Section 5949 of the FY2023 NDAA and will fundamentally reshape supply chain compliance requirements across the entire federal contracting base. Contractors must immediately audit their semiconductor supply chains, identify covered products, and prepare mitigation strategies before the 2027 deadline. This is not optional—non-compliance will result in contract ineligibility across all executive agencies.

Cabrillo Club·February 17, 2026
Blog post hero imageFlash Brief
Compliance & Risk

Federal Register: Posting of Informational Video: Cybersecurity Maturity Model Certification (CMMC) Program

The DoD Chief Information Officer has published an official informational video briefing on the CMMC 2.0 proposed rule, originally released for public comment on December 26, 2023. This video, presented by the Office of the Deputy CIO for Cybersecurity, provides authoritative guidance on the comprehensive assessment framework that will govern how defense contractors and subcontractors must implement security controls for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The proposed rule introduces a scalable, three-tiered certification model with new CUI security requirements for priority programs—signaling that CMMC enforcement is transitioning from 'proposed' to 'imminent operational reality.'

Cabrillo Club·February 17, 2026