What GAO Found
Federal broadband efforts are fragmented, with over 100 programs administered by 15 agencies, as GAO reported in May 2022. Some programs support broadband as their main purpose, while others support broadband as one possible purpose (see figure).
The Mosaic of Federal Programs with Broadband as a Main Purpose as of November 2021, by Purpose Category
GAO has found that a national strategy, continued interagency coordination, and better mapping data could strengthen federal broadband efforts.
National Strategy. Strategies to coordinate programs that address issues of broad national need can help mitigate the negative effects of fragmented federal programs, but no national strategy exists for federal broadband efforts. In May 2022, GAO recommended creating such a strategy to synchronize these efforts.
Interagency Coordination. With or without a national strategy, effective coordination among agencies that administer broadband programs is also important. In April 2025, GAO reported that the Federal Communications Commission (FCC), National Telecommunications and Information Administration (NTIA), and Departments of Agriculture (USDA) and the Treasury coordinate to administer the bulk of federal broadband funding and have mechanisms in place to do so. GAO recommended improvements to further strengthen those efforts. Agency officials reported taking steps to implement these recommendations, but have not yet fully addressed them, as of July 2026.
Mapping Data. Agencies rely on FCC’s National Broadband Map—which displays where broadband is already available—to target tens of billions of dollars in federal broadband funding, but the accuracy of the map’s availability data is uncertain. In April 2025, GAO recommended FCC document and evaluate the effectiveness of its processes for ensuring the map’s data quality. Not doing so could increase the risk of inaccurate data on the map, which could jeopardize agencies’ ability to make effective funding decisions. FCC has not yet addressed the recommendations as of July 2026, but officials reported taking steps to do so.
Why GAO Did This Study
Access to broadband is critical for employment, education, health care, and other daily activities. The federal government has invested tens of billions of dollars over the past decade across a myriad of broadband-related programs managed by different agencies. Yet millions of Americans lack broadband access.
Information on where broadband is already available is key to expanding access. Coordination among the federal agencies that administer the various federal programs is also key, particularly since U.S. broadband efforts are not guided by an overarching national strategy.
This testimony discusses findings from GAO’s previous reports on (1) a national broadband strategy and interagency coordination efforts, and (2) FCC’s efforts to ensure the quality of data in its National Broadband Map. It is primarily based on GAO’s May 2022 and April 2025 reports.
What GAO Found
The Department of the Treasury and the Internal Revenue Service (IRS) proposed 236 tax regulations and finalized 231 regulations between January 21, 2017, and March 31, 2026. These regulations included those that implemented provisions of the sweeping tax law changes of 2017, 2022, and 2025. IRS rulemaking procedures generally provided the public with an opportunity to comment on proposed tax regulations.
GAO found that Treasury and IRS could improve the usefulness of regulatory economic analyses required for economically significant tax regulations which have $100 million or more in economic effects, with 28 tax regulations designated as such in the period GAO reviewed. Treasury and IRS consistently used one of the Office of Management and Budget’s (OMB) recommended practices for the economically significant regulations reviewed. This practice of analyzing alternative ways to design the regulations resulted in decisions that made it easier for taxpayers to claim new tax benefits. However, Treasury and IRS used other recommended practices less consistently. These practices, if used, would help Treasury and IRS make more informed selections of regulatory alternatives by providing specific cost, benefit, and revenue estimates.
Use of Recommended Analysis Practices for Selected Final Tax Regulations
Treasury and IRS are not following leading practices for public engagement in rulemaking and risk not being prepared to address voluminous public comments, sometimes tens of thousands, on proposed tax regulations. IRS faces increasing challenges with AI-generated public comments which make it more difficult for IRS to identify duplicate comments. IRS has not developed policies for addressing mass public comments or comments written with the assistance of AI. Treasury and IRS hold public hearings on proposed regulations in Washington, D.C., upon request. Effective virtual participation by members of the public from across the United States is challenging because IRS only uses dial-in technology rather than widely available video conferencing technology. A federal advisory agency recommends that agencies reduce barriers to public regulatory participation. GAO also identified additional opportunities to document public comments made at hearings to ensure important concerns are considered.
Why GAO Did This Study
In recent years, Treasury and IRS have been affected by significant legal decisions, changes in the requirements for rulemaking, and rapidly evolving technologies that enable mass public comments.
The Inflation Reduction Act of 2022 (IRA) directed GAO to oversee the use of IRA funds including Treasury and IRS regulatory actions. GAO’s objectives included assessing: (1) the development of regulations in light of recent tax law changes, (2) the extent to which Treasury and IRS perform economic analysis for major tax regulations and measure revenue effects, and (3) the extent to which Treasury and IRS follow leading practices for public engagement in rulemaking.
GAO analyzed regulatory activity between January 2017 and March 2026; compared four selected regulatory economic analyses against recommended practices by OMB with the regulations selected, in part, because the economic analyses were the most relevant examples in selecting alternative regulatory designs; and compared public comment and regulatory hearing procedures against leading practices.
What GAO Found
In May 2025, GAO identified 14 priority recommendations for the Office of the Director of National Intelligence (ODNI). Since then, ODNI has implemented one of those recommendations.
In June 2026, GAO identified one additional priority recommendation, and removed the priority status from eight recommendations, bringing the total to six. GAO is highlighting the following two areas that warrant timely and focused attention:
Mitigating personnel vetting risks
Addressing intelligence enterprise management challenges
Addressing GAO's recommendations in these areas would improve the personnel security clearance process and enhance programs that have impacts across the intelligence community (IC). Taking action to implement all of GAO's open recommendations would help enhance the efficiency and effectiveness of operations across the IC.
Why GAO Did This Study
Priority open recommendations are the GAO recommendations that warrant priority attention from heads of key departments or agencies because their implementation could save large amounts of money; improve congressional and/or executive branch decision-making on major issues; eliminate mismanagement, fraud, and abuse; or make progress toward addressing a high risk or duplication issue, among other benefits. Since 2015, GAO has sent letters to selected agencies to highlight the importance of implementing such recommendations.
For more information, contact Cathy Berrick at berrickc@gao.gov.
What GAO Found
The National Transportation Safety Board (NTSB) investigates and determines the probable cause of transportation accidents in the United States, among other responsibilities, thus playing a vital role in advancing transportation safety. To support its mission, NTSB procures a variety of products (e.g., laboratory equipment) and services (e.g., services to develop and maintain systems and applications used to investigate accidents). NTSB is generally required to promote full and open competition in awarding contracts. However, in some cases, NTSB may award contracts through noncompetitive procedures. According to NTSB officials, the agency awards contracts pursuant to applicable statutes, federal regulations, executive orders, and internal guidance. NTSB’s policies and procedures for contracts include multiple reviews. Additional reviews or senior-level approvals are required for noncompetitive contract awards valued over $100,000 and for competitive contract awards valued over $500,000. In response to a February 2025 executive order, NTSB changed its policies to include that all new NTSB contract requirements with a value greater than $100,000 are approved by NTSB’s Chairwoman prior to awarding a contract, unless approval has been delegated to NTSB’s Managing Director.
For fiscal years 2020 through 2024, NTSB obligated a total of about $86 million on awarded contracts, adjusted for inflation to fiscal year 2024 dollars. About 84 percent of these obligations were on competitively awarded contracts and about 16 percent were on noncompetitively awarded contracts.
Obligations on competitively awarded contracts nearly doubled from fiscal year 2020 to fiscal year 2024, from about $10 million in fiscal year 2020 to nearly $20 million in fiscal year 2024. NTSB officials attributed most of the increase in obligations on competitively awarded contracts to increased investments in information technology products and services. According to NTSB officials, these investments have allowed NTSB to improve investigation timeliness and to meet congressional expectations for efficient data and knowledge sharing. Obligations on noncompetitively awarded contracts also increased, though slightly, rising from about $2.5 million to about $2.6 million over that same time frame.
National Transportation Safety Board’s Obligations on Competitively and Noncompetitively Awarded Contracts, Fiscal Years 2020–2024
Why GAO Did This Study
The FAA Reauthorization Act of 2024 includes a provision for GAO to review NTSB’s procurement and contracting planning, policies, and practices. This report describes NTSB’s policies and procedures for competitively and noncompetitively awarded contracts and provides information on NTSB’s obligations on awarded contracts for fiscal year 2020 through fiscal year 2024.
GAO reviewed NTSB’s contract obligation data for fiscal year 2020 through fiscal year 2024, the most recent years of complete data available at the time of GAO’s analysis. GAO downloaded the data from the Federal Procurement Data System (FPDS), as of September 25, 2025, and determined that FPDS’s obligation data were sufficiently reliable for GAO’s purposes of describing NTSB’s obligations on awarded contracts. GAO also reviewed statutes, regulations, an executive order, and guidance documents governing NTSB’s contracting activities and interviewed NTSB officials about (1) contracting policies and procedures and (2) the reasons for obligation changes over time.
For more information, contact Derrick Collins at CollinsD@gao.gov.
What GAO Found
The Office of Management and Budget annually designates a list of programs considered high-priority for improper payments. The Department of Veterans Affairs (VA) Community Care program and the Centers for Medicare & Medicaid Services’ (CMS) Medicare Advantage program are two of the 30 programs designated as high priority for fiscal year 2025. VA reported a Community Care improper payment estimate of $608 million for fiscal year 2025, or 2.4 percent of the program’s outlays. CMS reported a Medicare Advantage improper payment estimate of $23.7 billion for fiscal year 2025, or 6.1 percent of the program’s outlays. GAO found gaps in the agencies’ efforts to reduce improper payment and fraud risks.
Agency Efforts to Reduce Improper Payments and Fraud Risks
Community Care Program
Medicare Advantage Program
Developed and implemented a process to identify and assess the root causes of improper payments
●
●
Developed, implemented, and monitored corrective action plans that adequately address the identified root causes of improper payments
●
◐
Conducted a fraud risk assessment that identifies inherent fraud risks, assesses their likelihood and impact, determines risk tolerance, evaluates controls, and documents a fraud risk profile
○
○
Legend: ● Met; ◐ Partially met; ○ Not met.
Source: GAO. | GAO-26-107946
Note: Analysis based on the results of GAO work completed from November 2024 through June 2026.
For the fiscal years included in GAO’s review, VA developed and implemented a process to identify and assess the root causes of improper payments in the Community Care program. VA also developed, implemented, and monitored corrective action plans that adequately address the identified root causes. While VA has taken steps to identify and assess fraud risks, these efforts do not meet the key elements of a fraud risk assessment and have not resulted in a comprehensive fraud risk assessment for the program, leaving it vulnerable to fraud.
For the fiscal years included in GAO’s review, CMS developed and implemented a process to identify and assess the root causes of improper payments in the Medicare Advantage program. However, its estimated improper payment rate has not decreased but remained steady. CMS’s corrective action plans are not sufficiently detailed and do not adequately monitor progress. Specifically, CMS does not have a detailed plan for expediting Risk Adjustment Data Validation (RADV) audits. These audits are CMS’s primary corrective action for identifying and recovering improper payments. CMS’s backlog of RADV audits contributes to significant delays in its recovery efforts. Furthermore, CMS has not conducted a comprehensive fraud risk assessment for the program. CMS’s efforts to reduce improper payments and fraud in the Medicare Advantage program will be inadequate without comprehensive corrective action plans and fraud risk assessments.
Why GAO Did This Study
Reducing improper payments and fraud is critical to safeguarding federal funds and could help achieve cost savings and improve the government’s fiscal position.
GAO was asked to assess agency efforts to identify and address root causes of improper payments and fraud. In this report, GAO examines to what extent (1) VA has taken steps to identify and address the root causes of improper payments and mitigate fraud risks in the Community Care program and (2) CMS has taken steps to identify and address the root causes of improper payments and mitigate fraud risks in the Medicare Advantage program.
GAO examined documentation from VA, CMS, PaymentAccuracy.gov, and prior reports from agency Offices of Inspector General (OIG). GAO also interviewed agency officials, OIG staff, and trade association representatives.
What GAO Found
The size of passenger vehicles on U.S. roads has grown over the past 30 years. Selected studies that GAO reviewed generally found that larger vehicles, certain design features (see figure), and turning maneuvers may limit a driver’s visibility and pose greater risks to pedestrians and cyclists. Data on driver visibility, such as the size of blind zones around a vehicle, are not readily available. As such, GAO used turning maneuvers to analyze the potential relationship between vehicle type and involvement in fatal pedestrian crashes. GAO found that larger vehicles had higher odds of turning compared with going straight in fatal pedestrian crashes than cars in the same scenarios. For example, heavy-duty trucks (e.g., semi-trucks) had at least 12 times the odds compared with cars.
Vehicle Design Features and Their Potential Relationship to Driver Visibility
Auto and truck manufacturers that GAO interviewed have developed technologies to help mitigate limited driver visibility, such as side bicyclist alerts and pedestrian automatic emergency braking. Manufacturers have also conducted testing and benchmarking of their vehicles to assess driver visibility.
Two selected foreign jurisdictions—the European Union (EU) and London, England—have taken steps to reduce risks to pedestrians and cyclists related to limited driver visibility. The EU has adopted driver visibility standards that auto and truck manufacturers must meet. While similar regulations also apply in the United Kingdom, London has developed a driver visibility standard that requires some commercial truck operators to install additional safety equipment.
The Department of Transportation (DOT) has recognized risks to pedestrians and cyclists related to driver visibility but has not fully analyzed those risks or developed responses. DOT has conducted some research and begun to collect data that could be useful in conducting such an analysis. However, it has not analyzed specific risks that limited driver visibility may pose to pedestrians and cyclists, such as those related to turning maneuvers or vehicle design features. DOT has not done so because, in part, it has not determined a method to measure driver visibility in cars and trucks. Such a method could provide data on the size of blind zones and enable DOT to fully analyze the extent to which they pose risks to pedestrians and cyclists. Fully analyzing specific risks would also provide DOT with the information it needs to respond to them, and would better position DOT to meet its goal of reducing roadway fatalities
Why GAO Did This Study
In 2024, about 9,200 pedestrians and cyclists were killed on U.S. roadways—an increase of about 65 percent since 2010. A range of factors can contribute to increased pedestrian and cyclist fatalities, including larger vehicles, which make up an increasing share of vehicles on U.S. roadways and may limit driver visibility.
GAO was asked to review issues related to driver visibility. This report examines (1) what studies and federal data show about the relationship between vehicle characteristics, driver visibility, and pedestrian and cyclist fatalities; (2) actions selected auto and truck manufacturers have taken related to driver visibility; (3) approaches selected foreign jurisdictions have used to reduce driver visibility–related risks to pedestrians and cyclists; and (4) the extent to which DOT has analyzed and responded to potential driver visibility–related risks to pedestrians and cyclists.
GAO reviewed selected studies published from 2015 to 2025, analyzed DOT pedestrian fatality data, and selected and interviewed five auto and five truck manufacturers. GAO also reviewed driver visibility standards adopted by the EU and London and interviewed officials about their approaches. Finally, GAO reviewed DOT studies and planning documents and interviewed DOT officials.
GAO’s work regularly finds that federal programs are unable to assess their performance to determine if they are solving the problem they were created to fix. By defining goals and collecting and using relevant data, agencies could make informed decisions to improve their programs’ results.
The Big Picture
Each year, the federal government spends trillions of dollars on programs that Americans depend on, such as health care, public safety, and disaster support. Our recent reports have found that many federal programs do not have clearly defined goals to identify what they seek to achieve or relevant data to assess progress. Without this information, Congress and agency leaders cannot determine if federal programs funded by taxpayer dollars are delivering intended results and supporting the American people.
What GAO’s Work Shows
Through a three-step process, federal agencies can monitor and manage the results of their programs.
The program performance management process
Federal programs do not consistently manage their performance. Our work often finds programs are focused on inputs (such as money to spend) and outputs (such as number of individuals who received benefits). By contrast, outcomes are the results of a program (such as number of individuals whose lives improved in an intended way).
Programs often lack information on outcomes because they operate without clear, measurable goals or data to assess their results. Agency leaders and Congress need this information to determine if programs are solving the problems they were created to fix, and in turn, if they are a good return on investment for taxpayer money.
Selected Federal Programs that GAO Previously Found Had Incomplete Performance Management Processes
Moreover, federal programs rarely work in isolation. Our work often identifies sets of related programs—within an agency or across multiple agencies—that seek to achieve the same outcomes and may create overlapping efforts.
We also find these related programs have not always defined goals or collected data to manage their performance. This creates the potential for waste and inefficiency. It limits decision-makers’ abilities to (1) assess relative performance across programs and (2) make informed decisions to streamline efforts or provide resources to more effective programs.
Most Programs that Solely Support Pregnant Women, Young Children, and Their Families Had Established Performance Management Processes
Many pregnant women, children through age 5, and their families use support services like food assistance or childcare. In 2026, we identified 15 federal programs at five agencies that provide direct services only to this population.
Twelve of these 15 programs had performance management processes that set goals, collect data, and use the information to assess whether the programs are meeting goals. We recommended that the remaining three programs without these processes—one each at the Departments of Agriculture, Health and Human Services, and Veterans Affairs—fully develop them to ensure programs are meeting goals, identifying potential improvements, and targeting resources appropriately.
Source: GAO. | GAO-26-109130
When we have identified opportunities to improve program performance by developing goals and collecting and using data, agencies have taken action to implement our recommendations.
Actions to Improve Performance Management for the Securing the Cities Program
The Department of Homeland Security’s (DHS) Securing the Cities program seeks to help state and local governments detect and deter nuclear terrorism. In 2019, we found that DHS did not collect information to fully track cities' use of the program’s funds or assess performance. We recommended DHS do so.
Subsequently, we found in 2024 that the program had established goals, performance measures, and milestones, and conducted quarterly financial assessments. DHS is now better positioned to monitor the program’s performance and identify any needed actions to improve results.
Source: GAO. | GAO-26-109130
Additional evidence is needed to determine program effectiveness. Because of its ongoing nature, performance management can serve as an early-warning system to identify the need for real-time improvements. Collecting evidence beyond performance data can help determine whether a program is working and why. This includes robust studies known as program evaluations, which can provide valuable insights on program performance.
Types of Program Evaluations and Insights
Process evaluations assess the extent to which a program is being implemented as intended.
Outcome evaluations assess whether (1) program activities are aligned with desired outcomes and (2) changes in outcomes are consistent with program goals.
Impact evaluations assess the effect of a program by comparing results to what would have happened in its absence.
Source: GAO. | GAO-26-109130
When we asked federal managers in a 2020 survey about these robust evaluations, about one-third of respondents reported having access to them to help manage their programs.
Challenges and Opportunities
Statutory requirements provide a solid foundation for effective federal performance management. They have also increased agencies’ use of performance data in decision-making, such as identifying program problems to address and developing new strategies.
In contrast, Congress and the administration often do not have the performance data and evidence they need to make informed improvements and target resources to individual programs or across related programs.
Our work has identified approaches to help ensure decision makers have sufficient information, including
practices to help individual or sets of related programs manage performance and build evidence;
practices to effectively coordinate, and a guide to evaluate and manage, related programs; and
a guide to design program evaluations.
Consistently using these approaches could help agencies manage and assess their programs and provide policymakers and the public with vital information about federal program performance.
For more information, contact Lori Atkinson at atkinsonl@gao.gov.
What GAO Found
The Federal Home Loan Bank (FHLBank) System is a government-sponsored enterprise that consists of 11 federally chartered FHLBanks that support liquidity in the financial system by making loans—known as advances—to member financial institutions, including banks. These advances offer member institutions a low-cost source of funding to make mortgage loans or manage the risk of not meeting financial obligations in a timely and cost-efficient manner (liquidity risk).
A December 2025 GAO report found that as of June 2025, 93 percent of banks were FHLBank members and more than three-quarters had taken out at least one advance from June 2015 through June 2025. GAO’s analysis of banks’ quarterly Call Report data found that large banks—those with more than $10 billion in total assets—were responsible for a majority of banks’ FHLBank borrowing in this period. These banks represented approximately 3 percent of active FHLBanks members and held, on average, nearly 74 percent of all outstanding FHLBank borrowing during the period.
A March 2024 GAO report found that Silicon Valley Bank and Signature Bank had borrowed substantial advances before their failures in spring 2023.
Silicon Valley Bank increased the balance of its outstanding advances by 50 percent in the first week of March 2023 before its failure on March 10.
Signature Bank increased its outstanding advances by 37 percent in March 2023 before its failure on March 12.
The two FHLBanks continued to assess risk and provide advances to the two banks before they failed. FHLBanks generally lend to members if the requested amount is within the member’s available borrowing capacity based on its pledged collateral or credit limit. FHLBanks may limit or deny advances based on supervisory information from the member’s primary regulator. The FHLBanks and federal banking regulators increased their frequency of communication in March 2023, but the banks’ relatively fast decline limited further action.
Timely coordination between FHLBanks and Federal Reserve Banks is critical when a bank is at risk. This coordination must negotiate overlap in membership between the two systems. The March 2023 bank failures revealed such coordination challenges. After March 2023, the FHLBanks and Federal Reserve System initiated two efforts to improve coordination during periods of stress: (1) increasing engagement between FHLBanks and Federal Reserve Banks and (2) establishing a working group to improve interoperability.
These efforts are intended to address the coordination challenges experienced during the March 2023 bank failures and are consistent with federal internal control standards related to control activities and information and communication. At the time of GAO’s December 2025 report, these efforts were in the early stages. Continued commitment to these coordination efforts will be important to help ensure that the FHLBanks and Federal Reserve Banks are prepared to respond quickly to member liquidity needs during future periods of financial stress.
Why GAO Did This Study
The failures of Silicon Valley Bank and Signature Bank in March 2023 renewed questions about the FHLBanks’ role in providing liquidity during periods of financial stress. In the weeks leading up to the failures, these banks had borrowed large sums from their FHLBanks. That same month, total advances outstanding to all members reached about $1 trillion, exceeding levels reached during previous financial market disruptions.
This statement discusses (1) the FHLBank System's role in providing financial system liquidity through advances, (2) banks’ use of advances during the March 2023 bank failures, and (3) efforts to improve emergency coordination between FHLBanks and Federal Reserve Banks.
This statement is based on reports GAO issued from April 2023 to December 2025. For those reports, GAO reviewed relevant legislation, regulations, policies, and agency reports, and interviewed federal officials, representatives of FHLBanks and member banks, and other stakeholders.
For more information, contact Jill Naamane at NaamaneJ@gao.gov.
Why This Matters
The Office of Personnel Management (OPM) is the federal government's central agency for human resources and workforce management. Since December 2024, in alignment with presidential directives on the closure of certain offices and the reduction of the size of the federal workforce, OPM has undergone significant workforce and organizational structure changes. These actions have reduced institutional knowledge and operational capacity at the agency.
OPM’s Headcount Decreased by 35 Percent Between December 2024 and March 2026
GAO analysis of OPM’s Federal Workforce Data (FWD) found that OPM’s headcount decreased by 1,052 people (35 percent) between December 31, 2024 and March 31, 2026, with those 60 years and older particularly affected (see fig. 1).
Figure 1: OPM Headcount by Age, December 31, 2024–March 31, 2026
Note: Data obtained from OPM website in June 2026. Workforce statistics may not reflect updates made after that date.
Looking back, OPM’s headcount increased by 450 people (17 percent) between 2019 and 2024. Even so, OPM’s March 2026 headcount is down 602 people (23 percent) from 2019 levels.
Of those who separated between December 2024 and March 2026, 59 percent did so through a deferred resignation program and 10 percent through a reduction in force, according to analysis of FWD. Separations particularly affected older and younger employees at OPM. The number of employees aged 60 or older decreased by 49 percent from December 2024 to March 2026. Also, among employees under age 30 who separated, 60 percent were within their probationary period. For all separating employees, only 23 percent were within their probationary period.
OPM also reduced and eliminated certain offices. In its fiscal year (FY) 2026 Congressional Budget Justification, OPM reported that it eliminated 10 offices, such as the Office of Procurement Operations. These offices covered a range of responsibilities both within OPM and across the federal government. From FYs 2024 to 2026, only two offices had an increase in full-time equivalents (FTE) (see table 1). For example, the Office of the Chief Information Officer manages OPM’s IT and Retirement Services administers the federal civilian retirement systems. OPM reported that it experienced a historic surge of retirements in 2025 and responded by expanding the team. However, overall, Retirement Services shrunk 16 percent from FYs 2024 to 2026. The two offices with FTE increases assumed functions from other offices.
Table 1: Changes in OPM-Reported Full-Time Equivalents (FTE) at Selected OPM Offices, Fiscal Years 2024–2026
Office
Change in FTEs
Percent Change
Human Resources Solutions
-189
-36%
Office of the Chief Information Officer
-167
-49%
Retirement Services
-165
-16%
Workforce Policy and Innovation
-102
-45%
Merit System Accountability & Compliance
-38
-41%
Office of the General Counsel
8
21%
Office of the Director
23
79%
Source: GAO analysis of the Office of Personnel Management (OPM) Congressional Budget Justifications. | GAO-26-108916
Despite the reductions, some offices are assuming additional responsibilities. For example, while Merit System Accountability & Compliance experienced a 41 percent decline in FTEs from FYs 2024 to 2026, OPM has proposed transferring appeals of employees who have been separated by a reduction in force from the Merit Systems Protection Board to OPM, stating that the change is meant to improve efficiency. In its FY 2027 Congressional Budget Justification, OPM proposed using AI tools and modernizing its IT systems in offices with fewer staff. For example, the agency proposed exploring opportunities to leverage AI to enhance financial reporting and internal customer experience in the Office of the Chief Financial Officer.
OPM’s Workforce Reductions Risk Contributing to OPM’s Existing Skills Gaps
GAO and OPM have identified skills gaps as a long-standing challenge. The federal government's efforts to address government-wide and agency-specific skills gaps have been on GAO's High-Risk List since 2001. In March 2022, an OPM-sponsored assessment found that OPM had skills gaps that could compromise its ability to implement its strategic plan. In February 2023, GAO recommended that OPM establish an action plan to address these gaps (see GAO-23-105528). According to agency officials responding to that open GAO recommendation, OPM has not implemented the recommendation because it is prioritizing making workforce changes to align with its FY 2026–2030 strategic plan.
In November 2025, the OPM Office of the Inspector General (OIG) identified OPM’s workforce reduction as a top management challenge for 2026 (see OPM OIG annual report). The report says that staff reductions have created immediate gaps in operational capacity at the agency.
GAO and OPM have both reported that it is important to build a stronger pipeline of talent into mission-critical roles across government (GAO-19-181). In March 2026, OPM launched a new initiative to connect emerging professionals with career opportunities across the federal government. Leading up to this, from December 2024 to March 2026, 41 percent of OPM’s staff under age 30 separated.
Additionally, GAO’s analysis of FWD found that of those who separated from OPM from December 2024 to March 2026, 18 percent had at least 31 years of service and 57 percent had 11 or more years of service, representing a significant loss of institutional knowledge (see table 2). GAO has previously reported that if turnover is not strategically managed and succession plans are not in place, gaps can develop in an agency’s institutional knowledge and leadership as experienced employees retire (see GAO-19-181).
Table 2: Length of Service of Employees Separated from OPM, December 2024–March 2026
Length of service in years
Less than 2
2-5
6-10
11-20
21-30
31 or more
Number of employees
185
199
149
271
205
226
Percent
15%
16%
12%
22%
17%
18%
Source: GAO analysis of the Office of Personnel Management’s (OPM) Federal Workforce Data. | GAO-26-108916
To supplement GAO’s analysis of publicly available data, GAO requested documentation from OPM regarding changes made to offices or programs since 2025, the rationale behind the closure or consolidation of offices, and processes for strategic workforce planning, among other information. Other than comments on a preliminary draft of this report, OPM did not provide any requested documents or information, nor did it agree to meet with GAO or respond to written questions. As a result, in this report, GAO is unable to provide complete information on what changes OPM made, its rationale, the expected costs and benefits, and any effect on OPM’s ability to fulfil its mission.
For more information, contact Dawn G. Locke at LockeD@gao.gov.
What GAO Found
The Navy is currently 24 months behind in its efforts to modernize three DDG 1000 Zumwalt class destroyers to host the Conventional Prompt Strike (CPS) hypersonic missile as part of its surface strike mission. Both the DDG 1000 and CPS efforts face challenges:
Although modernization of the first ship in the class, USS Zumwalt (DDG 1000), was 94 percent complete as of January 2026, it is behind schedule due to unplanned work.
The DDG 1000 class ships have unique systems, such as its radar, combat, and network systems, that are costly and difficult to sustain and maintain.
The CPS effort was originally scheduled to begin flight testing on the DDG 1000 class in 2025 but this is now planned for 2027 due to funding and testing challenges.
The CPS program encountered quality and production issues putting the current rate well below the production goal of 12 missile rounds per year.
USS Zumwalt (DDG 1000)
DOD is planning to invest at least $50 billion into developing, testing, producing, and fielding CPS capability across several programs, including: CPS, Virginia class submarine, and the Army’s Long-Range Hypersonic Weapon, among others. While Navy and Army officials told GAO that they coordinate with each other, the services largely manage investment decisions for these programs separately, which contributes to inefficiencies and delays.
DOD does not have a comprehensive strategy across all programs that ensures that each program’s investments achieve CPS’s common objectives. Without a comprehensive investment strategy that includes more formal coordination, the Army and Navy are not well-positioned to make timely and efficient investments in key areas, such as addressing shortfalls on their shared production lines or ensuring the economical sustainment and performance of the DDG 1000.
Why GAO Did This Study
The Navy intends to provide its three DDG 1000 Zumwalt class ships with the ability to strike surface targets. In 2021, the Navy decided to add hypersonic CPS missiles—at a planned cost of nearly $50 million per missile—to the DDG 1000 class destroyers to enable the U.S. to strike valuable, heavily defended targets from a distance with a non-nuclear payload. To do so, the Navy is modernizing the ships to include installing a vertical launch system for CPS missiles. The Navy plans to add the CPS missile system to some Virginia class submarines. The Army is developing its own version of the CPS, called the Long-Range Hypersonic Weapon, and is responsible for producing the missile glide body for both services, among other responsibilities.
A House report includes a provision for GAO to review the Navy’s large surface combatant program, including efforts to modify the DDG 1000 for its new mission. This report examines (1) the status of the DDG 1000 modernization, including CPS development, testing, and integration, and what risks these programs face; and (2) the extent to which DOD has a comprehensive strategy across various programs needed to field the CPS missile capability.
GAO reviewed relevant Navy and Army documentation and interviewed Navy and Army officials and contractor representatives. GAO also visited ship and missile contractor facilities in Mississippi and Alabama.
Why This Matters
U.S. clinicians average a 57-hour workweek, including 7 hours of administrative work. Time spent on tasks like drafting patient visit notes or reviewing billing paperwork may contribute to clinician burnout. New AI tools could increase efficiency and reduce administrative burdens during and after patient visits.
Key Takeaways
Some health care providers are adopting AI tools to assist with note taking and medical coding, which may save time and reduce burnout.
The accuracy of these tools may be difficult to verify, and the overall effects on health care spending are uncertain.
Policymakers need more information about the performance of these tools to determine the appropriate level of oversight needed to help minimize mistakes and ensure proper billing.
The Technology
What is it? Accurate documentation and billing are vital administrative tasks in health care. Health care providers are adopting AI tools to automate these tasks. AI scribes can be used to draft clinical documentation during a patient’s visit and medical coding tools can automatically generate an insurance claim afterward for reimbursement.
How does it work? Traditionally, clinicians take notes during a patient visit and then elaborate on and clarify their notes later to develop a clinical summary. AI “scribes” record the conversation between a patient and clinician and, using conventional and generative AI, create a written summary of the visit for the clinician to review for accuracy. This technology is called “ambient” listening, because the AI tool can operate in the background during a patient visit.
After a visit, medical coders review the summary and other patient documentation and assign standardized codes to include in the insurance claim, which represent a patient’s diagnosis and the services rendered by a clinician. AI tools that analyze patient records and suggest codes for review by medical coders are already in widespread use. New AI tools may use generative and agentic AI technologies to review patient records and assign codes autonomously. This capability could make human coders faster or replace them entirely.
Figure 1. AI Tools for Medical Notes and Coding
How mature is it? The underlying technologies for both AI scribes and medical coding tools have existed for more than a decade. However, more advanced AI technologies, such as generative AI, are enabling companies and health care systems to build new, more capable AI software tools.
According to one AI medical coding software developer, when its software was deployed at a health system with five hospitals, it generated medical codes with more than 95 percent accuracy, and the system’s emergency departments reduced annual coding costs by more than $1 million.
In 2026, the American Medical Association found that between 2024 and 2026, the share of clinicians surveyed who use AI tools to assist with clinical documentation or medical coding increased from 21 to 28 percent.
Opportunities
Reduced administrative burden. AI scribe and medical coding tools could decrease the amount of time clinicians spend on administrative tasks and reduce burnout. In one study, clinicians reduced their documentation time by 20 percent, or two minutes per appointment, using AI scribes.
More detailed clinical summaries. AI scribe tools may improve accuracy and reduce clinicians’ cognitive load. For example, they may capture more details than manual note taking, while helping a clinician focus on the patient.
Increased operational efficiency. AI medical coding tools could streamline administrative processes, reducing the number of staff needed for administrative tasks.
Challenges
Difficulties verifying accuracy. There are few independent studies evaluating the accuracy of these tools. Some tools may not store patient recordings and transcripts, which may limit the extent to which health care providers can conduct independent assessments. Inaccuracies may result in patient harm or over- or under-reimbursement from insurers to providers.
Limited access due to costs. Under-resourced hospitals, health centers, clinics, and small medical practices may not be able to adopt AI scribe or medical coding tools because of constraints such as costs and the need for technical support or training.
Reimbursement and cost implications. AI scribing and medical coding tools could increase health care costs if they capture more diagnoses and services rendered during visits than non-AI approaches. While this could result in higher reimbursement to providers, it could also increase health care spending with costs borne by insurers, employers, patients, or taxpayers (the latter via federal programs like Medicare).
Data privacy and patient consent. Collecting patient data carries security and privacy risks, like breaches of personal information. Additionally, data retention practices vary across AI scribe vendors and patients may not always be informed that recordings are occurring.
Policy Context and Questions
As emerging technologies can cross multiple agencies’ jurisdictions, they can present oversight and regulation challenges. Key questions for stakeholders include:
What information do health care providers or policymakers need to ensure AI scribe and coding tools minimize mistakes and unintended consequences?
How can federal agencies and health insurers provide adequate oversight of the use of AI tools to ensure appropriate reimbursement?
Selected GAO Work
Science & Tech Spotlight: AI Agents, GAO-25-108519.
Science & Tech Spotlight: Generative AI in Health Care, GAO-24-107634.
Selected Reference
National Academies of Sciences, Engineering, and Medicine, An Artificial Intelligence Code of Conduct for Health and Medicine: Essential Guidance for Aligned Action (Washington, D.C.: The National Academies Press, 2025). https://doi.org/10.17226/29087.
For more information, contact Sarah Harvey at HarveyS@gao.gov.
What GAO Found
A Secretary of Energy memorandum directed revisions to the Department of Energy’s (DOE) construction order (known as 413.3B) to (1) allow increased delegation of approval authority for projects estimated to cost up to $300 million; and (2) limit independent reviews for projects estimated to cost between $300 million and $1 billion. As of January 2026, DOE and the National Nuclear Security Administration (NNSA) were managing 80 capital asset projects at laboratories and sites where daily operations are carried out by management and operating (M&O) contractors. The projects are collectively estimated to cost as much as $65.5 billion. Revisions could affect 66 of the ongoing projects and future ones.
Figure 1: Locations of Relevant Department of Energy and National Nuclear Security Administration Laboratories, Plants, and Sites
As of March 2026, officials said revising the order was on hold. However, some DOE offices and NNSA have taken steps to implement the changes. DOE’s Office of Science (Science) delegated critical decision approval authority to national laboratory directors, who are M&O contractor employees, for 20 projects at nine laboratories. NNSA is developing guidance on changes to independent reviews. The changes are too recent to have yet demonstrated an effect.
Science and NNSA officials said streamlining project approvals and conducting fewer independent reviews could improve efficiency and save costs. GAO’s analysis of DOE and NNSA guidance additionally found that eliminating certain independent reviews could reduce confidence in the reliability of cost and schedule estimates and result in late identification of potential problems. For example, a 2026 peer review helped support planning efforts to address expected cost increases for an NNSA project in New Mexico.
Science and NNSA officials said they will use the existing process for evaluating individual M&O contractors’ performance to assess the effectiveness of the revisions. But these evaluations do not assess agencywide progress toward achieving desired goals. By establishing specific goals, outcomes, and measures, the agencies would be better positioned to determine whether the revisions are achieving improved efficiency and cost savings.
Why GAO Did This Study
DOE and NNSA, a separately organized agency within DOE, carry out capital asset acquisitions for construction projects to modernize laboratory and site infrastructure and to acquire certain major items of equipment. Projects estimated to cost more than $50 million are managed according to DOE Order 413.3B. The order requires increasingly senior leadership officials to approve projects as they progress through various critical decision points (e.g., design approval) depending on the cost of the project.
In March 2025, the Secretary of Energy issued a memorandum directing revisions to this order to streamline capital asset project management and reduce unnecessary administrative burdens for the national laboratories operated by M&O contractors.
GAO was asked to examine the potential implications of the Secretary’s March 2025 memorandum. This report provides information on how DOE program offices and NNSA are implementing the memorandum for ongoing projects, and potential implications for project oversight.
GAO reviewed project data and documents from DOE and NNSA and interviewed officials responsible for project management and oversight.
What GAO Found
A resilient and skilled cybersecurity workforce is essential to protecting federal information technology (IT) systems and enabling the government’s day-to-day functions. The Federal Rotational Cyber Workforce program, managed by the Office of Personnel Management (OPM), provides opportunities for members of the federal cyber workforce to gain experience in IT, cybersecurity, and other cyber-related positions. Agencies can participate in the program by either advertising a position or by having an employee serve in a position at an outside agency.
As of May 2026, 13 agencies participated in the program, at least 106 positions were advertised, and 634 employees applied for rotational positions. Eight employees were approved to serve a rotation. OPM has effectively suspended the program. It did not advertise any positions in 2025 and officials stated that the agency does not intend to post advertised positions in 2026, due to low participation.
Number of Applicants, Positions, and Approved Employees in the Federal Rotational Cyber Workforce Program, 2023-2025
In October 2024, OPM issued a report on the challenges it experienced in implementing the rotational program. These challenges included a lack of applicants deemed eligible for cyber rotations and a lack of managerial support for the rotational program at the employees’ home agencies. OPM also outlined recommendations for improving program performance—such as encouraging agency leadership to approve participation in the program and advertising positions with lower qualification thresholds—and it did not take steps to implement the recommendations. Due to resources and shifting government-wide priorities, the program has effectively been halted.
Why GAO Did This Study
In 2022, Congress passed the Federal Rotational Cyber Workforce Program Act to help federal agencies enhance their cyber workforce. The program provides opportunities for cyber employees to serve 6- to 12-month voluntary reassignments at other agencies and develop knowledge and skills that they can bring back to their home agencies. As prescribed by the act, the program will sunset in June 2027.
The act includes a provision for GAO to assess the operation and effectiveness of the program. This report addresses (1) the extent to which agencies have participated in the Federal Rotational Cyber Workforce Program and (2) the extent to which OPM identified opportunities to improve the Federal Rotational Cyber Workforce Program.
GAO collected and analyzed OPM data to determine what positions were made available in the program, and how many employee requests to participate were made and approved. GAO reviewed OPM’s lessons learned report to identify the challenges facing the program, summarize lessons learned as identified by OPM, and describe what actions OPM took to address identified program weaknesses. GAO also interviewed OPM officials.
For more information, contact David Hinchman at hinchmand@gao.gov.
What GAO Found
The Federal Aviation Administration (FAA) and Transportation Security Administration (TSA) work together to ensure the cybersecurity of the interconnected systems operating in the National Airspace System (NAS). FAA defined the roles and responsibilities of the entities responsible for carrying out the agency’s related goals and objectives. In contrast, TSA did not. TSA defined its goals and objectives for prioritizing cybersecurity within the agency and in the transportation systems sector in its 2018 Cybersecurity Roadmap. However, the roadmap is outdated and no longer aligned with the latest Department of Homeland Security Cybersecurity Strategy. The roadmap also does not identify the offices responsible for implementing it or define the agency’s cybersecurity-related roles and responsibilities in overseeing airport and aircraft operator security programs. Until TSA updates its Cybersecurity Roadmap to clearly identify its aviation cybersecurity roles and responsibilities, the agency cannot fully hold relevant entities accountable or enable continuous improvements to its related efforts. Moreover, clarity in TSA’s cybersecurity roles, and in turn those of stakeholders, could help minimize the risk of covered systems being exploited.
Interconnection of Aircraft Avionics and Air Traffic Control Facilities on the Ground
Seven FAA entities are responsible for implementing the agency’s Cybersecurity Strategy. The President’s budget requests from fiscal years 2024 through 2026 included funding requests for these entities ranging from approximately $42 million to $11 billion. In addition, the budget requests described programs and costs associated with FAA’s implementation of its Cybersecurity Strategy. However, FAA did not report all of its cybersecurity activities and costs to the Office of Management and Budget’s (OMB) in each of the fiscal years from 2024 through 2026. Specifically, based on FAA’s submitted budget data, the agency did not include spending data for its Information Security/Cybersecurity Program that supports its research and development activities. Until FAA reports all its cybersecurity activities and costs to OMB, policy officials and Congress may not have a complete understanding of FAA’s cybersecurity activity spending that could also impact decisions regarding future cybersecurity funding needs.
FAA’s current and proposed aircraft certification and system security authorization processes align with all key federal and industry practices that GAO identified for mitigating cybersecurity risks and vulnerabilities to avionics and ground systems in the NAS. However, FAA’s Zero Trust Implementation Plan that describes the agency’s approach for transitioning its operating environments to a zero trust architecture (ZTA), including during its NAS modernization effort, did not include details on transition steps for its Research and Development operating environment. Additionally, the plan fully aligned with three of the seven practices that the National Institute of Standards and Technology (NIST) outlined for migrating to a ZTA. Without fully aligning its zero trust implementation plan with NIST’s best practices across all operating environments, FAA cannot ensure that it is effectively and comprehensively managing cybersecurity risks during NAS modernization.
FAA had not fully implemented the objectives supporting its Cybersecurity Strategy’s goal to protect and defend its networks and systems. Specifically, FAA fully implemented three of the seven objectives supporting the goal, as shown in the table below. GAO found that FAA had not fully implemented its Cybersecurity Strategy, in part, because the agency lacked a comprehensive process to monitor and evaluate the implementation of its goals. While the strategy established monitoring requirements for FAA entities, GAO found that one of the seven applicable FAA entities had demonstrated doing so. In March 2026, FAA updated the strategy, which now describes the agency’s plans to develop and use a centralized implementation plan to achieve its strategic objectives and develop performance metrics to track progress towards each of those objectives. As FAA implements its new strategy, taking steps to ensure it carries out the monitoring as planned, including incorporating lessons learned from its past experiences, would help position the agency to achieve its goals for protecting its networks and systems and to effectively mitigate cybersecurity risks. In addition, the agency will be better able to identify challenges, make adjustments, and prioritize resources to address identified risks to its missions and service delivery.
Assessment of Federal Aviation Administration’s (FAA) Efforts to Implement Its Cybersecurity Strategy Goal to Protect and Defend its Networks and Systems
Goal and associated objectives
GAO assessment
Improve cyber threat intelligence collection, processing, dissemination, and reporting
●
Improve FAA cyber monitoring, detection, and response capabilities
◐
Improve privileged user control, monitoring, and visibility
◐
Improve capabilities for detection and mitigation of threats, internal and external
●
Leverage cybersecurity research and development across FAA domains and systems
●
Ensure FAA information security controls, policies and processes are aligned with current National Institute of Standards and Technology standards and guidelines
◐
Develop and implement Zero Trust Architecture capabilities
◐
Legend: ○ = not implemented; ◐ = partially implemented; ● = fully implemented
Source: GAO analysis of the FAA Cybersecurity Strategy. | GAO-26-107693
Why GAO Did This Study
Commercial flight operations rely on interconnected systems that reside onboard an aircraft and on the ground in the National Airspace System. Given this interconnectivity, these systems are inherently more vulnerable to exploitation and are at an increased risk of being targeted by malicious actors. FAA and TSA are the primary federal agencies leading security and resilience efforts in the aviation subsector.
The FAA Reauthorization Act of 2024 includes a provision for GAO to evaluate FAA and TSA efforts to manage their roles and responsibilities for aviation cybersecurity. This report examines (1) the extent to which FAA and TSA defined their current roles and responsibilities for aviation cybersecurity; (2) the budget requests for the FAA entities responsible for implementing its Cybersecurity Strategy, and the extent to which they meet relevant OMB reporting requirements; (3) the extent to which the FAA’s Cybersecurity Strategy incorporates key federal and industry practices to address cybersecurity risks and vulnerabilities for avionics and ground systems; and (4) the extent to which FAA implemented its Cybersecurity Strategy to mitigate cybersecurity risks to its systems and networks.
To address these objectives, GAO compared FAA and TSA strategies and supporting documentation to determine how the agencies defined separate roles and responsibilities for aviation cybersecurity and compared them against the NIST Cybersecurity Framework 2.0 guidance on roles, responsibilities, and authorities. GAO also reviewed the fiscal year 2024 through 2026 President’s budget requests for FAA and evaluated the agency’s budget data and associated process to determine if the agency comprehensively reported its cybersecurity spending in accordance with OMB’s reporting requirements.
Additionally, GAO compared the FAA Cybersecurity Strategy as of February 2026 and associated processes for aircraft certification, system security authorization, and zero trust implementation against key practices GAO identified for mitigating risks and vulnerabilities for avionics and ground systems. Further, GAO evaluated documentation demonstrating FAA’s implementation of its Cybersecurity Strategy’s goal and associated objectives to protect and defend its networks and systems against risks. Lastly, GAO interviewed or collected written responses from FAA, TSA, and selected aviation stakeholders representing industry groups, avionics manufacturers, domestic airlines, and a research organization. GAO selected these aviation stakeholders based on a review of prior work, a literature search, and recommendations obtained from stakeholders interviewed during prior related work.
What GAO Found
GAO estimates that agencies recorded obligations for around 61 percent of the $39 billion in appropriated funds designated for Community Project Funding/Congressionally Directed Spending (CPF/CDS) projects in fiscal years (FY) 2022, 2023, and 2024, as of the end of FY 2024—the most recently completed fiscal year at the time that GAO started its review. GAO also estimates that around 16 percent of the funds have been outlayed as of the end of FY 2024. See figure below. GAO estimates that around 1 percent of FY 2022–2024 projects are not moving forward, for reasons such as recipients declining funds or not submitting required documentation.
Estimated Amount and Percent Obligated and Outlayed of Fiscal Year 2022-2024 Community Project Funding/Congressionally Directed Spending Funds, as of 9/30/24
Note: For more details, including confidence intervals for the estimates, see figure 4 in GAO-26-107944. Dollar amounts do not sum to the total due to rounding.
GAO estimates that nearly all (between 98 and 100 percent) of the FY 2022 and 2023 projects moving forward had a purpose consistent with the purpose cited in the joint explanatory statement designating the funding and that around two-thirds of these projects were underway or complete. An estimated 60 percent of recipients reported experiencing at least one challenge in implementing their CPF/CDS project, such as managing time frames for completing the project.
The 19 agencies administering CPF/CDS funds conducted various oversight activities based on existing policies and guidance for monitoring federal awards, such as reviewing recipient spend plans, conducting site visits, and monitoring project time frames. Officials from most of the agencies (16 of 19) stated they incorporated lessons learned from oversight of the projects in previous fiscal years to improve the overall CPF/CDS process. Most agencies (16 of 19) reported challenges that affected their ability to conduct oversight activities, such as working with recipients receiving funds for the first time and agency staffing issues.
Why GAO Did This Study
As part of recent congressional appropriations processes, Members of Congress could request that funds be designated to a particular recipient—such as a local government or nonprofit organization in their community—for a specified project. These projects are called CPF in the House of Representatives and CDS in the Senate.
The joint explanatory statements accompanying the appropriations acts designating funds for these projects include provisions for GAO to review a sample of projects as part of Congress’s commitment to increased transparency for CPF/CDS funds.
For this report, GAO used generalizable samples to describe (1) the amount of CPF/CDS funds from FY 2022, 2023, and 2024 annual appropriations that have been obligated and outlayed as of the end of FY 2024, (2) the implementation status of FY 2022 and 2023 projects, and (3) how agencies are overseeing implementation for the FY 2022 and 2023 projects.
GAO reviewed data on obligations and outlays for a generalizable sample of 790 projects from the 19 agencies that administer CPF/CDS funds; interviewed a generalizable sample of 167 project recipients about their use of funds; conducted 36 in-person site visits; reviewed recipient spend plans, audit reports, and other documents from 30 randomly selected projects; and interviewed officials from the 19 agencies regarding oversight activities.
For more information, contact Jeff Arkin at arkinj@gao.gov.
What GAO Found
The proliferation of cyberattacks on federal agencies and other organizations has led to an increased risk of stolen personally identifiable information (PII) being used to commit fraud. For example, malicious actors have used the information to fraudulently obtain government benefits and commit tax fraud, among other things. The Social Security Administration has reported that personal information of beneficiaries has been used to fraudulently redirect the beneficiary’s direct deposit benefits. Stolen PII also increases risks for financial fraud, such as fraudulent credit card applications. In this type of fraud, thieves use identifying data, such as Social Security numbers and driver’s license numbers, to open new financial accounts without a person’s knowledge. These types of attacks can result in financial loss and damage to the reputation of federal agencies and financial institutions.
To ensure that individuals accessing government services, benefits, and other resources are the individuals they claim to be, federal agencies use a variety of identity verification processes. To suppport these efforts, the General Services Adiministration (GSA) established Login.gov as a government-wide identity verification service. Login.gov uses a non-biometric, three-step process to verify an individual’s identity. In addition, to protect users’ PII, Login.gov uses security measures such as encryption, access restrictions, and monitoring capabilities.
GAO previously reported challenges in GSA’s implementation of Login.gov. These challenges involved:
ensuring that Login.gov data was backed up regularly to prevent data loss,
aligning Login.gov with federal digital identity guidelines to provide an appropriate level of assurance when verifying users’ identities,
resolving technical challenges reported by agencies using Login.gov, and
documenting and applying lessons learned from its Login.gov pilot programs.
To address these challenges, GAO made several recommendations in 2024 and 2025 to GSA. Since then, the agency has taken steps to implement all but one of these recommendations. For example, GSA took steps to ensure that Login.gov offers remote identity-proofing services that comply with federal digital identity guidelines. In addition, the agency provided evidence that it had begun testing processes for backing up Login.gov data. However, GSA still needs to take action to fully address one of GAO’s recommendations. Specifically, GSA has not established time frames with its partners for addressing agency-reported technical challenges. Without GSA-proposed actions and time frames for addressing the challenges, agencies will continue to experience technical issues with the system.
Protecting PII and preventing identity theft is critical, as the harms can range from lost funds to emotional distress and damage to the reputation of federal agencies. Fully implementing GAO’s remaining recommendation would help the federal government ensure PII is better protected and lessen the risk of identity theft. GAO will continue to monitor GSA’s efforts to address the recommendation.
Why GAO Did This Study
The vast amount of PII that federal agencies collect from individuals to verify their identity may be vulnerable to breaches, which can result in identity theft, fraud, and other harms. Accordingly, it is critical that federal agencies implement effective ways to verify the identity of individuals who access government websites to prevent fraud and protect PII.
To address this issue, GSA launched Login.gov in 2017 to provide federal agencies with a single sign-on system to verify the identity of individuals seeking access to government websites. In 2021, GSA allocated about $187 million in technology modernization funds to enhance Login.gov’s services, including strengthening its security and anti-fraud protections and improving ease of agency adoption.
This statement discusses (1) identity-related fraud threats and (2) Login.gov capabilities and the status of GSA efforts to address prior related GAO recommendations.
This statement is based primarily on GAO’s October 2024 (GAO-25-106640) and June 2025 (GAO-25-107000) reports on Login.gov’s identity proofing processes. This statement also includes updated information provided by GSA on efforts to address GAO’s recommendations.
For more information, contact Marisol Cruz Cain at CruzCainM@gao.gov.
What GAO Found
The Department of Justice’s Executive Office for Immigration Review (EOIR) conducts immigration court proceedings both in-person and using remote technology, such as WebEx—an internet-based video teleconferencing platform, or telephone. Per EOIR policy, immigration judges may use discretion to decide which, if any, remote medium is used by participants in a hearing. EOIR collects data on the medium used for each hearing, which reflects the location of only the judge and respondent. According to GAO’s analysis of this data, of the nearly 6 million hearings held from fiscal year 2022 through 2025, about 63 percent or 3.8 million hearings were in-person. Of the approximately 2.2 million remote hearings, most used WebEx (about 78 percent or 1.7 million). During this time, the number of remote hearings increased almost 50 percent, while the number of in-person hearings increased more dramatically. EOIR officials stated that as the COVID-19 pandemic subsided, immigration courts began scheduling more hearings overall, with more hearings taking place in-person.
Number and Percentage of Immigration Court Hearings Held Remotely and In-person, Fiscal Years 2022–2025
EOIR officials and selected immigration judges and attorneys described generally favorable experiences with remote immigration hearings. They identified benefits of using remote technology, such as reducing the time and cost associated with in-person hearings, increasing the efficiency of hearings, and allowing respondents increased access to private bar attorneys.
Some court stakeholders also provided perspectives on challenging aspects of remote hearings, such as variation in judge preferences for remote hearings, and technology limitations for language interpretation options. However, they told GAO these challenges did not outweigh the benefits of holding remote immigration hearings.
Why GAO Did This Study
Each year, EOIR immigration judges preside over immigration court proceedings for hundreds of thousands of respondents—foreign nationals charged on statutory grounds of removability. In 2017, GAO reported that EOIR would benefit from collecting more reliable data on the use of remote technology in immigration hearings, among other actions.
The Explanatory Statement accompanying the Consolidated Appropriations Act, 2024, includes a provision for GAO to update the portion of its 2017 report that addressed the use of remote technology in immigration courts. This report examines (1) what EOIR data show about remote and in-person immigration hearings from fiscal year 2022 through 2025 and (2) the benefits and challenges of using remote technology for immigration court hearings and any actions EOIR has taken to address challenges.
GAO reviewed EOIR policies and procedures regarding the use of remote technology in immigration hearings and analyzed EOIR data on immigration hearings from fiscal year 2022 through 2025. In addition, GAO interviewed officials from EOIR and the Office of the Principal Legal Advisor (OPLA) within the Department of Homeland Security‘s U.S. Immigration and Customs Enforcement.
GAO also interviewed immigration judges and OPLA attorneys from four immigration court locations selected to represent courts with variation in the size of geographic area of responsibility and hearing volume, and members of two nongovernmental organizations for immigration judges and attorneys who represent respondents. Further, GAO conducted in-person and remote observations of 22 immigration hearings from 11 immigration courts across the U.S.
For more information, contact Heather MacLeod at MacleodH@gao.gov.
What GAO Found
In July 2024, the National Nuclear Security Administration (NNSA) released an internal Integrated Science, Technology, and Engineering (ST&E) Plan documenting investments needed for ST&E capabilities over the next 20 years. NNSA’s plan identified and prioritized 46 ST&E facility investments across the nuclear security enterprise that support stewardship of the nuclear weapons stockpile and other NNSA missions. The investments were prioritized by mission importance and mission need time frame. They included sustainment and enhancement of existing facilities and construction of new facilities.
NNSA also collected initial estimates of related ST&E workforce and programmatic investment needs—such as needed equipment and materials—from the nuclear security enterprise sites for the 20-year period. However, NNSA did not fully assess these funding needs and has no plans to do so. NNSA officials said that the plan focused on facility investments due to a deadline to provide that information for the agency’s Enterprise Blueprint, which was publicly released. Completing a comprehensive analysis of the ST&E workforce and programmatic investment needs would allow NNSA to better understand the total funding needs for stockpile stewardship and proactively plan for those needs.
Annular Core Research Reactor, a National Nuclear Security Administration Facility Requiring Sustainment Investment
NNSA provided the most detailed cost information on seven high mission importance, near-term ST&E facility investment projects in the Department of Energy’s fiscal year 2026 budget justification. Cost information on other proposed facility investments was limited because the projects are in early planning phases or are sustainment investments.
NNSA officials said they have not updated their integrated assessment of future ST&E facility investment needs. NNSA’s ST&E facility priorities have already evolved and may further change over time to reflect changes in congressional priorities or new technologies in areas such as high energy density physics, artificial intelligence, or production. Regularly updating the agency’s integrated assessment of its ST&E facility needs would help guide future investment decisions to support stockpile stewardship and modernization.
Why GAO Did This Study
NNSA relies on unique science, technology, and engineering facilities and a skilled contractor workforce across the nuclear security enterprise to maintain and modernize the nuclear weapons stockpile without relying on nuclear explosive testing. According to NNSA, many ST&E facilities are decades old. A 2022 major review recommended that NNSA develop an enterprise-wide plan to revitalize its ST&E facilities and workforce.
Senate Report 118-58 accompanying a bill for the National Defense Authorization Act for fiscal year 2024 includes a provision for GAO to review NNSA’s plans for ST&E capabilities. This report examines (1) the extent to which NNSA’s Integrated ST&E Plan identified and prioritized the ST&E facilities, workforce, and programmatic investments needed to support stockpile stewardship; (2) the information available about estimated costs of these investments; and (3) the extent to which NNSA is regularly updating its integrated assessment of ST&E facility investment needs.
GAO reviewed agency and national security laboratory contractors’ documents related to the Integrated ST&E Plan and budget documents; made site visits to facilities at NNSA’s Los Alamos and Sandia National Laboratories in New Mexico; and interviewed NNSA officials and laboratory contractors.
What GAO Found
The Department of Transportation (DOT) and its component agencies are underutilizing their office space department-wide based on the Utilizing Space Efficiently and Improving Technologies (USE IT) Act benchmark of 60 percent utilization. Specifically, GAO found that 89 percent of DOT’s 189 office buildings, including the DOT and the Federal Aviation Administration (FAA) headquarters complexes, were underutilized in August and September 2025 based on the USE IT benchmark. This was largely consistent with DOT’s USE IT Act reporting in March 2026. DOT’s underutilized office space costs hundreds of millions of dollars annually to lease, operate, and maintain.
In August 2025, DOT announced its intention to consolidate Washington, D.C.-area FAA office space, including fully vacating the FAA headquarters complex by summer 2027. As of June 2026, DOT is reconfiguring its headquarters without a definitive housing plan for 950 of the FAA headquarters personnel or detailed savings estimates. Due to these uncertainties, the agency may complete the consolidation without fully vacating the FAA headquarters complex, potentially offsetting any savings from the consolidation.
Federal Aviation Administration and Department of Transportation Headquarters
DOT has not pursued department wide-consolidation to increase space utilization or implemented space-maximizing strategies to address underutilized office space. Specifically, as of March 2026, DOT did not have plans to consolidate other DOT offices beyond FAA headquarters despite widespread underutilization. There are department-wide opportunities to consolidate, as 89 percent of DOT office buildings did not meet the USE IT Act utilization threshold for a period in 2025, and its largest office buildings averaged 34 percent utilization. In addition, adopting space-maximizing strategies could help DOT efficiently use its office space and support further consolidations and savings. For example, implementing a desk reservation system could help DOT use space more efficiently and increase utilization because DOT officials said that many employees spend roughly half their time offsite conducting investigations or inspections. By developing and implementing a department-wide consolidation plan that includes space-maximizing strategies, DOT may be better able to meet the 60 percent utilization threshold throughout its portfolio of office space and reduce facility costs by hundreds of millions of dollars.
Why GAO Did This Study
Managing federal real property has been on GAO’s High Risk List since 2003. In 2023, GAO reported that the COVID-19 pandemic and increased telework had contributed to low utilization of agency headquarters buildings, including DOT’s. Since then, DOT has reinstated its in-office requirements and reduced its staff size.
GAO was asked to review DOT’s office space use across the United States. This report examines 1) DOT’s office space utilization department-wide and the costs of underutilized space, 2) DOT’s consolidation plans for the FAA headquarters complex, and 3) the extent to which DOT’s efforts address underutilized office space department-wide.
GAO collected office space size and attendance data from 189 DOT office locations for a selected period in August and September 2025. GAO then calculated the utilization of each building by dividing its in-office attendance for the sample period by the building’s capacity. GAO calculated capacity by dividing a location’s total usable square feet by the 150 square feet per-person benchmark established by the USE IT Act. GAO interviewed officials from DOT and the General Services Administration, visited DOT offices in Washington, D.C., Virginia, and California, and discussed space-maximizing strategies with four architecture and engineering firms selected based on their experiences with government and private sector clients.
Why This matters
Across the globe, over 24 million tons of plastic (as much weight as 12 million cars) enter the environment each year. Larger plastics gradually break down into smaller microplastics, which can move into the organs, blood, and cells of humans and other animals.
Key Takeaways
Major sources of microplastics include vehicle tires, synthetic fabrics, plastic bottles, and paint.
Exposure to microplastics is associated with health problems in humans and other organisms, but scientists have not determined the extent to which microplastics cause such problems.
Federal agencies have announced actions to measure and remove microplastics in the human body, consider potential regulation of microplastics in drinking water, and reduce microplastic exposure from synthetic fabrics.
The Science
What is it? Microplastics are plastic particles smaller than 5,000 micrometers (i.e., 5 millimeters). The smallest microplastics, called “nanoplastics,” are smaller than 1 micrometer (see fig. 1).
Figure 1. Relative Sizes of Microplastics
Some microplastics are intentionally produced. For example, exfoliating products and toothpastes containing plastic microbeads were common until the Microbead-Free Waters Act of 2015 prohibited their production in the U.S. However, most microplastics result from the gradual breakdown of larger plastics, and these particles may never fully decompose. Major sources include vehicle tires, synthetic fabrics, plastic bottles, and paint.
What is known? Microplastics are found in air, land, and water, and can carry toxic substances (e.g., phthalates, PFAS, heavy metals). When animals ingest them, it may lead to malnutrition and other cumulative effects higher on the food chain.
Larger microplastics can pass through the human body without interacting with tissues. In contrast, smaller microplastics—including nanoplastics—can cross the body’s natural barriers. Once inhaled, ingested, or absorbed through the skin, they can enter organs, blood, and cells (see fig. 2).
Figure 2. Microplastics in the Human Body
Some estimates place humans’ weekly microplastics intake in the microgram range. However, intake varies based on lifestyle. For example, some studies suggest reliance on bottled water may result in a higher intake.
Some studies have associated microplastics with a greater risk of certain health problems. For example, in a study of patients with plaque buildup in their arteries, patients whose plaques contained microplastics had a higher risk of heart attack, stroke, or death. However, the extent and level at which microplastics cause health problems are unclear. Through laboratory studies in mice, scientists have found that unusually high levels of exposure to microplastics can cause cognitive impairment, decreased testosterone levels, and other health problems.
What are the knowledge gaps? Most technologies to measure microplastics in the environment rely on significant sample preparation, preventing on-site testing. Also, highly effective removal technologies, like reverse osmosis, may be difficult to scale for use in public water supplies.
To help address knowledge gaps, in 2026, the Environmental Protection Agency (EPA) added microplastics to the Contaminant Candidate List—a list of contaminants that may require future regulation under the Safe Drinking Water Act. Also, the Department of Health and Human Services (HHS) announced STOMP: Systematic Targeting Of MicroPlastics—a program to measure and remove microplastics in the human body. Further, the Department of Agriculture (USDA) announced an initiative to strengthen domestic cotton production to reduce microplastic exposure from synthetic fabrics.
Opportunities
The following scientific advances and lifestyle changes could present opportunities to reduce exposure to microplastics:
Measurement technologies. Development of portable technologies could help scientists take real-time measurements of microplastics in the environment.
Removal technologies. Development of scalable technologies to remove the smallest microplastics from drinking water could help reduce community exposure.
Exposure reduction. Reducing use of plastic products, such as disposable water bottles, or substituting alternatives can reduce exposure, as can frequent indoor cleaning to remove plastic dust.
Challenges
Cost and convenience. Plastic products are often inexpensive and convenient. Some major sources of microplastics, such as vehicle tires, are essential.
Geographic spread. Since winds and ocean currents have spread microplastics to remote places, including Antarctica, it may be impossible to stop further spread.
Data interpretation. Certain findings have caused public concern, but, without standardized methodologies, it can be difficult to interpret study data on potential health effects.
Selected GAO Work
Textile Waste: Federal Entities Should Collaborate on Reduction and Recycling Efforts, GAO-25-107165.
Selected References
Marfella, Raffaele, Francesco Prattichizzo, Celestino Sardu, Gianluca Fulgenzi, Laura Graciotti, Tatiana Spadoni, Nunzia D’Onofrio, et al. "Microplastics and Nanoplastics in Atheromas and Cardiovascular Events." New England Journal of Medicine, vol. 390, no. 10 (2024): 900-910.
Zolotova, Natalia, Anna Kosyreva, Dzhuliia Dzhalilova, Nikolai Fokichev, and Olga Makarova. "Harmful Effects of the Microplastic Pollution on Animal Health: A Literature Review." PeerJ, vol. 10 (2022): e13503.
For more information, contact Karen L. Howard, PhD at HowardK@gao.gov.
Recent comments