Outcomes Are The New Compliance
Two agencies moved in the same direction this week without saying so out loud. CMS's top technology official told FedScoop the agency is shifting focus from how much artificial intelligence its staff use to what that use actually produces, and the FCC is drawing up a scorecard that will grade individual phone companies on how many robocalls they block rather than how many rules they say they follow. Put those next to a House committee voting to subpoena Oracle over the VA's $27 billion electronic health record contract, and a spending deal that blocks political control of grants, and a pattern appears. Compliance paperwork stopped being trusted as a proxy for results, and agencies are quietly building oversight around the number that actually matters instead of the form that says it was filed.
Listen to this piece 7 min
Two stories broke this week that would normally sit in separate sections of a policy newsletter. One was about the Centers for Medicare and Medicaid Services and how it measures its own use of artificial intelligence. The other was about the Federal Communications Commission and how it plans to grade phone companies on robocalls. Neither mentions the other. Read together, they describe the same decision made twice: stop counting activity and start counting outcomes.
CMS stops counting AI usage
FedScoop reported that a top CMS technology official said the agency is shifting its focus from AI usage to outcomes. That sounds like a small internal adjustment. It is not. For years, the default way a federal agency proved it was serious about a new technology was to publish a number: how many staff had access, how many tools were deployed, how many pilots were running. Those numbers are easy to produce and easy to defend in a hearing. They are also almost entirely disconnected from whether anything got better for the person on the other end of the process.
CMS deciding to grade outcomes instead of usage is an admission that the usage number was never the point. It was a stand-in for the point, chosen because it was measurable and the real thing was not. Once an agency says out loud that it is moving past that stand-in, it has to build a new scorecard, and that scorecard has to survive contact with Congress, auditors, and litigation. That is a harder thing to build than an adoption dashboard, which is exactly why nobody built it sooner.
The FCC's robocall scorecard makes the same bet
Ars Technica reported that the FCC plans a robocall scorecard to grade phone companies on spam call blocking. Carriers have spent years pointing to their compliance filings under the existing anti-robocall framework as proof they were doing their job. A scorecard changes the question from "did you file the right paperwork" to "how many of the calls that reached your customers were spam." Those two questions can produce completely different answers for the same carrier.
That is precisely the friction now playing out around the FCC's data breach rules, which telecom industry groups are asking the Sixth Circuit to overturn, according to Broadband Breakfast. An industry built around demonstrating procedural compliance is being asked to defend itself against a standard built around results, and it is pushing back in court rather than accepting the new premise. The robocall scorecard will meet the same resistance the moment a carrier with clean paperwork gets a bad grade.
The Federal Register's finalised rule bundle points the same way. Alongside "Delete, Delete, Delete," the FCC modernised the Form 477 data programme and established the Digital Opportunity Data Collection. Form 477 was a legacy reporting exercise; the new collection is built to describe where broadband actually reaches people, not just what carriers reported. Deleting the old form while building the new collection is the paperwork-to-outcomes trade in regulatory form.
What happens when nobody checks the outcome
The VA's electronic health record programme is the cautionary example sitting right next to all of this. FedScoop reported that a House committee voted to subpoena Oracle after a hearing on the VA's $27 billion EHRM contract turned hostile. A contract that size does not fail for lack of documented milestones. Programmes like this generate enormous paperwork trails, status reports, and compliance sign-offs, precisely the kind of activity metrics that used to satisfy oversight. A subpoena is what happens when lawmakers stop trusting that trail and go looking for the outcome underneath it.
The same tension shows up in smaller, more mundane form in the fight over the Universal Service Fund. Broadband Breakfast reports that prominent Republicans continue to question USF's future without reforms. USF has spent years defended by pointing to the money distributed and the programmes funded. The reform argument is really an outcomes argument dressed as a funding argument: distributing money is not the same as closing the access gap the money was meant to close, and the people asking for reform are, in effect, asking for a scorecard.
Grants, tokens, and who gets to grade
Not every move this week points the same direction cleanly, and that is worth taking seriously. Ars Technica reported that a spending deal comes with a bonus: blocking political control of grants. That is an outcomes-adjacent reform in spirit, insulating award decisions from political interference so that grants are judged on their merits rather than their politics, but it is also a reminder that "outcomes" is not a neutral word. Someone still decides which outcome counts, and who is allowed to measure it.
Broadband Breakfast's piece on a looming "tokenocracy" makes the sharper version of that warning: regulators trying to govern AI risk losing the ability to grade outcomes at all if the underlying systems become too opaque to audit. A scorecard is only as good as the institution's ability to actually see what it is scoring. CMS and the FCC are both betting they can build that visibility. NYC's decision to ban student use of generative AI in classrooms through middle school, reported by StateScoop, is the opposite bet: rather than try to grade outcomes from a technology it cannot yet audit well enough, the school system chose not to allow the activity at all. That is not a contradiction of the outcomes turn; it is what happens when an institution decides it cannot yet measure the outcome it would need to.
The paperwork era is not dead, but it is on notice
None of this means compliance filings disappear. The FTC's extended comment period on personalised pricing, and its warning to consumers not to scan unfamiliar QR codes, are both still paperwork-and-process tools, disclosure and caution rather than measured results. Colorado's new mobile driver's licence for TSA checkpoints is a service delivered, not yet a graded outcome. International airlines seeking rebates for gear upgrades tied to FCC auction rules are arguing, in effect, that they were made to spend money on activity the auction rules demanded without anyone checking whether it produced the intended result.
That last example is the tell. Complaints about compliance costs only land as complaints about fairness once the underlying premise, that following the rule was the whole job, stops being accepted. CMS and the FCC did not coordinate this week. They arrived separately at the same conclusion: a paperwork trail proving you did the thing is no longer proof that the thing worked. Building the scorecard that replaces it is the harder, slower job neither agency has finished, and the fights already underway over data breach rules and USF reform suggest nobody involved expects that job to finish quietly.
Wyre's opinion bylines are editorial personas of Floof Digital LLC, not separate members of staff. Essays are produced with AI assistance under human editorial direction. How Wyre works.