Independent newsroom The Wyre News Network OpEd desk

Analysis 5 min read

Outcomes Are The New Compliance

Two agencies moved in the same direction this week without saying so out loud. CMS's top technology official told FedScoop the agency is shifting focus from how much artificial intelligence its staff use to what that use actually produces, and the FCC is drawing up a scorecard that will grade individual phone companies on how many robocalls they block rather than how many rules they say they follow. Put those next to a House committee voting to subpoena Oracle over the VA's $27 billion electronic health record contract, and a spending deal that blocks political control of grants, and a pattern appears. Compliance paperwork stopped being trusted as a proxy for results, and agencies are quietly building oversight around the number that actually matters instead of the form that says it was filed.

Listen to this piece 7 min

Two stories broke this week that would normally sit in separate sections of a policy newsletter. One was about the Centers for Medicare and Medicaid Services and how it measures its own use of artificial intelligence. The other was about the Federal Communications Commission and how it plans to grade phone companies on robocalls. Neither mentions the other. Read together, they describe the same decision made twice: stop counting activity and start counting outcomes.

CMS stops counting AI usage

FedScoop reported that a top CMS technology official said the agency is shifting its focus from AI usage to outcomes. That sounds like a small internal adjustment. It is not. For years, the default way a federal agency proved it was serious about a new technology was to publish a number: how many staff had access, how many tools were deployed, how many pilots were running. Those numbers are easy to produce and easy to defend in a hearing. They are also almost entirely disconnected from whether anything got better for the person on the other end of the process.

CMS deciding to grade outcomes instead of usage is an admission that the usage number was never the point. It was a stand-in for the point, chosen because it was measurable and the real thing was not. Once an agency says out loud that it is moving past that stand-in, it has to build a new scorecard, and that scorecard has to survive contact with Congress, auditors, and litigation. That is a harder thing to build than an adoption dashboard, which is exactly why nobody built it sooner.

The FCC's robocall scorecard makes the same bet

Ars Technica reported that the FCC plans a robocall scorecard to grade phone companies on spam call blocking. Carriers have spent years pointing to their compliance filings under the existing anti-robocall framework as proof they were doing their job. A scorecard changes the question from "did you file the right paperwork" to "how many of the calls that reached your customers were spam." Those two questions can produce completely different answers for the same carrier.

That is precisely the friction now playing out around the FCC's data breach rules, which telecom industry groups are asking the Sixth Circuit to overturn, according to Broadband Breakfast. An industry built around demonstrating procedural compliance is being asked to defend itself against a standard built around results, and it is pushing back in court rather than accepting the new premise. The robocall scorecard will meet the same resistance the moment a carrier with clean paperwork gets a bad grade.

The Federal Register's finalised rule bundle points the same way. Alongside "Delete, Delete, Delete," the FCC modernised the Form 477 data programme and established the Digital Opportunity Data Collection. Form 477 was a legacy reporting exercise; the new collection is built to describe where broadband actually reaches people, not just what carriers reported. Deleting the old form while building the new collection is the paperwork-to-outcomes trade in regulatory form.

What happens when nobody checks the outcome

The VA's electronic health record programme is the cautionary example sitting right next to all of this. FedScoop reported that a House committee voted to subpoena Oracle after a hearing on the VA's $27 billion EHRM contract turned hostile. A contract that size does not fail for lack of documented milestones. Programmes like this generate enormous paperwork trails, status reports, and compliance sign-offs, precisely the kind of activity metrics that used to satisfy oversight. A subpoena is what happens when lawmakers stop trusting that trail and go looking for the outcome underneath it.

The same tension shows up in smaller, more mundane form in the fight over the Universal Service Fund. Broadband Breakfast reports that prominent Republicans continue to question USF's future without reforms. USF has spent years defended by pointing to the money distributed and the programmes funded. The reform argument is really an outcomes argument dressed as a funding argument: distributing money is not the same as closing the access gap the money was meant to close, and the people asking for reform are, in effect, asking for a scorecard.

Grants, tokens, and who gets to grade

Not every move this week points the same direction cleanly, and that is worth taking seriously. Ars Technica reported that a spending deal comes with a bonus: blocking political control of grants. That is an outcomes-adjacent reform in spirit, insulating award decisions from political interference so that grants are judged on their merits rather than their politics, but it is also a reminder that "outcomes" is not a neutral word. Someone still decides which outcome counts, and who is allowed to measure it.

Broadband Breakfast's piece on a looming "tokenocracy" makes the sharper version of that warning: regulators trying to govern AI risk losing the ability to grade outcomes at all if the underlying systems become too opaque to audit. A scorecard is only as good as the institution's ability to actually see what it is scoring. CMS and the FCC are both betting they can build that visibility. NYC's decision to ban student use of generative AI in classrooms through middle school, reported by StateScoop, is the opposite bet: rather than try to grade outcomes from a technology it cannot yet audit well enough, the school system chose not to allow the activity at all. That is not a contradiction of the outcomes turn; it is what happens when an institution decides it cannot yet measure the outcome it would need to.

The paperwork era is not dead, but it is on notice

None of this means compliance filings disappear. The FTC's extended comment period on personalised pricing, and its warning to consumers not to scan unfamiliar QR codes, are both still paperwork-and-process tools, disclosure and caution rather than measured results. Colorado's new mobile driver's licence for TSA checkpoints is a service delivered, not yet a graded outcome. International airlines seeking rebates for gear upgrades tied to FCC auction rules are arguing, in effect, that they were made to spend money on activity the auction rules demanded without anyone checking whether it produced the intended result.

That last example is the tell. Complaints about compliance costs only land as complaints about fairness once the underlying premise, that following the rule was the whole job, stops being accepted. CMS and the FCC did not coordinate this week. They arrived separately at the same conclusion: a paperwork trail proving you did the thing is no longer proof that the thing worked. Building the scorecard that replaces it is the harder, slower job neither agency has finished, and the fights already underway over data breach rules and USF reform suggest nobody involved expects that job to finish quietly.

Wyre's opinion bylines are editorial personas of Floof Digital LLC, not separate members of staff. Essays are produced with AI assistance under human editorial direction. How Wyre works.

More Opinion

From the same desk

Analysis

The Add-Back Economy

<p>Consumer brands have quietly built a second set of books that no auditor is asked to sign off on. When a company reports a loss under generally accepted accounting principles but tells investors a story of "adjusted" profit instead, it has not lied, but it has chosen which version of reality gets read aloud on the earnings call. This piece argues that the growing habit of leading with adjusted figures, and burying the GAAP number in a footnote, is not a technical accounting quirk but a narrative choice made by finance chiefs who understand that most readers will only remember the number that was said first. The audit still covers the statutory result. It was never asked to bless the story built on top of it.</p>

5 min

Analysis

The Patch Window Just Got Shorter

This week's reporting makes one argument in several registers: attackers no longer need to be clever, they only need somebody else to be slow. SecurityWeek's own experiment shows a PLC exploit ported with AI assistance in hours and for a few hundred dollars, work that used to require specialist engineering time. Meanwhile nearly 22,000 Microsoft Exchange servers remain vulnerable to hijack attacks with known fixes, and hackers are already exploiting a critical Langflow vulnerability and a critical JFrog Artifactory flaw in the wild. The gap between disclosure and patch, not the sophistication of the attacker, is where the damage is actually happening, and a financial watchdog has now named cyber risk from frontier AI the most immediate concern to the global financial system.

6 min

Analysis

Rivals Now Share the Same Operating System

Honda and Nissan have agreed to build their next generation of vehicles on a shared software architecture, and the news matters more than the companies' careful language about it suggests. Sold as a partnership, it reads as an admission: neither firm can afford to write the code for a modern car by itself anymore. The same week brought AI upgrades rolling out across dealership platforms, a leadership shake-up reportedly brewing at Volkswagen's American operation, and a factory deal that kept a Sierra line running in Ontario. Taken together, these are not separate stories about separate companies. They are one story about where the car industry's real competition has moved, and it is no longer under the bonnet.

5 min