Senate staff have had exactly three AI chat tools cleared for official work since March: OpenAI's ChatGPT Enterprise, Google's Gemini, and Microsoft's Copilot Chat. What they still can't touch, an NPR investigation reported this week, is anything more capable -- not Codex, OpenAI's coding agent, not Anthropic's Claude Code, not any tool built to act on a user's behalf rather than answer one message at a time. The chamber now writing the country's AI law is, by its own IT policy, working from less hands-on experience with agentic tools than a mid-sized law firm.
The approval came from the Senate Sergeant at Arms, the chamber's IT and security office, under a two-tier data-sensitivity system it set up in October 2025. Tier 1 covers non-sensitive work; Tier 2 covers official Senate data, and the three chatbots are the first tools ever cleared for it. Each staffer gets one free license to either Gemini Chat or ChatGPT Enterprise, plus Copilot bundled into Microsoft 365 at no added cost -- but, per the memo's own language, Copilot "does not search internal drives, shared folders, email, Teams chats, or any other Senate resources on its own." That restriction is the tell: the tools that made the cut are the ones that answer a question, not the ones that can go find the answer themselves.
That's the boundary NPR found still holds six months later: an agentic tool -- one that can be handed a goal and complete multi-step work with real access to files, a drive, an inbox -- carries exactly the exfiltration risk the Sergeant at Arms's own tiering system was built to keep out of Tier 2. Daniel Schuman of the American Governance Institute doesn't dispute that the risk is real. His objection is narrower: that unexplained institutional caution, not a documented security finding, is what's actually setting the pace. Adam Kovacevich of the Chamber of Progress goes further, calling the security framing "pretextual" -- Fortune 500 companies, he told NPR, run these same tools in production today. Both critiques can be true at once: exfiltration risk from a drive-connected agent is a real engineering problem, and an office with no public deadline, no published criteria, and no answer to reporters' questions about either is also a textbook case of an institution simply declining to move.
How the Senate's AI-tool policy got here
- Oct 2025 — Sergeant at Arms establishes a two-tier data-sensitivity system for Senate technology.
- Mar 2026 — First Tier 2 approvals issued: ChatGPT Enterprise, Gemini Chat and Copilot Chat, one free license per staffer.
- Sep 23, 2026 — NPR reports the approved list hasn't grown -- agentic tools remain unauthorized, no public timeline given.
Sen. Bernie Moreno (R-Ohio) gave NPR the clearest picture of what the gap looks like in practice: he described using an AI research tool he calls "Albert" for his own work, while complaining that "the Senate has some crazy rules" that limit what his office can actually deploy officially. That's a sitting senator describing real agentic-AI use happening around, rather than through, his chamber's own approved list -- which is close to the exact dynamic Kovacevich is warning about: legislators who reach for the more capable tools personally while writing rules for a body that hasn't formally cleared them.
“Lawmakers are writing the rules for a technology most of them have never actually used.” — Adam Kovacevich, Chamber of Progress, on Senate AI-tool policy
The House runs a materially different policy under a separate oversight body, the Chief Administrative Officer, which already authorizes tools from Microsoft, OpenAI, Google *and* Anthropic across specific approved use cases -- a wider vendor net and, per a House staffer's account to NPR, a clearer published structure of what's allowed where. Neither chamber, however, publishes a single list a reader can check against a specific tool and use case; that gap is what Aubrey Wilson of the PopVox Foundation, a nonpartisan group focused on congressional operations, was pointing at when she told NPR: "There's no public list of the tools that are approved or what it takes to be approved in these chambers."
Two chambers, two AI-tool policies
| Senate Sergeant at Arms | House Chief Administrative Officer | |
|---|---|---|
| Basic chat tools | ChatGPT, Gemini, Copilot Chat | Microsoft, OpenAI, Google and Anthropic tools |
| Agentic / autonomous tools | None approved | Approved for specific use cases, per a House staffer |
| Public list of approved tools | Not published | Not published |
None of this is happening in a policy vacuum. Congress has spent the back half of 2026 visibly struggling to move on AI: ten committee-passed bills sat without a floor vote as of mid-September, and the White House has answered growing pressure for federal rules with a promised "AI czar" role that's remained vacant since March rather than actual legislation. A body that can't agree on rules for the industry is also, per this week's reporting, a body whose own staff can't get their hands on the industry's more advanced products -- and (it's a genuinely open question which direction the causation runs: does institutional caution about the tools produce caution about the rules, or is a slow-moving legislative process just applying its usual pace to its own IT procurement too?) the honest answer is nobody quoted in this story claims to know which is cause and which is effect.
- Work with a narrower, less capable tool set than many private-sector counterparts while their own chamber legislates the technology they can't use.
- Hold a guaranteed baseline of Senate adoption for their entry-level chat products, with no agentic competitor yet cleared to challenge it.
- Claude Code is the House's fourth approved vendor but has no Senate foothold at all -- the widest gap of any major lab between the two chambers' policies.
What happens next is, per the Sergeant at Arms's own silence to NPR's questions, genuinely unscheduled. No agency in this story has committed to a date, a criterion, or even a public process for deciding when -- or whether -- an agentic tool clears Tier 2. Until one does, the practical state of affairs is this: the branch of government currently deciding what American businesses may build with autonomous AI is doing so with a staff largely restricted, on the record, to asking a chatbot questions.
- Senate staff have had ChatGPT, Gemini and Copilot for official work since a March memo.
- Agentic tools like OpenAI's Codex and Anthropic's Claude Code remain unapproved, with no timeline.
- Critics call the security rationale pretextual; the Sergeant at Arms cites data-exfiltration risk instead.
- The House's separate oversight body already approves broader multi-vendor AI use by comparison.
- Caveat: the Sergeant at Arms declined to answer questions about its approval process or timeline.