AI in SBIR Proposals: What Actually Changed in 2026

Every SBIR cycle now comes with the same question from first-time applicants: can I use AI to help write the proposal? The short answer is yes. The useful answer is more specific, because the landscape shifted in 2026 and most of what is written about it online is either vague or wrong.

This is not legal advice, and nothing here replaces reading your solicitation’s instructions. It is the practical picture as of September 2026, from a company that works in this space daily.

The core fact: no DoD disclosure requirement for AI text

As of September 2026, DoD SBIR solicitations do not require you to disclose that AI helped draft your proposal text. There is no checkbox, no AI usage statement, and no penalty clause for nondisclosure in the SBIR instructions themselves.

What exists is direction, not requirement. The binding layer for federal AI use sits in OMB Memoranda M-25-21 and M-25-22, the 2025 successors to M-24-10 and M-24-18, which set the responsible-use baseline for agencies. The White House National AI Policy Framework of March 2026 is a set of legislative recommendations to Congress, not a binding directive to agencies. Agencies are harmonizing toward transparency norms, and individual solicitations can add their own language, so read yours.

The practical consequence: the absence of an explicit rule is not an invitation to be sloppy. Reviewers evaluate human expertise, and the rules that do exist are tightening.

The risk that actually matters: data security

The disclosure question is mostly noise. The real risk in using AI on an SBIR proposal is data security, and it is the one that can actually disqualify you.

DoD SBIR Phase I work can touch Controlled Unclassified Information (CUI), and the topics often carry ITAR/EAR disclosure requirements in the statement of work. The unbreakable rule: do not put CUI, covered defense information, or proprietary technical data into a public LLM. Whatever convenience the tool offers, you cannot un-send a prompt.

The safe pattern is a hard segregation:

  • Public LLMs (any vendor): general writing, structure, plain-English rewrites of publicly available topic text. Nothing proprietary, nothing sourced from your actual technical approach.
  • Your actual proposal content: drafted and reviewed by humans, or run through enterprise tools with data-residency controls and no training on your inputs.

When in doubt, treat the model as a writing aid on public material, not a co-author on your technical volume.

What reviewers actually penalize

The failure modes are not “you used AI.” They are:

  1. Hallucinated citations. Models invent sources. Fabricated references are a credibility kill and are trivially caught by a reviewer who checks one.
  2. Vague, generic technical content. SBIR evaluation criteria reward specificity: your approach, your data, your team’s documented prior work. AI-generated filler reads as filler to someone who evaluates these for a living.
  3. Regurgitated solicitation language. Reviewers read the topic text all day. Echoing it back adds nothing.

None of these are disqualifying because you used AI. They are disqualifying because they signal shallow work. The fix is the same in every case: human verification of every claim, and your own technical substance on top of whatever the model drafts.

What we do

For our own work, the discipline is: AI for structure and plain-English drafting on public material, humans for the technical volume, and a verification pass on every factual claim before anything is submitted. The writing is faster; the accountability is not delegated.

The takeaway

Use AI to draft. Verify everything. Keep proprietary data out of public models. Read your solicitation, because it supersedes everything above. And if a tool vendor’s marketing page is telling you disclosure is mandatory and scary, check the actual solicitation. The truth is more boring, and more useful, than that.