OMB memos: how the federal government governs its own AI

Lesson 3 of 5 in The Federal Posture: Executive Orders, OMB, and the Preemption Fight.

Executive orders announce policy; OMB memoranda make it operational. The Office of Management and Budget sits at the center of the executive branch, and its memos tell every federal agency what it must actually do — with deadlines, roles, and reporting requirements. For AI, two memos issued 3 April 2025 are the operating system:

  • M-25-21agency use of AI: governance roles, risk practices, inventories.
  • M-25-22procurement of AI: how agencies buy it and what they must demand from vendors.

They replaced the Biden-era pair (M-24-10 and M-24-18), and the comparison is the cleanest before/after study in this module — because unlike the EO whiplash, OMB kept most of the machinery and changed the philosophy.

Biden-era vs current OMB AI memos
FeatureM-24-10 / M-24-18 (2024)M-25-21 / M-25-22 (Apr 2025)

Framing

Risk management first: guardrails for ‘responsible’ agency AI

Innovation first: ‘forward-leaning, pro-innovation’ adoption; remove bureaucratic barriers

Risk categories

Two: safety-impacting and rights-impacting AI, each with its own practice list

One consolidated category: high-impact AI — where output serves as a principal basis for decisions with significant effect on rights, safety, or access to critical services

Chief AI Officers

Created — compliance and risk emphasis

Retained — recast as change agents for adoption; agency AI strategies required

Minimum practices

Pre-deployment impact assessment, testing, ongoing monitoring, human oversight, notice

Substantially similar list for high-impact AI — assessment, testing, monitoring, human oversight, remedies — with more streamlined waivers

Inventories & waivers

Annual AI use-case inventories; waivers possible

Both retained — inventories continue; CAIOs may waive specific practices with documented justification

Procurement memo

M-24-18: risk-focused acquisition requirements

M-25-22: performance-based acquisition, competition emphasis (including preference for American AI), vendor data-use limits, avoidance of lock-in

Notice what did not change: Chief AI Officers, use-case inventories, minimum practices for the riskiest uses, and waiver mechanics all survived the transition. Agencies still cannot deploy high-impact AI without impact assessment, testing, human oversight, and monitoring — a requirements list any EU AI Act student will recognize. The continuity matters for practitioners: if you sell AI to the US government, the compliance artifacts you built for M-24-10 were not wasted; they were re-labeled.

Around the memos sits the rest of the machinery: CAISI (the renamed AI Safety Institute) doing model-security evaluation and standards work at Commerce; GSA’s USAi platform giving agencies a sandboxed path to approved generative AI tools; and NIST running the RMF revision and the Critical Infrastructure Profile work. None of these bodies regulates the private sector — hold that line firmly. The regulators come in the next module.

M-25-21: can this agency use case go live?

  1. Agency wants to deploy an AI use case
  2. Is it covered AI under M-25-21?

    National-security systems and certain R&D uses follow separate tracks.

  3. Is it high-impact AI?

    Output serves as a principal basis for decisions with legal, material, or significant effect on rights, safety, or access to critical government services — e.g. benefits eligibility, law-enforcement targeting, medical triage.

  4. Apply minimum risk practices

    Pre-deployment impact assessment and testing, ongoing monitoring, human oversight and accountability, remedies for affected individuals.

  5. Waiver needed?

    The CAIO may waive specific practices where they would increase risk or block critical operations — documented and reported.

  6. Record in the AI use-case inventory

    Agencies publicly inventory use cases annually — the transparency backbone of the regime.

  7. Deploy with monitoring

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.