United States - AI National Security Strategy (NSM-25)

National Security Memorandum on Artificial Intelligence (NSM on AI, Oct 24, 2024)

United States

RAI-US-NA-NSMAIXX-2024
Effective: October 24, 2024
In Force(In Force)
DecreeGovernance and OversightRisk ManagementCybersecurity and Model Security
Export PDF

On October 24, 2024 the U.S. President issued the first National Security Memorandum (NSM-25) on Artificial Intelligence, directing a whole-of-government approach to preserve U.S. leadership in AI, to harness AI for national security with safeguards, and to advance international governance. The NSM establishes an AI Framework for National Security that sets prohibited and high‑impact categories, requires agency governance structures, inventories, risk management practices, cybersecurity guidance, and a series of interagency reporting and implementation deadlines.

Overview

The National Security Memorandum on Artificial Intelligence (NSM-25), signed on October 24, 2024, establishes a coordinated, whole-of-government approach to: (1) preserve and expand United States leadership in the development of safe, secure, and trustworthy AI; (2) harness AI to advance national security objectives subject to democratic values; and (3) advance international AI governance that protects human rights and norms. The NSM complements Executive Order 14110 (Oct 30, 2023) and OMB memorandum M-24-10 (Mar 28, 2024) by creating a national-security-specific implementation instrument: the "Framework to Advance AI Governance and Risk Management in National Security" (the AI Framework). The NSM directs agency-level governance (Chief AI Officers, AI Governance Boards), defines regulated AI use categories (prohibited, high-impact, personnel-impacting), requires inventories and test-and-evaluation programs (including classified evaluations where necessary), and imposes time-bound requirements for cybersecurity guidance, international engagement, and interagency reporting. The primary published texts are available from the White House and related repositories: White House NSM page and the AI Framework PDF: Framework to Advance AI Governance and Risk Management in National Security.

Definitions

The NSM provides working definitions to guide implementation. Notable definitions include "National Security Systems (NSS)" (systems as defined under U.S. law used for national defense and intelligence), "Critical Technical Artifacts (CTAs)" (information such as model weights, training data and code that materially lower the cost of replicating capabilities), "frontier AI model" (general-purpose models near cutting-edge performance), "open-weight model" (models with publicly available weights), "covered agencies" (Intelligence Community and agencies using AI as component of NSS), and "AI security" (practices to protect models, data, and lifecycles from attack or theft). These definitions orient how agencies classify uses and deploy security and governance controls.

Governance and Institutional Framework

The NSM mandates institutional roles and governance structures within agencies. Each covered agency must name a Chief AI Officer and establish an AI Governance Board that includes privacy, civil liberties, and safety officials. The NSM establishes an AI National Security Coordination Group co-chaired by the Chief AI Officers of ODNI and DOD to harmonize NSS policies and develop cross‑agency guidance. Oversight includes annual inventories of high‑impact systems, integration of whistleblower protections, and the ability for senior leadership to receive findings from civil liberties officials. The AI Framework—approved through NSC Deputies Committee processes—operationalizes these structures and sets criteria for minimum risk management practices, waiver processes, and alignment with OMB's M-24-10. See the published framework for specifics: AI Framework (PDF).

Key Focus Areas

The memorandum focuses on a set of strategic priorities: (1) Promoting foundational AI capabilities—ensuring domestic compute and chip supply chain resilience and protecting intellectual property from foreign intelligence threats. (2) Risk categorization—delineating prohibited AI uses, high‑impact uses requiring minimum risk management practices (including testing, bias mitigation, transparency, and human oversight), and personnel‑impacting uses with extra safeguards. (3) Model security—treating CTAs with strict protection and managing frontier/open-weight model risks. (4) Biosafety and chemical risk—directing classified evaluations and DOE pilot projects to assess whether advanced models can generate or exacerbate biological/chemical threats. (5) Cybersecurity—ordering the National Manager for NSS to issue minimum cybersecurity guidance for AI within 150 days. (6) International engagement—directing State and USAID to produce strategies for advancing global governance norms aligned with democratic values. These focus areas are intended to balance operational needs with rights protections and global leadership obligations.

Implementation Framework

Implementation is organized through time‑bound tasks assigned to specific Departments. Key elements include formation of the AI National Security Coordination Group within 45 days; a 120‑day Department of State-led international governance strategy; 150 days for the National Manager for NSS to issue cybersecurity guidance; 180 days for covered agencies to issue or update NSS guidance that aligns with the AI Framework; and 210–270 day deliverables for classified roadmaps, DOE pilot projects, and agency reports. Agencies must maintain inventories of high‑impact AI and report annually for at least five years. The NSM also prescribes a waiver mechanism allowing agencies to seek exceptions when mission-critical needs would otherwise be impeded by risk mitigations, subject to balancing tests. Many implementation tasks reference existing authorities and internal agency processes rather than relying on new statutory powers. For the full implementation schedule and assigned responsibilities see the NSM text: NSM text (American Presidency Project).

Monitoring and Evaluation

The NSM prescribes an interagency reporting regime designed to monitor progress. Heads of State, DOD, Commerce, DOE, ODNI (for the IC), USUN, and USAID must submit detailed reports to the President through the Assistant to the President for National Security Affairs (APNSA) within 270 days and annually thereafter for at least five years. ODNI consolidates intelligence community appendices (CIA, NSA, DIA, NGA) into ODNI's report. The AI National Security Coordination Group and AI Governance Boards are responsible for ongoing monitoring, and covered agencies must maintain inventories and conduct test-and-evaluation, including classified assessments where appropriate. Metrics will include adoption of minimum risk management practices, inventory completeness, cybersecurity compliance, and outcomes from pilot and classified evaluations.

Penalties, Liability, and Appeals

The NSM itself is an Executive Branch policy instrument and does not create criminal penalties. Enforcement relies on administrative and programmatic levers within agencies: revocation or restriction of procurement authority, internal disciplinary actions, denial of waivers, funding conditions, contracting ineligibility, and OMB/NSC oversight. Agencies are instructed to integrate whistleblower protections and existing legal compliance mechanisms; appeals and redress are expected to follow established agency and federal employment processes. Liability for private actors remains governed by statute and contract law; the NSM strengthens pre-award and post-award risk controls in federal procurement and may lead to contractual restrictions or debarment where contractors violate terms or security protocols.

Relationship to Other Instruments

The NSM builds on and references multiple prior instruments. It implements subsection requirements from Executive Order 14110 (Oct 30, 2023) and is intended to align with OMB Memorandum M-24-10 (Mar 28, 2024). It also interacts with National Security Memorandum 2 (Feb 4, 2021) governing NSC Deputies Committee processes and National Security Memorandum 22 (Apr 30, 2024) on Critical Infrastructure Security and Resilience. The NSM instructs agencies to incorporate the AI Framework into existing procurement, classification, cybersecurity (including CISA responsibilities), and intelligence community policies; it is accompanied by a classified annex covering sensitive operational matters. For official copies of the NSM and associated materials see the White House and government document repositories: White House NSM and AI Framework (PDF).

International Alignment

The NSM emphasizes international leadership and coordination. Within 120 days, the Department of State—coordinating with DOD, Commerce, DHS, USUN, and USAID—must produce a strategy for advancing international AI governance aligned with democratic values, human rights, and international law. The memorandum references prior U.S. diplomatic achievements (multilateral AI safety summits, G7 code of conduct, UN resolution) and directs efforts to work with allies and partners to develop shared norms, standards, and interoperability approaches. The NSM also highlights export controls, foreign‑talent strategies, and diplomatic engagement to manage competitor behaviors and to promote U.S. technical and normative influence.

Implementation Timeline

EventDeadline (from Oct 24, 2024)Due Date
Form AI National Security Coordination Group45 days2024-12-08
State-led international governance strategy120 days2025-02-21
National Manager for NSS issues minimum cybersecurity guidance150 days2025-03-23
Covered agencies issue/update NSS guidance aligned to AI Framework180 days2025-04-21
DOE pilot project to support classified tests240 days2025-06-21
Initial consolidated agency reports to APNSA270 days2025-07-21

Compliance Checklist

RequirementAgency ActionCompleted?
Appoint Chief AI OfficerDesignate official with primary AI responsibilityAgency to report
Create AI Governance BoardEstablish board including civil liberties/privacy repsAgency to report
Maintain annual inventory of high-impact AI usesCatalog and submit updatesAgency to report
Implement minimum risk management practicesAdopt testing, bias mitigation, oversightAgency to report
Adopt NSS cybersecurity guidanceIntegrate National Manager guidance within 150 daysAgency to report

Sources and References

SourceType
National Security Memorandum on Advancing the United States' Leadership in Artificial Intelligence (NSM-25)Primary Source
White House Fact Sheet and NSM archivePrimary Source
Framework to Advance AI Governance and Risk Management in National Security (AI Framework) (PDF)Primary Source
Plain English

The National Security Memorandum on Artificial Intelligence (NSM-25) directs U.S. government agencies involved in national security to adopt a comprehensive framework for managing Artificial Intelligence risks and opportunities, while preserving U.S. leadership in AI. Effective October 24, 2024, this decree applies to "covered agencies," meaning the Intelligence Community and any agency using AI as a component of National Security Systems.

These agencies must establish robust AI governance, including appointing a Chief AI Officer and forming an AI Governance Board with privacy and civil liberties officials. A core obligation is to categorize AI uses (e.g., prohibited, high-impact, personnel-impacting) and implement minimum risk management practices for high-impact applications, including thorough testing, bias mitigation, transparency, and human oversight. Agencies must also maintain annual inventories of these systems and report progress to the Assistant to the President for National Security Affairs. Additionally, the National Manager for National Security Systems must issue minimum cybersecurity guidance for AI within 150 days, which agencies must then adopt. Protecting "Critical Technical Artifacts"—such as model weights and training data—is also a key focus.

While the NSM-25 itself doesn't carry criminal penalties, non-compliance for agencies can lead to administrative actions like restricted procurement authority or internal disciplinary measures. For private companies contracting with the government, this means stricter pre-award and post-award risk controls, potentially leading to contractual restrictions or debarment if terms or security protocols are violated. A practical pitfall for agencies and their partners is navigating the new waiver mechanism, which allows exceptions for mission-critical needs but requires careful balancing tests and senior approval, adding a layer of complexity to AI deployment.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 12 marked complete

Plain-English obligations under United States - AI National Security Strategy (NSM-25). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalGovernance and Institutional Framework

    Applies to: Each covered agency

    Each covered agency must name a Chief AI Officer
  2. #2CriticalGovernance and Institutional Framework

    Applies to: Each covered agency

    establish an AI Governance Board that includes privacy, civil liberties, and safety officials.
  3. #3CriticalGovernance and Institutional FrameworkDec 8, 2024

    Applies to: Chief AI Officers of ODNI and DOD (co-chairs)

    formation of the AI National Security Coordination Group within 45 days
  4. #4CriticalKey Focus AreasApr 21, 2025

    Applies to: Covered agencies using high-impact AI

    high‑impact uses requiring minimum risk management practices (including testing, bias mitigation, transparency, and human oversight)
  5. #5CriticalKey Focus Areas

    Applies to: Covered agencies developing or using AI

    Model security—treating CTAs with strict protection and managing frontier/open-weight model risks.
  6. #6CriticalKey Focus AreasMar 23, 2025

    Applies to: National Manager for NSS

    ordering the National Manager for NSS to issue minimum cybersecurity guidance for AI within 150 days.
  7. #7CriticalImplementation FrameworkApr 21, 2025

    Applies to: Covered agencies

    180 days for covered agencies to issue or update NSS guidance that aligns with the AI Framework
  8. #8CriticalMonitoring and EvaluationJul 21, 2025

    Applies to: Heads of State, DOD, Commerce, DOE, ODNI, USUN, and USAID

    Heads of State, DOD, Commerce, DOE, ODNI...must submit detailed reports to the President...within 270 days
  9. #9CriticalMonitoring and EvaluationAnnually after 2025-07-21

    Applies to: Heads of State, DOD, Commerce, DOE, ODNI, USUN, and USAID

    and annually thereafter for at least five years.
  10. #10ImportantGovernance and Institutional FrameworkAnnually after 2025-07-21

    Applies to: Covered agencies

    Agencies must maintain inventories of high‑impact AI and report annually for at least five years.
  11. #11ImportantGovernance and Institutional Framework

    Applies to: Covered agencies

    integration of whistleblower protections
  12. #12ImportantInternational AlignmentFeb 21, 2025

    Applies to: Department of State (coordinating with DOD, Commerce, DHS, USUN, USAID)

    Within 120 days, the Department of State...must produce a strategy for advancing international AI governance

© Regulations.AI — created on 13-Jun-2026