United States - Federal AI Governance (M-25-21)

OMB Memorandum M-25-21: Accelerating Federal Use of AI Through Innovation, Governance, and Public Trust

United States

RAI-US-NA-OMMAFXX-2025
Effective: April 3, 2025
In Force(In Force)
PolicyGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

OMB Memorandum M-25-21 (April 3, 2025) directs executive branch departments and agencies to accelerate the Federal use of artificial intelligence by prioritizing three themes: innovation, governance, and public trust. It rescinds and replaces M-24-10 and requires agencies to adopt enterprise AI strategies, designate Chief AI Officers, maintain public AI use-case inventories, and apply minimum risk management practices for "high-impact" AI while preserving privacy, civil rights, and security.

Summary

OMB Memorandum M-25-21, issued April 3, 2025, by the Office of Management and Budget, establishes government-wide policy and implementation guidance to accelerate and govern the Federal Government’s adoption of artificial intelligence. The memorandum articulates three central priorities: accelerating innovation and mission-driven AI adoption; strengthening governance and accountability across agencies; and maintaining public trust through transparency, protection of civil rights and civil liberties, and robust data privacy and security practices. M-25-21 explicitly rescinds and replaces the prior OMB memorandum M-24-10 and aligns with Executive Order 14179 and other legislative authorities (including provisions of the AI in Government Act and related statutes referenced in the memorandum).

Key structural requirements include designation of a Chief AI Officer (CAIO) at each agency to champion AI adoption and serve as a primary point of responsibility; establishment or reinforcement of agency AI governance boards to coordinate AI deployment across mission areas; and development of agency AI Strategies (CFO Act agencies must produce public AI Strategies within 180 days using an OMB template). The memorandum requires agencies to create and maintain annual, publicly available AI use-case inventories and to prepare biennial AI compliance plans consistent with the AI in Government Act. Agencies are also required to prioritize reuse of existing government data, models, and code, to maximize value to taxpayers and reduce duplicative spending, and to emphasize procurement of U.S.-developed or U.S.-produced AI systems where appropriate.

M-25-21 introduces a risk-based approach: it consolidates prior risk categories into a single “high-impact AI” classification that triggers minimum, mandatory risk management practices. Agencies must implement proportionate measures based on anticipated risk, including testing, monitoring, documentation, and contingency plans to discontinue or pause AI systems that do not meet performance or safety thresholds. The memo directs that, where high-impact AI cannot be made compliant through mitigation, agencies must cease use. It also redefines the CAIO role to be a change agent and enabler rather than an administrative bottleneck, aiming to remove unnecessary bureaucratic impediments to adoption while preserving required legal protections. The memorandum excludes National Security Systems and certain intelligence-community activities (which are governed by separate policy frameworks) but otherwise applies broadly to executive agencies as defined by 44 U.S.C. § 3502.

Implementation mechanisms include OMB convening and chairing an interagency council to coordinate AI governance, issuance of standard templates and technical resources, and reporting and accountability processes (inventories, compliance plans, and periodic reporting). While M-25-21 does not create new criminal penalties, it establishes enforceable administrative obligations and empowers agencies and OMB to require cessation of noncompliant AI uses and to withhold or restrict actions inconsistent with the memorandum. The memorandum emphasizes alignment with other Federal policies and standards, including collaboration with OSTP, NIST guidance, and applicable statutory protections for privacy and civil rights. Primary official sources include the OMB memorandum PDF and an accompanying White House fact sheet. Full text and accompanying materials are posted on the White House/OMB memoranda site and in the PDF of the memorandum.

Full article

Read full text ↗

Overview

OMB Memorandum M-25-21, "Accelerating Federal Use of AI through Innovation, Governance, and Public Trust," was issued on April 3, 2025 and rescinds M-24-10. The memorandum directs Heads of Executive Departments and Agencies to accelerate AI adoption across the Federal Government by focusing on three priorities: innovation, governance, and public trust. It requires agency-level leadership (Chief AI Officers), enterprise AI strategies, public AI use-case inventories, and mandatory minimum risk management practices for "high-impact AI". The full text and official PDF can be found on the Office of Management and Budget site and the White House document repository: OMB M-25-21 (PDF) and the memoranda index at Memoranda – OMB.

Definitions

The memorandum defines scope and terms for applicability. "Agency" follows the definition in 44 U.S.C. § 3502(1). "Covered AI" applies to AI developed, used, or acquired by or on behalf of agencies; the memo applies to system functionality that is AI-dependent rather than to entire IT systems. "High-impact AI" is a single consolidated risk category for AI uses that could have significant consequences for rights, safety, civil liberties, or critical mission outcomes; designation as "high-impact" triggers mandatory minimum risk management practices. The memorandum excludes National Security Systems and certain intelligence activities that are governed by other policy frameworks.

Governance and Institutional Framework

M-25-21 requires agencies to appoint a Chief AI Officer (CAIO) who will champion AI adoption, advise on AI investments, and support enterprise governance. Agencies must establish AI Governance Boards composed of senior leaders to coordinate policy, risk acceptance, and deployment decisions. The memo directs OMB to convene an interagency council to harmonize approaches, share templates, and maximize cross-agency reuse of data, models, and code. Agencies must integrate AI governance with existing enterprise IT, privacy, and civil rights compliance structures. For background and the OMB role, see the memoranda index and the memorandum PDF: OMB Memoranda and M-25-21 PDF.

Key Focus Areas

The memorandum highlights several focal areas: (1) Innovation and procurement — reduce unnecessary barriers to buy and deploy AI, emphasize U.S.-developed solutions, and maximize reuse of government assets; (2) Governance and accountability — CAIO roles and governance boards to accept and manage risk with clear delegation; (3) Transparency and public trust — publish AI strategies and maintain public-facing use-case inventories; (4) Risk management — identify "high-impact AI" and apply proportionate mandatory practices (testing, monitoring, access controls, documentation, and contingency/discontinuation plans); (5) Workforce and capacity — invest in AI talent and enabling infrastructure; and (6) Interagency coordination — OMB-led council and shared technical resources to avoid duplication. The White House fact sheet summarizes these priorities and the administration’s pro-innovation orientation: Fact Sheet (PDF).

Implementation Framework

Implementation includes specific, time-bound deliverables: CFO Act agencies must develop public AI Strategies within 180 days using an OMB-provided template; agencies must maintain annual AI use-case inventories and submit compliance plans (and biennial updates where required by statute). Agencies must allocate resources to scale AI adoption (data governance, IT infrastructure, workforce development). The memorandum requires agencies to proportionately apply minimum risk management practices to high-impact AI (including independent testing where appropriate) and to maintain an ability to pause or discontinue systems failing to meet performance or safety thresholds. OMB will provide template materials, convene the interagency council, and coordinate reporting requirements.

Monitoring and Evaluation

M-25-21 institutes ongoing monitoring through annual inventories, agency AI maturity assessments, and compliance reporting to OMB. Agencies are required to document testing results, monitoring logs, and mitigation actions for high-impact AI. OMB’s interagency council and reporting processes aim to surface systemic issues, share lessons learned, and provide centralized resources and templates. Performance indicators include timely delivery of AI strategies, inventory completeness, remediation of identified risks, and documented discontinuation of noncompliant systems where mitigation is infeasible.

Penalties, Liability, and Appeals

The memorandum does not create new criminal sanctions but establishes binding administrative obligations. Agencies are required to discontinue use of AI that cannot be made compliant; persistent failure to meet requirements may trigger OMB-directed corrective action, restrictions on continued funding or procurement of specific AI systems, and agency-level administrative consequences. Existing legal safeguards for civil rights, privacy, and statutory enforcement remain operative; agencies must continue to coordinate with legal counsel and inspectors general as appropriate. The memorandum relies on existing accountability mechanisms rather than prescribing novel penalties.

Relationship to Other Instruments

M-25-21 expressly rescinds and replaces OMB Memorandum M-24-10. It implements portions of the AI in Government Act and aligns with Executive Order 14179 while referencing relevant NIST and other technical guidance for risk management. Agencies must comply with M-25-21 in concert with other legal and policy obligations (privacy, civil rights statutes, procurement law). For cross-references, consult the memorandum appendix and OMB memoranda index: OMB Memoranda.

International Alignment

While focused on domestic Federal operations, M-25-21 encourages alignment with recognized technical standards and cross-government frameworks (e.g., NIST AI RMF) and promotes U.S. competitiveness in AI markets. Agencies are directed to prefer U.S.-developed solutions where appropriate and to ensure that adoption preserves national security, supply chain integrity, and interoperability. The policy underscores the importance of international engagement but leaves specific treaty- or foreign-affairs-level coordination to relevant agencies.

Implementation Timeline

MilestoneDeadline / Date
Memorandum issued2025-04-03
CFO Act agencies publish AI Strategy (using OMB template)Within 180 days of issuance (by 2025-09-30)
Annual AI use-case inventory (first public publication per OMB instructions)Annual, per OMB reporting cycle (inventory updates required)
Designation of Chief AI OfficersImmediate / as soon as practicable following issuance
Implementation of minimum risk management practices for high-impact AIAs agencies deploy or continue high-impact AI; ongoing

Sources and References

SourceType
OMB Memorandum M-25-21 (PDF)Primary Source
Fact Sheet: Eliminating Barriers for Federal Artificial Intelligence Use and Procurement (PDF)Primary Source
Memoranda – OMBPrimary Source

Requirements for a company

What an organisation has to do under United States - Federal AI Governance (M-25-21), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

10
  • Designate a Chief AI Officer (CAIO) to champion AI adoption and advise on investments.Heads of Executive Departments and Agencies
  • Establish an AI Governance Board composed of senior leaders to coordinate policy and deployment decisions.Agencies
  • Develop and publish a public AI Strategy using the OMB-provided template.CFO Act agencies
  • Maintain and annually submit a public AI use-case inventory in the OMB format.Agencies
  • Apply proportionate minimum risk management practices to high-impact AI systems.Agencies deploying or continuing high-impact AI
  • Document testing results, monitoring logs, and mitigation actions for high-impact AI.Agencies using high-impact AI
  • +4 more in the table below

Must not do

0

Nothing in this category.

Should do

1
  • Prioritize reuse of government assets and U.S.-developed AI solutions where appropriate.Agencies in procurement and acquisition

Should not do

0

Nothing in this category.

Who must do what

The obligations under United States - Federal AI Governance (M-25-21), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Heads of Executive Departments and AgenciesDesignate a Chief AI Officer (CAIO) to champion AI adoption and advise on investments.
M-25-21 requires agencies to appoint a Chief AI Officer (CAIO) who will champion AI adoption, advise on AI investments, and support enterprise governance.
Immediate / as soon as practicable following issuanceGovernance and Institutional FrameworkCritical
2AgenciesEstablish an AI Governance Board composed of senior leaders to coordinate policy and deployment decisions.
Agencies must establish AI Governance Boards composed of senior leaders to coordinate policy, risk acceptance, and deployment decisions.
Governance and Institutional FrameworkCritical
3CFO Act agenciesDevelop and publish a public AI Strategy using the OMB-provided template.
CFO Act agencies must develop public AI Strategies within 180 days using an OMB-provided template
Sep 30, 2025Implementation FrameworkCritical
4AgenciesMaintain and annually submit a public AI use-case inventory in the OMB format.
agencies must maintain annual AI use-case inventories and submit compliance plans
Annual, per OMB reporting cycleImplementation FrameworkCritical
5Agencies deploying or continuing high-impact AIApply proportionate minimum risk management practices to high-impact AI systems.
apply minimum risk management practices for 'high-impact AI'
As agencies deploy or continue high-impact AI; ongoingKey Focus AreasCritical
6Agencies using high-impact AIDocument testing results, monitoring logs, and mitigation actions for high-impact AI.
Agencies are required to document testing results, monitoring logs, and mitigation actions for high-impact AI.
OngoingMonitoring and EvaluationCritical
7Agencies deploying or continuing high-impact AIMaintain the ability to pause or discontinue high-impact AI systems failing performance or safety thresholds.
maintain an ability to pause or discontinue systems failing to meet performance or safety thresholds.
OngoingImplementation FrameworkCritical
8AgenciesDiscontinue the use of AI systems that cannot be made compliant with requirements.
Agencies are required to discontinue use of AI that cannot be made compliant
OngoingPenalties, Liability, and AppealsCritical
9AgenciesIntegrate AI governance with existing enterprise IT, privacy, and civil rights compliance structures.
Agencies must integrate AI governance with existing enterprise IT, privacy, and civil rights compliance structures.
Governance and Institutional FrameworkImportant
10AgenciesAllocate resources to scale AI adoption, including data governance, IT infrastructure, and workforce development.
Agencies must allocate resources to scale AI adoption (data governance, IT infrastructure, workforce development).
Implementation FrameworkImportant
11Agencies in procurement and acquisitionPrioritize reuse of government assets and U.S.-developed AI solutions where appropriate.
emphasize U.S.-developed solutions, and maximize reuse of government assets
Key Focus AreasRecommended

© Regulations.AI · updated on 13-Jun-2026