United States - AI Governance and Risk Management (M-24-10)

OMB Memorandum M-24-10: Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence

United States

RAI-US-NA-OMMAGXX-2024
Effective: March 28, 2024
In Force(In Force)
PolicyGovernance and OversightRisk Management
Export PDF

OMB Memorandum M-24-10 (March 28, 2024) directs executive branch agencies to strengthen governance, advance responsible AI innovation, and manage risks from AI uses that may affect public rights and safety. It requires agencies to designate Chief AI Officers, inventory AI use cases, adopt minimum risk-management practices for rights- and safety-impacting AI, publish certain materials publicly, and follow procurement and monitoring guidance.

Overview

OMB Memorandum M-24-10, published March 28, 2024, sets expectations for executive branch agencies to strengthen governance, promote responsible AI innovation, and manage risks tied to agency use of AI—especially where those uses may affect the rights and safety of the public. The memorandum requires agencies to designate a Chief AI Officer (CAIO), create internal governance mechanisms, maintain inventories of AI use cases, and adopt minimum risk-management practices for systems that are presumed to be rights-impacting or safety-impacting. The memo also instructs agencies to publish plans and public-facing inventories and to coordinate through OMB and interagency mechanisms. The full text and authoritative source are available from the White House and OMB: OMB Memorandum M-24-10 (PDF) and OMB policy channels. The policy complements Executive Order 14110 and related statutes by focusing on operational governance and minimum practices tailored to rights- and safety-impacting AI.

Definitions

M-24-10 defines or operationalizes core terms to align agency implementation. Key terms include "AI use cases" (applications that employ AI to inform, influence, or execute agency decisions or actions), "rights-impacting AI" (systems whose outputs have legal, material, binding, or similarly significant effects on individuals or communities), and "safety-impacting AI" (applications that could create or exacerbate physical or safety risks). The memorandum distinguishes these risks from enterprise IT, privacy, accessibility, or general cybersecurity requirements and clarifies that its risk focus is on outcomes tied to agency reliance on AI outputs. It also references the Chief Financial Officers (CFO) Act agencies for certain reporting thresholds and connects to existing definitions used in the AI in Government Act and related OMB guidance.

Governance and Institutional Framework

M-24-10 requires agencies to strengthen governance at the enterprise level. Each agency must designate a CAIO within 60 days of the memorandum and appoint or designate an AI governance board or coordination mechanism that includes senior leaders from relevant mission, legal, privacy, IT, procurement, and compliance functions. The CAIO's responsibilities include coordinating AI use, promoting innovation consistent with law and policy, managing AI-related risks, convening governance boards, and interfacing with OMB and the interagency CAIO council. Agencies must develop plans to achieve consistency with M-24-10 and post either those plans or a written determination of non-use on agency websites; initial plans are due to OMB within 180 days of the memorandum and every two years thereafter. OMB and the Office of Science and Technology Policy (OSTP) will coordinate government-wide activities and create shared templates, technical resources, and a consolidated federal AI use-case inventory (CIO Council / OSTP reference). Agencies are encouraged to recruit AI talent and to align enterprise processes to permit reuse of models, code, and data where lawful and appropriate.

Key Focus Areas

The memorandum centers on three policy pillars: strengthening governance, advancing responsible innovation, and managing risks. Strengthening governance includes CAIO designation, governance boards, integration with enterprise risk processes, and public transparency obligations (plans, inventories, and aggregate metrics). Advancing responsible innovation encourages reuse of agency code and models, development of testbeds and controlled environments, workforce development, and interagency sharing of best practices and templates. Managing risks is the memo's most prescriptive element: it identifies categories of AI that are presumed to be rights- or safety-impacting (for example, law enforcement systems, eligibility determinations for benefits, hiring/admissions, immigration and border adjudications, public health and medical determinations, and safety-critical infrastructure controls) and instructs agencies to apply minimum risk management practices before deployment. These minimum practices include pre-deployment testing under controlled conditions, documentation and risk assessments, legal review, data quality assessment, human oversight and escalation points, monitoring and measurement of performance, and mitigation plans. The memo also provides procurement guidance: procurements must align with law, encourage competition, require transparency, and promote supplier accountability and model provenance. To balance agility and safety, the memo permits controlled testing, pilot deployments, and limited waivers where justified.

Implementation Framework

Implementation is structured with concrete deliverables and timelines. Agencies must submit either a plan to achieve consistency with M-24-10 or a written determination that they do not use covered AI within 180 days of issuance (initially due Sept 24, 2024). Agencies must inventory AI use cases at least annually and post a public-facing inventory; CFO Act agencies and other higher-use agencies have additional reporting expectations. The CAIO and governance boards are responsible for internal policies and checklists for procurement, testing, documentation, privacy and civil rights review, and monitoring. Implementation guidance emphasizes reuse and interoperability of inventory formats and encourages agencies to post code, models, and data consistent with law. The memorandum allows limited extensions and waivers when agencies demonstrate appropriate mitigation and justification, and it defines procedures for escalating instances where risks exceed acceptable levels, including stopping use of an AI system pending remediation.

Monitoring and Evaluation

M-24-10 requires ongoing post-deployment monitoring focused on degradation of performance, changes in impact to rights and safety, and detection of AI-specific exploits or vulnerabilities. Agencies must scale feature rollouts incrementally when feasible, perform periodic human reviews at least annually for qualifying tools, and involve independent oversight not directly involved in development or operations. Monitoring must include metrics and thresholds to trigger mitigation actions, and agencies must re-evaluate whether minimum practices remain adequate as risks evolve. If monitoring reveals unacceptable risk, agencies are required to mitigate (by updating models, changing procedures, or halting deployment) and report actions to appropriate internal authorities and, in many cases, publicly.

Penalties, Liability, and Appeals

As a policy memorandum, M-24-10 does not create new criminal penalties but establishes administrative expectations and remedial pathways. Enforcement is administrative: OMB can require corrective actions, withhold approvals, require remediation plans, or direct suspension of an AI deployment that presents unacceptable risks. Agencies are expected to use existing disciplinary, procurement, and contract-remedy tools where vendor behavior or noncompliance is identified. The memorandum also signals that agencies must preserve individuals' existing rights to redress under applicable statutes; where AI outputs drive adverse agency actions, agencies must ensure procedures for appeal and due process consistent with law. Some agencies implement internal sanctions or procurement disqualifications for vendors that fail to meet risk-management requirements.

Relationship to Other Instruments

M-24-10 complements and builds on statutory authorities and prior executive actions: it implements aspects of the AI in Government Act of 2020, the Advancing American AI Act, and Executive Order 14110 (Safe, Secure, and Trustworthy Development and Use of AI). The memorandum is not a substitute for sector-specific laws (e.g., HIPAA, financial regulations, civil rights statutes) and does not override existing privacy, accessibility, or cybersecurity rules; rather, agencies must apply M-24-10 in conjunction with those obligations. The memorandum also references the NIST AI Risk Management Framework and other interagency guidance as supporting materials for technical standards and evaluation practices. Agencies should coordinate M-24-10 implementation with agency-specific statutes and regulator guidance.

International Alignment

OMB frames M-24-10 as consistent with U.S. commitments to democratic values and international law and encourages interoperability with international approaches to AI governance. The memorandum's emphasis on transparency, rights protection, and minimum risk-management practices aligns with global trends in responsible AI regulation and standards development led by bodies such as the OECD and standards organizations. OMB and OSTP will engage internationally to promote U.S. approaches and to harmonize where feasible while preserving lawful protections for classified and national-security information.

Implementation Timeline

MilestoneDeadline / Date
OMB memorandum issuance2024-03-28
Designation of Chief AI Officer (CAIO)Within 60 days (by 2024-05-27)
Submit plan or written determination to OMBWithin 180 days (initially by 2024-09-24)
Public posting of plan and public-facing AI use-case inventoryWithin 180 days and then annually
Post-deployment monitoring minimum effective date (noted compliance expectations)By 2024-12-01 initial monitoring standards
Biennial plan update to OMBEvery two years after initial submission

Compliance Checklist

RequirementCompliant (Y/N)
Designate a CAIO and publish contact
Establish or designate an AI governance board
Submit plan or non-use determination to OMB
Publish a public-facing AI use-case inventory
Identify rights- and safety-impacting AI and apply minimum risk-management practices
Conduct pre-deployment testing in controlled conditions
Implement post-deployment monitoring and annual human reviews
Align procurements with memo guidance and document vendor assurances
Post aggregate metrics and compliance reporting publicly

Sources and References

SourceType
Office of Management and Budget, Memorandum M-24-10: Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial IntelligencePrimary Source
Plain English

This U.S. government policy directs executive branch agencies to strengthen their management of Artificial Intelligence (AI) systems, particularly those that could affect public rights and safety. It applies to all U.S. executive branch agencies, setting clear expectations for how they must govern, innovate with, and manage risks from AI.

Agencies must take several key steps. First, each agency needs to designate a Chief AI Officer (CAIO) within 60 days of the policy's issuance (by May 27, 2024) and establish an AI governance board with senior leaders. Second, agencies must create and publicly post an inventory of all their AI use cases, submitting a plan to the Office of Management and Budget (OMB) within 180 days (by September 24, 2024) detailing how they will comply or stating they don't use covered AI. The most critical obligation is for AI systems that impact public rights (like eligibility for benefits, law enforcement, or hiring) or safety (like critical infrastructure controls). For these systems, agencies must implement minimum risk-management practices before deployment, including: - Pre-deployment testing in controlled environments. - Thorough documentation and risk assessments. - Human oversight and clear escalation points. - Ongoing monitoring of performance and impact.

The policy took effect on March 28, 2024, with various deadlines for compliance milestones. While this memorandum doesn't create new criminal penalties, enforcement is administrative. OMB can demand corrective actions, withhold approvals, or even order the suspension of an AI system deemed too risky. Agencies are also expected to use their existing disciplinary and contract tools for non-compliance. A practical pitfall for agencies is the broad definition of "rights-impacting" and "safety-impacting" AI, which means many common government functions will fall under these strict risk-management requirements, demanding significant internal process changes and resources.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 14 marked complete

Plain-English obligations under United States - AI Governance and Risk Management (M-24-10). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalGovernance and Institutional FrameworkMay 27, 2024

    Applies to: Executive Branch Agencies

    Each agency must designate a CAIO within 60 days of the memorandum
  2. #2CriticalGovernance and Institutional Framework

    Applies to: Executive Branch Agencies

    appoint or designate an AI governance board or coordination mechanism that includes senior leaders
  3. #3CriticalGovernance and Institutional FrameworkSep 24, 2024

    Applies to: Executive Branch Agencies

    initial plans are due to OMB within 180 days of the memorandum
  4. #4CriticalGovernance and Institutional FrameworkSep 24, 2024

    Applies to: Executive Branch Agencies

    post either those plans or a written determination of non-use on agency websites
  5. #5CriticalImplementation FrameworkSep 24, 2024

    Applies to: Executive Branch Agencies

    Agencies must inventory AI use cases at least annually and post a public-facing inventory
  6. #6CriticalKey Focus AreasBefore placing on market

    Applies to: Executive Branch Agencies deploying rights- or safety-impacting AI

    instructs agencies to apply minimum risk management practices before deployment.
  7. #7CriticalKey Focus AreasBefore placing on market

    Applies to: Executive Branch Agencies deploying rights- or safety-impacting AI

    These minimum practices include pre-deployment testing under controlled conditions
  8. #8CriticalKey Focus AreasBefore placing on market

    Applies to: Executive Branch Agencies deploying rights- or safety-impacting AI

    human oversight and escalation points
  9. #9CriticalMonitoring and EvaluationDec 1, 2024

    Applies to: Executive Branch Agencies deploying AI systems

    requires ongoing post-deployment monitoring focused on degradation of performance
  10. #10CriticalMonitoring and EvaluationImmediately upon detection

    Applies to: Executive Branch Agencies deploying AI systems

    If monitoring reveals unacceptable risk, agencies are required to mitigate... and report actions
  11. #11CriticalPenalties, Liability, and Appeals

    Applies to: Executive Branch Agencies using AI for actions affecting individuals

    agencies must ensure procedures for appeal and due process consistent with law.
  12. #12ImportantImplementation FrameworkAnnually

    Applies to: Executive Branch Agencies

    Agencies must inventory AI use cases at least annually
  13. #13ImportantMonitoring and EvaluationAnnually

    Applies to: Executive Branch Agencies deploying qualifying AI tools

    perform periodic human reviews at least annually for qualifying tools
  14. #14ImportantKey Focus Areas

    Applies to: Executive Branch Agencies procuring AI systems

    procurements must align with law, encourage competition, require transparency, and promote supplier accountability

© Regulations.AI — created on 13-Jun-2026