Skip to content
Article reader Listen + reading controls
LISTEN + READ YOUR WAY

Article reader

Preparing the reader…

0:00 0:00
Reading settings
Text size
100%

AI Policy Should Leave Behind Institutions, Not Checklists

Revised and substantially expanded July 17, 2026, with the subsequent change in federal AI policy reflected explicitly.

Executive Order 14110 was remarkable in scope. Issued in October 2023, it assigned artificial-intelligence actions across a wide portion of the federal government: safety and security, privacy, civil rights, consumer protection, workforce, innovation, competition, international leadership, federal use, and technical standards. Many assignments carried deadlines measured in days or months.

By early 2024, progress was naturally reported as a sequence of completed actions. Agencies had issued requests for information, convened experts, begun standards work, created hiring pathways, launched pilots, and prepared guidance. The original version of this post praised that momentum but did little to explain what “progress” should mean.

The later policy record creates a useful natural experiment. In January 2025, a new administration revoked Executive Order 14110 and established a different federal AI policy. OMB subsequently replaced core agency-use and acquisition guidance. Yet many technical problems, statutory obligations, agency missions, and organizational constraints remained.

This reveals the correct unit of progress. It is not the number of executive-order tasks marked complete. It is the amount of durable state capacity created: people, evidence, standards, architectures, acquisition mechanisms, data, evaluation systems, and decision processes that remain useful when the policy language changes.

Executive Orders Are Mobilization Instruments

Executive Order 14110 used presidential authority to coordinate a government that otherwise tends to address emerging technology through fragmented statutes, appropriations, missions, and regulatory jurisdictions. Its deadlines forced issues onto leadership agendas and created a common planning horizon.

That is a legitimate function. An executive order can:

  • establish policy and priorities across departments;
  • assign accountable officials and coordination bodies;
  • direct the use of existing legal authorities;
  • require agencies to produce standards, guidance, reports, or plans;
  • create urgency where ordinary processes would move slowly;
  • expose gaps requiring legislation or appropriations.

It cannot, by signature alone, produce the technical and organizational capabilities necessary to implement its ambition. Nor can it guarantee policy continuity. Executive action is inherently revisable by a successor administration within the limits of law.

President Trump's January 2025 Executive Order 14179 revoked the prior order, directed review of actions taken under it, and shifted the policy emphasis toward removing barriers, global leadership, economic competitiveness, and national security. OMB's April 2025 M-25-21 memorandum replaced prior agency-use guidance while retaining several operational ideas: Chief AI Officers, use-case inventories, governance, public trust, risk management for high-impact uses, workforce, and reuse of data, models, code, and performance assessments.

The policies differ materially. The persistence of certain operating needs is equally instructive.

Separate Policy Intent From Institutional Capability

Policy intent answers: What outcomes and values should government pursue? Institutional capability answers: What can government reliably do?

An agency may be directed to accelerate AI adoption, protect civil rights, manage high-impact uses, or promote competition. To execute any of those directions it still needs:

  • an inventory of systems and accountable owners;
  • technical staff capable of evaluating architectures and evidence;
  • usable data with known provenance and permissions;
  • secure platforms and development pathways;
  • acquisition terms that preserve data rights, observability, competition, and exit;
  • evaluation methods tied to mission outcomes and affected populations;
  • governance that assigns risk acceptance and escalation authority;
  • monitoring, incident response, and change management after deployment.

These are policy-agnostic assets in the best sense. Different leaders may set different thresholds or priorities, but they need the capacity to know what systems exist, how they perform, whom they affect, what they cost, and what alternatives are available.

The mistake is to implement each directive as a temporary compliance project. That produces a memorandum, spreadsheet, committee, or report calibrated to one administration's terminology. When policy changes, the artifact becomes obsolete and the institution starts again.

Convert Mandates Into Reusable Operating Primitives

A more durable approach treats policy requirements as demand signals for shared operating capabilities.

From use-case inventories to an AI system registry

A once-yearly spreadsheet can satisfy a reporting deadline while becoming stale almost immediately. A living registry connects each AI system to its mission owner, technical owner, vendor, model and data dependencies, intended users, affected population, risk classification, evaluations, authorizations, incidents, cost, and lifecycle state. Different reporting views can then be generated as policy definitions change.

From impact assessments to evidence pipelines

A static impact document often describes intentions before deployment. An evidence pipeline attaches test results, data-quality measures, user feedback, subgroup performance, operational metrics, incidents, and change records to the system over time. New oversight questions can be answered without reconstructing the history from email.

From governance boards to decision rights

Committees are easy to establish and difficult to make effective. Durable governance specifies who can approve experimentation, accept residual risk, authorize production, halt use, require mitigation, and adjudicate disagreement. It also defines time limits and escalation paths so governance does not become an unbounded queue.

From pilots to paved production paths

Agencies repeatedly prove that a model can perform a task in a sandbox. The missing capability is a secure, observable path from experiment to production: approved environments, reusable architectures, identity and data controls, evaluation gates, acquisition patterns, monitoring, and operational ownership. Each pilot should improve that path for the next team.

From workforce plans to multidisciplinary teams

AI capacity is not synonymous with hiring data scientists. Agencies need product leaders, software and platform engineers, data stewards, acquisition professionals, privacy and civil-rights experts, security engineers, evaluators, domain operators, and change leaders. Durable progress is a team capable of delivering and challenging a system, not a headcount under an AI occupational label.

Standards Work Is Durable When It Produces Technical Commons

One of the most valuable legacies of a time-bounded policy directive can be a reusable public technical resource. Work initiated under Executive Order 14110 produced or accelerated NIST guidance that remains useful beyond the order itself. For example, NIST's Secure Software Development Practices for Generative AI and Dual-Use Foundation Models extends an existing secure-development framework with AI-specific practices.

This kind of output has several advantages:

  • it is method-centered rather than administration-centered;
  • it can be adopted voluntarily across public and private sectors;
  • it creates a shared vocabulary for producers and acquirers;
  • it can be revised as evidence and technology evolve;
  • it preserves technical learning even if the initiating mandate is revoked.

Not every report becomes a durable commons. The strongest artifacts are implemented, testable, versioned, and connected to actual workflows.

Measure the Residue, Not the Motion

Government progress reporting tends to reward visible activity: meetings held, guidance issued, people hired, pilots launched, and deadlines met. Those measures tell leaders whether the mobilization is moving. They do not tell the public what capability remains.

A durability-oriented review would ask:

  1. What can the agency do now that it could not do before? Can it evaluate a model, deploy within an approved environment, negotiate data rights, or monitor a high-impact system?
  2. What has been reused? Which architectures, datasets, evaluation suites, contract clauses, or training materials served more than one program?
  3. What became observable? Does leadership have better evidence about cost, performance, risk, user impact, and dependencies?
  4. What became faster without becoming less controlled? Did lead time from idea to responsible production decrease, and where?
  5. What survived a change in policy? Which systems and practices could accommodate new definitions and priorities without wholesale reconstruction?
  6. What was stopped? Mature capability includes recognizing poor use cases and ending them before sunk costs become strategy.

These measures treat institutional learning as the outcome.

Design the AI Operating Model Around Stable Questions

Policy vocabulary will continue to change. Terms such as “safety-impacting,” “rights-impacting,” “high-impact,” “trustworthy,” “unbiased,” and “responsible” encode different priorities and scopes. Agencies must implement current law and policy faithfully. They should build the underlying operating model around questions that remain necessary across those changes:

  • What decision or service is the system influencing?
  • Who owns the outcome and who is affected?
  • What data, models, software, and vendors does it depend on?
  • What evidence supports effectiveness in the actual context?
  • What failures matter and how are they detected?
  • Which human has authority to act, override, escalate, or stop?
  • What changes invalidate the existing evidence?
  • What rights, legal requirements, security constraints, and public obligations apply?
  • What is the exit path if performance, policy, cost, or provider behavior changes?

Answer those questions in a structured, living system and the agency can map new policy requirements onto existing knowledge. Fail to answer them and every new memorandum becomes another manual inventory exercise.

The Strategic Inference: Governance Is Part of Delivery

The usual debate frames governance and innovation as competing forces: more review slows adoption; less review accelerates it. That is often a symptom of poor operating design.

Unclear governance creates delay because teams discover requirements late, wait for committees with ambiguous authority, and rebuild evidence for each reviewer. Well-designed governance creates paved roads. It tells teams which path applies, what evidence is required, which controls are reusable, who decides, and how exceptions work. Lower-risk work moves quickly. Higher-impact work receives proportionate scrutiny. Both become more predictable.

The durable achievement of federal AI policy would not be a perfectly stable set of rules. That is impossible. It would be an adaptive delivery system capable of translating changing democratic priorities into technical and operational behavior without losing institutional memory.

The 2023 executive order created a powerful mobilization. Its 2025 revocation demonstrated the limits of treating mobilization as permanence. The correct lesson is not that executive action was futile. It is that every time-bound directive should be implemented with a second objective: leave behind capabilities that the next policy regime will still need.

Building those adaptive operating models—where governance, software engineering, data, knowledge, and mission delivery reinforce one another—is a core theme in my public-sector AI work. If your organization is trying to turn policy activity into durable technical capacity, you can send a direct inquiry or connect with me on LinkedIn.

READER-NEUTRAL SUBSCRIPTION

Follow Field Notes via RSS.

Copy this address into the RSS reader you already use. New notes will appear there automatically—no account, email address, or tracking required.