Skip to content
Article reader Listen + reading controls
LISTEN + READ YOUR WAY

Article reader

Preparing the reader…

0:00 0:00
Reading settings
Text size
100%

Federal AI governance needs a memory

Federal artificial intelligence (AI) policy changed substantially between 2024 and 2025. The need to know which systems government uses, who owns them, how they affect people, and what evidence supports them did not.

That is the enduring idea behind the Federal AI Governance and Transparency Act. Introduced as House bill H.R. 7532 in March 2024, the bipartisan proposal would have consolidated several federal AI governance requirements in statute. It directed agencies to create governance charters for certain systems, strengthened the Office of Management and Budget's government-wide role, expanded public visibility, and required contractors to provide information agencies would need for oversight.

The bill advanced out of committee by a 36–3 vote and was reported to the House in December 2024. It did not become law before the Congress ended.

Its most useful contribution was not a particular form or office. It was the recognition that accountable AI requires an institutional memory: a durable connection between the system, its public purpose, the decisions made about it, and the evidence available to challenge those decisions.

Revised and substantially expanded July 17, 2026, to reflect the bill's legislative outcome and the federal policy changes that followed.

Policy changes faster than operating reality

Executive policy can change quickly. Data pipelines, contracts, deployed models, legacy integrations, workforce routines, and effects on the public do not.

In April 2025, Office of Management and Budget (OMB) Memorandum M-25-21 replaced the previous administration's guidance for agency AI use. It changed terminology and policy emphasis while retaining several persistent operating requirements: Chief AI Officers, use-case inventories, governance, risk practices for high-impact uses, public reporting, and agency accountability.

That continuity is instructive. Different administrations can disagree about thresholds, priorities, and the right balance between speed and control. Both still need reliable answers to basic questions:

  • What systems exist?
  • What mission or service do they support?
  • Who owns the outcome, system, data, and risk decision?
  • Which people are affected?
  • What models, vendors, data, and infrastructure does the system depend on?
  • What evidence supports its use?
  • What incidents, complaints, overrides, or material changes have occurred?
  • Who can constrain, suspend, or retire it?

If those answers live in temporary spreadsheets and committee members' memories, every policy transition forces the agency to rediscover its own technology estate.

A governance charter should be a living record

The reported version of H.R. 7532 proposed AI governance charters for high-risk federal systems and systems trained on, using, or producing records about individuals. The idea has promise, but only if “charter” means more than a document approved before deployment.

A static charter records intention. An accountable system needs a record of change.

The charter should connect:

  1. Purpose and authority. What public function does the system serve, and what law, policy, or delegated authority permits the use?
  2. Decision rights. Who may approve, modify, expand, pause, or retire the system? Who adjudicates disagreement?
  3. System lineage. Which model versions, data sources, vendors, components, interfaces, and human processes produce the outcome?
  4. Evidence. Which evaluations support the present use, for which populations and operating conditions, and when do those evaluations expire?
  5. Risk decisions. Which limitations, mitigations, exceptions, and waivers were accepted, by whom, and for how long?
  6. Operating history. What material changes, incidents, complaints, appeals, overrides, and monitoring results have accumulated?
  7. Public obligations. What notice, explanation, records retention, accessibility, privacy, and disclosure requirements apply?

This is not a demand that every detail be public. Security, privacy, procurement-sensitive information, law-enforcement methods, and other protected material require appropriate handling. It is a demand that the agency itself retain an auditable chain of knowledge and publish the portions necessary for public accountability.

Governance fails at the handoffs

AI responsibility is often distributed across a Chief AI Officer, Chief Information Officer, Chief Data Officer, privacy office, civil-rights staff, security organization, general counsel, acquisition team, records officer, inspector general, mission owner, and vendor.

Each may perform its assigned review correctly while the end-to-end system remains poorly governed. A privacy condition may never reach the engineering backlog. A model update may not trigger a new impact assessment. A contract may not provide the logs needed to investigate a complaint. A program office may assume that an approval transfers responsibility to a governance board.

The charter should make those handoffs visible. It should name not only roles but also events:

  • acquisition or contract modification;
  • access to a new data source;
  • movement from experiment to operational use;
  • a material model, prompt, interface, or workflow change;
  • expansion to a new population or decision context;
  • a consequential incident or pattern of overrides;
  • renewal, recompete, or retirement.

Each event should identify who must act, what evidence must be refreshed, and where the decision is recorded. Governance becomes effective when it is attached to the lifecycle, not when it exists beside it.

Contractors are part of the evidence chain

The bill's reported text anticipated an important acquisition problem. Agencies cannot govern a system if the contractor controls the information needed to understand it.

Federal AI contracts should secure access to the evidence appropriate to the use: model and service version history, data provenance, evaluation results, performance logs, incident notification, material-change notice, subcontractor dependencies, security information, portability, and exit support. The government may not need every proprietary detail. It does need enough visibility to discharge its own legal and operational responsibilities.

This is especially important for AI delivered as a service. The model can change without a conventional software release inside the agency. Data may cross several providers. A vendor's safety or performance assertion may apply to a general product rather than the agency's configured workflow and population.

The U.S. Government Accountability Office (GAO) has repeatedly identified weaknesses in federal AI inventories and implementation. Its 2023 government-wide review found incomplete and inaccurate inventory data, and its 2026 acquisition review urged agencies to collect and apply lessons from AI procurements. A governance system that cannot see across the contract boundary will preserve neither evidence nor learning.

Build a system of record, not another reporting burden

The predictable failure mode is to implement governance charters as a parallel paperwork exercise. Program teams fill out a template, central staff compile it, and both return to different systems where the actual work continues.

A durable approach uses one living record to support multiple obligations. Acquisition data, impact assessments, security decisions, model evaluations, incident records, public inventory fields, and executive reporting should be connected rather than repeatedly transcribed.

The agency should enter information at the point of work and generate views appropriate to different audiences. A public inventory needs a different level of detail than an inspector general review, but both should derive from the same underlying system history. When a field changes, downstream reporting should show the change and its provenance.

This architecture reduces burden and improves accountability at the same time. It also makes governance adaptable. New policy can change required fields, thresholds, or review paths without destroying the history of the system.

Institutional memory is a control

The Federal AI Governance and Transparency Act did not become law. Several of the operating needs it addressed persisted in later executive guidance because they arise from the technology and the structure of government, not from one administration's vocabulary.

The strategic lesson is larger than the bill. Responsible AI is not a set of principles attached to a model. It is the organizational ability to reconstruct what the system did, why people authorized it, what evidence they relied upon, which obligations applied, and how the organization responded when conditions changed.

An agency that preserves that chain can adapt to new policy without starting over. It can learn across programs, investigate failure, negotiate better contracts, and explain consequential uses to the public. An agency that does not preserve it will repeatedly produce governance artifacts while forgetting how its own systems came to operate.

Federal AI governance needs rules. More fundamentally, it needs memory.

Sources

READER-NEUTRAL SUBSCRIPTION

Follow Field Notes via RSS.

Copy this address into the RSS reader you already use. New notes will appear there automatically—no account, email address, or tracking required.