Article reader Listen + reading controls
Article reader
Preparing the reader…
Reading settings
Federal AI governance is moving into the operating model¶
Two April 3 Office of Management and Budget (OMB) memoranda make federal artificial intelligence (AI) policy more operational: M-25-21 on agency AI use and governance and M-25-22 on AI acquisition.
Policies change across administrations. The durable lesson in these documents is institutional: trustworthy use has to be built into roles, inventories, procurement, measurement, and delivery practice.
AI governance often begins as a committee and a set of principles. That can establish intent, but it does not tell a product team how to classify a use case, a contracting officer how to request evidence, or an executive how to know whether systems in operation still perform acceptably.
Acquisition is part of assurance¶
The two memoranda belong together. An agency cannot govern a system after deployment if the contract does not preserve access to the information, data rights, testing pathways, performance measures, and change notifications needed for oversight.
Procurement decisions shape technical architecture. They determine whether an agency can change models, inspect logs, export data, reproduce an evaluation, or exit a supplier relationship. They also distribute accountability across vendor, integrator, program office, and mission owner.
This is why acquisition teams need to enter the conversation before requirements harden. A model card attached at delivery cannot repair a contract that never defined operational metrics or government access to evidence.
The inventory can become useful¶
Agencies have been required to inventory AI use cases. Inventories are sometimes treated as reporting burdens: collect a list, publish it, and move on. A living inventory can do much more.
It can connect each use case to an owner, affected population, data sources, vendor, model version, risk classification, evaluation evidence, incidents, and retirement decision. It can show concentration risk across shared providers and reveal where similar programs are solving the same problem independently.
The inventory then becomes an operating instrument—a way to govern a portfolio rather than a static disclosure.
Put governance in the delivery path¶
Agencies can translate the memoranda into a repeatable path:
- Frame the mission decision and expected public value.
- Map affected people, data, and failure consequences.
- Choose an acquisition and technical architecture that preserves evidence and exit options.
- Evaluate the complete human-machine workflow.
- Assign a named operational owner before launch.
- Monitor outcomes, incidents, appeals, and material changes.
- retire systems whose value no longer justifies their risk or cost.
The National Institute of Standards and Technology (NIST) AI Risk Management Framework provides a useful common language, but agencies still have to make it part of everyday work.
The important shift is from governance as review to governance as capability delivery. When product, acquisition, legal, security, data, and mission teams share the same evidence trail, oversight becomes more than a brake. It becomes how the organization learns to adopt AI responsibly at scale.
Sources and research trail¶
- Office of Management and Budget, M-25-21: Accelerating Federal Use of AI through Innovation, Governance, and Public Trust (April 3, 2025).
- Office of Management and Budget, M-25-22: Driving Efficient Acquisition of Artificial Intelligence in Government (April 3, 2025).
- National Institute of Standards and Technology, AI Risk Management Framework 1.0 (2023).
- U.S. Government Accountability Office, Artificial Intelligence accountability framework (2021).