AI Governance Policy Requirements for Federal Agencies Under OMB M-24-10
Federal agencies must appoint AI officers and inventory their AI tools annually.

OMB Memorandum M-24-10 laid out, in enforceable language for the first time, each federal agency's obligations for governing how it uses artificial intelligence. Dated 28 March 2024, under the heading Advancing Governance plus Innovation alongside Risk Management covering how each Agency may Use Artificial Intelligence, it told agencies to pick a Chief AI Officer role, create oversight boards, share annual inventories listing every AI tool running, and terminate any program that does not comply with the memo’s risk-management requirements. The memo carried out a mandate from Executive Order 14110, issued the previous October, and it finalized a proposed version OMB had issued in November 2023. This goes requirement by requirement and shows how agencies ended up against the deadlines from OMB.
A pair of points frame what comes next. M-24-10 deals with a limited piece of AI risk, covering only the use of outputs from AI when agency decisions affect public well-being or personal rights. It doesn't swallow any existing mandate which touches AI; National Security Systems sit outside it, under the Defense Department's and Intelligence Community's own inventory rules. The memo has since been replaced. As of a September 2026 check, OMB Memorandum M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust, has replaced M-24-10. This succession reads more as a continuation than a stop: the structure below guided today’s federal AI work, while those requirements were carried forward in the later memo, which replaced it. Six months after M-24-10, OMB also issued M-24-18 in October 2024, extending the same risk logic into procurement and contracting. The memos were built as a pair, the first governing use, the second covering purchases.
The CAIO requirement: what the role is, what it must do, and how agencies have structured it
Every agency had 60 days from the memo's release to name a Chief AI Officer. That's a tight window for a government-wide personnel action, and it shows in how differently agencies approached the role afterward.
They made sure seniority expectations weren't vague. For agencies under the CFO Act, their CAIO must be Senior Executive Service, or comparable Scientific and Professional staff or a Senior Leader. Tiny agencies can use GS-15 as their minimum, but that baseline keeps this job far beyond any mid-level program leader. OMB required the CAIO to be a senior official with decision-making authority, not merely an advisory role.
This job description mixes chief technologist with chief risk officer. CAIOs coordinate the agency's use of AI, encourage adoption in the right places, help guide the agency’s use of AI, and hold a central role in risk decisions. These officials are supposed to run the governance board for the agency, oversee compliance obligations from the memo while acting as its chief AI guide. CAIOs also serve an interagency role, standing in for the agency at AI councils and standard-setting talks.
How agencies put the job together on the ground diverged more than the description hints. In the first months of 2024, that Federal Reserve Board unit launched its AI Program inside the Office for Chief Operating Officer leadership, picked one CAIO person to lead it, and divided governance between a Program Team plus an Enablement Working Group: one focused on practices and operations, while the other addressed technical implementation and workforce development. FTC did something else: it renamed the existing Data Governance Board as its Board for Data and AI Governance, chaired by that agency's Chief Officer for Data and AI, a name that folds both roles into one. On October 3, 2024, USAGM's published compliance plan placed the CAIO in a governance role alongside senior leadership, including a board with representation from key agency functions.
Each of these choices fits under memo's rules, since M-24-10 set the role, not dictating any org setup. Such latitude brought real differences: certain agencies built whole units, and the rest merely relabeled departments they already had. Those differences probably came as much from the 60-day deadline as from a deliberate choice. Agencies needed to act quickly, and that usually means using the setup already in place.
AI governance boards: the 90-day cross-functional mandate and how CFO Act agencies built them
CFO Act agencies had a 90-day runway to convene their AI governance board. That requirement was clear to avoid any rubber-stamp group: IT, data, cybersecurity, and spending stakeholders needed to be there.
Instead of providing ceremonial oversight, the boards handle actual tasks. Their job includes setting internal procurement checklists, establishing standards for testing and documentation, running reviews that cover privacy and civil rights, plus keeping watch on systems in operation. Some agencies seemed to think one group couldn't handle all of it.
Commerce uses a pair of governance bodies: the Commerce AI Governance Board, plus its distinct Commerce AI Council. HHS put together one HHS Governance AI Board. EEOC assembled its fresh governing group with people drawn from the Information Technology Office, the Chair’s Office, and the Office for General Counsel. No data point here is more telling than the dual-track approach: this splitting of policy-level governance and operational coordination suggests no single board could manage both roles at once, and this deserves attention should OMB release more rules on board design.
These boards do more than follow their own rules, since they must create and keep an inventory of AI use cases. That requirement shifts governance out of paperwork and into public view.
The AI use case inventory requirement: what agencies must track, classify, and publish
Each agency, excluding DoD plus the Intelligence Community, must inventory each AI case it uses, buys, or has built in-house, once annually. OMB shares how to turn in the inventory using its Integrated Data Collection setup, and each agency's site must display it openly.
Each tool inside the inventory is sorted for impact: low, moderate, or high impact, if it affects eligibility decisions, civil rights, or funding allocation. High-impact systems bring a wave of follow-on requirements: assessments of impact, testing for disparities, human review, and transparency documentation laying out each tool in everyday terms.
By splitting the high-impact group, that memo makes a much sharper cut between safety-impacting and rights-impacting AI systems, which determines your risk-management level. AI lands in this bucket when its results mostly drive a choice with major consequences for civil rights, personal data, equal treatment, or public services. This group includes tracking, prediction of recidivism, and decisions about homes, jobs, loans, and school. Safety-related AI deals with choices that matter a lot for people, nature, or key systems, and the memo itself points to healthcare, the police, and clinical assessment as cases. It's simple to mix this up backward, but voting is classified as safety-impacting.
A data-quality point tucked inside the memo proves far more important than it seems: use case IDs must persist from one inventory cycle to the next, so even a redescribed or renamed use case stays tracked. Without persistence, an annual inventory's whole point, tracking shifts across years, breaks down.
The mandate has also spread outward. At least 12 states have formally issued requirements for state and local government agencies to publish AI use case inventories. They are copying a template drawn from Federal work.
How dramatically inventory numbers have grown, and what the growth actually reveals
These figures are so large that unpacking matters more than reciting them. GAO looked at 11 agencies in a review spanning June 2024 to July 2025, released on 2025's July 29, which showed AI use cases more than doubled, rising from 571 during 2023 up to 1,110 by 2024. The count for generative-type AI use hit 282, up from 32.
The same thing shows up in federal numbers as well. OMB's consolidated inventory logged 3,611 reported use cases across 56 submitting agencies in 2025, up from 1,757 in 2024, a rough doubling in a single year, according to Nextgov's reporting on the 2025 Federal Agency AI Use Case Inventory. CDT's own look at the 2024 data turned up 1,400 additional use cases over the prior period, a 200% leap.
NASA stands out so much it gets its own mention. The agency reported 425 use cases in 2025, up from just 18 in 2024, a change on the order of 2,260%, per FedScoop. A shift that big makes you wonder: has NASA truly been deploying far more AI, or was it merely beginning to log the systems it had long kept off the books? Those inventory figures won't settle it by themselves.
One tool appears repeatedly in the filings, so it is worth naming. Agencies list Anthropic's Claude in 25 use case records, mostly concentrated within the State Department plus HHS, showing that federal offices buy outside AI instead of making it all in-house.
Still, no expansion shows governance working. Some agency lists have not used identical IDs that the guidance calls for, hurting the reason for annual checks, per FedScoop's coverage. GAO found numerous AI programs lacked clear budget and timeline data, giving agency heads a distorted sense of how work is progressing. Yet AI adoption looks uneven across agency groups: use is scaling at large agencies ahead of lesser, midsized agencies, a divide that may point to staffing and funding more than purpose, as FedScoop reported. For transparency, this inventory is serving its purpose. The numbers are bigger, more granular, and more public than they were two years ago. Yet a larger count doesn't equal stronger governance, and where data has gaps, the view at the use-case stage stays incomplete.
The minimum risk management practices M-24-10 requires for rights- and safety-impacting AI
M-24-10 requires each agency to finish an impact review before putting AI touching people's rights, or any safety-impacting area, into use, laying out the intended purpose of that system's work plus expected benefit, what risks exist and how they get mitigated past baseline practices from the memo, and whether data is good. Agencies must also assess the system's performance in real-world conditions prior to it going live, verifying that it actually works as intended.
This memo won’t hedge if the testing looks poor. That instruction stays direct: skip using the AI whenever, following mitigation, its expected benefit cannot outweigh every risk.
Once an AI is in use, its obligations keep going. Agencies must stay on it, with human review in place, reassess its risk while it evolves, and get employees ready so they can properly oversee how it runs, not merely rubber-stamp what it produces. When rights or danger mean an AI shouldn't act alone, human oversight must be built in early rather than bolted on as an afterward fix. People must also tell the public early and clearly about each AI in use with rights or safety concerns, before it does something that changes a person’s situation.
For AI affecting civil rights, agencies must assess its effects before deployment.
This memo's deadlines were what gave it force. By December 1, 2024, agencies were required to ensure existing AI systems affecting rights complied with the memo’s requirements. M-24-18 added its own buying rules: they had to find deals involving AI that could touch on rights or endanger safety by November 1 of 2024, then fix each one, fresh or already running, to follow them by that same December 1 date.
The compliance plan requirement and how badly agencies missed the first deadline
Within 180 days of the memo's release, by September 24, 2024, every agency had to file a compliance plan with OMB, or a written statement that it doesn't use covered AI at all, and post it publicly.
The outcome was ugly. As of September 23, 2024, only about half of federal agencies had actually published a compliance plan, according to EPIC's analysis released that November. And the missing filings weren't the only concern EPIC raised: agencies that did submit fell short on transparency, often offering thin information about which AI deployments were in play and how those tools might affect someone's rights.
USAGM's plan demonstrates one approach to meeting the requirements, covering organizational areas and agency technology systems. The document defines what AI falls under the memo's rules, explicitly carving out simple automation. It lays out governance arrangements, use case inventory steps, timelines, funding, and workforce literacy efforts. It keeps use-case-specific practices in their own reporting lane under Section 5(c)(iv) plus (v) of the memo, with those practices folded into the annual inventory.
A 50% compliance rate on what amounts to a documentation exercise, filing a plan, not executing one, is a hard number to explain away. If putting plans on paper alone caused that much trouble, the more difficult tasks in practice (checking effects, having people look at calls, pulling the plug on systems that break the rules) were surely worse.
Where compliance stands as of 2026 and what the uneven picture means going forward
That memo, M-24-10, isn't operative anymore. A September 2026 check shows it was superseded by OMB Memorandum M-25-21, Accelerating Federal Use of AI via Innovation, Governance, plus Public Trust. M-24-10 was followed, not dropped, with its CAIOs, boards, and inventories carried forward into the next memo.
As 2026 starts, Compliance throughout federal agencies stays uneven. For agencies that are least-compliant, the results are harder to miss, while rules keep tightening, not loosening, as AI keeps outpacing how governance was built for it.
The throughline to close on is unequal funding. FedScoop's work says bigger federal bodies have moved into AI more quickly than smaller and middle-size ones, perhaps because of money and people as much as purpose. One memo used uniformly in any agency holding lots of AI systems or one with just a few was bound to hit unevenly. M-24-10 showed federal agencies could set enforceable rules for AI with deadlines that had teeth. But hitting those targets proved harder, and what we've seen suggests each agency hasn't done it.
Sources
- Federal Agencies Largely Miss the Mark on Documenting AI Compliance Plans as Required by AI Executive Order – EPIC – Electronic Privacy Information Center
- usagm.gov
- FTC Compliance Plan on Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence
- Compliance Plan for OMB Memorandum M-24-10
- federalreserve.gov
- bidenwhitehouse.archives.gov
- github.com


