← Back to the Overview
Deep Dive · Federal AI Governance

The Evidence Map for the Federal AI Rules

The action layer behind the core verdict: how to move a federal AI use case toward sign-off without overstating what the memos, or the outcome evidence, support.

Source  Storm Research Verification  5 citation clusters checked Prepared for  Leader discussion
How to use this

Use this before a federal AI use case goes to a sponsor, an investment review, or a solicitation. The policy is openly pro-adoption, so the point is not to slow everything down. The point is to attach the right controls to the consequential uses and keep the compliance duty where the memos put it: inside the agency.

First moves before hiring anyone

01
Build one use-case record that survives intake, acquisition, deployment, and monitoring.

Capture the intended decision, principal-basis analysis, owner, scope and data boundary, high-impact result, evidence, and review date. The record turns the inventory into a control surface instead of a spreadsheet.

02
Separate must from should in every brief and proposal.

Mark M-25-21 must language, should language, exemptions, pilots, and waiver candidates. Never package optional governance features as if the memo requires them.

03
Make the high-impact call before the procurement is framed.

Use M-25-22's foreseeable-use analysis to request the supplier documentation an impact assessment needs. The determination, risk acceptance, and stop decision stay with the agency.

04
Design high-impact work to be reversible.

Test against real-world outcomes, name the independent reviewer and risk acceptor, train operators, define intervention and appeal, and rehearse safe discontinuance. Human in the loop is not a design specification.

05
Ask providers for evidence, not a compliance badge.

Request capability limits, data provenance and handling, performance results, test access or output evidence, monitoring support, and the M-26-04 contract terms where a large language model is procured. Treat any vendor compliance assertion as a claim to evaluate.

Owner, briefing, proof

Owner

An agency-named determination owner, risk acceptor, and chief AI officer chain. The duty never transfers to a supplier, whatever the contract says.

Briefing

A one-page read per use case: scope status, must versus should, the high-impact result, and the evidence gap that blocks sign-off.

Proof

A living record holding the testing, impact assessment, independent review, monitoring, and the rehearsed stop path.

Where to start

Start with one consequential use case and run it through the determination and evidence test. If the gap is material, widen to a readiness look at the inventory, determinations, waivers, and stop paths across the portfolio. Build the operating cadence only when the sponsor wants it run.

Claim ledger

5
Checked
citation clusters independently traced to primary sources on July 19, 2026
0
Fabricated
no invented or unsupported source clusters surfaced in verification
2
Corrected
the executive-order sequence and the M-26-04 scope narrowed after source review
0
Demoted
no claims dropped from the headline after checking; reliability labels stand
CorrectedExecutive Order 14148: This order, not EO 14179, revoked the 2023 AI executive order; the briefing corrected the attribution.federalregister.gov
ConfirmedExecutive Order 14179: Directed OMB to revise the 2024 memos; it did not revoke the prior executive order.whitehouse.gov
ConfirmedOMB M-25-21: Primary source for scope, chief AI officers, inventories, high-impact determinations, minimum practices, waivers, and discontinuance.whitehouse.gov
ConfirmedOMB M-25-22: Puts foreseeable-use and initial likely-high-impact analysis on the agency during acquisition, to the greatest extent practicable.whitehouse.gov
CorrectedOMB M-26-04: Read as a complementary LLM-procurement layer with defined scope and a two-year sunset, not the general baseline.whitehouse.gov
ConfirmedGAO-25-107653: Reported use cases grew from 571 to 1,110 and generative AI from 32 to 282 across 11 agencies; descriptive counts, not outcome evidence.gao.gov
Where the evidence stops

The verified base establishes what the memos require and where the duties sit. It does not establish that the required artifacts reduce real-world errors, rights harms, or safety incidents; the briefing holds that outcome question open. It also cannot show whether the promised human review and appeal paths work for the people they cover, and GAO reviews have found inventory quality and completeness uneven. Read published counts and plans as a floor for questions, not proof of safe operation.

What would change our mind
Deep Dive staged from verified Storm Research · nothing here asserts above the registry calibration