The Evidence Map for the Federal AI Rules
The action layer behind the core verdict: how to move a federal AI use case toward sign-off without overstating what the memos, or the outcome evidence, support.
Use this before a federal AI use case goes to a sponsor, an investment review, or a solicitation. The policy is openly pro-adoption, so the point is not to slow everything down. The point is to attach the right controls to the consequential uses and keep the compliance duty where the memos put it: inside the agency.
First moves before hiring anyone
Capture the intended decision, principal-basis analysis, owner, scope and data boundary, high-impact result, evidence, and review date. The record turns the inventory into a control surface instead of a spreadsheet.
Mark M-25-21 must language, should language, exemptions, pilots, and waiver candidates. Never package optional governance features as if the memo requires them.
Use M-25-22's foreseeable-use analysis to request the supplier documentation an impact assessment needs. The determination, risk acceptance, and stop decision stay with the agency.
Test against real-world outcomes, name the independent reviewer and risk acceptor, train operators, define intervention and appeal, and rehearse safe discontinuance. Human in the loop is not a design specification.
Request capability limits, data provenance and handling, performance results, test access or output evidence, monitoring support, and the M-26-04 contract terms where a large language model is procured. Treat any vendor compliance assertion as a claim to evaluate.
Owner, briefing, proof
Owner
An agency-named determination owner, risk acceptor, and chief AI officer chain. The duty never transfers to a supplier, whatever the contract says.
Briefing
A one-page read per use case: scope status, must versus should, the high-impact result, and the evidence gap that blocks sign-off.
Proof
A living record holding the testing, impact assessment, independent review, monitoring, and the rehearsed stop path.
Start with one consequential use case and run it through the determination and evidence test. If the gap is material, widen to a readiness look at the inventory, determinations, waivers, and stop paths across the portfolio. Build the operating cadence only when the sponsor wants it run.
Claim ledger
The verified base establishes what the memos require and where the duties sit. It does not establish that the required artifacts reduce real-world errors, rights harms, or safety incidents; the briefing holds that outcome question open. It also cannot show whether the promised human review and appeal paths work for the people they cover, and GAO reviews have found inventory quality and completeness uneven. Read published counts and plans as a floor for questions, not proof of safe operation.
- OMB rescinds, supersedes, materially amends, or issues binding implementation instructions for M-25-21, M-25-22, or M-26-04.
- A new executive order changes the agency AI governance baseline.
- OMB's detailed inventory, compliance-plan, or public-summary instructions change the required fields or the disclosure boundary.
- GAO, an inspector general, or OMB publishes cross-agency evidence that determinations, waivers, or minimum practices diverge from this plain reading.
- A well-designed government study measures whether the required assessment, oversight, or appeal controls change rights, safety, accuracy, or service outcomes.