← Back to Insights
Advisory Brief · Federal AI Rules

The Federal AI Rules Require a System, Not a Product

A verified plain reading of the live federal AI-use policy: which obligations attach to a use case, which scope lines change them, and why procurement leaves the compliance duty with the agency.

Date  Jul 2026 Prepared as  Outcome brief ✓ Verified  5 citation clusters checked
Conditional sign-off verdict

It is safe to say yes to a federal AI use case only if the sponsor can show the decision system behind it: a named chief AI officer chain, a current use-case record, a written high-impact determination, and, where that determination lands high-impact, the documented evidence M-25-21 requires plus a rehearsed path to safely discontinue. A vendor can supply evidence toward that system. No purchase, badge, or human-in-the-loop label satisfies it.

The obligation ladder

Govern

Each covered agency keeps a chief AI officer. CFO Act agencies convene a governance board, and compliance plans post publicly through 2036.

Inventory

Agencies other than DoD and the Intelligence Community inventory AI use cases at least annually, report to OMB, and post a public version.

Determine

High-impact status turns on whether output becomes a principal basis for a consequential decision. A human reviewer does not settle it.

Prove and stop

High-impact uses carry documented testing, impact assessment, independent review, monitoring, trained operators, appeal where appropriate, and a safe stop.

The sign-off test

Owner

Who inside the agency owns the high-impact determination, the signed risk acceptance, and the authority to stop the use case?

Briefing

Which obligations on the table are must language, should language, exemptions, pilots, or waiver candidates under M-25-21?

Proof

Can the team produce the use-case record: intended decision, principal-basis analysis, boundary, evidence, review date, and stop path?

What leaders should take from it

1
Start from the current baseline, not the 2024 memo.

EO 14148, not EO 14179, revoked the 2023 AI executive order; EO 14179 directed the rewrite, and M-25-21 expressly replaced M-24-10. M-26-04 adds contract requirements for procured large language models. Advice built on the superseded memo misstates the obligation.

2
Governance is a standing management obligation with public artifacts.

Covered agencies keep a chief AI officer; most inventory their AI use cases at least annually and post public versions; compliance plans continue on a two-year cycle through 2036. Publication proves management attention, not that any listed use case is safe or effective.

3
The high-impact call follows the use case, not the reviewer.

M-25-21 says a use can be high-impact with or without human oversight, and presumed categories exit only through written notice to the chief AI officer. A human-in-the-loop label settles nothing.

4
High-impact means evidence plus a stop path.

Pre-deployment testing, a lifecycle impact assessment with independent review and signed risk acceptance, monitoring, trained operators, intervention, and appeal where appropriate. Noncompliant uses must be safely discontinued. Waivers exist, but only as written, tracked, publicly summarized decisions.

5
Procurement keeps the duty inside the agency.

M-25-22 asks the agency to frame foreseeable uses and make the initial likely-high-impact call; suppliers provide documentation to support that assessment, not a certification. GAO's count of reported federal use cases nearly doubled to more than 1,100, which shows scale, not proven safety or value.

Where the evidence stops

Three claims run ahead of the evidence: that a human reviewer makes a use case safe or non-high-impact, that a vendor product or attestation can carry an agency's compliance duty, and that the required artifacts have been shown to reduce real-world errors or rights harms. The policy reading is verified; the outcome evidence behind the controls stays open, and GAO reviews have found inventory quality uneven.

The Deep Dive holds the action map: the single use-case record, must-versus-should separation, the pre-procurement determination, reversible operating design, vendor evidence requests, the full claim ledger, and refresh triggers.

Open the Deep Dive
Outcome brief staged from verified Storm Research v2 · 5 citation clusters checked · 0 fabricated · 2 corrected · 0 demoted