The Federal AI Rules Require a System, Not a Product
A verified plain reading of the live federal AI-use policy: which obligations attach to a use case, which scope lines change them, and why procurement leaves the compliance duty with the agency.
It is safe to say yes to a federal AI use case only if the sponsor can show the decision system behind it: a named chief AI officer chain, a current use-case record, a written high-impact determination, and, where that determination lands high-impact, the documented evidence M-25-21 requires plus a rehearsed path to safely discontinue. A vendor can supply evidence toward that system. No purchase, badge, or human-in-the-loop label satisfies it.
The obligation ladder
Each covered agency keeps a chief AI officer. CFO Act agencies convene a governance board, and compliance plans post publicly through 2036.
Agencies other than DoD and the Intelligence Community inventory AI use cases at least annually, report to OMB, and post a public version.
High-impact status turns on whether output becomes a principal basis for a consequential decision. A human reviewer does not settle it.
High-impact uses carry documented testing, impact assessment, independent review, monitoring, trained operators, appeal where appropriate, and a safe stop.
The sign-off test
Owner
Who inside the agency owns the high-impact determination, the signed risk acceptance, and the authority to stop the use case?
Briefing
Which obligations on the table are must language, should language, exemptions, pilots, or waiver candidates under M-25-21?
Proof
Can the team produce the use-case record: intended decision, principal-basis analysis, boundary, evidence, review date, and stop path?
What leaders should take from it
EO 14148, not EO 14179, revoked the 2023 AI executive order; EO 14179 directed the rewrite, and M-25-21 expressly replaced M-24-10. M-26-04 adds contract requirements for procured large language models. Advice built on the superseded memo misstates the obligation.
Covered agencies keep a chief AI officer; most inventory their AI use cases at least annually and post public versions; compliance plans continue on a two-year cycle through 2036. Publication proves management attention, not that any listed use case is safe or effective.
M-25-21 says a use can be high-impact with or without human oversight, and presumed categories exit only through written notice to the chief AI officer. A human-in-the-loop label settles nothing.
Pre-deployment testing, a lifecycle impact assessment with independent review and signed risk acceptance, monitoring, trained operators, intervention, and appeal where appropriate. Noncompliant uses must be safely discontinued. Waivers exist, but only as written, tracked, publicly summarized decisions.
M-25-22 asks the agency to frame foreseeable uses and make the initial likely-high-impact call; suppliers provide documentation to support that assessment, not a certification. GAO's count of reported federal use cases nearly doubled to more than 1,100, which shows scale, not proven safety or value.
Three claims run ahead of the evidence: that a human reviewer makes a use case safe or non-high-impact, that a vendor product or attestation can carry an agency's compliance duty, and that the required artifacts have been shown to reduce real-world errors or rights harms. The policy reading is verified; the outcome evidence behind the controls stays open, and GAO reviews have found inventory quality uneven.
The Deep Dive holds the action map: the single use-case record, must-versus-should separation, the pre-procurement determination, reversible operating design, vendor evidence requests, the full claim ledger, and refresh triggers.
Open the Deep Dive