Last updated:
OMB Memorandum M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust, directs US federal agencies to appoint a Chief AI Officer, publish an AI use case inventory, and apply minimum risk management practices to "high-impact AI". Issued in April 2025, it replaced M-24-10 and is paired with M-25-22 on AI acquisition.
What counts as "high-impact AI"?
M-25-21, issued on 3 April 2025, replaced the earlier "rights-impacting" and "safety-impacting" categories from M-24-10 with a single category, high-impact AI. An AI use case is high-impact where its output serves as a principal basis for decisions or actions that materially affect rights, safety, access to government services, or significant agency operations. The consolidation has a practical effect: agencies now run one determination and one set of minimum practices, instead of maintaining two parallel classification tracks.
What must agencies do?
Designate a Chief AI Officer. Required by 30 June 2025. At CFO Act agencies the role must sit at Senior Executive Service, Scientific and Professional or equivalent level, with real budget and decision-making authority.
Publish an AI strategy and maintain a public AI use case inventory.
Apply minimum risk management practices to high-impact AI. These cover pre-deployment testing, ongoing monitoring, transparency and human oversight, both before deployment and continuously afterwards.
Discontinue non-compliant use cases. A high-impact use case that cannot meet the minimum practices must be stopped.
Waivers are available, but only by written determination from the CAIO, where compliance would itself increase risk to safety or rights, or create an unacceptable impediment to operations.
Who is in scope?
M-25-21 binds federal executive agencies. National security systems sit outside it. Its reach extends beyond government, because vendors selling AI into federal agencies inherit the evidence burden. An agency cannot classify and monitor a high-impact system it has no visibility into, so the documentation requirements pass to suppliers.
How does M-25-21 relate to M-25-22?
M-25-22 is the companion memorandum covering AI acquisition. M-25-21 governs how agencies use AI, and M-25-22 governs how they buy it. Vendors usually meet M-25-22 first, in procurement language, and M-25-21 second, in the ongoing evidence their agency customer has to keep producing. Both point at the same underlying requirement: a maintained record of what each AI system does, who owns it, and what testing supports it. That is a third-party AI risk management problem as much as an internal one.
Real world example:
A federal health agency plans to deploy an AI tool that prioritises patient appointment scheduling. Because the output materially affects access to a government service, the CAIO designates it high-impact. Before deployment the agency tests for demographic disparities, defines the human review step for any denied or deprioritised case, and publishes the use case in its public inventory. The vendor cannot supply performance data broken down by patient group, so the agency has no way to evidence the minimum practices, and the deployment is held until that data arrives.




