Ask what US federal AI policy requires and you will get a list mixing executive orders, a strategy document, several OMB memoranda and a handful of NIST frameworks, as though they were the same kind of thing. They are not, and the differences decide whether something is a requirement, a direction or an aspiration.

Four instruments, four kinds of force

InstrumentExampleBinds
Statute AI in Government Act of 2020 Whoever it says. Changed only by Congress.
Executive order EO 14179, Removing Barriers to American Leadership in Artificial Intelligence (23 Jan 2025) The executive branch. Directs agencies; can be revoked by the next order.
OMB memorandum M-25-21, M-25-22, M-26-04 Agencies, with dated deadlines. This is where the requirements live.
Strategy document Winning the Race: America's AI Action Plan (23 Jul 2025) Nobody. It states intent and prompts other instruments.

Two consequences worth holding on to. A policy action announced in a strategy document is not a requirement until an order or memorandum creates one. And an executive order is not law: it directs the executive branch, and a later order can revoke it — EO 14179 revoked EO 14110 on the day it was signed.

What OMB M-25-21 actually requires

M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust, was issued on 3 April 2025 and signed by the OMB Director. It rescinds and replaces M-24-10, so any guidance built on that earlier memorandum is describing rescinded policy.

It is worth being precise about scope: the memorandum applies to agencies, and the Department of Defense and National Security Systems are exempt from its provisions.

The deadlines are in days, not dates

This is the detail that causes most of the confusion in secondary coverage. M-25-21 does not say "by 30 September 2025." It says "within 180 days of the issuance of this memorandum." Every published table of absolute dates is somebody's arithmetic, and the published tables do not agree with each other.

Counting from 3 April 2025:

As writtenWorks out asWhat is required
Within 60 days2 June 2025Each agency head must retain or designate a Chief AI Officer
Within 90 days2 July 2025Each CFO Act agency convenes its AI Governance Board; OMB convenes the Chief AI Officer Council
Within 180 days30 September 2025Each CFO Act agency develops an AI Strategy; agencies develop compliance plans (and every two years thereafter)
Within 270 days29 December 2025Agencies revisit and update internal policies; agencies should develop a generative AI policy
Within 365 days3 April 2026Agencies document implementation of the minimum practices for high-impact AI

Two further clocks run continuously rather than once: agencies must notify OMB within 30 days when the designated Chief AI Officer changes or the post falls vacant, and Chief AI Officers must report to OMB within 30 days of granting or revoking a waiver.

If you have seen a different set of dates, that is not surprising. At least two widely-circulated summaries give different dates for the Chief AI Officer deadline, and neither matches 60 days from 3 April 2025. Where a date matters to you, count it from the memorandum yourself.

High-impact AI is the concept that carries the weight

M-25-21 keeps a risk-tiering approach, with the heaviest obligations attaching to high-impact AI — the successor to the earlier memorandum's "safety-impacting and rights-impacting" category. Minimum practices, waiver procedures and the requirement to terminate non-compliant AI all hang off that classification.

For anyone selling into or working with an agency, this is the classification that determines how much scrutiny a system attracts. It is worth knowing which side of it your use case falls on before a procurement does.

The other two memoranda, briefly

  • M-25-22, Driving Efficient Acquisition of Artificial Intelligence in Government (3 April 2025), replaced M-24-18 and governs how agencies buy AI. It applies to solicitations issued on or after 30 September 2025, and brings cross-functional procurement teams, performance validation and pre-award testing for high-impact AI, and data and IP protections.
  • M-26-04 (December 2025) implements EO 14139 and requires agencies to include contractual terms about two "Unbiased AI Principles" — truth-seeking and ideological neutrality — in solicitations and orders for large language models. Agencies had to update their procurement policies by 11 March 2026, and the memorandum sunsets two years after issuance unless the OMB Director provides otherwise.

We cover the vendor-facing consequences of both in selling AI to the federal government.

Where NIST fits

NIST's AI Risk Management Framework and its profiles are voluntary. They are not a federal requirement, and describing them as one is a common error.

What makes them consequential is that other instruments point at them. Federal memoranda reference NIST work as the reference practice, and at least one state statute attaches a legal consequence to it — Texas frames an affirmative defence around an internal review process that substantially complies with NIST's Generative AI Profile. Voluntary at the federal level does not mean inconsequential.

What this means if you are not a federal agency

None of the above regulates private companies directly. It reaches you in three indirect ways, in descending order of immediacy:

  1. Through contracts. If you sell AI to an agency, M-25-22 and M-26-04 arrive as terms in the solicitation. That is the direct route.
  2. Through convergence. Pre-award testing, documentation and data-handling terms are the same demands enterprise buyers and insurers are making. Building for one largely serves the others.
  3. Through state law. Federal policy has moved away from binding private-sector constraints, which leaves states as the source of enforceable duties. See the state AI law map.

How to check any claim about federal AI policy

  1. Name the instrument. If a claim does not say which order, memorandum or statute it comes from, treat it as unsourced.
  2. Check what kind it is. Strategy documents do not create duties.
  3. Check it has not been rescinded. M-24-10 and M-24-18 were both replaced in April 2025, and content built on them is still circulating.
  4. Count the deadline yourself. The memoranda use periods from issuance; published date tables disagree.
  5. Check scope. Much of this applies to CFO Act agencies specifically, and the Department of Defense and National Security Systems sit outside M-25-21 entirely.

Nothing here is legal advice. Where a bid, a contract term or a compliance obligation turns on any of this, read the instrument and take advice from counsel experienced in federal practice.