By Jennifer Mahoney, Director of Data Governance, AI Governance and Privacy
In today’s rapidly evolving technological landscape, private and public organizations are increasingly turning to artificial intelligence (AI) to enhance efficiency, drive innovation, and maintain global competitiveness. With the recent publication of key memos by the U.S. Office of Management and Budget (OMB), federal agencies and companies working with them should be prepared to align with new expectations to ensure compliance and capitalize on emerging opportunities. These policies emphasize the importance of responsible AI adoption and highlight the need for robust governance frameworks, privacy safeguards, and strategic procurement practices. As the federal government accelerates its AI initiatives, it is crucial for organizations to stay ahead of the curve and adapt to these transformative guidelines.
Key Background and Requirements
On April 7, 2025, the White House published a factsheet on two key memos recently published by the U.S. Office of Management and Budget (OMB) – M-25-21 Accelerating Federal Use of AI through Innovation, Governance, and Public Trust and M-25-22 Driving Efficient Acquisition of Artificial Intelligence in Government on AI procurement. These memos are follow-on to the January 23, 2025 Executive Order (E.O.) 14179, Removing Barriers to American Leadership in Artificial Intelligence.
The factsheet states, “[t]hese policies fundamentally shift perspectives and direction from the prior Administration, focusing now on utilizing emerging technologies to modernize the Federal Government… rather than pursuing the risk-averse approach of the previous administration.” While the memos are touted as a shift from the previous Administration, hallmarks of sound governance remain such that while there is an emphasis on AI enablement, activities must “[maintain] strong safeguards for civil rights, civil liberties, and privacy.”
Theme highlights include:
- Pro-Innovation Mindset:
- Shifting from risk-averse approaches to embrace emerging technologies.
- Maximizing the use of American AI systems to enhance efficiency and global competitiveness.
- Promoting Responsible AI Adoption (M-25-21):
- Agencies to redefine Chief AI Officer roles as advocates and change agents.
- Introduction of a “high-impact AI” category for heightened due diligence.
- Production of an AI adoption maturity assessment to track progress.
- Accountability aligned with existing government IT practices.
- Streamlined AI Acquisition (M-25-22):
- Policies encourage performance-based techniques and transparency.
- Avoidance of vendor lock-in and burdensome reporting requirements.
- Creation of shared repositories for AI procurement resources.
Three examples are provided where federal agencies have already maximized AI to “promote human flourishing”:
- Department of Veterans Affairs (VA) using AI for detection of lung cancer.
- Department of Justice (DOJ) using AI to address drug trafficking investigations.
- National Aeronautics Space Administration (NASA) using AI to navigate the Mars2020 Rover.
Each memo contains a number of required actions that apply to specific agencies or departments across the government. The shortest deadline (60 days) applies to the requirement to identify a Chief AI officer while select public reporting requirements begin in 180 – 365 days.
Required General Services Administration Actions (in coordination with OMB):
- Develop a plan to provide guidance to assist agencies with AI procurement (100 days)
- Develop web-based repository of tools and resources to enable AI procurement (200 days)
Required OMB Actions:
- Establish a Chief AI Officer Council, led by the Director of OMB (or designee) (90 days)
Required Actions by Each Agency:
- Retain or designate a Chief AI Officer (60 days)
- Achieve full compliance with the memos (180 days)
- Submit to OMB and release publicly an agency compliance plan to achieve compliance (or written determination that the agency does not use and does not anticipate using covered AI) (180 days and every two years until 2036)
- Identify process by which agencies will standardize treatment of data ownership and IP rights in procurements for AI systems or services as part of policy and process updates (200 days)
- Update internal policies on IT infrastructure, data, cybersecurity, and privacy (270 days)
- Develop a Generative AI policy (270 days)
- *Implement the minimum risk management practices for high-impact use cases of AI* (365 days)
- *Report to OMB any determinations and waivers that are granted or revoked (Annually and 30 days after significant modifications)
- *Publicly report determinations and waivers for AI use cases* (365 days)
- **Publicly release an AI use case inventory consistent with OMB instructions** (Annually)
Required Actions by Each Chief Financial Officers Act (CFO Act) Agency (per 31 U.S.C. §901(b)):
- Establish an AI Governance Board comprised of relevant agency officials (90 days)
- Develop and release publicly an agency strategy for removing barriers to the use of AI and advancing AI maturity (180 days)
* Excluding elements of the Intelligence Community.
** Excluding elements of the Intelligence Community. Department of Defense is exempt.
Key Steps to Prepare:
Companies that work with federal agencies continuing along a journey of implementing secure and responsible AI should be prepared to align with these expectations. The memos’ guidelines are likely to influence future AI regulation as 19 U.S. States are evaluating more than 40 legislative bills to shape development and use of AI. Steps to prepare may include:
- AI Governance Framework Development:
- Build frameworks for evaluating AI maturity, ensuring organizations meet the adoption maturity assessments required by M-25-21.
- Identify and categorize “high-impact AI” use cases for robust due diligence practices.
- Privacy and Risk Management:
- Implement mechanisms to safeguard privacy, civil rights, and civil liberties during AI adoption and procurement.
- Collaborate to assess risks tied to higher-impact AI scenarios.
- Vendor Compliance and Competition Support:
- Ensure AI solutions adhere to federal standards for accountability, performance-based acquisition, and competition.
- Develop procurement strategies that prevent vendor lock-in, aligning with M-25-22 guidance.
- Training and Education:
- Empower your organization with AI leadership training, ensuring compliance with redefined Chief AI Officer roles.
- Enable secure adoption of AI tools.
The new policies are phrased to champion a balanced approach—embracing rapid innovation without compromising safety, privacy, or rights. With thoughtful guidance, organizations can confidently navigate this landscape, fostering collaboration and strengthening ties between federal agencies and private industry.
How are you preparing for the federal government’s updated AI expectations?
At Arcova, our experts stand at the intersection of innovation and responsibility, guiding organizations as they leverage artificial intelligence to transform processes, maximize efficiency, and meet regulatory requirements.
Contact us to learn more about how Arcova can help you adapt and thrive under these retooled expectations. Let’s explore innovative solutions together!
