Skip to content

OMB Memorandum M-24-10 and What Replaced It

11 min read · updated August 11, 2026

M-24-10 is still the document most often cited for what a federal agency must do before deploying AI, and it has not been the governing memorandum since April 2025. The substance largely survived the replacement; the categories, the deadlines and the citation did not.

Start with the status

The Office of Management and Budget issued Memorandum M-24-10, Advancing Governance, Innovation, and Risk Management for Agencies’ Use of Artificial Intelligence, on 28 March 2024, implementing Executive Order 14110 of October 2023. A companion memorandum, M-24-18, addressed the acquisition of AI.

Executive Order 14179 of 23 January 2025 revoked Executive Order 14110. On 3 April 2025, OMB issued M-25-21 on the use of AI and M-25-22 on AI acquisition, replacing M-24-10 and M-24-18 respectively. Anything that cites M-24-10 as current authority was written before that date or has not been updated.

OMB memoranda are policy directed at executive agencies. They are not regulations, they create no private right of action, and they can be rescinded or replaced without notice or comment — as this pair demonstrates. Verify the current memorandum before relying on any requirement described here, and treat this page as background rather than legal advice. Current memoranda are published at OMB’s memoranda index.

The reason to understand M-24-10 anyway is that it is the origin of the vocabulary everyone in federal AI still uses, it remains the most detailed articulation of the practices, and vendors selling to agencies continue to be asked for artefacts defined by it.

Rights-impacting and safety-impacting

M-24-10’s central move was to define two categories of AI use and attach obligations to them rather than to the technology.

  • Safety-impacting AI — AI whose output serves as a principal basis for a decision or action with the potential to significantly affect human life or wellbeing, climate or environment, critical infrastructure, or strategic assets.
  • Rights-impacting AI — AI whose output serves as a principal basis for a decision or action affecting civil rights, civil liberties, privacy, equal opportunities, or access to critical government resources or services.

Two mechanisms made the categories operable. The memorandum listed purposes presumed to fall into each category — among them biometric identification, screening for benefits eligibility, decisions affecting employment, risk assessment in law enforcement and immigration — so that an agency had to rebut a presumption rather than build a case from scratch. And it turned on the phrase principal basis: AI that informs a decision a human makes on other grounds is treated differently from AI the decision actually rests on.

That phrase is where most classification arguments happen, and it has the same weakness as the equivalent concept in Article 22 of the GDPR. A human who approves nearly every recommendation is nominally deciding and functionally rubber-stamping. Neither instrument establishes a threshold at which nominal review stops counting, and neither agency practice nor case law has settled one.

The minimum practices

The operative requirement was a deadline with teeth: by 1 December 2024, an agency using safety-impacting or rights-impacting AI had to implement the minimum practices or stop using the system. Continued use required a waiver, individually justified by the agency’s Chief AI Officer, reported to OMB and published — a design that makes non-compliance visible rather than merely prohibited.

For both categories the practices were, in substance:

  • Complete an AI impact assessment documenting intended purpose, expected benefit, quality and appropriateness of the data, and potential impacts.
  • Test the system for performance in a real-world context, not only against a benchmark.
  • Independently evaluate it, by a body not directly involved in development.
  • Conduct ongoing monitoring and periodic human review after deployment.
  • Mitigate emerging risks to rights and safety as they appear.
  • Ensure adequate human training and assessment for the people operating and overseeing it.
  • Provide additional human oversight, intervention and accountability.
  • Provide public notice and plain-language documentation of the use.

Rights-impacting uses carried five further practices: identify and assess impacts on equity and fairness and mitigate algorithmic discrimination; consult affected groups and incorporate feedback; monitor for discrimination after deployment; notify individuals negatively affected and provide a means of human consideration and remedy; and maintain the option to opt out where practicable.

The governance scaffolding around them included a Chief AI Officer at each agency within sixty days, AI Governance Boards at CFO Act agencies, published compliance plans, and expanded public AI use case inventories. National security systems were carved out.

What M-25-21 changed

M-25-21 is framed around accelerating adoption while retaining risk management, and the significant structural change is to the categories. The two-category scheme was consolidated into a single class of high-impact AI, defined by reference to output serving as a principal basis for decisions with legal or similarly significant effects on individuals, again with a list of presumed uses.

The minimum-practice concept survived. A high-impact use requires pre-deployment testing, an AI impact assessment, ongoing monitoring, human oversight and a documented waiver process, with the memo setting its own compliance date and its own waiver and extension machinery. The Chief AI Officer role was retained but reoriented toward enabling adoption as well as managing risk. Several of M-24-10’s consultation and opt-out provisions did not carry across in the same form, which is the substantive difference rather than a matter of drafting.

M-25-22 addresses acquisition, with an emphasis on protecting government data from use in training without agreement, on avoiding vendor lock-in, and on performance-based requirements. Its practical consequences for a vendor are covered in the GSA page.

Deadlines in M-25-21 and M-25-22 are set relative to their April 2025 issuance and have their own extension provisions. Read the current text rather than a date quoted anywhere else, including here.

The obligations that survive a memo

The useful discipline when a memorandum is replaced is to ask which requirements had a statutory source, because those did not move.

  • AI use case inventories. The Advancing American AI Act, enacted as part of the FY2023 National Defense Authorization Act, directs agencies to prepare and maintain inventories of artificial intelligence use cases and to make them public where appropriate. Inventories are a statutory duty, not a memo artefact.
  • AI governance capacity. The AI in Government Act of 2020 established programme responsibilities within OMB and GSA that persist across administrations.
  • Privacy analysis. The E-Government Act of 2002 requires privacy impact assessments before developing or procuring information technology that collects identifiable information, and the Privacy Act of 1974 requires system of records notices. Neither has an AI exception, and both bite on exactly the systems the memos classify as high-impact.
  • Non-discrimination. Constitutional due process and equal protection constraints on government decisions, and the statutes implementing them, apply to a decision made with a model as they do to one made without.
  • Records. The Federal Records Act and agency schedules govern retention of what the system produced, and the Freedom of Information Act governs disclosure of it.

For a vendor, the practical translation is that artefacts should be built to the statutes and mapped to whichever memorandum is current. An impact assessment, a real-world test report, a monitoring plan and a model documentation package satisfy both memos and align with the NIST AI Risk Management Framework, which OMB has consistently pointed agencies toward. The general question of what evidence to keep is treated in the page on AI compliance evidence.