←
AI for Government
Aware · M7 · lesson 7 of 31 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
📖
in this lesson

Government AI Policy Landscape

10 min

Priya Raman, a grants analyst at a federal agency's regional office, got a one-line email from her division chief: "Are we allowed to use the new AI tool for the quarterly report, or not?" Priya spent two hours hunting through executive orders, OMB memos, and an internal intranet page that contradicted itself. She came back with a shrug. That shrug is the problem. Across government, capable people freeze on AI not because they lack the skill, but because nobody has explained the rules in plain English. This lesson hands you that map, so the next time someone asks "are we allowed," you can answer in two minutes instead of two hours.

You do not need to memorize document numbers. You need to understand what the policy landscape is trying to do, who issues the rules, and how to find the one rule that applies to your task. Treat the named documents below as landmarks, not homework. And treat them as requirements rather than suggestions: this is not optional guidance, and non-compliance can produce audit findings, loss of funding, or worse. These policies exist because past AI deployments caused real harm, so the landscape is essentially a record of lessons other people learned the hard way.

The rules come in three layers

Government AI policy looks chaotic until you see that it stacks in three layers, each one narrower than the one above.

  • The White House layer. The President sets direction through executive orders. These say, in effect, "the government will use AI, and it will do so responsibly and safely." They are the why.
  • The OMB layer. The Office of Management and Budget turns that direction into binding rules for agencies through memos. OMB memos are the how: inventories, risk reviews, named officials, procurement standards. This is the layer that actually changes your day.
  • The agency layer. Your own agency translates OMB's rules into local policy: which tools are approved, what data you may enter, who signs off. This is the layer you live in.

When Priya got stuck, she was reading the top layer for an answer that lives in the bottom one. The chief's question, "can we use this tool," is almost always answered by agency policy, informed by OMB rules. Start at the bottom and work up only if you must. Policy in general is how government translates principles into requirements, and knowing the layers is how you tell what is required from what is merely advisable, what resources you are entitled to demand, and which lines you should not cross.

The landmarks worth knowing

Here are the documents people will name in meetings, in plain terms. Know what each one is for, not its full text.

LandmarkWhat it does, in plain English
Executive Orders (e.g. 14110, 14179)White House direction on using AI safely and seizing its benefits. Sets priorities; agencies must follow.
OMB M-24-10The core "how agencies manage AI" memo. Requires risk practices for AI that affects people's rights or safety, and accountability roles.
OMB M-24-18The companion on buying AI responsibly. Shapes how agencies procure AI from vendors.
OMB M-25-21 / M-25-22Later guidance refining how agencies use and acquire AI. Updates and extends the earlier memos.
NIST AI Risk Management FrameworkNot a rule but a widely used toolkit. The shared vocabulary agencies use to identify and manage AI risk.

One key idea cuts across all of them. The rules get stricter as the AI's impact on real people grows. A tool that drafts your meeting notes faces light scrutiny. A tool that helps decide benefits, enforcement or safety faces heavy scrutiny. Policymakers call these higher-stakes uses rights-impacting or safety-impacting AI, and they carry extra requirements such as testing, human oversight, and the right of a person to appeal. So the question is never just whether something is allowed. It is how much this use touches a real person's rights or safety, because that answer decides how many rules apply.

What Executive Order 14110 set up

Executive Order 14110, on safe, secure and trustworthy AI, dates from late 2023 and is the foundational one. It established a risk-based approach in which requirements scale with the stakes: using a language model to draft emails is low-risk, using AI to make benefit eligibility determinations is high-risk, and the same technology can sit in either bucket depending on what it decides. That single principle is why so much of what follows is conditional rather than uniform.

It also established four concrete expectations that shape agency life. Each federal agency must have a Chief AI Officer responsible for AI governance. AI systems must be tested before deployment, especially for high-risk applications. Agencies using AI must inform the public about what decisions the AI is influencing. And there are specific requirements to test for and mitigate bias and discrimination.

What that means for you is a set of questions you are entitled to ask out loud. Your agency should have an AI governance structure. If your agency is using or considering AI, ask whether it has been reviewed by the Chief AI Officer's office and whether bias testing has been done. If the answer to either is no, that is not a curiosity. That is a problem you have just found.

What OMB M-24-10 requires

OMB M-24-10, on advancing governance, innovation and risk management for agency use of AI, is the operational guidance, issued in 2024, and every federal agency must comply. Where the executive order says what government values, this memo says what agencies must actually do, which is why it is the one your compliance staff will quote at you.

It requires a governance structure with clear roles: who approves AI use, who oversees fairness, who has the authority to stop a deployment. It requires impact assessments before deploying AI that affects decisions about federal benefits, civil rights, civil liberties or safety. Those assessments document six things: what the system does, its risk level, testing for bias and fairness, human oversight mechanisms, appeal processes, and monitoring plans. It requires transparency and notification, so agencies tell the public when AI is influencing decisions about them rather than using it quietly. It requires human review for high-impact AI, where the machine provides input and a person decides. And OMB audits agencies for compliance.

For you, that means expecting impact assessments, governance reviews and public notification whenever your agency uses or proposes AI in that territory. None of it is optional, and none of it is something a project team can waive for itself because a deadline is close. It also means the paperwork is not the point. Each requirement maps to a way these systems have actually gone wrong: assessments because nobody wrote down what the thing does, bias testing because the harm fell unevenly, human review because a machine cannot be held to account, appeals because the person on the receiving end had nowhere to go, monitoring because performance drifts after launch.

Procurement, coordination and later guidance

OMB M-24-18 is the companion memo on buying AI responsibly, and it shapes how agencies procure AI from vendors. That matters more than it sounds, because most government AI is bought rather than built, and the moment to impose testing obligations, documentation duties and data-handling terms is while the contract is being written rather than after the system is live.

Alongside the formal memos, the OMB layer built coordination machinery: a community of practice for AI governance across federal agencies, regular reporting on agency AI use and risks, and work toward shared standards. The practical consequence is that you are not the first person in government to face your question. Your agency's Chief AI Officer should be plugged into that network, and lessons learned at one agency are supposed to travel.

OMB M-25-21 and M-25-22 extend and refine the earlier memos. They address emerging risks such as prompt injection, model manipulation and supply chain security; responsible AI innovation, meaning encouragement for agencies to pilot new uses while keeping safeguards in place; and international coordination with other democracies on AI governance. The direction of travel is worth noticing: government is being deliberate about both adopting AI and defending against AI-enabled threats, and those are not the same programme of work.

Beyond the federal layer

Federal policy is not the whole map. State and local governments run their own AI policies, and California has been among the most active states on AI governance, so a state or county employee may be working under requirements that have nothing to do with OMB. If you work at that level, your binding layer is your own jurisdiction's, with federal guidance as influence rather than instruction.

Two other instruments come up constantly. The EU AI Act regulates AI, including AI sold to government, and is stricter than United States federal policy, which matters to any agency buying from a vendor that also sells into Europe. And the NIST AI Risk Management Framework, in its version 1.0, is not a mandate but a standard that federal and many state agencies align with, providing structure for risk assessment and, just as usefully, a shared vocabulary so that a conversation between a lawyer, an engineer and a programme manager can converge.

The practical use of knowing this wider map is that it tells you which rules you can actually cite. A frontline employee arguing that a vendor tool needs testing is on firmer ground quoting the agency's own obligations than quoting a foreign statute, and a procurement officer negotiating with a multinational supplier has more leverage knowing that supplier already faces stricter obligations elsewhere. Policy knowledge is only useful at the point where it changes what someone does.

What this means for your daily work

Strip away the document numbers and the practical rules for a frontline employee come down to a handful of habits:

  • Use approved tools only. Your agency maintains a list. A free tool you found online is almost certainly not on it, and pasting government data into it may violate policy.
  • Mind the data. Never enter sensitive, classified or personally identifying information into a tool not cleared for it. This is the single most common way people get into trouble.
  • Keep a human in the loop on decisions. AI can draft and suggest. A person must review and decide anything that affects a citizen.
  • Disclose AI assistance when required. Many agencies require you to note when AI helped produce a work product.
  • Know your use case might be on the inventory. Agencies must catalog their AI uses. If your team builds or buys an AI use, it likely needs to be reported.

How the process actually runs

If your agency proposes a new AI system, the Chief AI Officer reviews and approves it. If it is high-impact, meaning it affects federal benefits, civil rights, civil liberties or safety, then an impact assessment is required, bias testing is required, public notification is required, human review is required, ongoing monitoring is required, and the agency reports annually to OMB. That is a long list on purpose. The requirements are proportional to the harm a wrong answer would do to a person who never chose to be processed by the system.

If you identify an AI problem, whether biased outcomes, errors affecting people or a security breach, report it to your Chief AI Officer or equivalent and document the issue. You have protections against retaliation under whistleblower protections. That sentence deserves emphasis rather than a footnote, because the most expensive government AI failures are almost always ones somebody noticed early and did not feel safe naming.

And if parts of your agency are running unapproved AI tools, sometimes called shadow AI, understand what that costs. It is not compliant with policy. It puts the agency at risk. And it puts you personally at risk if sensitive data leaks through a tool nobody vetted, because the accountability for the paste sits with the person who pasted.

How Priya answers in two minutes

Replay the email with the map in hand. Priya runs four quick questions:

  1. Is the tool on our agency's approved list? If no, the answer is no, full stop. If yes, continue.
  2. What data goes into it? The quarterly report uses aggregated grant figures, no personal data. Cleared.
  3. Does this use decide anything about a person? No. It summarizes spending, so on its face it is not rights-impacting. Note that this is a first read, not a self-issued risk classification: where the call is genuinely close, it belongs with the Chief AI Officer's office rather than with the analyst who wants the answer to be yes.
  4. Do we need to disclose and keep human review? Yes. Priya will note that AI assisted and will check the output herself.

Her reply to the chief: "Yes, with the approved tool, since we are only summarizing non-personal data. I will verify the figures and note that AI helped draft it." Two minutes, defensible, done, and if anyone later asks why she thought it was low-risk, the reasoning is written down rather than reconstructed.

Your quick decision card

Keep these four questions at your desk. They resolve most "are we allowed" questions without a single document lookup.

  • Is the tool on our agency's approved list?
  • Is the data I am entering free of sensitive, classified or personal information, or cleared for this tool?
  • Does this use make or influence a decision about a person? If yes, escalate for proper review and human oversight.
  • Will I disclose AI assistance and personally verify the output?

If you can answer those four cleanly, you are working inside the policy landscape rather than guessing at it. When any answer is unclear, that is not a reason to freeze. It is a reason to ask your agency's AI or privacy point of contact, which is itself the right move under the rules.

Anti-Patterns to Avoid

Policy failures in practice are rarely defiance. They are three specific shortcuts, plus the everyday habit that makes all three easier.

  • Governance theater. Conducting impact assessments to check a box rather than to address risks. The document exists, the risks do not get managed, and the assessment becomes evidence in the wrong direction when something goes wrong. Governance has to be genuine to be worth doing at all.
  • Avoiding the impact assessment. Deliberately classifying an AI system as low-risk so the assessment requirement never triggers. This is the anti-pattern to watch in yourself, because the person best placed to misclassify a system is the person who wants it deployed. Honesty about risk level is the whole basis of a proportional regime.
  • No appeals process. Deploying AI-influenced decisions without a meaningful route for affected people to contest them. People harmed by AI decisions have a right to appeal, and a process that exists only on an org chart is not one.
  • Shadow AI. Using unapproved tools because the approved one is slow or missing. It is non-compliant, it puts the agency at risk, and it transfers personal risk to you the moment sensitive data goes through it.
  • Reading the top layer for a bottom-layer answer. Priya's original two hours. Executive orders will not tell you whether your specific tool is approved; your agency's list will.

Practice Prompts

These are short and they will each surface something you did not know about your own agency.

  • Policy mapping. Determine whether your agency is subject to these federal policies. If it is, find out who your Chief AI Officer is by name, and how to contact that office.
  • Governance audit. Does your agency have AI governance? If so, review it against OMB M-24-10 and write down what is missing rather than what is present.
  • Impact assessment exercise. Pick a high-stakes decision your agency makes and draft what an impact assessment would have to cover: what the system does, risk level, bias and fairness testing, human oversight, appeals, monitoring.
  • Compliance timeline. Work out when your agency needs to be compliant with each requirement that applies to it, and when audits should be expected.
  • Accountability mechanism. If you identified an AI problem tomorrow, what exactly is the reporting process, and who is the first person you would tell?

Reflection

Answer these honestly, because each one exposes a gap that is cheaper to find now than during an audit.

  • Which layer do I actually work in, and do I know where my agency's approved tool list lives?
  • Have I ever assumed a use was low-risk because calling it high-risk would have slowed something down?
  • If a citizen affected by a decision my office makes asked whether AI was involved, could I answer accurately?
  • Do I know whether any tool my team uses is on the agency AI inventory, and who would put it there?
  • If I reported a problem tomorrow, do I believe the retaliation protections would hold, and what would make me more confident?

Glossary

  • Impact assessment. Documentation of what an AI system does, its risks, its testing and its safeguards. Required before deployment of high-impact systems.
  • Chief AI Officer. The designated leader responsible for AI governance in a federal agency.
  • High-impact AI. Systems affecting federal benefits, civil rights, civil liberties or safety, subject to the strongest requirements.
  • Rights-impacting and safety-impacting AI. The policy labels for higher-stakes uses that trigger extra obligations such as testing, human oversight and a right of appeal.
  • Human review. The requirement that a person examines AI-influenced decisions before they become final in high-impact cases.
  • Bias testing. Systematic evaluation of whether an AI system performs differently for different demographic groups.
  • Public notification. The requirement to inform citizens when AI is influencing decisions about them.
  • Shadow AI. Use of AI tools that the agency has not approved, outside the governance process entirely.

This lesson is the map. The ones below are the territory it points at.

Closing

You now have the framework, and the point of having it is to use it. When your agency makes decisions about AI, these rules apply whether or not anyone in the room can name them, so name them. Reference the requirements. Hold your agency accountable to the process it is already obliged to run, and hold yourself to it first.

The concrete next step is small. Find your agency's Chief AI Officer or AI governance point of contact. If that person does not exist, you have found something worth raising. If they do, you have found the answer to the next email that lands in your inbox asking whether something is allowed, and you will not need two hours to answer it.

Key Takeaways

  • Rules stack in three layers. The White House sets direction, OMB makes binding rules, your agency translates them locally. Start at the agency layer for everyday questions.
  • This is regulatory, not advisory. Non-compliance can produce audit findings, loss of funding and reputational damage, and the policies exist because earlier deployments caused harm.
  • Executive Order 14110 is the foundation. It established the risk-based approach, the Chief AI Officer role, pre-deployment safety testing, public transparency and bias testing.
  • OMB M-24-10 is the operational mandate. Governance roles, impact assessments, transparency and notification, human review for high-impact AI, and OMB audits for compliance.
  • Stakes drive scrutiny. The more a use touches a person's rights or safety, the more applies: testing, human oversight, appeals, monitoring and annual reporting.
  • Approved tools and clean data come first. Most violations are someone using an uncleared tool or entering sensitive data into the wrong place.
  • Keep a human on every decision, and disclose. AI may draft and suggest, but a person reviews and owns anything affecting a citizen, and agencies must tell the public when AI influences decisions about them.
  • Raise problems through the process. Report biased outcomes, errors and breaches to your Chief AI Officer, document them, and know that retaliation protections exist.
  • Four questions resolve most cases. Approved tool, safe data, decision impact, disclosure and review. Unclear answers mean ask, not freeze.

Frequently Asked Questions

Do I really need to know the memo numbers? No. You need to know what each layer does and where your answer lives. Executive orders set direction, OMB memos turn that into binding requirements, and your agency turns those into the approved tool list and sign-off rules you actually operate under. The numbers are useful when you need to look something up or point a colleague at the source, not as things to recite.

What makes a use "high-impact"? Whether it affects decisions about federal benefits, civil rights, civil liberties or safety. That classification is the trigger for the heavy requirements: impact assessment, bias testing, public notification, human review, ongoing monitoring and annual reporting. Because so much follows from the label, deliberately classifying a system as low-risk to avoid the work is one of the named anti-patterns in this area.

I work for a state or county, not a federal agency. Does any of this apply to me? Your binding layer is your own jurisdiction's policy. State and local governments run their own AI rules, and California has been among the most active. Federal guidance still matters as influence, and the NIST AI Risk Management Framework is deliberately not a mandate, which is exactly why many state agencies align with it voluntarily.

Our vendor says their product is compliant. Is that enough? No. Compliance is a property of your deployment, not of a product, and the obligations to assess impact, test for bias, notify the public and keep a human in the loop sit with the agency. The moment to build those expectations in is during procurement, which is what the buying-side guidance addresses, rather than after the system is live and the contract is signed.

What if I think an AI system in my agency is causing harm? Report it to your Chief AI Officer or equivalent and document what you observed, including dates, examples and who else has seen it. You have protections against retaliation. The requirement for appeals processes exists because people affected by AI-influenced decisions have a right to contest them, and an internal report is often what reveals that the appeal route was never actually built.