USUnited States (federal)In forceUS federal

What US federal AI policy requires

US federal AI policy (EO 14179, AI Action Plan, OMB M-25-21/22)

Status
In force
Binding
Yes
Object analysed
AI system
Requirements
4
Next milestone
2027

In short

No federal statute. Deregulatory policy since January 2025; duties limited to federal agencies (high-impact AI) and their procurement. Push to pre-empt state laws.

Steps to compliance

  1. Qualify each AI systemAxes to decide: High-impact AI (OMB M-25-21).
  2. Determine your roleDuties vary by role: Federal agency and Vendor.
  3. Apply the 4 requirementsThey focus on: Governance & accountability, Inventory & categorisation, Impact assessments and Accuracy & robustness.
  4. Prove it with checks9 checks to document, 9 of which also serve NIST AI RMF, ISO 42001 and RGPD.
  5. Track the deadlinesNext milestone: 2027, Federal pre-emption statute (potential).

Scope and penalties

Kind
Executive policy
Scope
Federal agencies and their vendors.
Territorial reach
Federal government.
Penalties
No direct penalty; contractual and budget conditions.
Jurisdiction
United States (federal)

Timeline

Oct 30, 2023EO 14110 (safe AI)
Jan 20, 2025EO 14110 revoked
Jan 23, 2025EO 14179: removing barriers to AI
Apr 3, 2025OMB memos M-25-21 (use) and M-25-22 (procurement)
Jul 23, 2025America's AI Action Plan
Dec 11, 2025EO on a national framework: challenge to state laws
Release
2027Federal pre-emption statutePotential
PastSet in the textPotentialTo verify

Qualifying a system

Classification axes and possible verdicts

High-impact AI (OMB M-25-21)

High impact on rights or safetyOther use

Requirements

4 requirements

CodeArticleRequirementApplies toChecks
USF-01M-25-21 §3Chief AI Officer and AI governance board
Federal agency
USF-02M-25-21 §3(b)Annual AI use case inventory
Federal agency
USF-03M-25-21 §4Minimum practices for high-impact AI: testing, impact assessment, oversight, monitoring, appeal
Federal agencyHigh-impact AI (OMB M-25-21)
USF-04M-25-22Procurement: data rights, lock-in prevention, performance
Federal agencyVendor

Checks to document

Evidence collected for a check counts for every regulation that uses it.

CodeCheckScopeThemesAlso used by
CHK-EXEC-ACCOUNTExecutive leadership is accountable for AI risk decisions (board committee, risk appetite)Organisation
CHK-ROLES-CLARIFIEDRoles, responsibilities and delegated authorities are documented and clear to relevant stakeholdersOrganisation
CHK-INVENTORYA mechanism to inventory AI systems is in place and resourcedOrganisation
CHK-IMPACT-ASSESSAn impact assessment is performed, documented and used in go/no-go and risk decisionsSystem
CHK-TEVVTEVV plan, test sets, metrics and data considerations are documentedSystem
VER-008-02System designed to allow human oversight (stop button, override)System
VER-021-F-01Operational monitoring planSystem
CHK-BR-CONTESTProcedure to contest a decision and obtain human review publishedOrganisation
CHK-THIRDPARTY-POLPolicies address third-party AI/data risks, incl. IP, transparency and testingOrganisation

Themes covered

Frequently asked questions

Who is in scope of US federal?

Federal agencies and their vendors. Federal government.

What penalties does US federal carry?

No direct penalty; contractual and budget conditions.

When do the US federal obligations apply?

Jul 23, 2025: America's AI Action Plan; Dec 11, 2025: EO on a national framework: challenge to state laws; 2027: Federal pre-emption statute.

Is US federal binding?

Yes. Kind: executive policy. Status: in force.

How does US federal relate to other regulations?

The same checks serve several texts. Shared checks: NIST AI RMF (8), ISO 42001 (6) and RGPD (4).

Related regulations

Official sources

Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo