What US federal AI policy requires
US federal AI policy (EO 14179, AI Action Plan, OMB M-25-21/22)
- Status
- In force
- Binding
- Yes
- Object analysed
- AI system
- Requirements
- 4
- Next milestone
- 2027
In short
No federal statute. Deregulatory policy since January 2025; duties limited to federal agencies (high-impact AI) and their procurement. Push to pre-empt state laws.
Steps to compliance
- Qualify each AI systemAxes to decide: High-impact AI (OMB M-25-21).
- Determine your roleDuties vary by role: Federal agency and Vendor.
- Apply the 4 requirementsThey focus on: Governance & accountability, Inventory & categorisation, Impact assessments and Accuracy & robustness.
- Prove it with checks9 checks to document, 9 of which also serve NIST AI RMF, ISO 42001 and RGPD.
- Track the deadlinesNext milestone: 2027, Federal pre-emption statute (potential).
Scope and penalties
- Kind
- Executive policy
- Scope
- Federal agencies and their vendors.
- Territorial reach
- Federal government.
- Penalties
- No direct penalty; contractual and budget conditions.
- Jurisdiction
- United States (federal)
Timeline
Qualifying a system
Classification axes and possible verdicts
High-impact AI (OMB M-25-21)
Requirements
4 requirements
| Code | Article | Requirement | Applies to | Checks |
|---|---|---|---|---|
| USF-01 | M-25-21 §3 | Chief AI Officer and AI governance board | ||
| USF-02 | M-25-21 §3(b) | Annual AI use case inventory | ||
| USF-03 | M-25-21 §4 | Minimum practices for high-impact AI: testing, impact assessment, oversight, monitoring, appeal | ||
| USF-04 | M-25-22 | Procurement: data rights, lock-in prevention, performance |
Checks to document
Evidence collected for a check counts for every regulation that uses it.
| Code | Check | Scope | Themes | Also used by |
|---|---|---|---|---|
| CHK-EXEC-ACCOUNT | Executive leadership is accountable for AI risk decisions (board committee, risk appetite) | Organisation | ||
| CHK-ROLES-CLARIFIED | Roles, responsibilities and delegated authorities are documented and clear to relevant stakeholders | Organisation | ||
| CHK-INVENTORY | A mechanism to inventory AI systems is in place and resourced | Organisation | ||
| CHK-IMPACT-ASSESS | An impact assessment is performed, documented and used in go/no-go and risk decisions | System | ||
| CHK-TEVV | TEVV plan, test sets, metrics and data considerations are documented | System | ||
| VER-008-02 | System designed to allow human oversight (stop button, override) | System | ||
| VER-021-F-01 | Operational monitoring plan | System | ||
| CHK-BR-CONTEST | Procedure to contest a decision and obtain human review published | Organisation | ||
| CHK-THIRDPARTY-POL | Policies address third-party AI/data risks, incl. IP, transparency and testing | Organisation |
Themes covered
Frequently asked questions
Who is in scope of US federal?
Federal agencies and their vendors. Federal government.
What penalties does US federal carry?
No direct penalty; contractual and budget conditions.
When do the US federal obligations apply?
Jul 23, 2025: America's AI Action Plan; Dec 11, 2025: EO on a national framework: challenge to state laws; 2027: Federal pre-emption statute.
Is US federal binding?
Yes. Kind: executive policy. Status: in force.
How does US federal relate to other regulations?
The same checks serve several texts. Shared checks: NIST AI RMF (8), ISO 42001 (6) and RGPD (4).
Related regulations
Official sources
Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.