Table of Contents
Summarize and analyze this article with
Two memos set the federal AI baseline
On 3 April 2025, the Office of Management and Budget issued two companion memoranda that define federal AI governance: M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust, and M-25-22, Driving Efficient Acquisition of Artificial Intelligence in Government. They implement Executive Order 14179 and rescind the prior administration’s M-24-10 and M-24-18, but preserve the core architecture: Chief AI Officers, governance boards, public use-case inventories, and minimum risk practices for the highest-impact systems. For agencies, this is the operating baseline. For contractors in IT, data, and emerging technology, it is a preview of what the Federal Acquisition Regulation will eventually require in binding form.
This guide explains what the memos require and how to prepare. It is educational and not legal advice.
What M-25-21 requires of agencies
| Requirement | What it means |
|---|---|
| Chief AI Officer | Designate a CAIO to champion adoption, advise on investments, and support governance |
| Governance board | Establish an internal AI governance board and join the interagency CAIO council |
| AI use-case inventory | Maintain and publicly release an AI use-case inventory annually in the OMB format |
| Enterprise AI strategy | CFO Act agencies develop a public AI strategy on the OMB template within the set window |
| High-impact minimum practices | Apply minimum risk-management practices to AI presumed high-impact; document rebuttals and waivers to the CAIO |
What M-25-22 requires of AI acquisition
- A competitive American AI market. Favor high-quality, cost-effective, US-produced AI products and services.
- Protect taxpayer dollars. Track AI performance and manage risk across the contract, aligned to the M-25-21 high-impact practices.
- Data rights and IP. Bar the use of nonpublic government data to train external AI systems without agency consent, and protect contractor IP.
- Exit and transparency provisions. Update clauses, evaluation criteria, and statements of work for transparency, data rights, and exit.
The memos do not by themselves bind contractors; changes to the FAR and agency supplements will give AI-specific directives binding effect. The signal, though, is acceleration: agencies want more AI in production, and the contractors who internalize the framework now will move faster than those waiting for further guidance.
The inventory is the load-bearing artifact
The annual, public AI use-case inventory is where federal AI governance becomes concrete, and it is the deliverable most agencies and their contractors underestimate. It must capture AI across the agency, including embedded and acquired systems, identify high-impact uses, and support the minimum-practices and waiver process. Built well, it answers oversight in one export. Built reactively, it becomes a scramble to reconstruct what AI the agency runs and how it is governed. The same inventory discipline that regulated banks and insurers are adopting, scoring risk from the use case and capturing third-party systems, is what makes the federal inventory hold up.
Where PiTech fits
PiTech Solutions builds the AI governance and inventory infrastructure federal agencies and their contractors need: an AI use-case inventory in the OMB format that captures embedded and acquired systems, high-impact identification and minimum-practices evidence, and the data-rights and documentation controls M-25-22 pushes into acquisition. It brings the regulated-industries discipline of decision-based risk scoring and tested controls to the federal context. Delivery runs under CMMI Level 3 and ISO 27001, 9001, and 42001 certifications with FedRAMP-aligned practices, and PiTech holds federal contract vehicles including GSA MAS, OASIS+, SeaPort-NxG, Army RS3, and ITES-3S. See the government practice, AI, GenAI and ML, and Data Solutions. PiTech Solutions Inc. is headquartered in Durham, North Carolina (UEI GNLRY5LNNVH6, CAGE 530K4) and is distinct from similarly named companies.
The bottom line
Federal AI governance runs on M-25-21 and M-25-22: a Chief AI Officer, an annual public use-case inventory, minimum practices for high-impact AI, and acquisition rules on American-made AI, data rights, and exit. Build the inventory and the evidence now, before the FAR makes the directives binding.
Frequently Asked Questions (FAQs)
What are OMB M-25-21 and M-25-22?
They are two companion Office of Management and Budget memoranda issued on 3 April 2025 that set federal AI policy. M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust, governs how executive agencies use AI. M-25-22, Driving Efficient Acquisition of Artificial Intelligence in Government, governs how they acquire it. Together they implement Executive Order 14179 and rescind the prior administration’s M-24-10 and M-24-18, while preserving core elements such as Chief AI Officers, governance boards, public use-case inventories, and minimum risk practices for high-impact AI. They apply to executive departments and agencies, and M-25-22 shapes what the government expects from AI vendors and contractors.
What is a federal AI use-case inventory?
It is an inventory of an agency’s AI use cases that M-25-21 requires each agency to maintain and publicly release annually in the OMB-provided format. It gives the public and oversight bodies transparency into where and how the agency uses AI, identifies high-impact uses, and underpins the minimum-practices and waiver process. A complete inventory must capture AI across the agency, including systems embedded in acquired products, not just those the agency built. It is the load-bearing artifact of federal AI governance, because it is the single document that answers what AI the agency runs, and it is increasingly what oversight and contractors are measured against.
Who needs a Chief AI Officer under M-25-21?
Each federal executive agency must designate a Chief AI Officer. Under the 2025 framework the role is reframed as a change agent and AI advocate who champions adoption, advises on AI investments, and supports enterprise governance, rather than a layer of oversight bureaucracy. Agencies also establish internal AI governance boards and participate in an interagency CAIO council coordinated by OMB. For high-impact AI, agency officials document determinations, rebuttals, and waivers to the CAIO. A Chief AI Officer without budget, staff, or authority is a paper position, so the practical question for agencies is whether the CAIO is genuinely empowered to govern the AI portfolio the inventory describes.
What is high-impact AI under the federal framework?
High-impact AI is AI whose use is presumed to carry significant impact, based on a defined list of categories in M-25-21. Where a use case falls into one of those categories, it is presumed high-impact, and agency officials must either document to the Chief AI Officer to rebut the presumption or apply the minimum risk-management practices the memo requires, certifying waivers where appropriate. The minimum practices are intended to be the smallest set necessary for trustworthy, responsible use and to be understandable and implementable. Identifying high-impact uses is a core function of the use-case inventory, because those are the systems that carry the heaviest governance obligations under the framework.
How does M-25-22 affect AI contractors?
M-25-22 shapes federal AI procurement in ways contractors must anticipate: a preference for competitive, US-produced AI; requirements to track AI performance and manage risk consistent with the high-impact minimum practices; protection of contractor intellectual property alongside a bar on using nonpublic government data to train external AI without agency consent; and updated clauses, evaluation criteria, and statements of work covering transparency, data rights, and exit. The memos themselves do not directly bind contractors; changes to the Federal Acquisition Regulation and agency supplements will give AI-specific directives binding effect. Contractors who align to the framework now, especially on data rights and evidence, are better positioned as those binding changes arrive.
Do M-25-21 and M-25-22 apply to state or private organizations?
They apply directly to federal executive departments and agencies, not to state governments or private companies. However, they are widely treated as useful guidance beyond the federal context, because they codify a workable AI governance pattern, a Chief AI Officer, a use-case inventory, high-impact identification, and minimum practices, that private and state entities can adapt. For companies that sell AI to the federal government, the acquisition memo effectively reaches them through procurement, and eventual FAR changes will make certain expectations contractual. So while the direct legal scope is federal agencies, the practical reach extends to contractors and to any organization looking for an established governance template.
How is the 2025 federal framework different from the Biden-era memos?
The 2025 memos rescind and replace M-24-10 and M-24-18 but preserve much of their architecture: Chief AI Officers, governance boards, public inventories, and minimum practices for high-impact AI all remain. The changes are emphasis and framing. The Chief AI Officer is recast as an adoption champion rather than an oversight layer, the tone shifts toward accelerating AI use and reducing bureaucratic friction, and procurement moves from responsible-acquisition-and-vendor-disclosure language toward efficient acquisition with an American-made preference. Some references to bias present in the earlier memos are reduced. The continuity matters as much as the change: agencies that built to the prior framework retain most of the same load-bearing components under the new one.
How should an agency or contractor prepare now?
Build the inventory and the evidence before oversight or a binding FAR change forces it. For agencies, that means a complete AI use-case inventory in the OMB format that captures embedded and acquired systems, high-impact identification with documented minimum-practices and waivers, an empowered Chief AI Officer, and a public AI strategy where required. For contractors, it means refreshing acquisition templates, standard clauses, and statements of work for transparency, data rights, and exit, and being able to evidence AI performance and risk management. The organizations that internalize the framework proactively move faster than those waiting for further guidance, which is the explicit direction of federal AI policy.
How do EO 14179 and the OMB memos fit together?
Executive Order 14179, Removing Barriers to American Leadership in Artificial Intelligence, issued 23 January 2025, set the policy direction that the two OMB memos implement. M-25-21 and M-25-22, both issued 3 April 2025, operationalize that direction for federal agencies, governing AI use and AI acquisition respectively, and they rescind the prior administration’s M-24-10 and M-24-18. So the EO is the top-level policy and the memos are the implementing guidance beneath it. Because executive-branch AI policy can shift with further executive orders and OMB memoranda, agencies and contractors should track the current stack, later actions such as EO 14319 and subsequent OMB memoranda have already added requirements, and confirm what is operative at any given time.
Does PiTech help with federal AI governance?
Yes. PiTech Solutions builds the AI governance and inventory infrastructure federal agencies and their contractors need: an AI use-case inventory in the OMB format that captures embedded and acquired systems, high-impact identification and minimum-practices evidence, and the data-rights and documentation controls M-25-22 pushes into acquisition. It brings the regulated-industries discipline of decision-based risk scoring and tested controls to the federal context. Delivery runs under CMMI Level 3 and ISO 27001, 9001, and 42001 certifications with FedRAMP-aligned practices, and PiTech holds federal contract vehicles including GSA MAS, OASIS+, SeaPort-NxG, Army RS3, and ITES-3S. PiTech is positioned as a specialist federal AI governance and modernization partner.


