OMB Memorandum M-24-10, titled "Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence," is a memorandum issued by the Executive Office of the President, Office of Management and Budget (OMB), on March 28, 2024. It establishes a federal-agency AI governance baseline built around three elements: designation of a Chief AI Officer (CAIO) at each covered agency, an annual public inventory of AI use cases, and a set of minimum practices for AI that is rights-impacting or safety-impacting. The memorandum was issued by then-OMB Director Shalanda Young pursuant to Section 10.1(b) of Executive Order 14110 (Executive Order 14110 — Safe, Secure, and Trustworthy AI), the AI in Government Act of 2020, and the Advancing American AI Act.
Status and timeline
The memorandum was issued March 28, 2024. It set a CAIO designation deadline of May 27, 2024 (60 days from issuance), required agency AI compliance plans approximately 180 days from issuance, and required the minimum practices for rights- and safety-impacting AI to be in place by December 1, 2024. The annual AI use-case inventory and its public posting are ongoing requirements.
Executive Order 14365 — Ensuring a National Policy Framework for AI revoked Executive Order 14110 — Safe, Secure, and Trustworthy AI but did not expressly revoke M-24-10. Practitioner analyses from Covington, Wiley, and Crowell, as of 2025, treat M-24-10 as presumptively in force, though the incoming administration had signaled that a rescission or revision was likely. The CAIO structure has bipartisan federal-procurement support and may survive in modified form.
Scope
M-24-10 applies to all Chief Financial Officers Act agencies (the 24 large federal civilian and defense agencies) and to other executive-branch agencies covered by OMB guidance. It expressly does not cover national security systems (subject to NSM-10, since partly rescinded), regulatory actions by independent agencies in their regulatory capacity, or Intelligence Community activities.
Definitions
The memorandum defines two categories of higher-risk AI. Rights-impacting AI produces outputs with a legal, material, binding, or similarly significant effect on rights, opportunities, or access to critical resources or services, including employment, housing, credit, government benefits, education, criminal justice, and healthcare. Safety-impacting AI is AI whose outputs could create or exacerbate substantial risk to human life, well-being, critical infrastructure, strategic assets, or the environment. The memo lists activities presumed to be rights- or safety-impacting (for example, facial recognition in law enforcement and risk assessment in benefits eligibility); agencies can rebut the presumption with a documented justification.
Key provisions
Chief AI Officer and governance board
Each covered agency must designate a CAIO within 60 days of issuance. The CAIO must be a senior career or political official with sufficient authority, and is responsible for coordinating AI adoption, managing AI risks, convening an AI governance board, interfacing with OMB, and chairing the Interagency CAIO Council established by the memorandum. Each agency must also establish an AI Governance Board, chaired by the CAIO, including senior leadership from mission, IT, procurement, civil rights, legal, privacy, and workforce functions.
AI use-case inventory
Agencies must maintain an annual inventory of AI use cases, publicly posted (with national security and law enforcement exclusions). Use cases must be tagged as rights-impacting, safety-impacting, both, or neither.
Minimum practices
For all rights- or safety-impacting AI, agencies must, before use and throughout deployment, complete an AI impact assessment; test the AI for performance in its real-world context; independently evaluate the AI; conduct ongoing monitoring; mitigate emerging risks; provide adequate human training; provide appropriate human consideration and oversight; and provide remedies for adverse decisions.
For rights-impacting AI, agencies must additionally identify and mitigate algorithmic discrimination; notify affected individuals when AI is used; provide a consultation and feedback opportunity; and provide an opt-out from AI use, with access to a human alternative where practicable.
These minimum practices were required by December 1, 2024. Failure to meet them by that date required the agency to either cease use of the AI system or seek an extension or waiver.
Waivers
A CAIO may grant waivers where applying the minimum practices would increase risk to safety or rights, or create an unacceptable impediment to critical agency operations. Waivers must be documented, reported to OMB, and posted publicly, with limited exceptions.
Removal of barriers to responsible use
Agencies are instructed to reduce internal barriers to AI adoption, including by providing appropriate infrastructure, generative-AI access for the workforce, and modernized IT procurement.
Relation to other instruments
M-24-10 governs federal-agency use of AI through internal governance plus binding minimum practices. It is the federal-agency analog of the private-sector frameworks: it imposes binding practice requirements rather than the voluntary guidance of the NIST AI RMF, and it is narrower than the EU AI Act's market-wide scope. The following table compares it with related instruments.
| Instrument | Regulates | Theory | Binding? |
|---|---|---|---|
| OMB M-24-10 | Federal agency use of AI | Internal governance + minimum practices | Yes (binds agencies) |
| OMB Memorandum M-24-18 | Federal agency acquisition of AI | Vendor/contract requirements | Yes (binds agencies) |
| Executive Order 14110 — Safe, Secure, and Trustworthy AI (rescinded in part) | Whole federal AI regime | Comprehensive strategy | Yes (revoked by Executive Order 14365 — Ensuring a National Policy Framework for AI) |
| Executive Order 14365 — Ensuring a National Policy Framework for AI | State AI regulation | Ceiling preemption | Yes |
| NIST AI Risk Management Framework (AI RMF 1.0) (when covered) | All organizations | Voluntary risk management | No |
| DoD Directive 3000.09 — Autonomy in Weapon Systems (source summary) | DoD autonomous weapons | Mission-specific | Yes (DoD only) |
| EU AI Act (Regulation 2024/1689) | Private-sector AI in EU | Risk-tier classification | Yes |
M-24-10 established the CAIO role as a government-wide position and created the first federal-agency-wide minimum-practices floor for AI with real-world harm potential. Its public AI use-case inventory is a transparency artifact that, according to practitioner analyses, is distinctive among major jurisdictions. Several states have since adopted analogous internal-AI-use orders for their executive branches.
Reactions and tensions
Practitioner and civil-society commentary has identified several points of tension in the memorandum's design and implementation:
- Rights-impacting scope versus operational burden. Agencies, particularly the Social Security Administration, the Department of Veterans Affairs, and the Centers for Medicare & Medicaid Services, noted that the broad rights-impacting presumption captures hundreds of decision-support tools, imposing heavy documentation loads.
- Opt-out impracticability. Many government functions, such as tax processing and benefits adjudication, cannot practically offer a human alternative at scale.
- Waiver transparency. Civil-society critics including the ACLU and the Center for Democracy & Technology have argued for stronger public transparency on waivers granted.
- Interaction with classified and Intelligence Community use. Exclusions for national security systems and IC activities leave some of the highest-risk federal AI domains under a separate, largely non-public regime.
- Durability across administrations. The memo was issued under a Biden-era OMB; a subsequent rescission or amendment could unwind the governance architecture quickly.
Relationships
- depends-on: Executive Order 14110 — Safe, Secure, and Trustworthy AI — implementing directive for Sec. 10.1(b)
- related: OMB Memorandum M-24-18 — acquisition analog; the two memos are a matched set
- related: Executive Order 14365 — Ensuring a National Policy Framework for AI — current EO regime; did not expressly revoke M-24-10
- related: NIST AI Risk Management Framework (AI RMF 1.0) — voluntary private-sector analog
- related: California SB 896 (Generative AI Accountability Act) — California state-government analog (state-employee generative-AI governance)
- related: US AI Regulatory Approaches Compared — federal-executive-branch dimension
Sources
- Text (PDF): https://www.whitehouse.gov/wp-content/uploads/2024/03/M-24-10-Advancing-Governance-Innovation-and-Risk-Management-for-Agency-Use-of-Artificial-Intelligence.pdf
- Secondary: Regulations.AI OMB M-24-10 entry; Covington & Burling (Oct 2024); govCDOiq; AHIMA AI regulatory resource guide; Carahsoft mirror of the PDF
- DoD Statement on Compliance with M-24-10 (ai.mil)