AI Policy Wiki
Dashboard

OMB Memorandum M-24-18

high confidence · updated 2026-06-06

OMB memorandum (Oct 3, 2024) governing federal AI acquisition: vendor requirements, contract clauses, data protections, generative-AI procurement standards, and competition provisions. Complements M-24-10 on the acquisition side.

OMB Memorandum M-24-18, titled "Advancing the Responsible Acquisition of Artificial Intelligence in Government," is a U.S. Office of Management and Budget memorandum issued October 3, 2024 that governs how federal civilian agencies acquire AI systems and services. It sets vendor requirements, contract clauses, data protections, generative-AI procurement standards, and competition provisions, and serves as the acquisition-side complement to OMB Memorandum M-24-10, which governs federal AI use. It was issued pursuant to the Advancing American AI Act and Section 10.1(f) of Executive Order 14110 — Safe, Secure, and Trustworthy AI.

Status and timeline

The memorandum was dated September 24, 2024 and issued October 3, 2024. Its implementation deadlines ran in sequence: agencies were to inventory existing rights-impacting and safety-impacting AI contracts by November 1, 2024; bring existing contracts into compliance by December 1, 2024; and apply the memorandum's terms to new solicitations from March 23, 2025 onward.

The memorandum was not expressly revoked by Executive Order 14365 — Ensuring a National Policy Framework for AI. As with OMB Memorandum M-24-10, it remains in effect under the current executive-order regime but is widely expected to be revised.

Scope and definitions

M-24-18 applies to all federal civilian acquisitions of AI systems and services, covering general AI acquisitions, generative AI systems and services, AI-enabled biometric systems, and rights-impacting or safety-impacting AI systems and services as defined in OMB Memorandum M-24-10. It does not apply to the Department of Defense's combat-related AI acquisitions, which are governed separately under DoD Directive 3000.09 — Autonomy in Weapon Systems (source summary) and Chief Digital and Artificial Intelligence Office (CDAO) policies, nor to Intelligence Community (IC) procurements.

Key provisions

The memorandum states three strategic goals: to manage AI risk and performance through required contract terms; to drive cross-functional and interagency collaboration, with Chief AI Officers (CAIOs), CIOs, CFOs, and senior procurement executives coordinating; and to promote a competitive AI market through acquisition methods designed to prevent vendor lock-in.

Vendor and contract requirements

On data rights and protections, agencies must require vendors to provide "appropriate handling, access, and use" of agency data, defined to include input data, prompts, processed data, output data, weights, and models. Agencies must opt out of or prohibit contractor use of agency data to train AI without explicit agency consent, and vendors must meet agency privacy, security, and confidentiality standards.

On documentation and disclosure, contracts must require disclosure of training-data categories, model capabilities and limitations, testing and evaluation documentation, and known risks. For rights-impacting AI, agencies must disclose M-24-10's notice and appeal requirements to contractors and require their cooperation.

On incident reporting, vendors must notify agencies of material AI incidents — including performance degradation, security incidents, and unsafe outputs — within agency-specified timelines.

On testing and ongoing evaluation, pre-award testing and post-award monitoring are required, and vendors must cooperate with independent evaluation.

Generative AI best practices

A separate section addresses procurement of enterprise-wide generative AI. It calls for contractual requirements to provide transparency about generated content (source attribution and provenance), to protect against inappropriate use through agency-defined prompt controls and guardrails, to prevent harmful and illegal output, to provide evaluation and testing documentation, and to mitigate environmental impacts. The environmental-impact provision asks for water and energy disclosures for large-scale generative-AI deployment, the first formal federal acquisition requirement to address AI resource consumption; operationalizing it across water, power, and embodied carbon remains under-specified.

Biometric AI

AI-enabled biometric systems carry heightened requirements: testing for demographic-performance disparities, documentation of false-positive and false-negative rates by demographic group, and alignment with NIST AI Risk Management Framework (AI RMF 1.0) and, where applicable, NIST AI 600-1 — Generative AI Profile (the generative-AI profile).

Competition provisions

To reduce lock-in, the memorandum encourages contract terms for knowledge transfer, including open-source licenses for vendor models and datasets where practicable; transparent pricing with disaggregated line items; and interoperability and data-portability clauses. It permits multiple-award and modular contracting for AI.

Obligations by actor

M-24-18 is the acquisition-side complement to M-24-10's use-side governance. An agency using a rights-impacting AI system acquired from a vendor must comply with M-24-10's minimum practices, and the vendor contract must support that compliance under M-24-18.

The memorandum binds federal civilian agencies as buyers and, through them, imposes contractual obligations on vendors. Several implementation tensions follow from this structure. The opt-out from contractor training on agency data departs from prior practice, under which vendors historically used customer usage logs for model improvement; contract renegotiation under the requirement has been significant. The knowledge-transfer and open-source provisions push toward more open defaults, which major vendors including OpenAI, Anthropic, Microsoft, and Google have resisted with respect to open-weight disclosure. Pass-through of M-24-18 obligations is also complicated by contracting structure: tier-one model providers typically reach agencies through cloud resellers such as Microsoft Azure, Google Cloud, and AWS Bedrock, and propagating the memorandum's obligations through multi-tier contracts is legally complex. Because DoD and the IC maintain parallel AI-acquisition policies (CDAO, the Defense Innovation Unit, and IC procurement) not bound by M-24-18, the federal AI buyer baseline is uneven across government.

Comparison with other instruments

M-24-18 governs the acquisition side, shaping the federal AI market from the buyer's position. It does not regulate private-sector AI use directly, but because the federal government is the largest single AI customer in the United States, its requirements function as a de facto floor for commercially available federal-grade AI. The memorandum was the first government-wide AI-specific acquisition policy in the United States, and it established data-use and environmental-impact disclosure as contract-award criteria. By making federal-contract eligibility conditional on the included practices, it indirectly reaches private-sector AI. Some other large buyers — states, EU member states, and allied governments — have begun to mirror the approach.

InstrumentAddressesLevel
OMB M-24-18Federal agency acquisition of AIFederal (binding on agencies)
OMB Memorandum M-24-10Federal agency use of AIFederal (binding on agencies)
BIS Framework for AI Diffusion — Interim Final Rule (Jan 13, 2025)Export of AI models / chipsFederal (binding on private actors)
EU AI Act (Regulation 2024/1689)Private-sector AI in EUEU (binding on private actors)
EU General-Purpose AI Code of Practice (Final Version, 2025)General-purpose AI models in EUEU (voluntary for GPAI providers)

Relationships

Sources

  • Text (PDF): https://www.whitehouse.gov/wp-content/uploads/2024/10/M-24-18-AI-Acquisition-Memorandum.pdf
  • Secondary: Covington & Burling (Oct 2024); Wiley (Oct 2024); Mintz AI: The Washington Report (Oct 2024); Perkins Coie client alert; Ropes & Gray (Apr 2025); Crowell & Moring; Epstein Becker Green
  • Fact sheet: OMB/White House (archived, Oct 3, 2024)