GAO-25-107933 is a performance audit by the U.S. Government Accountability Office, authored by Kevin Walsh, Director of Information Technology and Cybersecurity, and dated September 9, 2025. Conducted between November 2024 and September 2025 under the statutory authority of the Comptroller General, it catalogs the federal AI compliance landscape as of July 2025. The report had two objectives: to describe AI-related requirements in laws, executive orders, and guidance, and to describe the roles and responsibilities of federal AI oversight and advisory groups.
Findings
GAO identified 94 AI-related government-wide requirements (or requirements with government-wide implications) drawn from 5 laws, 6 executive orders, and 3 guidance documents. It also identified 10 executive branch oversight and advisory groups that manage federal AI efforts.
On implementation, GAO reported that of the 35 recommendations it had made to 19 agencies in a 2023 report, only 4 had been implemented as of July 2025. OMB did not respond to GAO's comment request for this report.
Confidence is high for the existence of these requirements, given the authoritative government source; the report's implementation status is self-reported and GAO-audited as of July 2025, and is treated here with medium confidence.
The 94-requirement landscape
As of July 2025, the requirements were assigned across six categories of responsible party:
- OMB (15 requirements): issue guidance on AI use, inventories, acquisition, and training; maintain the Chief AI Officer Council; update guidance every 2 years through 2037.
- OSTP (9 requirements): lead the NAIAI Act; establish the NAIAI Office; provide science-and-technology advisory support.
- Commerce/NIST/NAIAC (~8 requirements): maintain NAIAC; develop and update the AI risk management framework (NIST AI Risk Management Framework (AI RMF 1.0)); develop technical standards.
- GSA (~5 requirements): operate the AI Center of Excellence; develop acquisition guidance; support knowledge sharing.
- NSF (~3 requirements): run AI scholarship programs; maintain a network of AI research institutes.
- All federal agencies (~53 collectively): produce annual AI use case inventories; designate Chief AI Officers; submit AI strategies (due September 30, 2025); adhere to AI acquisition guidance; and ensure LLM procurements comply with unbiased AI principles (EO 14319).
The 10 oversight and advisory groups
The report describes ten executive branch bodies, with their year of establishment and function:
- OSTP (1976) — advise the President on science and technology; coordinate R&D.
- NSTC (1993) — coordinate science-and-technology policymaking.
- NSTC Subcommittee on ML/AI (2016) — operations arm.
- Select Committee on AI (2018) — advise on AI R&D priorities.
- Committee on S&T Enterprise (2018) — advise NSTC.
- NITRD AI R&D IWG (2018) — coordinate AI R&D across 32 agencies.
- GSA AI Center of Excellence (2019) — convene agencies and industry on AI acquisition.
- NAIAI Office (2021) — point of contact for federal AI activity.
- NAIAC (2022) — external advisory body drawn from academia, civil society, and industry.
- PCAST (re-established January 2025) — co-chaired by the OSTP Director and the Special Advisor for AI & Crypto.
Implementation track record
GAO's 2023 report had made 35 recommendations to 19 agencies for implementing federal AI requirements. By July 2025, 4 had been implemented, including OPM's AI expertise rotational programs and DOT's submission of a consistency plan to OMB, plus two others. The remaining 31 recommendations were unimplemented across 16 agencies. GAO noted that OMB declined to respond to the comment request, which the report frames against OMB's own 15 requirements.
Policy transition
The report documents the Trump administration's 2025 AI policy changes in compliance terms. EO 14148 (January 2025) rescinded EO 14110, the Biden administration's October 2023 AI executive order. OMB memorandum M-25-21 replaced M-24-10, and M-25-22 replaced M-24-18. EO 14319 added "unbiased AI principles," described as ideological neutrality, to LLM procurement requirements. America's AI Action Plan (July 2025) was issued pursuant to EO 14179.
Provenance and connections
The report functions as an audit-level inventory of the federal AI governance landscape. It complements Executive Order 14179 — Removing Barriers to American Leadership in Artificial Intelligence, Executive Order 14319 — Preventing Woke AI in the Federal Government, and Executive Order 14320 — Promoting the Export of the American AI Technology Stack by setting out their concrete implementation requirements, and documents America's AI Action Plan in its legislative-requirement context. It connects to GSA OneGov Program and USAi Platform (August 2025) through the GSA AI Center of Excellence requirements, and reinforces NIST AI Risk Management Framework (AI RMF 1.0) as an ongoing compliance requirement that Commerce and NIST must update continuously rather than a one-time framework document. The finding that 31 of 35 recommendations remained unimplemented bears on Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race and Regulatory Typology: Self-Regulation, Co-Regulation, Traditional Government Regulation as an example of binding requirements with enforcement gaps. The report also documents the context of EO 14365, noting that PCAST was re-established in January 2025 with the Special Advisor for AI & Crypto.
Relationships
- supports: Executive Order 14179 — Removing Barriers to American Leadership in Artificial Intelligence, Executive Order 14319 — Preventing Woke AI in the Federal Government, Executive Order 14320 — Promoting the Export of the American AI Technology Stack, America's AI Action Plan
- supports: NIST AI Risk Management Framework (AI RMF 1.0) (as an ongoing compliance requirement, not just a framework document)
- instance-of: Regulatory Typology: Self-Regulation, Co-Regulation, Traditional Government Regulation (traditional regulation category — binding requirements with enforcement gaps)
- related: GSA OneGov Program and USAi Platform (August 2025), Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race, Regulating Under Uncertainty
- supports: Risk-Based AI Regulation (requirement landscape shows risk-based approach embedded in M-25-21)