Advancing American AI Act: OMB Memos, Compliance, and Executive Orders

The Advancing American AI Act is a federal law enacted in December 2022 that directs U.S. government agencies to accelerate their adoption of commercially proven artificial intelligence while protecting privacy, civil rights, and civil liberties. Introduced by Senator Gary Peters of Michigan as Senate Bill 1353 with Senator Rob Portman of Ohio as cosponsor, it was folded into the James M. Inhofe National Defense Authorization Act for Fiscal Year 2023 and signed on December 23, 2022.1Congress.gov. S.1353 Advancing American AI Act Cosponsors The Act’s provisions appear as Sections 7221 through 7228 of Public Law 117-263 and are codified as notes to 40 U.S.C. § 11301, which governs the OMB Director’s responsibilities over federal information technology.2Office of the Law Revision Counsel. 40 U.S.C. § 11301 Notes

What the Act Requires

The statute’s central push is to get federal agencies deploying leading-edge, commercially proven AI to improve mission effectiveness and cross-agency collaboration. Its obligations fall into a handful of categories, and a five-year sunset applies to the core AI policy and inventory requirements.3GovInfo. Senate Report 117-270

Public AI Use Case Inventories

Agency heads must create, maintain, and publish inventories of their AI use cases, making them available both to the public and to prospective vendors. Initial inventories were due within 60 days of enactment and must be maintained for five years. The Act also encouraged OMB to build a central, publicly accessible directory of use cases across the government.3GovInfo. Senate Report 117-270

Pilot Programs

OMB was directed to identify and lead the piloting of four new AI use cases within 270 days of enactment, drawing on commercially available technologies. At least one pilot had to focus on predictive supply chain and logistics capabilities such as disaster response, and at least one had to address management challenges like workforce upskilling or compliance. Within three years, the pilots were expected to produce AI capabilities that support interagency collaboration and cut reliance on manual data processing.3GovInfo. Senate Report 117-270

Procurement Changes

To make it easier for agencies to buy innovative AI from the private sector, the Act amended existing procurement authorities. It raised the dollar threshold for General Services Administration and Department of Homeland Security pilot programs for acquiring innovative commercial items from $10 million to $25 million. It extended the authority for both agencies to use commercial solutions opening pilot program procedures through September 30, 2027, and extended DHS “other transaction authority” for research and prototype projects through September 30, 2024.3GovInfo. Senate Report 117-270 The Act also encouraged GSA to pilot commercial off-the-shelf supply chain risk management tools that use AI to monitor and respond to threats.2Office of the Law Revision Counsel. 40 U.S.C. § 11301 Notes

DHS-Specific Obligations

The Secretary of Homeland Security had 180 days from enactment to issue department-wide policies on AI acquisition and use, specifically addressing privacy, civil rights, civil liberties, and protection against system misuse. The DHS Inspector General was directed to identify the training and investments its staff would need to audit and investigate AI-assisted systems effectively.3GovInfo. Senate Report 117-270

How OMB Is Implementing the Act

The statute hands OMB broad authority to set government-wide AI policy, and the operational rules agencies actually follow now live in OMB memoranda that have gone through two major versions.

M-24-10 (March 2024)

OMB’s first major guidance, Memorandum M-24-10, established the initial governance framework under the combined authority of the Advancing American AI Act, the AI in Government Act of 2020, and Executive Order 14110.4White House. M-24-10 Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence Each agency had 60 days to designate a Chief AI Officer and convene an AI Governance Board, and it had to begin flagging use cases as “safety-impacting” or “rights-impacting.” CFO Act agencies had 365 days to publish an enterprise AI strategy. M-24-10 named 28 specific purposes where federal AI use was presumed to be safety- or rights-impacting and therefore subject to impact assessments, real-world testing, ongoing monitoring, and human decision-making in the loop.5Center for American Progress. Taking Further Agency Action on AI

M-25-21 (April 2025)

On April 3, 2025, OMB replaced M-24-10 with Memorandum M-25-21, issued under the same statutory authorities plus Executive Order 14179. The core governance structure carried over, but timelines tightened. CFO Act agencies now have 180 days (down from 365) to publish an AI strategy, 90 days to convene governance boards, and 180 days to submit compliance plans, with fresh plans due every two years through 2036. Agencies must update internal policies on IT infrastructure, data, cybersecurity, and privacy within 270 days and issue a separate generative AI acceptable-use policy in the same window.6White House. M-25-21 Accelerating Federal Use of AI Through Innovation, Governance, and Public Trust

M-25-21 also created the Chief AI Officer Council, an interagency body chaired by the Federal Chief Information Officer. The Council coordinates AI implementation across the government, develops shared templates and technical resources, and promotes best practices. Membership includes agency Chief AI Officers and representatives from the White House Office of Science and Technology Policy and the Office of the Director of National Intelligence.7Councils.gov. Chief Artificial Intelligence Officers Council The Council carries a five-year sunset.6White House. M-25-21 Accelerating Federal Use of AI Through Innovation, Governance, and Public Trust

M-25-22 (Procurement)

OMB issued Memorandum M-25-22 the same day, directly implementing the Act’s acquisition provisions. It applies to contracts awarded under solicitations issued 180 days or more after its release.8White House. M-25-22 Driving Efficient Acquisition of Artificial Intelligence in Government Agencies must convene cross-functional teams for AI procurements, prioritize data portability and interoperability to reduce vendor lock-in, and prohibit contractors from using non-public agency data to train commercially available AI without agency consent. Contracts must spell out vendor testing procedures, and agencies cannot be barred from disclosing test results.

Where Agency Compliance Stands

By 2025, federal agencies had reported 3,611 AI use cases in their annual inventories, a nearly 70 percent jump from the 2,133 reported in 2024.9Center for Democracy & Technology. One Year Retrospective on the Federal Government’s Implementation of Updated AI Guidance Adoption is uneven, though, and gaps persist.

DHS convened its AI Governance Board on July 2, 2025, meeting the M-25-21 deadline. It has published annual use case inventories since 2022 and is working toward an April 2026 deadline for minimum risk management practices on all high-impact AI systems.10Department of Homeland Security. DHS Compliance Plan for OMB M-25-21 Of DHS’s 205 active use cases in 2025, however, 46 were tagged “presumed high-impact but determined not high-impact,” a new designation critics say clouds transparency.9Center for Democracy & Technology. One Year Retrospective on the Federal Government’s Implementation of Updated AI Guidance

Other agencies have fallen further behind. According to a June 2026 analysis by the Center for Democracy and Technology, the Department of Education and the Department of Justice failed to publish updated AI compliance plans and strategies. Justice’s 2025 inventory contained no information on risk management practices even though it labeled 114 of its 315 use cases high-impact. Health and Human Services reported less than one percent of its use cases as high-impact.9Center for Democracy & Technology. One Year Retrospective on the Federal Government’s Implementation of Updated AI Guidance Several agencies, including USDA, HHS, DHS, and the State Department, have consolidated AI governance oversight into a single individual rather than building cross-departmental review structures, which critics called short of the Act’s intent.

A Government Accountability Office report found that OMB’s guidance does not adequately specify the privacy-related risks agencies must consider when setting AI policies and fails to fully address eight expert-identified privacy challenges.11Government Accountability Office. GAO-26-107681

How Executive Orders Have Reshaped Implementation

On July 23, 2025, President Trump signed an executive order titled “Preventing Woke AI in the Federal Government” during the “Winning the AI Race” summit in Washington. The order directed agencies to stop contracting with AI developers whose models “manipulate responses in favor of ideological dogmas such as DEI,” defining that term broadly to include critical race theory, intersectionality, and “manipulation of racial or sexual representation in model outputs.”12STAT News. Trump AI Order on DEI Bias

OMB followed in December 2025 with a seven-page implementing memorandum. It laid out two “Unbiased AI Principles” for federal procurement of large language models: truth-seeking, emphasizing historical accuracy, scientific inquiry, and objectivity; and ideological neutrality, requiring LLMs to function as “neutral, nonpartisan tools.” Agencies had to update procurement policies by March 2026 and apply the requirements to new LLM procurements and, where practicable, existing contracts. The memorandum carries a two-year sunset.13Lawfare. OMB Releases Guidance on Trump’s ‘Woke AI’ Executive Order According to CDT, the ideological neutrality requirements have created uncertainty about which directives take precedence when they conflict with earlier OMB guidance issued under the Act itself.9Center for Democracy & Technology. One Year Retrospective on the Federal Government’s Implementation of Updated AI Guidance

Where the Act Sits Alongside Other AI Laws

The Act built on the AI in Government Act of 2020, which established an AI Center of Excellence within GSA and directed the Office of Personnel Management to update occupational job series for AI-related positions.2Office of the Law Revision Counsel. 40 U.S.C. § 11301 Notes In June 2024, Senators Peters and Thom Tillis introduced the PREPARED for AI Act, which they described as building on the Advancing American AI Act.14Senate Committee on Homeland Security and Governmental Affairs. Peters and Tillis Introduce Bipartisan Bill on AI Procurement That bill would add a mandatory risk classification system (unacceptable, high, medium, or low), require standardized “model card” documentation for procured AI, and give agencies the right to suspend AI use if risks become unacceptable. Its text says it would supersede any conflicting requirements in OMB guidance issued under the Advancing American AI Act.15Congress.gov. S.4495 PREPARED for AI Act Text As of December 2024, it had been reported to the Senate and placed on the calendar but had not received a floor vote.

The Advancing American AI Act does not itself mandate use of the NIST AI Risk Management Framework, but OMB’s guidance treats the framework as the de facto standard for federal AI governance, and agencies are expected to align their risk work with its four core functions: govern, map, measure, and manage.16NIST. Artificial Intelligence Bipartisan House legislation introduced in May 2026 would make agency use of the NIST AI RMF a legal requirement and direct NIST to recommend training standards for agencies acquiring AI systems.17FedScoop. Federal Agencies AI Guidelines NIST House Bill

The Act’s focus is federal government procurement and internal use. It does not regulate private-sector AI development or deployment outside government contracts, and it does not preempt state AI laws.