AI for Government
Visionary · M34 · lesson 34 of 47 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
OMB M-24-10 Deep Dive: Full Implementation
📖
now learning

OMB M-24-10 Deep Dive: Full Implementation

15 min

Learning Objectives

After this lecture, agency leaders will be able to: (1) state the scope and effective dates of OMB Memorandum M-24-10, issued March 28, 2024 as 'Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence,' and its relationship to Executive Order 14110 (October 30, 2023), the NIST AI Risk Management Framework, OMB M-24-18 (procurement), and subsequent CAO guidance; (2) identify the three pillars, Strengthening AI Governance, Advancing Responsible AI Innovation, Managing Risks from the Use of AI, and the sections within each; (3) apply the Section 5 definitions to classify each agency AI use case as safety-impacting, rights-impacting, both, or neither, using Appendix I presumptions (including examples such as law-enforcement AI, critical-infrastructure monitoring, health diagnostics, employment screening, and public-benefits eligibility determinations); (4) operationalize the Section 5(c) minimum practices, AI impact assessments, real-world testing, independent evaluation, ongoing monitoring, training, notice to individuals, plain-language explanations, opt-out and human alternative where feasible, and appeal mechanisms, against concrete agency programs; (5) establish the M-24-10 governance architecture (Chief AI Officer, AI Governance Board, cross-agency CAO Council) and integrate it with existing CIO, CISO, SAOP, civil-rights, and procurement functions; (6) execute the public-reporting obligations including the annual AI Use Case Inventory under Section 3 and waiver reporting under Section 5(c)(v); and (7) map M-24-10 obligations to the NIST AI RMF functions (Govern, Map, Measure, Manage) and to operational artifacts (playbooks, SOPs, templates).

Key Topics Covered

Section 1 - Purpose and Scope, including applicability to CFO Act and non-CFO Act agencies, national-security exclusions under NSM-10, and the EO 14110 anchor. Section 2 - Strengthening AI Governance: CAO designation, AI Governance Board requirements, CAO Council participation, and integration with the Federal CIO Council's AI Community of Practice. Section 3 - AI Use Case Inventory: the annual public disclosure, the integration with agency AI strategy, and the specific data elements (use-case descriptions, risk classifications, vendor relationships, decommissioning plans). Section 4 - Advancing Responsible AI Innovation: agency AI strategies, removing barriers to responsible adoption, workforce planning, and sharing of AI code and models under EO 14110 Section 10.1. Section 5 - Managing Risks from the Use of AI: the heart of the memo, including the definitions of safety-impacting and rights-impacting AI, the minimum practices, waiver mechanics, and Appendix I presumptions. Integration with OMB M-24-18 on procurement, FedRAMP authorization baselines for AI SaaS, FISMA system authorization, Privacy Act System of Records Notice (SORN) obligations, Section 508 accessibility, Section 504 disability accommodation, Title VI civil-rights obligations, and the constitutional due-process baseline from Goldberg v. Kelly and Mathews v. Eldridge. Agency-specific illustrations: VA clinical AI, IRS taxpayer-service AI, HHS CMS prior authorization (CMS-0057-F), DOJ and DHS law-enforcement AI, SSA disability determinations, DOL UI fraud detection, VA benefits adjudication, SBA loan processing, USDA SNAP eligibility, ICE and CBP border AI. This lecture is operational: by the end you will have templates and sequencing for your agency's 30-60-90-180-365 day compliance plan.

Why This Matters for Government

OMB Memorandum M-24-10 Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence (issued March 28, 2024) is the single most important federal AI governance document for agency implementers because it translates Executive Order 14110 (October 2023) direction into specific agency duties with deadlines, Chief AI Officer accountability, public reporting, and waiver discipline. It replaced the earlier M-21-06 framework and sits alongside NIST AI RMF 1.0 (January 2023), the NIST Generative AI Profile NIST AI 600-1 (July 2024), OMB M-24-18 (October 2024) on AI procurement, OMB M-22-18 and M-23-16 on software supply chain attestation, OMB Circular A-130 on information resource management, FISMA and NIST SP 800-53, the Privacy Act of 1974, Section 508 of the Rehabilitation Act, the Paperwork Reduction Act, the E-Government Act of 2002 Section 208 on Privacy Impact Assessments, and the existing record of EO 13960 on trustworthy AI in federal agencies. The memo does four things at once: it establishes the governance architecture (Section 2) including the CAIO designation and the agency AI Governance Board; it mandates public transparency through the AI Use Case Inventory (Section 3); it pushes agencies toward responsible innovation (Section 4) including shared resources, generative AI pilots, and cross-agency talent; and it imposes hard risk-management requirements on safety-impacting and rights-impacting AI (Section 5) with a minimum-practices floor and a narrow, documented waiver pathway approved by the CAIO and reported to OMB.

Every federal leader working on AI must know the memo by section number rather than by headline. Section 3 requires each CFO Act agency to designate a CAIO within sixty days of issuance (by May 27, 2024), convene an AI Governance Board, publish and annually update the use-case inventory, and submit a compliance plan to OMB. Section 4 directs agencies to reduce barriers to responsible AI innovation including through shared services, talent flexibilities (Title 5 details, IPAs, Presidential Innovation Fellows, USDS tours), and pilots involving generative AI under appropriate controls. Section 5 establishes the minimum practices for safety-impacting and rights-impacting AI including completion of AI Impact Assessments, testing for performance in a real-world context, independent evaluation, ongoing monitoring, mitigation of emerging risks, and accessible human alternatives, remediation, and opt-out where consistent with law. The memo's definitions for safety-impacting AI (systems whose output could meaningfully influence decisions or actions affecting human life or physical well-being, critical infrastructure, or critical safety operations) and rights-impacting AI (systems whose output serves as a principal basis for decisions or actions affecting civil rights, civil liberties, privacy, equal opportunities to key resources, or access to critical government services) shape the entire compliance posture because inclusion in those categories triggers the Section 5 minimum-practices floor. The waiver process in Section 5(c)(iii) permits narrowly tailored, documented exceptions approved by the CAIO and reported to OMB, but waivers are not shortcuts; they are high-scrutiny paper trails that will be reviewed by Inspectors General and GAO.

The stakes of getting M-24-10 wrong are concrete. The Government Accountability Office has published GAO-24-106675 on federal AI inventory accuracy and GAO-23-105923 on law-enforcement AI. Inspector General reports across Treasury TIGTA, DHS OIG (including OIG-22-49 on CBP Biometric Entry/Exit), VA OIG, and SSA OIG have flagged governance gaps in AI deployments. Congressional hearings before the Senate Homeland Security and Governmental Affairs Committee, the House Oversight Committee, Senate Finance, and Senate Judiciary regularly interrogate agency AI posture. The case record shows why the memo matters: the IRS ID.me rollout in 2022 paused after public outcry and senate letters because no disciplined governance process had tested the deployment against civil rights, Section 508 accessibility, and voluntary-alternative obligations; Michigan MIDAS produced roughly forty thousand false fraud accusations and more than twenty million dollars in settlements before statutory reform restricted fully automated adjudication; Houston Federation of Teachers v. Houston ISD (S.D. Tex. 2017) found due-process failures in an algorithmic teacher-evaluation system; K.W. v. Armstrong (D. Idaho) required disclosure and reform of a Medicaid benefits algorithm; SyRI was struck down by The Hague District Court in February 2020 on European Convention on Human Rights Article 8 grounds; the Dutch toeslagenaffaire scandal ended the Rutte III cabinet in January 2021. Each of these outcomes is the kind of failure M-24-10 is designed to prevent in US federal AI deployments.

For CAIOs, agency heads, General Counsels, Chief Privacy Officers, CISOs, CDOs, mission owners, senior procurement executives, and Inspector General liaisons, M-24-10 implementation requires an integrated program. The AI Governance Board must be chartered, staffed, and cadenced. The use-case inventory must be accurate, updated at least annually, and consistent with the OMB-published common data schema. The AI Impact Assessment template must be developed and applied before deployment for every safety-impacting and rights-impacting AI. The minimum-practices stack must be documented: real-world testing, independent evaluation, ongoing monitoring aligned with FISMA continuous monitoring, risk mitigation, and accessible human alternatives. Waivers must be rare, narrow, documented, and reported. Integration with adjacent regimes must be deliberate: FedRAMP authorization for cloud-hosted AI, NIST SP 800-53 controls including the SR supply chain family, Privacy Act compliance with System of Records Notices, Section 508 accessibility, Paperwork Reduction Act clearance for information collections, Federal Records Act preservation of AI decision artifacts, EO 14028 software supply chain attestation, and EO 14117 on bulk personal data access. Coordination with the interagency CAIO Council, the CIO Council AI Community of Practice, the GSA AI Center of Excellence, the NIST AI Safety Institute, and OSTP's National AI Initiative Office is expected, not optional. This seminar operationalizes each of those requirements with templates, cross-agency examples (VA NAII, IRS post-ID.me, CMS-0057-F, DOJ and DHS law-enforcement AI guidance under EO 14110 Section 7.1, SSA disability determinations, DOL unemployment insurance post-MIDAS, USDA SNAP, SBA loan processing), and a compliance roadmap anchored to the appropriations cycle and the M-24-10 reporting calendar.

M-24-10 Is the Operational Spine of Federal AI Governance

Executive Order 14110 set the direction. OMB Memorandum M-24-10 is how that direction becomes agency action. The memo was issued March 28, 2024 and replaced the earlier M-21-06 framework. It is the single most important federal AI governance document for agency implementers because it translates principle into specific duties with deadlines, with Chief AI Officer accountability, with public reporting, and with waiver discipline. It does four things at once: it establishes the governance architecture (Section 2), it mandates public transparency through the AI Use Case Inventory (Section 3), it pushes agencies toward responsible innovation (Section 4), and it imposes hard risk-management requirements on safety- and rights-impacting systems (Section 5). Every federal leader working on AI must know the memo by section number, not by headline. The Section 5(c) minimum-practices list is the floor below which federal agencies cannot deploy safety- or rights-impacting AI; the waiver process is the narrow escape hatch, and even waivers must be documented, approved by the CAO, and reported to OMB. Failing to know this is not just a career risk. It is the kind of failure that produces Inspector General findings, GAO reports (see GAO-24-106675 on federal AI inventory accuracy and GAO-23-105923 on law-enforcement AI), and congressional hearings.

The Scope and Timing You Must Know

Applicability: M-24-10 applies to executive-branch agencies as defined in 44 U.S.C. § 3502, with tailored applicability to non-CFO Act agencies, and specific exclusions for national-security systems as defined in 44 U.S.C. § 3552(b)(6) and managed under NSM-10 and subsequent national-security AI frameworks. The memo itself addresses its relationship to IC AI activities separately. Key effective dates: CAO designation by May 27, 2024 (60 days from issuance); AI Governance Board convening by May 27, 2024 for major agencies; initial compliance with Section 5 minimum practices for existing safety- and rights-impacting AI by December 1, 2024; and full operational alignment of agency AI strategies by subsequent milestones. Agencies that have fallen behind these dates should not pretend otherwise; instead, they should document the gap, establish a remediation plan, and brief the CAO Council and OMB transparently. In 2025 and beyond, updated guidance (including successor memos and CAO Council templates) continues to refine the implementation expectation. L5 leaders should track the OMB 'Chief AI Officer Guidance,' the OMB M-24-18 procurement memo (October 2024), and NIST AI RMF-aligned implementation artifacts from the AI Safety Institute.

Section 2 - The Governance Architecture in Detail

Section 2 requires every CFO Act agency to designate a Chief AI Officer at the senior-executive level and to stand up an AI Governance Board chaired by the CAO. The CAO is not a technical role alone; the memo explicitly contemplates the CAO as the agency's accountable executive for responsible AI adoption, policy coordination, and risk management. The CAO reports to agency leadership (typically the Deputy Secretary or equivalent) and coordinates with the CIO, CISO, SAOP (Senior Agency Official for Privacy), civil-rights officer, and mission owners. The AI Governance Board is the standing decision body. Typical composition includes the CAO as chair, General Counsel, CIO, CISO, SAOP, civil-rights or equity lead, senior procurement executive, and mission-owner representation rotated by agenda. The board's authorities include approving safety- and rights-impacting use cases, approving waivers with notice to OMB, reviewing impact assessments, managing the Use Case Inventory, and overseeing incident response. Most agencies also form a tiered structure: the governance board for enterprise decisions, and working groups for specific domains (generative AI, biometrics, fraud detection) that surface recommendations to the board. The Chief AI Officer Council is the cross-agency body composed of agency CAOs; it produces harmonized templates and provides the interface with OMB's Office of the Federal CIO. The CIO Council's AI Community of Practice is the practitioner layer below the CAO Council.

Section 3 - The AI Use Case Inventory

Section 3 institutionalizes the federal AI Use Case Inventory as the single most important public transparency instrument for federal AI. Each agency must publish an inventory annually, including all AI use cases whether developed in-house, procured, or used via SaaS. The inventory elements include use-case name and description, mission area, development status, risk classification (safety-impacting, rights-impacting, or neither), vendor information where applicable, data sources, and decommissioning or retirement status. Inventory accuracy has been a persistent concern: GAO-24-106675 and reporting by organizations such as the Ada Lovelace Institute, Stanford HAI, and Electronic Privacy Information Center has documented gaps, duplicates, and inconsistent categorization across agencies. The memo addresses this by requiring CAO sign-off, governance-board review, and integration with agency strategic planning. Operationally, the inventory should be maintained continuously, not just at annual publication, new use cases enter the inventory when they enter development, and retirements are recorded in real time. Cross-agency harmonization through the CAO Council aims to make inventories comparable across agencies and across years. For the public, the inventory is the starting point for any oversight question. For the agency, it is the chief mechanism by which governance makes itself visible.

Section 5 - The Minimum Practices

Section 5(c) is the operational heart of M-24-10. For safety-impacting and rights-impacting AI, the memo prescribes minimum practices that the agency must implement before and during operational use. These include: (i) a written AI impact assessment covering intended use, potential impact on rights and safety, data quality, performance expectations, and risk mitigations; (ii) real-world testing of the AI in context that approximates operational conditions, not just vendor-provided lab metrics; (iii) independent evaluation of the system by a party without conflicts; (iv) ongoing monitoring including performance and disparity metrics with pre-established thresholds that trigger review; (v) adequate training for operators and reviewers; (vi) notice to individuals affected by the AI, including plain-language explanation of how the AI is used; (vii) opportunity to opt out of the AI and receive a human alternative where feasible; and (viii) a meaningful mechanism to appeal AI-informed decisions. Waivers of specific practices require CAO approval with documented rationale, compensating controls, sunset, and notice to OMB. Appendix I of the memo provides presumptions: categories of AI that are presumptively safety- or rights-impacting, including law enforcement, criminal justice, health diagnostics, public benefits eligibility, housing, credit, employment, education, voting infrastructure, child welfare, and immigration enforcement. Agencies that believe a specific use case does not trigger the presumption must document the analysis and may need to consult OMB.

Cross-Agency Examples of Minimum-Practices Implementation

VA's clinical AI: clinical AI use cases have been governed through the VA National AI Institute, the Office of Information and Technology, and the Veterans Health Administration's clinical governance, with impact assessments covering patient safety, model performance on veteran populations (accounting for demographic composition), and integration with clinical workflow. IRS taxpayer service AI: following the February 2022 ID.me pause, the IRS has rebuilt its identity-verification approach with emphasis on voluntary participation, alternatives, and privacy-centered design, exactly the posture M-24-10 now formalizes. CMS prior authorization under CMS-0057-F (April 2024): the rule integrates the Office of the National Coordinator for Health IT's interoperability work with M-24-10-aligned governance for AI-assisted prior-authorization decisions, requiring transparency about criteria, human review, and appeal. DOJ/DHS law-enforcement AI: EO 14110 Section 7.1 tasked these agencies with guidance reflecting M-24-10 principles applied to law-enforcement AI, including biometric and predictive analytics. SSA disability determinations: AI-assisted SSA adjudication has been subject to long-running oversight; M-24-10 adds specific transparency and appeal requirements on top of existing disability-determination due-process obligations. DOL unemployment-insurance fraud detection: post-MiDAS, state UI systems are expected to align to the M-24-10 minimum practices for federally funded activities, with particular attention to false-positive ceilings and human review. USDA SNAP eligibility, SBA loan processing, and similar benefits-adjudication systems all fall within the rights-impacting category and require the full minimum-practices stack.

Integration with Adjacent Regimes

M-24-10 does not replace other legal or policy regimes; it layers on top of them. Procurement: OMB M-24-18 (October 2024) sets procurement obligations that must be harmonized with M-24-10, including vendor disclosure of training data, performance evidence, and post-award monitoring. Security: FISMA system authorization (FIPS 199/200, NIST SP 800-53, and continuous monitoring under OMB M-14-03) remains required; FedRAMP Moderate is the typical baseline for SaaS AI handling CUI. Privacy: the Privacy Act, Privacy Impact Assessments under the E-Government Act of 2002 Section 208, and the SAOP's authorities under OMB Circular A-130 remain fully applicable. Civil rights: Title VI of the Civil Rights Act, Section 504 of the Rehabilitation Act, Section 508 accessibility obligations, and constitutional due-process baselines (Goldberg v. Kelly, Mathews v. Eldridge) are the legal floor below which agency AI cannot operate. Records: the Federal Records Act (44 U.S.C. Chapter 29) governs AI-generated records, including model outputs used in decisions. Internal oversight: the Inspector General Act of 1978 provides the statutory basis for IG audits, and GAO conducts its own reviews under 31 U.S.C. § 712. An agency compliance program that addresses M-24-10 without integrating these adjacent regimes will fail.

A 30-60-90-180-365 Day Implementation Sequence

Days 1-30: confirm CAO designation and governance-board charter; inventory existing AI use cases and classify each against Section 5 definitions; identify gaps in documentation, testing, and monitoring; establish the SOP for new use-case intake. Days 31-60: complete impact assessments for all presumptively safety- or rights-impacting systems; begin or refresh independent evaluation for high-risk systems; design public notice and human-alternative/appeal mechanisms; execute on M-24-18 procurement alignment for in-flight contracts. Days 61-90: stand up continuous monitoring for high-risk systems with pre-defined disparity and drift triggers; publish the updated Use Case Inventory; conduct board-level review of waivers and Use Case Inventory accuracy; report status to agency leadership and the CAO Council. Days 91-180: cover the long tail of lower-risk systems; integrate training and awareness across the workforce; publish the agency AI strategy required under Section 4; align workforce planning with AI roles identified by the OPM AI Talent Surge and agency-specific mission needs; integrate with the generative AI guidance and NIST AI 600-1 Generative AI Profile where applicable. Days 181-365: operationalize annual reporting cycles; institutionalize incident response; measure outcomes (decisions supported, waivers granted, corrective actions taken, harms avoided) rather than inputs; prepare for IG and GAO audit readiness. The point of the sequence is not to do everything at once; it is to do the right things in the right order and to be able to demonstrate the trajectory when an auditor asks.

Common Implementation Pitfalls and How to Avoid Them

Pitfall 1 - Treating M-24-10 as an IT compliance exercise. AI is a mission function; governance must be led by mission-accountable leaders supported by IT, not delegated to IT alone. Pitfall 2 - Letting the Use Case Inventory drift. Inventory maintenance requires a named owner, a recurring review cadence, and integration with procurement and development intake. Pitfall 3 - Allowing the 'doesn't apply' argument to spread. If a use case is in Appendix I, the presumption is that Section 5 applies; an exemption requires documented analysis and, often, CAO sign-off. Pitfall 4 - Skipping real-world testing in favor of vendor lab metrics. The memo's 'real-world testing' requirement is a hard obligation. Pitfall 5 - Hiding waivers. Waivers are a legitimate escape hatch for genuine exigencies, but they require documentation, notice, and sunset; pretending an active use case does not need a waiver is worse than filing one. Pitfall 6 - Treating 'human alternative' as 'human-in-the-loop.' The memo's human-alternative provision is a rights-protection for affected individuals, not a process control for the agency; the two concepts are distinct and both are often required. Pitfall 7 - Failing to coordinate with adjacent oversight. The SAOP, CISO, CIO, civil-rights officer, and procurement officer all have statutory interests that must be integrated with M-24-10, not displaced by it. Pitfall 8 - Assuming vendors will carry the M-24-10 burden. Vendors produce artifacts; the agency owns the compliance.

Reflection and Application

Before moving on, work through these exercises against your agency. (1) Read M-24-10 Sections 1-5 carefully and Appendix I. Note every requirement that applies to your agency and every requirement you cannot yet meet. (2) For your three highest-risk AI use cases, write a one-page M-24-10 alignment memo covering classification, impact assessment status, testing evidence, monitoring, notice, human alternative, appeal, and waiver status. Share with your CAO and General Counsel. (3) For each identified gap, establish a named owner, a deadline, and the specific Section/subsection of the memo that drives the remediation. (4) Draft the public summary you would publish alongside your Use Case Inventory next cycle, the story of how your agency is complying and where it is still building. (5) Identify the single most important cross-agency template or example that, if adopted, would accelerate your agency's compliance, and bring it to the CAO Council through your chief AI officer.

Key Terms

M-24-10: OMB Memorandum M-24-10, 'Advancing Governance, Innovation, and Risk Management for Agency Use of AI,' issued March 28, 2024. SAFETY-IMPACTING AI: AI whose output could meaningfully affect human safety. RIGHTS-IMPACTING AI: AI whose output could meaningfully affect civil rights, civil liberties, or access to critical services. MINIMUM PRACTICES: the Section 5(c) floor of impact assessment, testing, independent evaluation, monitoring, training, notice, alternative, and appeal. WAIVER: written CAO approval to waive a specific minimum practice, with documented rationale, compensating controls, sunset, and OMB notice. APPENDIX I: the list of presumptively covered AI use cases. CAO: Chief AI Officer. CAO COUNCIL: the interagency council of CFO Act agency CAOs. AI CoP: Federal CIO Council's AI Community of Practice. USE CASE INVENTORY: the annual public disclosure of agency AI use cases under Section 3. SAOP: Senior Agency Official for Privacy under OMB Circular A-130. NSM-10: National Security Memorandum 10, setting out the national-security AI framework separate from M-24-10's scope.

L5 5.3.1 - EO 14110 Implementation
L5 5.3.2 - OMB M-24-18 Procurement Deep Dive
L5 5.3.3 - NIST AI RMF and the Generative AI Profile