The April 15 deadline under OMB Memorandum M-25-21 is not aspirational. It is a compliance deadline with an explicit consequence: high-impact federal AI systems that cannot demonstrate compliance must be discontinued until they achieve it.

Federal agencies are twelve days out and the picture is not uniformly good.

M-25-21 — the OMB memorandum on responsible AI use in the federal government — requires agencies to maintain inventories of their AI systems, classify those systems by risk impact, and implement minimum practices for high-impact AI by April 15, 2026. High-impact AI is defined as AI systems “whose output serves as a principal basis for decisions that have legal, financial, safety, or other significant impacts on individuals.”

That definition is broader than most agencies initially assumed when planning their compliance timelines.

What Falls Under High-Impact AI

When agencies first built their AI inventories under OMB’s direction, many focused on the obvious cases: automated benefits eligibility determination, risk scoring in law enforcement contexts, AI-assisted medical diagnosis. Those are clearly high-impact.

What caught agencies off-guard was how the “principal basis for decisions” threshold applies in practice. AI systems that surface ranked lists of applicants for review. Fraud detection systems that flag cases for human follow-up. Predictive models that determine which households get priority outreach in benefits programs. Grant scoring systems that affect which organizations receive funding.

These are all systems where AI output materially shapes downstream decisions that affect individuals. The human may technically make the final call, but if they’re systematically approving the AI’s recommendations without independent analysis, the AI is effectively making the decision. That’s what the guidance targets.

Agencies that scoped their high-impact inventory narrowly in the initial assessment pass should revisit those inventories before April 15. Getting caught with an unregistered high-impact system in use after the deadline is a worse outcome than disclosing one now and entering a compliance remediation process.

What M-25-21 Actually Requires for High-Impact AI

The minimum practices for high-impact AI in M-25-21 are specific. Agencies need to be able to demonstrate compliance in each area:

Pre-deployment testing: High-impact AI must be tested for performance, bias, and reliability before deployment and after significant updates. This means documented test plans, test results, and evaluation criteria — not informal internal reviews. For systems already deployed, agencies need retroactive testing documentation or a plan for achieving it.

Ongoing monitoring: Post-deployment performance monitoring with defined metrics and thresholds. Agencies need to be able to demonstrate that they’re detecting performance degradation, demographic disparities, and other indicators that a system’s behavior has changed from its validated state.

Transparency requirements: Individuals affected by high-impact AI decisions must have access to meaningful information about how AI was used in their case. The specific form this takes depends on the context, but the baseline is that “an AI system made this decision” is not sufficient disclosure — individuals need enough information to understand how to contest or seek review of outcomes.

Human oversight mechanisms: High-impact AI decisions must have accessible human review processes. Agencies need to document who reviews AI-influenced decisions, what authority they have to override AI recommendations, and how individuals can request human review.

Data quality assurance: The training and operational data for high-impact AI must meet documented quality standards. Agencies using systems trained on historical data need to assess whether that data reflects biases or patterns that would produce disparate outcomes.

Vendor accountability: For high-impact AI procured from vendors, agencies need contracts that ensure the vendor provides performance data, supports audit requirements, and enables the agency to meet its oversight obligations. Agencies with existing vendor contracts that lack these provisions have a problem that procurement law makes difficult to retroactively fix.

Where Agencies Are Actually Struggling

Based on conversations with agency IT and compliance staff across multiple departments, the hardest elements of M-25-21 compliance are:

Retroactive testing documentation for legacy AI systems. Many high-impact AI systems in federal use were deployed before the current testing standards existed. Agencies are trying to reconstruct documentation for systems that have been in operation for years, sometimes without access to the original development team or testing artifacts. Where reconstruction isn’t feasible, agencies need to either conduct current baseline testing or begin shutdown planning.

Vendor contracts for commercial AI. Federal agencies are extensive users of commercially developed AI — scoring engines, fraud detection systems, benefits eligibility tools — often through existing contracts that predate M-25-21’s requirements. Renegotiating those contracts for additional transparency and audit provisions is slow and sometimes impossible within the current contract period.

Meaningful transparency to individuals. The guidance says individuals must have access to meaningful information. What that means in practice — what level of explanation is “meaningful” for a complex model — is genuinely contested, and agencies are implementing very different approaches. Some are providing model-level documentation. Some are providing case-level explanation of which factors drove the AI’s output. The guidance will need more specificity before this element is consistently implemented.

Inventory completeness. Agencies that have been operating AI systems in non-IT managed environments — data science teams, program offices, procurement units doing their own ML — are discovering during compliance reviews that their official AI inventories are incomplete. AI tools acquired through credit cards, free-tier commercial accounts, or embedded in vendor products often don’t appear in central IT records.

What to Do in the Next Twelve Days

If your agency has high-impact AI systems that aren’t in a demonstrably compliant state by April 15, you have three options:

Complete compliance: If the gaps are documentation, process, or governance gaps that can be closed in twelve days, close them. This requires prioritizing — pick the systems with the widest public impact and get them compliant first.

Formal remediation commitment: For systems where full compliance isn’t achievable by April 15 but shutdown is unacceptable operationally, agencies can document a formal remediation plan with specific milestones and submit it with their compliance certification. This doesn’t exempt the agency from the requirement — it acknowledges the gap and commits to a correction timeline.

Controlled shutdown: For systems where compliance is not achievable in a reasonable timeframe and the operational need can be met through other means, planned shutdown is better than continued operation out of compliance. Document the shutdown, the alternative approach, and the lessons learned.

April 15 is twelve days away. That is not enough time to build compliance from scratch. It is enough time to assess honestly where you stand, escalate gaps to senior leadership, and make decisions that you can defend.

The agencies that handle this with discipline now will be in a better position for M-25-21’s ongoing requirements. The ones that paper over the gaps will face harder conversations later.