OMB Memorandum M-24-10 landed in March 2024 with specific, time-bound requirements for how federal agencies govern and use artificial intelligence. By December 2024, agencies were required to have completed AI use case inventories, designated Chief AI Officers with defined authorities, and implemented minimum risk management practices for high-risk AI.
We’re now in Q2 2026. The honest assessment is that compliance across the government is uneven, the consequences for the least compliant agencies are starting to become visible, and the requirements are getting stricter rather than more relaxed as AI capabilities evolve faster than governance frameworks.
For organizations operating in the federal technology space — whether as agencies, contractors, or solution providers — understanding where things actually stand matters for how you structure programs, price risk, and position offerings.
The Inventory Problem
The AI use case inventory requirement sounds administrative but is operationally significant. You can’t govern what you don’t know about, and most agencies discovered during the inventory process that AI was in use in more places, in more ways, than their official technology management processes had captured.
Shadow AI deployments — employees using commercial LLM services, automated tools with AI components that weren’t explicitly procured as AI, legacy analytics systems that were recategorized as AI under the new definitions — showed up in inventories at agencies that thought they had modest AI footprints.
The ongoing governance challenge is that the inventory isn’t a one-time exercise. AI is being deployed continuously, often at the team level without centralized visibility. Maintaining an accurate inventory requires either a very effective governance process or a very active audit and discovery function — and most agencies have neither fully built yet.
Rights-Impacting AI: The Hard Implementation Cases
The M-24-10 requirements are strictest for AI systems that make or substantially influence decisions affecting individual rights — benefits eligibility, enforcement actions, employment decisions, housing determinations. For these systems, agencies must implement specific human oversight mechanisms, impact assessments, and in some cases the ability for affected individuals to opt out of automated processing.
This is where the compliance gap is most visible, for a straightforward reason: many of the AI systems in use for these high-stakes decisions were procured and deployed before the current governance requirements existed. Retrofitting oversight mechanisms, audit logging, and opt-out pathways onto systems built without those capabilities is expensive and technically complex.
Agencies that are actively working on this challenge are finding that it often requires substantive system rearchitecting, not just policy changes. And the acquisition vehicles to fund that rearchitecting may be separate from the original procurement.
What Contractors Need to Know
For contractors providing AI-enabled solutions to federal agencies, the compliance landscape has a few practical implications.
Explainability and audit trail requirements are real procurement criteria now. Agency program offices are asking — sometimes with more sophistication than before — how the AI component of a solution documents its decision reasoning and what audit trail it produces. Black-box models without explainability capabilities are harder to sell into rights-impacting use cases.
Human oversight architecture matters for contract structure. If your solution automates a process that has human oversight requirements, the contract needs to address how that oversight is implemented, who is responsible for it, and what happens when the oversight fails. Leaving this ambiguous creates downstream contract performance risk.
The CAIO is a new stakeholder in your sales process. Chief AI Officers with real authority are increasingly involved in AI procurement decisions. Understanding their priorities — governance, risk management, interoperability, auditability — and addressing them in your positioning is increasingly necessary.
Your own AI use matters. If you’re using AI tools in the delivery of services to federal clients — AI-assisted coding, document generation, analysis support — you may have disclosure obligations and certainly have risk management considerations. Documenting how AI is used in delivery and ensuring it meets your client’s governance requirements is becoming a standard expectation.
The Direction of Travel
The current AI governance framework was designed for a capability landscape that’s already changing. As agentic AI, multi-modal systems, and AI with extended autonomy become more prevalent in government operations, the framework will evolve.
The organizations positioned well for that evolution are the ones building genuine governance capability — not just compliance checklists. The difference matters when the framework changes faster than the compliance cycle, which is the reality we’re in.