Skip to main content

Techné AI · Free reference · Edition 3.0.0

US Federal

Federal AI policy, agency-use and procurement requirements, NIST guidance and selected statutory obligations, with primary-source links.

Reviewed Download complete PDF Corrections
On this page
  1. Executive Orders 14148 and 14179
  2. Federal agency use and procurement
  3. America’s AI Action Plan
  4. National framework and state-law challenges
  5. June 2026: advanced AI and national security
  6. Center for AI Standards and Innovation (CAISI)
  7. NIST AI Risk Management Framework
  8. TAKE IT DOWN Act
  9. Export controls: non-enforcement is not the same as repeal
  10. Employment and sectoral law still matters

Federal AI policy combines statutes, executive directions, agency requirements and voluntary technical frameworks. Do not treat an executive policy announcement as a repeal of underlying law, or an agency’s internal AI plan as a rule for every private organisation.

This chapter distinguishes those instruments as of 7 September 2026. It is not a complete inventory of federal rulemaking, current litigation or transaction-specific export controls.

Executive Orders 14148 and 14179

Executive Order 14110 was revoked on 20 January 2025 by the initial-rescissions order. EO 14179, signed 23 January 2025, then directed a new AI Action Plan and review of actions taken under EO 14110.12

EO 14179 required agencies to identify inconsistent actions and, as appropriate and consistent with law, suspend, revise or rescind them—or propose doing so. It also directed OMB to revise its AI-use and acquisition memoranda. It did not automatically erase every regulation, guidance document or statutory obligation associated with the prior policy. Check the action and authority separately.

Federal agency use and procurement

On 3 April 2025, OMB issued:

  • M-25-21, replacing M-24-10: governance, transparency and risk-management requirements for agency AI use, including specified high-impact AI safeguards.3
  • M-25-22, replacing M-24-18: acquisition guidance addressing competition, interoperability, data use, performance and risk in federal AI procurement.4

M-25-21’s compliance-plan requirement applies to agencies within its scope, not only cabinet departments. Agencies must publish a compliance plan or a determination that they do not use and do not anticipate using covered AI, with recurring updates. An agency’s published plan describes its own implementation; it does not by itself impose equivalent duties on the firms it regulates.3

M-26-04, issued 11 December 2025, adds implementation guidance for the administration’s Unbiased AI Principles in agency LLM procurement. It addresses contract terms and vendor information, with specified exclusions and scope rules; it is not a general standard governing all commercial LLMs. Its agency procurement-policy update deadline was 11 March 2026.5

For a supplier, the practical question is which solicitation, contract terms, agency policy and legal authority apply to the proposed service—not whether the supplier has made a generic “federal AI compliant” claim.

America’s AI Action Plan

Published 23 July 2025, the Action Plan groups policy recommendations under innovation, infrastructure, and international diplomacy/security. It is a government policy roadmap, not a single directly applicable private-sector statute.6

The accompanying measures include the American AI Exports Program, which supports full-stack export packages. The export order expressly requires compliance with relevant export controls; it should not be summarised as simply relaxing or replacing them.7 Other July measures address data-centre permitting and federal AI procurement. Their distinct scopes matter.

National framework and state-law challenges

EO 14365, signed 11 December 2025, is titled Ensuring a National Policy Framework for Artificial Intelligence. It directs a DOJ task force to challenge selected state laws, Commerce evaluation of state laws, funding-related actions within legal authority, an FTC policy statement, and a legislative recommendation.8

The FCC direction is to initiate a proceeding to determine whether to adopt a federal reporting/disclosure standard after the specified Commerce evaluation—not a declaration that such a standard already exists. The order’s listed child-safety, infrastructure and state-procurement exclusions constrain the legislative recommendation; they are not blanket exemptions from every section of the order.

On 20 March 2026, the White House published a national AI legislative framework and called on Congress to enact it. That announcement is a recommendation, not itself an enacted preemption statute.9

Neither announcement is a sound basis for ignoring a state law. Determine whether an applicable statute, valid federal measure or actual court order changes the obligation. This chapter does not infer current case outcomes from litigation announcements.

June 2026: advanced AI and national security

EO 14409, signed 2 June 2026, directs cybersecurity initiatives, benchmarking of covered frontier models and development of a voluntary framework for government access before release to trusted partners. It expressly disclaims authorising a mandatory government licence, preclearance or permit for developing or releasing models.10

NSPM-11, dated 5 June 2026, addresses AI in the national-security enterprise, including adoption, assurance, accountability and acquisition policy. Its federal national-security context should not be presented as a general private-sector certification requirement.11

Deadlines directing officials to develop a programme do not prove that every implementing action has been completed.

Center for AI Standards and Innovation (CAISI)

NIST’s CAISI conducts research, evaluations and standards work relating to AI capabilities and security.12 On 5 May 2026, NIST announced testing agreements with Google DeepMind, Microsoft and xAI, building on earlier partnerships that it said had been renegotiated to reflect current directives.13

These collaborations support predeployment evaluations and research. Participation is not a government certification that a model is safe, nor does the announcement establish that every version has completed testing. See Frontier Models.

NIST AI Risk Management Framework

AI RMF 1.0, released 26 January 2023, remains a voluntary framework, and NIST states that a revision is underway. Do not label draft work or a concept note “AI RMF 2.0.”14

The four interconnected functions offer a useful structure:

FunctionWorking question
GovernWho owns the decisions, policies and escalation process?
MapWhat is the use context, who may be affected and what could go wrong?
MeasureWhat evidence and evaluation methods characterise the risks?
ManageWhich risks require treatment, monitoring or a changed decision?

The functions are iterative rather than a mandatory one-way sequence. The companion Playbook offers selectable suggestions, not an exhaustive checklist or a guarantee of legal compliance.15

Profiles and work in progress

  • NIST AI 600-1, Generative AI Profile: released 26 July 2024. The March 2025 adversarial-machine-learning taxonomy is a separate NIST AI 100-2 publication, not an update to this profile.1416
  • NIST IR 8596, Cyber AI Profile: the official record identifies a December 2025 preliminary draft; the January 2026 comment period has closed. It is organised around CSF 2.0, not a replacement for the AI RMF.17
  • Critical-infrastructure AI RMF profile: a concept note was released 7 April 2026; distinguish that development stage from a final profile.14
  • Control Overlays for Securing AI Systems (COSAiS): NIST’s development project includes a January 2026 annotated discussion outline. These materials are not a single final, mandatory AI overlay.18

Record the exact publication, edition and draft status used in an assessment.

TAKE IT DOWN Act

The TAKE IT DOWN Act, signed 19 May 2025, addresses specified non-consensual intimate depictions, including digital forgeries. Criminal liability depends on the statute’s elements and exceptions; not every synthetic image is covered.19

Covered platforms had until 19 May 2026 to implement the notice/removal process. Following a valid request, they must remove the identified depiction as soon as possible and within 48 hours, and make reasonable efforts to identify and remove known identical copies. FTC enforcement of the platform obligations began on 19 May 2026.1920

For an in-scope service, maintain an accessible reporting process, response ownership and evidence of handling.

Export controls: non-enforcement is not the same as repeal

On 13 May 2025, BIS announced that it would not enforce the AI Diffusion Rule and planned to formally rescind and replace it. It also issued chip-related guidance.21

In its 12 May 2026 decision, GAO distinguished the announced non-enforcement policy from a completed rescission and found the policy subject to Congressional Review Act submission requirements. GAO recorded Commerce’s explanation that formal rescission was not yet final.22

These dated records do not establish that a particular export is permitted today. Check current EAR text, licence requirements, item classification, destinations, end users and end uses before a transaction; do not reduce the remaining controls to “China and a handful of countries.”

Employment and sectoral law still matters

Changing AI policy or withdrawing agency guidance does not repeal the underlying statutes. Covered employment decisions remain subject to laws such as Title VII and the ADEA; disability, credit-reporting, lending and other duties require their own applicability analysis.23

State and local rules also need separate review, including Illinois’s HB 3773 / Public Act 103-0804 employment-AI amendment and New York City Local Law 144. See US State Laws and Sectoral.

Footnotes

  1. The White House. (2025, January 20). Initial rescissions of executive orders and actions.

  2. The White House. (2025, January 23). EO 14179 — Removing Barriers to American Leadership in Artificial Intelligence.

  3. OMB. (2025, April 3). M-25-21 — Accelerating Federal Use of AI through Innovation, Governance, and Public Trust. 2

  4. OMB. (2025, April 3). M-25-22 — Driving Efficient Acquisition of Artificial Intelligence in Government.

  5. OMB. (2025, December 11). M-26-04 — Increasing Public Trust in AI Through Unbiased AI Principles.

  6. The White House. (2025, July). America’s AI Action Plan.

  7. The White House. (2025, July 23). Promoting the Export of the American AI Technology Stack.

  8. The White House. (2025, December 11). EO 14365 — Ensuring a National Policy Framework for Artificial Intelligence.

  9. The White House. (2026, March 20). National AI legislative framework announcement.

  10. The White House. (2026, June 2). EO 14409 — Promoting Advanced AI Innovation and Security.

  11. The White House. (2026, June 5). National Security Presidential Memorandum / NSPM-11.

  12. NIST. Center for AI Standards and Innovation.

  13. NIST. (2026, May 5). CAISI frontier AI testing agreements announcement.

  14. NIST. AI Risk Management Framework and current revision status. 2 3

  15. NIST. AI RMF Playbook.

  16. NIST. AI technical publication register.

  17. NIST. IR 8596 preliminary draft record.

  18. NIST. Control Overlays for Securing AI Systems project.

  19. Public Law 119-12 — TAKE IT DOWN Act, especially Sections 2–4. 2

  20. FTC. (2026, May). TAKE IT DOWN Act enforcement starts.

  21. BIS. (2025, May 13). AI Diffusion Rule non-enforcement and planned rescission announcement.

  22. GAO. (2026, May 12). Decision B-337935.

  23. EEOC. Title VII and ADEA.

This free handbook is a dated educational reference, not a determination of your organization's obligations. Check the source, jurisdiction and role before applying a requirement. For working documents, see TalentSight Intelligence and BoardSight Intelligence.