Federal

What OMB’s AI mandates require of contractors

← All InsightsBy Dr. Derek A. Smith6 min read

If you sell to the federal government and there is any AI in what you deliver, two memos issued in April 2025 changed your obligations — even though they were written for agencies, not for you. Their requirements flow downhill through the contract, and the contractors who understand that will win work the others get disqualified from.

On April 3, 2025, the Office of Management and Budget issued M-25-21 (federal use of AI) and M-25-22 (federal acquisition of AI), implementing Executive Order 14179 and replacing the Biden-era guidance. The framing is deliberately pro-innovation and pro-competition — but it is not light-touch, and the procurement memo lands squarely on vendors.

What agencies now have to do

Covered agencies must publish compliance plans, adopt generative-AI policies, maintain annual AI use-case inventories, and run this through a Chief AI Officer. For “high-impact AI” — systems whose outputs significantly affect rights, safety, health, or critical services — agencies must conduct pre-deployment testing and impact assessments, monitor performance in production, and provide human oversight and a path to appeal.

What that means for contractors

Here is the part vendors miss: an agency cannot meet those obligations unless you help it. So expect contract terms requiring you to provide:

  • Transparency and explainability documentation — enough for the agency to understand and defend how your system works.
  • Performance and evaluation data so the agency can track the system against its stated purpose.
  • Data and IP protections — notably, prohibitions on training your commercial models on non-public government data without consent, and agency access to the components needed to operate the system.
  • Anti-lock-in provisions — data and model portability, knowledge transfer, pricing transparency, and agency rights to code and models produced under the contract.

The memos also push “American-made AI” preferences and direct GSA to publish procurement guides and standard contract language, so expect this to show up as boilerplate in solicitations.

The winners won’t be the vendors with the best model. They’ll be the ones who can show their governance.
Get ahead of it
  • Build your own AI inventory and model documentation before an RFP demands it.
  • Get your data-use and IP terms clean — especially around training on customer data.
  • Be ready to demonstrate testing, monitoring, and human-oversight practices on request.

One accuracy note for planning: these memos removed the prior equity-assessment and algorithmic-discrimination provisions. The compliance surface shifted — it did not disappear. Read the contract language, not the headlines.

Dr. Derek A. Smith is founder of DAS Advisory Group and author of The Defensible AI Program. He advises federal agencies and enterprises on governing and securing AI.

Want this applied to your organization?

A 30-minute conversation on where you are and what governing your AI actually takes.

Book a Consultation

Get new briefs in your inbox

Practical AI governance and security notes, sent when there's something worth reading. No spam.