The Federal AI Framework Was Rewritten Twice
What survived, and why it was never the citation that mattered

This article is for educational purposes and does not constitute legal, regulatory, or policy advice. Government employees should consult with their agency's legal counsel, AI governance office, and relevant oversight bodies.
This is a follow-up to Tuesday's guide, AI Collaboration in Government and Public Sector. That piece covers the practice: how government professionals verify AI output in policy work, procurement, and constituent services. This one goes underneath it, to the regulatory ground that shifted while the practice stayed still.
Every Citation From 2024 Is Now Wrong
If you learned federal AI governance in 2024, everything you learned to cite has been withdrawn.
Executive Order 14110 on Safe, Secure, and Trustworthy AI was revoked on January 20, 2025. Its two implementing memoranda, OMB M-24-10 and M-24-18, were rescinded and replaced on April 3, 2025. The governing order and both operating documents were gone inside fifteen months.
This matters beyond bookkeeping. A compliance program keyed to a specific memorandum's section numbers had to be rebuilt twice. A workforce that had internalized the underlying verification behavior needed a document update and nothing more. That difference is the whole argument of this piece.
The Change History
| Date | What changed |
|---|---|
| 2023-10-30 | EO 14110 issued. OMB M-24-10 and M-24-18 follow in 2024 as its implementing guidance |
| 2025-01-20 | EO 14110 revoked. EO 14179 directs the revision of M-24-10 and M-24-18 |
| 2025-04-03 | OMB issues M-25-21 and M-25-22, which rescind and replace M-24-10 and M-24-18 |
| 2025-07-23 | EO 14319 sets unbiased-AI principles for federal procurement |
| 2025-12-11 | OMB M-26-04 implements EO 14319. The same day, the state law preemption EO issues |
| 2026-04-03 | M-25-21 deadline: agencies must have documented minimum risk management practices for high-impact AI |
| 2026-06-02 | EO 14409 establishes a voluntary frontier model regime |
What Actually Governs Federal Agency AI Use Now
OMB M-25-21, "Accelerating Federal Use of AI through Innovation, Governance, and Public Trust" (April 3, 2025) rescinds and replaces M-24-10 in terms. The framing shifted toward acceleration, the Chief AI Officer role was recast to promote adoption alongside governance rather than sit in an oversight posture, and CAIOs gained authority to waive minimum practices for a specific application on a written risk determination, recertified annually.
But look at what survived. M-25-21 collapsed the old safety-impacting and rights-impacting categories into a single "high-impact AI" definition, then imposed seven minimum risk management practices on it: pre-deployment testing, a documented impact assessment, ongoing monitoring, operator training, human oversight with a fail-safe, an appeal path for affected individuals, and a public feedback channel. The impact assessment must cover data fitness and civil rights impacts, carry an independent internal reviewer who was not involved in development, and bear the signature of whoever accepts the risk. Non-compliant high-impact use must be discontinued. Agencies had until April 3, 2026 to document implementation.
OMB M-25-22 (same date) rescinds and replaces M-24-18, covering competitive sourcing, vendor lock-in avoidance through data portability, and performance tracking.
EO 14319 and OMB M-26-04 (December 11, 2025) layer procurement obligations on top. Agencies buying large language models must contractually require the unbiased AI principles plus vendor documentation covering model and data cards, training data provenance, acceptable use policies, and disclosed inappropriate use cases. Compliance is material to eligibility and payment, with explicit termination authority. Procurement policies had to be updated by March 11, 2026.
The December 2025 state law preemption EO directs DOJ to run an AI Litigation Task Force challenging state AI laws and Commerce to identify conflicting state statutes, with broadband funding eligibility attached. Carveouts preserve state authority over child safety, AI infrastructure, and government procurement. For a state or local employee, the law governing your agency's AI use may be under active federal challenge while you are trying to comply with it.
The states have not slowed down. Sixteen new state AI statutes were enacted in the eight months after the preemption order. Texas TRAIGA took effect January 1, 2026 with a NIST AI RMF safe harbor; Utah's framework runs to a July 2027 sunset. A professional in one state now works under a different obligation set from a counterpart in another, with the federal position contesting both. EveryAILaw tracks what is actually in force.
The Citation Churned. The Behavior Did Not.
Across a revoked executive order, two rescinded memoranda, and a change of administration, the operational duties on the person using the AI barely moved.
Read that list of seven practices again and ask which one is new. Test before deployment. Document what the system does and what data it was built on. Have someone who did not build it review the assessment. Sign your name to the risk acceptance. Monitor after deployment. Train the operators. Keep a human in the loop with authority to intervene. Give affected people an appeal.
None of it is new. M-24-10 did not invent the idea that you should check the output before it affects someone's benefits eligibility. These practices survived a framework replacement because they were never artifacts of the framework in the first place.
Why This Should Change What You Invest In
The obvious lesson is to write policies that cite less and describe more. That is correct but shallow.
The deeper one concerns where capability actually lives. When guidance is prescriptive, an organization can pass an audit without anyone in it exercising judgment: the rule specifies what to check, and compliance is a matter of following it. When the guidance shifts toward acceleration, when your Chief AI Officer can waive minimum practices for your specific application, and when what remains arrives through contract clauses and unsettled preemption, no document tells you what to verify. Someone has to decide.
That is a behavioral capability, not a documentary one. It does not appear on an org chart and it is not established by a policy PDF. It shows up in whether the person reviewing an AI-drafted memo notices that the authority it cites was rescinded eighteen months ago.
This is the premise PAICE (People + AI Collaboration Effectiveness) is built on: that how a person works with AI is an observable behavior rather than a policy attestation. Its Accountability dimension carries the heaviest weight for the reason this history illustrates. The person who signs an output owns it regardless of which framework happened to be in force when they signed. A framework replacement changes what you cite. It does not change who is answerable.
Deregulation reads like reduced exposure for the individual. It is the opposite. Fewer prescriptive rules at the agency level put more weight on the behavior of the person signing the output.
The Failure Mode This Creates
There is a specific trap in this particular history, and it is worth naming because AI will walk into it confidently.
EO 14110 and M-24-10 generated an enormous volume of guidance, agency implementation plans, law firm client alerts, and conference material while they were in force. That corpus is heavily represented in model training data. The revocation is a single event, and the rescission of M-24-10 is one sentence inside a memorandum. Far less text stands behind the correction than behind the error.
Ask a general-purpose AI assistant what governs federal agency AI use and there is a real chance it describes EO 14110 and M-24-10 as current, with correctly formatted section references. Neither instrument is in force.
What makes this dangerous is that it fails subtly rather than obviously. Much of the substance carried forward, so an AI-drafted memo citing M-24-10 will describe requirements that are largely still real, under a citation that is dead, using a category name ("rights-impacting AI") that no longer appears in the governing document. A reviewer skimming for whether the content sounds right will pass it. A reviewer checking whether the cited authority still exists will not.
An output can be substantively reasonable, internally consistent, well-cited, and still resting on a legal authority that was rescinded. That is the verification problem in its most concrete form, and no amount of policy documentation solves it. Only a person who checks does.
Making "Is This Still In Force?" A Cheap Question
Verification fails when it is expensive. If confirming that an executive order is still in effect means reading a Federal Register notice and reasoning about what it superseded, most people will skip it and trust the confident-looking citation instead.
This is the problem EveryAILaw exists to solve, and it is why we built it as structured data rather than as articles. Every instrument carries an explicit status. Revoked and superseded instruments are not quietly deleted; EO 14110 is recorded as revoked, with the date and what replaced it, so the answer to "is this current?" is a lookup rather than a research project. The reference tracks 63 regulations, 9 standards and frameworks, and 212 provisions across 43 jurisdictions, alongside an exclusions register recording which laws were evaluated and deliberately left out.
The schema underneath it is the same argument in a different register. ObligationFirst treats stable obligations as the anchors and specific provisions as the things that implement them, rather than making the statute the primary unit. Order the data that way and this post's history becomes tractable rather than chaotic: provisions are precisely the layer that churned, obligations are the layer that did not. Pre-deployment testing did not stop being required because the memorandum requiring it was rescinded.
The surfaces are free and unauthenticated, which matters for the failure mode described above:
- Stable permalinks for citation, so a memo can point at
everyailaw.com/regulation/us-eo-14319/rather than a paraphrase - A static JSON API at
everyailaw.com/api/v1/covering regulations, provisions, obligations, jurisdictions, authorities, standards, and evidence - A
recently_changedfeed in the upcoming endpoint, listing what was added or updated in the last 30 days - An MCP server with 14 tools, so the assistant drafting your memo can check the corpus directly instead of recalling it from training data
That last one is the direct countermeasure. The reason a model confidently cites M-24-10 is that it is answering from memory, where the revoked instrument is overrepresented. Give it a tool that queries current status and the failure mode largely closes. It stops being a recall problem and becomes a lookup.
EveryAILaw Pro is the paid surface for teams that need change monitoring rather than ad-hoc lookups. It is in market testing: subscription and key issuance are live, while the Pro-only tooling, webhooks, saved profiles, audit logging, and service-level target are still being implemented and are not yet callable. The free reference above is complete and usable today, and the JSON API stays free and unauthenticated regardless.
Neither of these removes the human judgment. A lookup tells you an instrument was rescinded; it does not tell you whether the analysis built on it still holds. That remains the reviewer's call. What the tooling does is remove the excuse that checking was too expensive.
Want to assess your team's AI collaboration readiness? Learn about PAICE for organizations or take an individual assessment to see it firsthand.
Get Involved:
- Take the assessment (free, always)
- Explore our Baseline offerings (for organizations)
- Read the whitepaper (comprehensive framework)
- Contact us about your specific requirements
Recommended Reading
📖 Government and Public Sector:
- AI Collaboration in Government and Public Sector - The practitioner guide this analysis was drawn from
- Your AI Policy Is Not Enough - Why measuring behavior matters more than documenting intent
📖 The PAICE Legal Graph:
- EveryAILaw - Which instruments are in force, superseded, or revoked, across 43 jurisdictions
- ObligationFirst - The obligation-first schema: stable obligations as anchors, provisions as implementations
- AI Posture - Declaring how an organization actually governs its AI use
- EveryAILaw for agents - The MCP server and JSON API, for wiring current regulatory status into an assistant
- EveryAILaw Pro - Change monitoring for teams, currently in market testing
- EO 14319 and the federal LLM procurement regime - Vendor documentation requirements agencies must enforce
Curious but short on time?
Take the 3-minute PAICE Pulse — a quick confidence check that maps how you see your own AI collaboration posture. No login required.