Apply minimum risk-management practices to high-impact AI
Under OMB M-25-21, Section 4
What does it require?
For AI whose output serves as a principal basis for decisions with significant effects on rights, safety or access to services, agencies must complete pre-deployment testing, an AI impact assessment, ongoing monitoring, operator training, human oversight and a mechanism for affected people to seek remedy, or stop using the AI.
Practical action
Vendors should prepare test evidence and documentation that agencies can reuse in impact assessments.
Who does it apply to?
Federal agencies using high-impact AI; indirectly their vendors.
Evidence examples
- AI impact assessment (report)
- Pre-deployment test results (report)
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| NIST AI RMF 1.0 | MAP, MEASURE, MANAGE | The memo is aligned with the AI RMF vocabulary. | medium |
Similar obligations in other instruments
- Establish a risk management system for high-risk AI — EU AI Act, European Union
- Deployers must implement a risk management policy and programme — Colorado AI Act, Colorado (United States)
- Ensure AI systems are safe, secure and robust throughout their lifecycle — UK AI regulation framework, United Kingdom (voluntary)
- Prioritise, respond to and monitor AI risks (Manage) — NIST AI RMF, United States (voluntary)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.