Legal requirement AI risk management United States In force

Apply minimum risk-management practices to high-impact AI

Under OMB M-25-21, Section 4

Source-linked Open official source

What does it require?

For AI whose output serves as a principal basis for decisions with significant effects on rights, safety or access to services, agencies must complete pre-deployment testing, an AI impact assessment, ongoing monitoring, operator training, human oversight and a mechanism for affected people to seek remedy, or stop using the AI.

Practical action

Vendors should prepare test evidence and documentation that agencies can reuse in impact assessments.

Who does it apply to?

Federal agencies using high-impact AI; indirectly their vendors.

Evidence examples

  • AI impact assessment (report)
  • Pre-deployment test results (report)

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

Framework mappings
FrameworkReferenceNoteConfidence
NIST AI RMF 1.0MAP, MEASURE, MANAGEThe memo is aligned with the AI RMF vocabulary.medium

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.