M-24-10: Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence
- Document
- 28 March 2024
- Event
- 28 March 2024
- Retrieved
- 16 September 2026
Start here
Anyone trying to understand how a large organisation actually governs AI, rather than merely announces enthusiasm for it, can look at a real compliance document instead of a mission statement. In March 2024 the US Office of Management and Budget told every federal agency what governing AI would require in practice: a named accountable officer, a public inventory, and rules an agency had to follow or stop using the system.
What the documents say
OMB Memorandum M-24-10, dated 28 March 2024, required each agency to designate a Chief AI Officer within 60 days and to inventory its AI use cases at least annually. For AI the memo classed as ‘safety-impacting’ or ‘rights-impacting,’ agencies had until 1 December 2024 to implement listed minimum practices — including, where practicable, ‘a mechanism for individuals to conveniently opt-out from the AI functionality in favor of a human alternative’ — or stop using the system. Agencies could seek a waiver from these practices, but had to publicly release a summary of each waiver and its justification. A year later, OMB Memorandum M-25-21, dated 3 April 2025 and issued after Executive Order 14179, states plainly that it ‘rescinds and replaces’ M-24-10; it keeps the Chief AI Officer role and the AI use-case inventory but collapses the earlier ‘safety-impacting’ and ‘rights-impacting’ categories into a single ‘high-impact AI’ designation, and replaces the earlier individual opt-out with a right to human review and appeal.
Check this
If a report or agency page cites ‘M-24-10’ as current federal AI policy, check the date: the memo it names was rescinded in April 2025. The mechanism worth checking in either version is the same — does the agency's published use-case inventory actually list a determination or waiver for the system in question, or does it state that none exist. That is a public record, not an internal assurance.
What holds and what fails
What holds across both memos is the structural idea: someone named and accountable, a public inventory, and a category of AI treated as higher-risk than the rest. What changed is where that higher-risk line sits and what a person is offered instead of it — M-24-10's explicit individual opt-out is not carried into M-25-21 in the same terms. Editorially, the fact that a binding federal governance memo was fully rescinded within thirteen months is itself the boundary worth remembering: any specific compliance detail dated to a single memorandum should be treated as provisional, checked against the current version rather than summarised from memory.
- Search an agency's website for its current AI use-case inventory before assuming a rule still applies.
- Look for whether human review or an appeal is offered where an agency's AI affects you directly.
- Note the date on any AI-policy memo you cite, federal or otherwise, before treating it as current.
A single memorandum is a compliance requirement with a shelf life, not a permanent structure. Reading M-24-10 in September 2026 means reading a superseded document for what it reveals about what governance requires in practice — inventories, named officers, public reporting — even though its specific categories no longer bind agencies.
Sources & reading trail
Establishes Chief AI Officers, minimum practices for safety- and rights-impacting AI, a 1 December 2024 deadline, and a public opt-out requirement.
Source published: 28 March 2024 · Retrieved: 16 September 2026
States it rescinds and replaces M-24-10 and replaces the rights/safety-impacting categories with a single high-impact AI category.
Source published: 3 April 2025 · Retrieved: 16 September 2026
Documentation, regulator guidance and studies establish the record; the checks and the boundary are AI Use Field Guide editorial analysis. This retrospective draft does not imply the site published on the event date.