Policy Briefing — OMB Issues M-24-10 AI Risk Management Guidance
The U.S. Office of Management and Budget released Memorandum M-24-10 on March 19, 2024, requiring federal agencies to inventory AI use cases, implement risk management controls, and publish transparency dashboards by December 2024.
Executive briefing: The Office of Management and Budget issued Memorandum M-24-10 on , setting governance expectations for federal AI systems that also influence vendors serving public-sector customers.
Key updates
- AI inventories. Agencies must maintain system-level AI inventories, categorize use cases by risk, and publish public dashboards.
- Safety guardrails. Mandatory impact assessments, independent evaluation, and human oversight are required for safety-impacting AI applications.
- Vendor obligations. Contractors supplying AI to agencies must provide documentation covering training data provenance, testing, and governance processes.
Implementation guidance
- Align federal account teams and product managers on documentation packages needed to support agency AI inventories.
- Embed AI risk management controls (model cards, evaluation pipelines, human-in-the-loop workflows) into public-sector product roadmaps.
- Update compliance roadmaps to meet the December 2024 dashboard deadline and annual reporting cycles.
Continue in the Governance pillar
Return to the hub for curated research and deep-dive guides.
Latest guides
-
Public-Sector Governance Alignment Playbook — Zeph Tech
Align OMB Circular A-123, GAO Green Book, OMB M-24-10 AI guidance, EU public sector directives, and UK Orange Book with digital accountability, risk management, and service…
-
Third-Party Governance Control Blueprint — Zeph Tech
Deliver OCC, Federal Reserve, PRA, EBA, DORA, MAS, and OSFI third-party governance requirements through board reporting, lifecycle controls, and resilience evidence.
-
Governance, Risk, and Oversight Playbook — Zeph Tech
Operationalise board-level governance, risk oversight, and resilience reporting aligned with Basel Committee principles, ECB supervisory expectations, U.S. SR 21-3, and OCC…




