Logo
BlogsArtificial IntelligenceResponsible AI in Government: Building Governance, Ethics, and Compliance That Hold

Responsible AI in Government: Building Governance, Ethics, and Compliance That Hold

Responsible AI in government is the practice of deploying artificial intelligence in public agencies with documented risk assessment, human oversight, and public accountability. In the United States it is enforced through OMB Memorandum M-25-21 at the federal level and a growing set of state statutes. Governance only works where it attaches to a decision someone can refuse.

Key Takeaways

  • Governance is a control, not a document. A policy binds only where it attaches to a refusable decision: procurement, data access, deployment approval, or shutdown.
  • The federal rulebook changed in 2025. OMB M-25-21, issued April 3, 2025, replaced M-24-10 and consolidated "safety-impacting" and "rights-impacting" AI into a single high-impact category.
  • The deadlines are already behind us. Agencies had until April 3, 2026 to apply minimum risk-management practices to high-impact AI or discontinue it. FedScoop reported that several agencies missed it.
  • Policy coverage is near-universal; control is not. NASCIO’s 2025 State CIO Survey found 88% of states have responsible-use policies, guardrails, or ethics requirements, and 84% inventory AI uses.
  • Federal preemption does not release agencies. The December 2025 executive order targeting state AI laws expressly carves out state government procurement and use of AI.

What is responsible AI in government?

Responsible AI in government is a set of enforceable controls that determine which AI systems an agency may buy, what data those systems may use, whether they may go live, and when they must be switched off. It is distinct from AI ethics, which describes principles; responsible AI is the machinery that turns principles into decisions with owners and dates.

Three terms carry most of the weight. High-impact AI, as defined in OMB Memorandum M-25-21, is AI that serves as a principal basis for decisions or actions affecting an individual’s rights, liberties, safety, or access to critical government services. An AI impact assessment is a documented pre-deployment review of a system’s intended purpose, data, expected benefits, and potential harms. The NIST AI Risk Management Framework (AI RMF 1.0, published January 2023) is a voluntary US standard organized around four functions: Govern, Map, Measure, and Manage.

Governance is also where most public-sector AI value gets unlocked or lost, because agencies that cannot answer "who approved this and on what basis" tend to stall every use case equally. The same discipline applies in commercial settings; for the wider picture, see our guide to enterprise AI solutions.

Which rules actually govern AI use by US agencies in 2026?

Five instruments do most of the work: two OMB memoranda, one voluntary NIST framework, a small number of state statutes, and each state’s own internal AI policy. The table below summarizes what binds whom.

Instrument Who It Binds Core Requirements Status
OMB M-25-21 (April 3, 2025) Federal executive agencies Designate a Chief AI Officer, publish an AI strategy, maintain a public AI use-case inventory, apply minimum risk-management practices to high-impact AI In force; replaced M-24-10
OMB M-25-22 (April 3, 2025) Federal AI acquisition Acquisition practices covering performance, vendor lock-in, data rights, and IP protection Applies to contracts awarded or renewed on or after October 1, 2025
NIST AI Risk Management Framework 1.0 Voluntary Govern, Map, Measure, Manage functions for AI risk Voluntary; M-25-21 dropped the explicit NIST mandate that M-24-10 carried
Texas TRAIGA (HB 149) Developers and deployers doing business in Texas, including state and local government entities Prohibits specified uses; government entities must disclose AI interaction; NIST AI RMF compliance is an affirmative defense In force since January 1, 2026
Colorado SB 26-189 Deployers of automated decision-making technology Narrowed successor to the 2024 Colorado AI Act (SB 24-205) Signed May 14, 2026; effective January 1, 2027
State Internal AI Policies State agencies Responsible-use rules, use-case inventories, review boards, human-review requirements 88% of states report policies or ethics requirements (NASCIO, 2025)

Note the direction of travel. M-25-21 is framed as pro-adoption rather than restrictive, yet it kept the governance spine from the memo it replaced: a named accountable officer, a public inventory, and a hard stop for non-compliant high-impact systems.

Why do AI governance policies fail to change what agencies deploy?

Most AI governance policies fail because they are written as guidance rather than attached to a decision anyone can refuse. We call the places where governance either bites or does not the Four Binding Points. A policy that touches none of them is a statement of intent, not a control.

Binding Point The Decision It Governs What Binding Looks Like What Non-Binding Looks Like
1. Procurement and Intake Whether the agency may buy or pilot the system at all AI-specific clauses in the solicitation; an intake form that routes every request to a risk tier before spend is approved A principles document published after contracts are already signed
2. Data Access What records the system is permitted to see and retain Role-based access, documented data lineage, retention limits enforced in the platform A privacy policy that no system configuration reflects
3. Pre-Deployment Authorization Whether the system may go live A named approver, a completed impact assessment, and documented pre-deployment testing against expected real-world conditions A launch date set before the review is scheduled
4. Operation and Redress Whether the system stays live Ongoing monitoring for adverse impacts, a working appeal route for affected individuals, and a person with authority to switch it off Annual attestation with no monitoring data behind it

The evidence for this gap is unusually clear. NASCIO’s 2025 State CIO Survey found 88% of states have responsible-use policies, guardrails, or ethics requirements, and 82% have created AI advisory committees or task forces. Yet at the federal level, where the obligations are binding and dated, FedScoop reported that several agencies had still not met the April 3, 2026 deadline for high-impact AI risk-management practices, with some reclassifying use cases rather than remediating them.

Policy coverage and operational control are different measurements. Ask which of the four points your agency can produce evidence for, not how many policies it has published.

What are the minimum risk-management practices for high-impact AI?

OMB M-25-21 specifies a defined set of practices that every federal high-impact AI use case must meet, and it directs agencies to safely discontinue any high-impact use that does not. Those practices are:

  • Pre-deployment testing that simulates expected real-world conditions and outcomes.
  • A completed AI impact assessment covering intended purpose, data, benefits, and potential harms.
  • Ongoing monitoring for adverse impacts after the system goes live.
  • Adequate training and assessment for the staff who operate or rely on the system.
  • Appropriate human consideration and fail-safes that limit harm when the system errs.
  • A consistent appeal process for individuals affected by an AI-influenced decision.
  • A feedback mechanism for end users.

State and local agencies are not bound by M-25-21, but this list is the closest thing the US has to a default standard. Adopting it voluntarily gives a state or municipal program a defensible baseline and makes federal grant-funded work considerably easier to justify.

A Chief AI Officer may waive specific requirements where meeting them would raise overall risk or block critical operations, but the waiver must be certified annually and can be revoked. That structure is worth copying: exceptions are allowed, but they are named, time-bound, and reversible. Building that into your own responsible AI frameworks is what keeps governance from becoming a blanket "no."

Does federal preemption remove state and local AI obligations?

No. The December 11, 2025 executive order that directs federal agencies to challenge state AI laws expressly carves out state government procurement and use of AI, alongside child-safety protections and AI infrastructure. According to analysis from Latham & Watkins, those categories sit outside the preemption effort.

This is the point most public-sector readers miss. The deregulation debate is largely about what states may require of private AI developers and deployers. It is not about what a state may require of its own agencies. A state’s AI review board, procurement clauses, and human-review rules are unaffected by the preemption fight.

There is a second reason not to wait for the dust to settle. As of September 2026 there is still no comprehensive federal AI statute, and preemption remains an executive-order strategy plus a legislative proposal rather than enacted law. An agency that pauses governance work pending federal clarity will be waiting a while, and will be deploying AI in the meantime regardless.

How should an agency sequence responsible AI without stalling delivery?

Tier the use case first, then apply proportionate controls. Blanket governance applied equally to a meeting-summarizer and a benefits-eligibility model is the single most common reason agency AI programs stall.

Tier 1, internal productivity. Drafting, summarization, translation, code assistance. Controls: acceptable-use policy, staff training, human review before anything is sent externally. These can move quickly.

Tier 2, constituent-facing information. Chatbots and search that answer questions but make no determinations. Controls: grounded retrieval from verified agency content, disclosure that the user is interacting with AI, escalation to a human, and accuracy monitoring.

Tier 3, high-impact. Anything that influences eligibility, enforcement, safety, or access to services. Controls: the full minimum-practices set, a named approver, and an appeal route before launch.

Sequencing this way lets Tier 1 deliver visible value while Tier 3 goes through proper review, which is usually what buys a program its political runway. Vendor selection matters at every tier, and the questions worth asking are covered in our guide to choosing a government AI partner. For the wider set of agency use cases these controls apply to, see our overview of AI solutions for public sector organizations.

How JBS helps agencies put responsible AI governance into practice

JBS (Jaffer Business Systems) designs AI governance as part of delivery rather than as a review layer bolted on afterward. That approach is grounded in 100+ AI implementations across 46+ enterprise customers in 12+ countries, supported by 30 AI specialists.

The engagement model maps closely to the Four Binding Points. An AI readiness assessment examines data, systems, workflows, security, and governance ownership before any build begins. Use-case discovery and prioritization score opportunities by impact, feasibility, data availability, and risk, which is the tiering step most agencies skip. The AI governance model then defines data access, human review, escalation, approvals, monitoring, and ownership, so the controls exist in the workflow rather than in a document.

On the compliance side, JBS aligns deployments to US data-privacy and security standards including CCPA/CPRA, HIPAA, SOC 2, and NIST frameworks. For agencies handling benefits, health, or identity data, that posture is the difference between a pilot that can scale and one that cannot clear review.

Agencies that need governance defined before the first deployment, not after it, can review JBS’s responsible AI frameworks and readiness assessment approach.

Frequently asked questions

What is responsible AI in government?

Responsible AI in government is the deployment of artificial intelligence by public agencies under documented risk assessment, human oversight, and public accountability. In practice it means a named accountable officer, a published use-case inventory, impact assessments before launch, monitoring after launch, and a working appeal route for affected individuals.

What is OMB M-25-21?

OMB Memorandum M-25-21, issued April 3, 2025, is the primary federal AI governance policy for executive agencies. It replaced M-24-10 and requires agencies to designate a Chief AI Officer, publish an AI strategy and use-case inventory, and apply minimum risk-management practices to high-impact AI systems.

What counts as high-impact AI?

Under M-25-21, high-impact AI is AI that serves as a principal basis for decisions or actions affecting an individual’s rights, liberties, safety, or access to critical government services. Certain uses are presumed high-impact, including safety-critical infrastructure functions and medically relevant functions of medical devices.

Is the NIST AI Risk Management Framework mandatory for agencies?

No. The NIST AI Risk Management Framework is voluntary, and M-25-21 dropped the explicit NIST mandate that its predecessor carried. It remains the most widely used US reference, and Texas TRAIGA treats substantial compliance with it as an affirmative defense for covered entities.

Do state AI laws still apply to government agencies?

Yes. The December 2025 federal preemption executive order expressly carves out state government procurement and use of AI. State internal AI policies, review boards, and procurement requirements continue to apply to agencies regardless of how the broader preemption dispute is resolved.

Conclusion

Responsible AI in government succeeds or fails at four points: what you buy, what data it sees, whether it may go live, and whether anyone can switch it off. Agencies with strong policies and none of those controls are exposed; agencies with all four can move faster, because every use case has a defined path rather than an open question.

To tier your current AI use cases and define the governance controls each one needs before deployment, review JBS’s AI strategy, readiness, and governance approach.

Ready to turn AI readiness
into AI excellence?

Let's empower your people with the skills, confidence, and mindset to lead in an AI-powered world.

Consult an expert