One-Year Retrospective on the Federal Government’s Implementation of Updated AI Guidance: Accelerating Usage with Incomplete Safeguards
Introduction
One year ago, the Trump Administration released updated Office of Management and Budget (OMB) guidance to federal agencies about their use and procurement of AI. At the time, CDT noted that this guidance generally demonstrated bipartisan support for commonsense AI governance practices within federal agencies, and the primary question ahead was one of implementation. As federal agencies have taken steps to implement this guidance over the past year, however, a much more worrying picture comes into view. Agencies are operating with fewer resources, unclear requirements, and ideological pressures that have resulted in concerning gaps. The seeming lack of transparency and meaningful oversight within federal agencies is even more troubling given how the federal government has aggressively pursued increased adoption through heavily subsidized deals with major AI vendors.
As this blog explores, the following trends that have emerged over the past year risk undercutting the important progress made within federal agencies on AI governance:
Enacting contradictory, ideologically-driven requirements while reducing agency capacity
Allowing inconsistent and missing public reporting of AI uses despite legal requirements and growing AI adoption
Uneven implementation of AI governance and risk management practices
Enacting Contradictory, Ideologically Driven Requirements while Reducing Agency Capacity
As the Trump Administration’s first major measure on federal agency AI use, the revised OMB memos marked welcome bipartisan progress on public sector AI governance. But only a few months later, the woke AI Executive Order sent a conflicting and opaque message to federal agencies about the White House’s expectations around AI adoption — directing agencies to both rapidly expand AI adoption and limit use of tools that don’t comply with ill-defined “ideological neutrality” requirements.
On top of these competing directives, federal agencies are contending with limited resources and personnel at the same time that the GSA is entering into deals with major AI firms to encourage the quick adoption of these tools. As CDT explored, GSA’s low and no-cost deals risk vendor lock-in and leaving agencies unprepared to manage the rising costs of tools. Since the launch of this effort, current agency personnel have publicly acknowledged these risks, stating that “they get you hooked, and then you’ll pay anything to continue to use it.” These actions have taken place all while federal agencies have seen dramatic reductions in personnel and resources, including the loss of AI experts.
Taken together, this landscape leaves federal agencies with competing, mixed messages about how to effectively use AI tools and without the needed expertise to oversee responsible implementation.
Allowing Inconsistent and Missing Public Reporting of AI Uses Despite Legal Requirements and Growing AI Adoption
As required under the Advancing American AI Act and OMB’s guidance, federal agencies recently published their 2025 AI use case inventories. These reports are key transparency mechanisms and help to provide some insight into what this environment has meant for AI adoption and governance.
OMB’s consolidated version of all federal agencies’ AI inventories shows a dramatic increase (nearly 70%) in reported AI use cases, totalling 3,611 reported use cases in 2025 (as opposed to only 2,133 during 2024). This dramatic increase likely underrepresents the actual extent of AI use within federal agencies. OMB recently updated its reporting guidance to allow agencies to separately report their use of commercial products in a consolidated format. While this may assist the usability and interpretability of the use cases, this also risks obscuring the total increased use of AI in the government.
Although a number of agencies saw significant increases in their total number of AI use cases, the actual substance of the inventories have many of the same inadequacies that CDT has noted in past years. Most notably, there is inconsistent reporting across agencies and insufficient detail about high-impact use cases.
Several examples from the 2025 inventories help to highlight these shortcomings. For the second year in a row, the inventory for the Department of Justice does not include any information about risk management practices, in spite of the fact that 114 of their 315 use cases were deemed high-impact. Additionally, the Department of Homeland Security (DHS) reported a number of significantly risky use cases, but determined that a relatively high percentage of them do not in fact count as high-impact and are thus not subject to heightened risk management requirements. Of the 205 active use cases in the DHS inventory, 51 were determined to be high-impact use cases and 46 were determined to be “presumed high-impact but determined not high-impact.” Designating such a high number of use cases as “presumed high-impact but determined not high-impact” is not only out of step with other federal agencies, but marks a significant departure from DHS’s past inventories which included no such designations. This raises significant concerns about the degree to which DHS is using this designation to potentially underplay or obscure the riskiness of particular use cases and avoid subjecting them to heightened risk management measures.
Across a number of agencies it is still unclear how high-impact determinations are being made. At HHS, for example, less than 1% of all reported use cases were determined to be high-impact in spite of a significant increase in overall use. This sits in stark contrast with agencies like the Department of Veterans Affairs, which comparably saw a significant increase in overall use cases but reported 59% of those as high-impact.
This level of inconsistency between agencies and clear gaps in reporting significantly diminish the utility of agency AI inventories and undermine public trust in agency AI adoption. This lack of progress in agency transparency reporting is especially concerning given that it is happening at the same time that agencies are quickly accelerating their use of these tools.
Uneven Implementation of AI Governance and Risk Management Practices
In addition to federal agencies’ reported AI use cases, OMB’s guidance also requires agencies to publish plans for complying with their risk management obligations and strategies for their overall adoption of AI. Similar to the inconsistencies that CDT noted in our analysis of agencies’ compliance plans in 2024, there is significant variance across agencies’ approaches to AI governance, with a number of agencies lacking a multi-phase, multidisciplinary AI governance process and many agencies failing to explicitly address civil rights and privacy.
Although many agencies have now established multi-phase processes for the review and oversight of their AI tools, a number of agencies still assign their Chief AI Officer with the sole responsibility for reviewing and certifying agency use cases, including the Department of Agriculture, HHS, DHS, and the State Department. When these types of reviews and determinations are made by a single individual without cross-departmental review, risks of potential harms and implementation challenges grow significantly, especially considering most Chief AI Officers were appointed and are serving in this role in addition to pre-existing, fulltime responsibilities.
There are also continued gaps around the substantive involvement of privacy and civil rights experts in agencies’ AI decision-making processes. The Department of Labor and Department of Transportation stand out for their inclusion of such experts throughout the governance process, but a majority of agencies only include these experts in advisory roles. Moreover, many agencies that publicly state that such officials are involved in advisory roles have faced significant cuts to their civil rights and privacy teams — ranging from mass layoffs in DHS civil liberties offices to removing most of the privacy team at the Office of Personnel Management — leaving open questions about whether or not such staff are actually involved in AI decision-making.
Beyond these gaps, a handful of critical agencies have failed to publish their updated AI compliance plans and strategies altogether, including the Department of Education and the Department of Justice, raising significant concerns about what, if any, steps these agencies are taking to ensure that their use of AI tools is safe and trustworthy. These concerns are underscored by the fact that recent reporting indicates that some agencies may not be meeting OMB’s deadline for implementing risk management practices.
Conclusion
The federal government has an obligation to lead by example, showing the American people as well as state and local governments across the country what responsibly using AI within government should look like. At a minimum, this should mean that federal agencies take all reasonable steps to implement the risk management and governance practices required by OMB. But the developments over the last year are worrying indications that trends at the federal level are moving in the opposite direction, with AI adoption accelerating at a rapid rate while commonsense guardrails fall to the wayside.
The Privacy Paradox: How Government Data Has Become Less Private and Less Useful
Providing ready access to information collected and maintained by the government promotes accountability, innovation, and research, making transparency a core responsibility of serving as a steward of the public’s data. Public agencies must also safeguard sensitive information when making data publicly available.
Defending State Data: Lessons from California v. USDA
As the federal government increasingly seeks access to state administrative data, policymakers should consider not only legal authority and privacy implications, but also the practical effects on public confidence, program effectiveness, and states’ ability to fulfill their obligations to residents.
CDT, EFF, EPIC, and Upturn Submit Comments on GSA’s Updated Draft AI Terms and Conditions for Federal Contracts
Today, the Center for Democracy & Technology and allies submitted comments to the General Services Administration (GSA) in response to the request for comment regarding their updated draft AI Terms and Conditions for federal solicitations and contracts.
Bias at Scale: Understanding AI’s Impact on Student Achievement and Opportunity Gaps
Schools have an opportunity and responsibility to ensure that new technologies support, rather than undermine, their longstanding goal of expanding opportunity.