Regulation — federal / OMB memorandum
OMB M-24-10 — AI Use Case Inventory + governance + risk management
Advancing Governance, Innovation, and Risk Management for Agency Use of AI (March 28, 2024). The memo agencies + program offices actually signed against. It defines "safety-impacting AI" + "rights-impacting AI" in ways that pull sustainment-AI into scope, and it requires named-owner accountability for each inventoried use case.
What the memorandum actually says
"Agencies shall ensure appropriate minimum practices for safety-impacting and rights-impacting AI … including completing an AI impact assessment before deploying the AI … testing the AI for performance in a real-world context … independently evaluating the AI … conducting ongoing monitoring … and providing adequate human training, assessment, and oversight."
OMB M-24-10 §5(c)(iv) — the minimum-practices language for safety-impacting AI
"AI is presumed to be safety-impacting when it is used or expected to be used, in real-world conditions, to control or significantly influence … safety of Federal facilities, personnel, or equipment; or safety-of-life applications."
OMB M-24-10 Appendix I — safety-impacting AI definition
What this means in plain English for sustainment AI
A predictive-maintenance AI making red_ground_urgent decisions on defense assets in operational-tempo scenarios controls or significantly influences safety of Federal equipment. That is the safety-impacting definition, and the minimum-practices bar attaches:
- AI impact assessment before deployment
- Real-world testing — not just lab / accreditation testing
- Independent evaluation — distinct from the vendor's own dashboard
- Ongoing monitoring — between-attestation cadence
- Human training, assessment, oversight — the "appropriate human judgment" chain
The AI Use Case Inventory attestation on file must be answerable against these five practices, on demand.
What triggers the exposure in the sample
The Use Case Inventory question — "does your program office monitor AI-driven readiness decisions for group-differential patterns?" — now has a much harder-to-answer shape. If the attestation says yes and the fleet-readiness dashboard is the only monitoring in place, the attestation is not answerable against OMB M-24-10 minimum practice #3 (independent evaluation) or #4 (ongoing monitoring).
What the $499 Snapshot shows against this memorandum
- Independent evaluation — distinct model family, distinct math, distinct retention (minimum practice #3)
- Ongoing-monitoring evidence — distributional-shape sensor + KL-divergence + group-differential thresholds (minimum practice #4)
- Real-world-context testing — sample scenario walkthrough matches the safety-impacting definition (minimum practice #2)
- Signed declaration + reproducibility drill — supports the human-oversight chain (minimum practice #5)
See the independent-verifier declaration →
$499 Snapshot. 3 business days.
The evidence the OMB M-24-10 minimum-practices attestation actually rests on — not vendor screenshots.
Buy $499
Snapshot credit applies to Baseline ($2,500) or Enterprise Attestation ($35-55K) upgrade within 30 days.