cd /news/ai-policy/the-federal-ai-compliance-deadline-i… · home topics ai-policy article
[ARTICLE · art-136794] src=forkast.news ↗ pub= topic=ai-policy verified=true sentiment=↓ negative

The Federal AI Compliance Deadline Is Here. The Memo Behind It Has Vanished.

Federal agencies face a September 22, 2026 compliance deadline to report implementation of minimum risk management practices for high-impact AI under OMB Memorandum M-25-21, but the White House page hosting the memorandum now returns a 404 error. A September 21 analysis by Emily Froude of Democracy Forward, published by Tech Policy Press, found that the Department of Homeland Security has used the memo's "principal basis" loophole to avoid classifying Anduril's Autonomous Surveillance Tower and Palantir's ELICE deportation-targeting system as high-impact AI. The avoidance comes as the administration announced a Trump AI Force and a new AI Czar on September 19, three days before the deadline, and EO 14409, signed in June 2026, added DHS and CISA obligations on top of M-25-21.

by read4 min views4 publishedSep 22, 2026
The Federal AI Compliance Deadline Is Here. The Memo Behind It Has Vanished.
Image: Forkast (auto-discovered)

Eighteen months ago, the Office of Management and Budget issued a directive that represented a rare point of continuity between administrations. OMB Memorandum M-25-21, “Accelerating Federal Use of AI through Innovation, Governance, and Public Trust,” carried over protections first established under the Biden-Harris White House, reflecting a shared recognition that government AI systems can significantly harm the public’s rights and safety. Today, September 22, 2026, is the compliance deadline the memo established. Every federal agency must report its implementation of minimum risk management practices for high-impact AI to OMB – or discontinue those systems. The White House page that hosted the memorandum now returns a 404 error.

The core of M-25-21 rests on a specific definition. High-impact AI is a system whose output serves as a principal basis for decisions or actions that have a legal, material, binding, or significant effect on rights or safety. This classification triggers mandatory safeguards: pre-deployment testing, AI impact assessments, adequate human oversight, remedies and appeals for affected individuals, and the obligation to or discontinue any system that fails to meet these standards. Agencies had eighteen months to build this infrastructure. Today is the test.

The policy’s language, however, contains a structural vulnerability that has already been exploited. The Department of Homeland Security has relied on the “principal basis” loophole to avoid classifying some of its most consequential AI tools as high-impact, according to a September 21 analysis by Emily Froude of Democracy Forward published by Tech Policy Press. The logic is narrow: as long as a human technically makes the final call, the AI’s output was never the principal basis for anything – no matter how much that output shaped the decision.

DHS has applied this reasoning to two systems that directly determine where armed government forces deploy. The Autonomous Surveillance Tower, manufactured by Anduril, sends alerts when it detects persons, vehicles, or animals in its image frame. DHS claims the system “merely alerts to the presence of an item it was trained to detect.” But the tower independently selects what to ignore and what to flag. Unable to scan the entire border themselves, border officials are entirely dependent on its output: the system’s alerts dictate where agents are dispatched. By the memo’s own definition, the tower’s classification should be the principal basis for deployment decisions.

The second system is ELICE, Palantir’s Enhanced Lead Identification and Targeting application, which ICE uses to view a map of potential deportation targets with each address scored for likelihood. DHS claims ELICE outputs are “limited to normalized addresses” and that officers “review and validate the AI-driven outputs before determining actions.” But as Froude’s analysis argues, agents are likely demonstrating automation bias – an over-reliance on algorithmic output without being positioned to exercise meaningful scrutiny. ELICE’s entire purpose is to identify and prioritize addresses for enforcement, leading agents to locations they would not otherwise know to target.

This pattern of avoidance is occurring against a backdrop of sharp political reorientation. On September 19, three days before the compliance deadline, the administration announced the creation of a Trump AI Force and a new AI Czar, signaling a growth-first mandate that explicitly dismisses AI safety as a hoax. EO 14409, signed in June 2026, had already added DHS and CISA obligations on top of M-25-21. Agencies now operate between the legacy requirements of the memo and a deregulatory posture from the same White House that issued it.

The timing raises a question the compliance deadline was designed to answer: does the federal government actually possess a comprehensive inventory of the high-impact AI systems currently in operation? The deadline was intended to force this transparency. The evidence suggests the mechanisms for accountability are being dismantled or reinterpreted before they can be fully tested.

The structural gap between policy and practice extends beyond the United States. The European Union’s AI Act is grappling with its own accountability challenges, particularly regarding lifecycle liability during the testing phase – a gap we examined in our analysis of EU product law and autonomous agents. The bipartisan Pro-Human Coalition in the Senate continues to push for safety legislation, while the executive branch’s recent maneuvers suggest a preference for speed over scrutiny. The ambiguity surrounding agent liability and the potential for a Bessent-style liability shield further complicate the path toward a coherent accountability framework.

As the deadline passes, the focus shifts from compliance to the reality of deployment. These systems have not ceased to function; they are operating in a regulatory environment where the principal basis loophole ensures that the most consequential AI tools remain shielded from the assessments designed to protect the public. The mechanisms of oversight are being systematically weakened – whether through technical erasure, administrative reinterpretation, or the simple passage of a deadline without consequence. Policy is only as effective as the political will to enforce it, and the events of this week suggest that will is fracturing along the exact fault line M-25-21 was built to bridge.

── more in #ai-policy 4 stories · sorted by recency
── more on @office of management and budget 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/the-federal-ai-compl…] indexed:0 read:4min 2026-09-22 ·