Operationalizing OMB M-25-22: AI Acquisition Compliance
OMB Memorandum M-25-22 mandates a new standard for AI acquisition, focusing on risk management, performance tracking, and competitive marketplaces. Contractors must align their internal AI governance to meet these federal expectations.
The New Mandate for AI Acquisition
In April 2025, the Office of Management and Budget (OMB) issued Memorandum M-25-22, 'Driving Efficient Acquisition of Artificial Intelligence in Government' [11, 13]. This policy is the primary driver for how federal agencies are currently procuring AI systems and services [16, 19]. For government contractors, this is not just a policy for the government; it is a set of requirements that will increasingly be baked into RFPs and task order requirements.
Three Pillars of M-25-22
According to the GAO and OMB, M-25-22 focuses on three overarching themes that contractors must address in their proposals and service delivery [16]:
- Ensuring a Competitive AI Marketplace: Agencies are directed to avoid vendor lock-in and promote interoperability [16]. If your AI solution is proprietary and closed-loop, you will face increasing friction in federal procurements. Focus your messaging on open standards and modularity.
- Tracking AI Performance and Managing Risk: Agencies must now track the performance of AI systems throughout the acquisition lifecycle [16]. This means your proposal must include a clear plan for continuous monitoring, performance metrics, and risk mitigation strategies. You cannot simply deliver an AI tool and walk away; you must provide a framework for ongoing governance [12, 14].
- Promoting Cross-Functional Engagement: AI acquisition is no longer just an IT procurement. It involves legal, privacy, and security stakeholders [16]. Your proposal team must demonstrate that your AI solution has been vetted by these cross-functional groups within your own organization.
Actionable Compliance Steps
To align with M-25-22, contractors should take the following steps:
- Audit Your AI Stack: Ensure your AI tools are compliant with FedRAMP requirements, as agencies are increasingly prioritizing authorized cloud environments for AI deployment [8, 28].
- Develop an AI Governance Framework: Document how your organization manages AI risk, including data privacy, bias mitigation, and security [12, 14]. This documentation should be ready to be included in your technical volume.
- Leverage GSA AI Vehicles: The GSA has established specific 'OneGov' agreements to facilitate the acquisition of AI tools [17, 20]. Ensure your company is positioned to offer your AI solutions through these vehicles to reduce the friction for agency buyers [17].
The Future of AI Proposals
As agencies move toward more efficient AI acquisition, the 'black box' approach to AI is dead. Evaluators are looking for transparency, auditability, and clear alignment with the risk management frameworks outlined in M-25-22 [16]. When writing your next proposal, explicitly map your AI solution to the requirements of M-25-22. Show the evaluator that you understand the agency's need for performance tracking and risk management, and you will immediately differentiate your firm from competitors who are still treating AI as a 'magic' solution.
The GovCon Architect editorial team writes practitioner guidance on federal capture, compliance, and proposal operations. GovCon Architect is an AI-powered federal government contracting platform for opportunity intelligence, capture, compliance, competitive intelligence, and proposal workflows.
