Skip to main content
v2026.11,858 entries · CC-BY 4.0

OMB M-26-04 and EO 14319: The Unbiased AI Principles Clause Federal LLM Contracts Must Carry

OMB Memorandum M-26-04, issued 11 December 2025, implements Executive Order 14319 by requiring every federal solicitation or order for a large language model to include contractual requirements addressing compliance with the two Unbiased AI Principles. This guide covers the documentation floor, the scope carve-outs for national security systems and openly licensed models, the 11 March 2026 policy deadline and end-user reporting channel, the two-year sunset, and the unresolved problem that “ideological neutrality” is made material to payment without any published test.

Written and maintained by CASRAI Editorial Board

Last updated

Since 11 December 2025, federal contracting officers have had a new clause to write. OMB Memorandum M-26-04, “Increasing Public Trust in Artificial Intelligence Through Unbiased AI Principles,” signed by OMB Director Russell T. Vought, is the implementing guidance for Executive Order 14319 — and unlike the executive order itself, it lands directly in solicitation documents. Its core instruction is a single sentence: agencies “must ensure that any solicitation or order for procurement of an LLM they issue after the date of this memorandum includes contractual requirements addressing compliance with the Unbiased AI Principles.” This guide covers what that clause has to ask for, which procurements are in and out of scope, and the three dates that matter. It also flags, honestly, the part nobody has solved: there is no published test for one of the two principles the clause makes a material contract term. CASRAI tracks the disclosure-boundary question this raises in NIKOLAI, its own independent frontier-AI-safety dictionary, under the redaction element on the N8 transparency-and-review track.

Two documents, one obligation

Executive Order 14319, “Preventing Woke AI in the Federal Government,” was signed 23 July 2025. It is the policy instrument: it identifies two Unbiased AI Principles and, in Section 4, directs the Director of the Office of Management and Budget to issue guidance to agencies implementing them. M-26-04 is that guidance. The memo says so explicitly, and adds that it “complements OMB Memorandum M-25-22, Driving Efficient Acquisition of Artificial Intelligence in Government” — it does not replace M-25-22, and it does not replace M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust. Both of those memos were issued 3 April 2025 and both remain the baseline; M-26-04 adds a layer on top for one class of acquisition. EO 14319 is also a separate instrument from the two orders that get most of the attention in this area — see CASRAI’s explainer on EO 14179 and EO 14365, the other two Trump AI executive orders, neither of which creates a procurement clause.

That two-document structure is why this is a procurement question rather than a policy-commentary question. An executive order directs agencies. A contract clause binds a vendor. The path from one to the other runs through M-26-04, and the practical compliance work sits in the documents an agency now has to request and the terms it now has to insert.

The two Unbiased AI Principles, as the memo states them

Truth-seeking. “LLMs shall be truthful in responding to user prompts seeking factual information or analysis. LLMs shall prioritize historical accuracy, scientific inquiry, and objectivity, and shall acknowledge uncertainty where reliable information is incomplete or contradictory.”

Ideological Neutrality. “LLMs shall be neutral, nonpartisan tools that do not manipulate responses in favor of ideological dogmas. Developers shall not intentionally encode partisan or ideological judgments into an LLM’s outputs unless those judgments are prompted by or otherwise readily accessible to the end user.” Section 3 of the executive order itself gives DEI as an example of such a dogma; the memo’s restatement drops the example and keeps the rule.

“LLM” is defined in Section 2 of the executive order as “a large language model, which is a generative AI model trained on vast, diverse datasets that enable the model to generate natural-language responses to user prompts.” That definition carries into the memo, and it is the scope trigger for everything below.

The four agency actions, and their dates

Requirement Force Date
New solicitations or orders for an LLM must include contractual requirements addressing compliance with the Unbiased AI Principles Must Any issued after 11 December 2025
Existing LLM contracts modified to include those requirements, to the extent practicable Should At the latest, before exercising any option that extends the period of performance
Agency procurement policies and procedures updated, including a process for agency LLM users to report violating outputs Must No later than 11 March 2026
Memorandum ceases to have force or effect Sunset Two years after issuance (11 December 2027), unless the OMB Director provides otherwise

Three details in that table are easy to read past. First, the new-contract duty attaches to the solicitation or order, not to the award — a task order placed under an existing vehicle after 11 December 2025 is an order, and it carries the requirement. Second, the memo extends the same duty to “any solicitation or order for AI models other than LLMs to which the requirements of this memorandum should apply, as determined by the agency,” so the agency’s own applicability determination, not the model’s architecture, sets the boundary. Third, the option-exercise trigger converts the “should” on existing contracts into something with a real schedule: every option year on a live LLM contract is a forcing event.

The March 2026 policy deadline has a second half that is easy to miss and harder to build. Updated policies “must include processes for agency users of LLMs to report outputs that violate the Unbiased AI Principles.” That is an internal intake channel, triage path and escalation route for end users of a deployed model — closer in shape to an internal incident-reporting programme than to a procurement policy edit, and it has the same deadline.

What the clause has to ask the vendor for

Appendix A sets the documentation floor. When procuring an LLM, agencies “must obtain sufficient information from the vendor to determine whether that LLM complies with the Unbiased AI Principles,” and the memo is candid that how much information is obtainable depends on where the vendor sits: resellers, integrators and platform operators may be several steps removed from the developer, and “the availability of product information and potential for direct product interventions will depend on the willingness of the actual AI developer to collaborate through the third-party distributor.”

Minimum threshold for LLM transparency

In solicitations for LLMs, agencies must request four things:

  • Acceptable Use Policy — the developer’s own characterization of appropriate and inappropriate use of the product.
  • Model, system, and/or data cards — the memo notes it is uncommon for a vendor to produce all three.
  • End user resources — tutorials, developer guides, or similar material to help customers use the LLM properly.
  • A mechanism for end user feedback — satisfiable by “a general inbox, specific product point of contact, or similar mechanism for providing feedback to the vendor on outputs that violate the Unbiased AI Principles.”

Enhanced threshold, where the agency decides it needs more

Where the planned use warrants it — the memo names public-facing LLMs as a likely case — agencies may request more, focused on what is “directly relevant to the Principles”:

  • Pre-training and post-training activities: actions affecting factuality and grounding; system-level prompts, “particularly with regard to how a model responds when reliable information is incomplete, contradictory, or subject to individual interpretation”; the types of output restricted by content moderation and safety filters; use of red teaming as continuous assessment against bias in generated output; any training or development conducted outside the United States, including the activity type and country; and any modifications made to comply with a non-U.S. government’s regulation.
  • Model evaluations: bias-evaluation results and the methodology used (the memo’s own example is “testing prompt pairs for politically-oriented topics”), plus benchmark scores for bias, helpfulness, honesty or accuracy on ambiguous versus straightforward questions, and cross-language comparisons where necessary.
  • Enterprise-level controls: customizable system instructions layered on the base model’s prompts, model-evaluation tooling for comparing outputs or models, and features that make a model cite sources or otherwise expose output provenance.
  • Third-party modifications: where the vendor is not the developer, disclosure of classifiers, system prompts, fine-tuning and content moderation the vendor has applied on top.

There is a counterweight built in. “Where practicable, agencies should avoid requirements that compel a vendor to disclose sensitive technical data, such as specific model weights.” Documentation requests are meant to reach far enough to assess risk-management actions at the model, system and/or application level — not into the model itself. Anyone running a vendor-diligence process will recognise the shape of this trade-off from ordinary third-party AI vendor risk assessment; the difference here is that the floor is mandatory and the answers become contract record.

The materiality hook

The clause is not decorative. Agencies “should explicitly identify relevant requirements … as material to eligibility and payment under the contract, to support termination of the contract for default,” where a vendor refuses corrective action in identified cases of noncompliance. The executive order goes one step further on consequences: agreements are to specify that decommissioning costs are charged to the vendor if the agency terminates for non-compliance after a reasonable cure period. Materiality plus default termination plus vendor-borne decommissioning is the enforcement chain, and it runs on documents the vendor supplies about itself.

Where the scope lines actually fall

The memo applies to each agency — executive departments, military departments, independent establishments within 5 U.S.C. 101, 102 and 104(1), and wholly owned Government corporations within 31 U.S.C. 9101. Within that, it reaches any LLM procured by an agency, “regardless of the manner in which the LLM will be deployed, further modified, or used by the agency.” Fine-tuning it, wrapping it in an internal application, or restricting it to a back-office workflow does not take it out of scope.

Out of scope:

  • National security systems as defined in 44 U.S.C. 3552(b)(6) — excluded outright, though application “to the extent practicable, is encouraged.” The memo points to existing regimes instead, naming the Department of War’s Responsible AI Strategy and Implementation Pathway, ODNI’s Principles of AI Ethics for the Intelligence Community, and DoD Directive 3000.09 on autonomy in weapon systems.
  • Agency regulatory actions prescribing law or policy about non-agency uses of AI.
  • Enforcement and investigative assessments — where the AI provider is the target of a regulatory, law-enforcement or national-security action, or the application is being evaluated because a criminal suspect used it.
  • General-purpose measurement work — developing metrics, methods and standards to test AI for the public or the Government as a whole, rather than for a particular agency application. The memo’s examples are standards or testing methodologies for evaluating or red-teaming AI capabilities, which is the remit of standards bodies rather than of an individual buying office.
  • Contractor-incidental AI — “AI used incidentally by a contractor during performance of a contract for administrative purposes (e.g., AI used at the option of a contractor when not directed or necessary to fulfill requirements).”

Determined case-by-case, under the Appendix A.2 factors: agency-developed LLMs and small language models, and AI models other than LLMs. For agency-developed models, the memo expects documentation covering how pre-training and training were conducted, how the model was evaluated and whether evaluation recurs, what enterprise controls are built in and how they are configured, and how the development team handles end-user feedback. For other generative capabilities — image, voice, multimodal — agencies “shall, where practicable, use this guidance to inform the documentation requirements imposed for the procurement.”

The free and open-source carve-out

Agencies are “not required to apply the requirements of this memorandum to LLMs acquired pursuant to a free, open-source license.” The carve-out lives in a footnote, not the body, and it comes with an obligation attached: agencies “should establish procedures to perform due diligence on the alignment of such models with E.O. 14319’s Unbiased AI Principles, as well as with the requirements of OMB Memorandum M-25-21, prior to use.” The memo also points back to M-16-21 on responsibly leveraging open-source offerings.

The practical effect is a swap, not an escape: the contractual mechanism disappears and an internal diligence duty replaces it. Agencies that respond to this memo by moving workloads onto openly licensed models will find they have exchanged a clause they can enforce against a vendor for a process they have to run themselves. The structure will look familiar to anyone who has worked through the EU AI Act’s open-source exemption under Article 53, where a licence-based carve-out similarly narrows what a downstream party can demand, and for similar reasons.

The unsolved part: neutrality has no test

Read the memo as a compliance document and one gap is hard to miss. “Ideological neutrality” is made material to payment and default termination, but neither the executive order nor the memo defines a threshold, a benchmark, or a methodology for determining whether a model meets it. What the memo actually requires is that the agency request the vendor’s own bias-evaluation results and the methodology behind them. Nothing establishes a government test, an accepted benchmark, or an independent evaluator.

The memo is aware that relevance varies. Its own footnote observes that “the Unbiased AI Principle of truth-seeking will likely be more relevant than ideological neutrality for LLMs that operate as part of a tool to summarize cybersecurity incidents for a security operations center.” That is a sensible concession, and it is also an admission that applicability is a judgement call made per procurement.

So the near-term work is contractual and evidentiary before it is technical. A vendor is being asked to represent compliance with a principle that has no published pass mark, and an agency is being asked to evaluate that representation using documents the vendor produced. The memo does gesture at future tooling — consistent with Section 3(g) of M-25-22, “best practices, including new sample AI transparency terms and conditions developed by GSA, will be made available in a shared repository, when available.” Until that repository lands, each agency is drafting its own terms against an undefined target, and two agencies buying the same model can reasonably reach different conclusions about whether it qualifies.

What this means for research administration

The honest framing first: M-26-04 binds agencies as buyers. It does not regulate grantees. Nothing in it imposes a duty on a university because that university holds NIH or NSF funding, and nobody should read it as a new term-and-condition on a grant award. Two narrower hooks are real, though.

Grant-making agencies are covered agencies. NIH, NSF and every other executive-branch funder is inside the scope definition when it procures an LLM. Any language model an agency buys and uses in or around proposal intake, triage support, reviewer administration or award management now sits behind a contract carrying these requirements, and behind an internal channel — due by 11 March 2026 — for agency staff to report outputs that violate the principles. For research administrators tracking how funders are deploying AI in the proposal pipeline, that reporting channel is a new, concrete accountability artifact that did not exist before.

University units that sell LLM capability to the government are vendors. A research computing organisation, FFRDC-adjacent centre or university-affiliated entity that provides or hosts language-model capability under a federal contract is the vendor in this relationship and receives these terms directly — including the minimum documentation set and the materiality treatment. The contractor-incidental exclusion is the boundary worth knowing: AI a contractor uses at its own option for administrative purposes, not directed by or necessary to the requirement, is outside the memo. Using an LLM to help draft an internal status report on a federal contract is not what this reaches; delivering LLM capability as the thing being bought is.

For institutions building governance around either hook, the role questions this raises — who signs the attestation, who owns the reporting channel, who reviews the vendor documentation — are the same ones covered in the Chief AI Officer scope and mandate, a role M-25-21 already requires at federal agencies.

Where NIKOLAI fits

M-26-04 sets a disclosure floor and a disclosure ceiling in the same appendix: agencies must request acceptable use policies, model and system cards, end-user resources and a feedback mechanism, and should avoid compelling disclosure of sensitive technical data such as model weights. That is a boundary question about what a developer publishes, what it withholds, and whether the withholding is visible — which is exactly what NIKOLAI’s redaction element on the N8 transparency-and-review track is built to record: the location and extent of a removal, the reason drawn from a controlled vocabulary, the deciding party, and the disclosure that a removal occurred at all, as distinct from silent omission. A vendor response that quietly omits its bias-evaluation methodology and a vendor response that states it is withholding that methodology are very different compliance artifacts, and only one of them gives a contracting officer something to act on.

NIKOLAI is CASRAI’s own independent frontier-AI-safety dictionary. It is not a standard, and no agency, lab or regulator has endorsed it. Every crosswalk row in it is a shadow mapping — CASRAI’s own reading of a published document — unless the organisation named on that row has filed a Mapping Declaration confirming it. No mapping to M-26-04 or EO 14319 carries any endorsement from OMB.

Frequently asked questions

What is OMB M-26-04?

OMB Memorandum M-26-04, “Increasing Public Trust in Artificial Intelligence Through Unbiased AI Principles,” issued 11 December 2025 by OMB Director Russell T. Vought, is the guidance implementing Executive Order 14319. It requires federal agencies to include contractual requirements addressing compliance with the two Unbiased AI Principles in solicitations and orders for large language models, and to update their procurement policies by 11 March 2026.

Which contracts does M-26-04 apply to?

Any solicitation or order for the procurement of an LLM issued by a covered agency after 11 December 2025, regardless of how the model will be deployed, further modified or used. Existing LLM contracts should be modified to the extent practicable, at the latest before exercising an option that extends the period of performance. Agencies may also extend the requirements to agency-developed LLMs and to non-LLM AI models using the factors in Appendix A.2.

Are open-source LLMs exempt from M-26-04?

Agencies are not required to apply the memorandum’s requirements to LLMs acquired under a free, open-source license, but the memo says they should establish procedures to perform due diligence on such models’ alignment with the Unbiased AI Principles and with M-25-21 before use. It is a shift from contractual enforcement to internal diligence, not a removal of the obligation to check.

Does M-26-04 replace M-25-21 or M-25-22?

No. The memo states that it complements M-25-22, Driving Efficient Acquisition of Artificial Intelligence in Government, and Appendix A builds on both M-25-22 and M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust, both issued 3 April 2025. All three operate together.

How is compliance with “ideological neutrality” measured?

There is no published government test. The memorandum requires agencies to request the vendor’s own bias-evaluation results and the methodology used to produce them, along with benchmark scores for bias, helpfulness, honesty or accuracy, but it does not set a threshold or name an approved benchmark. Compliance is established through vendor documentation and contractual representation rather than an independent evaluation standard.

What happens if a vendor does not comply?

Agencies should identify the relevant requirements as material to eligibility and payment under the contract, which supports termination for default where the vendor refuses corrective action after noncompliance is identified. Executive Order 14319 further directs that agreements specify decommissioning costs are charged to the vendor if the agency terminates for non-compliance following a reasonable cure period.

Does M-26-04 apply to universities that receive federal grants?

No. The memorandum governs federal agencies as purchasers of LLMs; it does not impose requirements on grant recipients. It becomes relevant to a university only if a unit of that university is itself the vendor supplying LLM capability under a federal contract, in which case the contract terms apply to it directly.

When does M-26-04 expire?

The memorandum states that it ceases to have any force or effect two years after the date of its issuance — 11 December 2027 — unless the Director of OMB provides otherwise.

Related reading

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about OMB M-26-04 and EO 14319: The Unbiased AI Principles Clause Federal LLM Contracts Must Carry

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Ask CASRAI · Regulatory Radar

AI policy question? Get an answer citing the framework.

An AI assistant specialized in research administration. Every answer links its sources to check before you act. 2 questions free, no account. $29/month after.

  • Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
  • Every answer numbers its sources and links each one, so you can check the source yourself.