AI Action Plan 2025: What Federal AI Policy Actually Changed
The rescission of Executive Order 14110 and the release of America's AI Action Plan changed federal executive-branch guidance and stated priorities, not enforceable law. Sector regulation, contractual obligations, the NIST AI Risk Management Framework, and state AI statutes remain in effect.
Key Takeaways
- EO 14110 was rescinded on January 23, 2025. It was executive-branch policy, not statute, so the rescission affects internal federal agency direction.
- America's AI Action Plan is a priorities document. It does not create new binding legal obligations on private enterprises.
- NIST AI RMF 1.0 remains published and unchanged. It was not withdrawn by the 2025 executive actions.
- Colorado's AI Act (SB 24-205) and Texas's TRAIGA remain in force. A proposed federal moratorium on state AI regulation was removed from 2025 budget legislation.
- Governance teams should identify which existing controls were adopted specifically for EO 14110 compliance and which are required by other legal or contractual sources before adjusting programs.
Federal AI policy shifted visibly in early 2025, and governance teams at enterprises deploying AI systems have had to work through what the changes actually mean. The short answer is that they are more limited than headlines suggest: the primary change is to executive-branch direction, not to the body of statute, sector regulation, or state law that governs most enterprise AI risk.
What Changed at the Federal Level
Executive Order 14110, issued October 30, 2023, established federal requirements for AI safety, security, and risk management across executive branch agencies. Among other provisions, it directed agencies to assess AI risks, required safety testing for frontier models above specified thresholds, and established reporting and coordination structures across federal departments.
On January 23, 2025, Executive Order 14179, titled "Removing Barriers to American AI Leadership," rescinded EO 14110 and directed agencies to review and revise their AI-related policies to remove what the order characterized as barriers to AI development.
It is worth being precise about what this mechanism does. Executive orders are policy directives to federal agencies. They do not create private rights of action, and a subsequent administration can modify or reverse them without any legislative process. The rescission changes internal federal agency direction. It does not, by itself, repeal statutes, alter contracts, or preempt state law.
| Item | Status After January 2025 | Binding on Private Enterprises? |
|---|---|---|
| EO 14110 | Rescinded January 23, 2025 | Was not directly binding; directed federal agencies |
| America's AI Action Plan | Released mid-2025 as federal priorities | No: policy and priorities document only |
| NIST AI RMF 1.0 | Unchanged; still published guidance | Voluntary; remains widely referenced |
| Colorado AI Act (SB 24-205) | In force | Yes: applies to developers and deployers of high-risk AI in Colorado |
| Texas TRAIGA | In force (enacted 2025) | Yes: applies to covered entities operating in Texas |
| FTC authority over unfair or deceptive practices | Unaffected | Yes: applies to AI system behavior and consumer claims |
| Sector-specific financial and health data rules | Unaffected | Yes: sector obligations continue regardless of AI EO status |
What America's AI Action Plan Does and Does Not Do
The White House followed the rescission with America's AI Action Plan in mid-2025, organizing federal priorities around accelerating AI innovation, building domestic AI infrastructure, and advancing international AI competitiveness. The plan reflects a deliberate shift in federal emphasis from risk-management mandates toward growth and development priorities.
This is a policy and priorities document. It does not itself create new binding legal obligations on private enterprises. Agency implementation of both the rescission and the Action Plan appears uneven: federal procurement or agency-use guidance previously tied to EO 14110 may be withdrawn on different timelines by different agencies, and some elements of the Action Plan may remain aspirational rather than actioned.
For enterprises with federal contracts: Confirm directly with your contracting agency whether EO 14110-linked guidance has been formally rescinded or replaced, rather than assuming uniform federal-wide change. Agency-level implementation varies.
What Remains Unaffected by the Rescission
Several sources of obligation sit outside the executive order and are unaffected by its rescission.
NIST AI Risk Management Framework
NIST's AI Risk Management Framework (AI RMF 1.0), published January 2023, remains available as voluntary guidance. It operates independently of executive order status and was not withdrawn by the 2025 executive actions. The framework's four core functions, Govern, Map, Measure, and Manage, continue to provide a widely recognized structure for enterprise AI risk programs whether or not an administration endorses them by executive directive.
Sector-Specific Federal Regulation
Sector-specific federal regulation, including FTC authority over unfair or deceptive practices and existing financial and health data rules, continues to apply to AI systems regardless of AI-specific executive order status. The rescission of EO 14110 does not alter FTC jurisdiction over consumer harm, HIPAA obligations for health data processed by AI systems, or banking-sector model risk management guidance.
State AI Statutes
State AI statutes are not preempted by federal executive action. Colorado's AI Act (SB 24-205), enacted in 2024, imposes obligations on developers and deployers of high-risk AI systems independent of federal policy, including requirements for impact assessments, risk management disclosures, and consumer rights. Texas passed its Responsible AI Governance Act (TRAIGA) in 2025, creating a separate set of state-level obligations applicable to covered entities operating in that state.
A proposed federal moratorium on state AI regulation, considered during 2025 congressional budget legislation, was removed before passage, leaving these state laws in effect. This does not guarantee the issue will not recur in future legislation, and it should be tracked accordingly by compliance and legal teams.
Federal Signal Versus Enforceable Obligation
The distinction between a change in federal policy signal and a change in enforceable legal obligation matters considerably for governance program design. A deregulatory executive order removes internal federal agency requirements. It does not remove obligations that arise from statute, sector regulation, contractual terms with customers or partners, or state law.
Governance programs that were built to satisfy EO 14110 requirements alone may have more room to adjust. Programs that cite EO 14110 as one justification among several, alongside sector regulation, contractual requirements, or NIST alignment, should evaluate each justification independently before concluding that a control is no longer required.
A useful framing: Ask not whether the EO changed, but whether the underlying legal or operational reason for each control changed. Most runtime governance controls are justified by security, privacy, and sector-regulatory requirements that were never contingent on EO 14110 being in force.
Questions to Answer Before Adjusting Governance Controls
Before scaling back or removing controls that reference EO 14110, governance teams should work through a set of practical questions:
- Was this control adopted solely to comply with EO 14110, or does it also satisfy a sector regulation, contract term, or state statute?
- Does the enterprise have federal contracts that include EO-linked clauses? Have those agencies formally rescinded or replaced the relevant guidance?
- Does the enterprise deploy AI systems that qualify as high-risk under Colorado's AI Act or Texas TRAIGA? If so, what controls does that require?
- Does the enterprise's AI risk management documentation reference NIST AI RMF alignment? Has the NIST framework changed?
- Do existing customer contracts or data processing agreements require specific AI risk controls regardless of federal executive order status?
- Has legal counsel reviewed the impact of the rescission on any commitments made to customers, regulators, or auditors?
Runtime Governance Still Requires a Documented Basis
The practical question for governance leaders is not whether federal signaling changed, but whether the underlying justification for existing controls changed with it. Runtime governance and monitoring controls implemented for AI systems are typically justified by security, privacy, and sector-regulatory requirements that exist independently of the rescinded EO.
Systems built to align with NIST AI RMF categories, covering Govern, Map, Measure, and Manage, remain aligned with a still-published federal framework even after the rescission. Controls such as agent identity management, tool approval workflows, permission scoping, and audit logging address operational security and accountability requirements that are not contingent on any single executive order being in force.
Governance programs should avoid removing runtime controls based solely on federal EO rescission without first verifying the continued applicability of other legal or contractual drivers. The deregulatory signal from Washington is real, but it operates within a landscape of sector regulation and state law that has not followed the same direction.
Frequently Asked Questions
Does the rescission of EO 14110 affect contracts signed before January 2025?
Not automatically. Contracts that reference EO 14110 compliance requirements are governed by their own terms and any agency-specific guidance. Enterprises with federal contracts should review the contract language and confirm with the contracting agency whether EO-linked requirements have been formally modified. Commercial contracts between private parties are unaffected by the executive action.
Is the NIST AI Risk Management Framework still the right reference for enterprise AI governance?
Yes. The NIST AI RMF 1.0 remains published, unchanged, and widely used as a voluntary framework for enterprise AI risk programs. Its four core functions, Govern, Map, Measure, and Manage, remain applicable regardless of the current executive order landscape. Many organizations use it as a structuring tool independent of any regulatory mandate.
Do Colorado's AI Act and Texas TRAIGA apply to companies outside those states?
The applicability of these statutes depends on whether the enterprise develops or deploys AI systems that affect residents of those states, not solely on where the enterprise is incorporated or headquartered. Enterprises that offer products or services to consumers in Colorado or Texas, or that deploy AI systems making consequential decisions affecting residents of those states, should assess coverage with legal counsel.
Could a future federal law preempt the Colorado and Texas AI statutes?
Potentially. A proposed federal moratorium on state AI regulation was removed from 2025 budget legislation, but the underlying legislative debate has not concluded. Congress could pass a preemptive federal AI statute in future sessions. Governance teams should track federal legislative developments, but should not treat a future possibility as a present reality for compliance planning purposes.
What is the practical effect of America's AI Action Plan on enterprise AI programs?
The Action Plan signals federal priorities around innovation and infrastructure, which may influence future agency rulemaking, federal procurement preferences, and funding programs. It does not impose immediate compliance obligations on private enterprises. Enterprises may want to monitor how it shapes agency-specific policies, particularly those relevant to their sector, over the following 12 to 24 months.
Reassess Your Governance Baseline Before Removing Controls
Federal deregulatory signaling does not remove obligations tied to sector regulation, contracts, or state law. Confirm what your runtime governance program actually depends on before scaling it back.
Explore Runtime Governance