AI Governance Institute

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
VoluntaryFrameworkUS

Executive Order 14110 on Safe, Secure, and Trustworthy Artificial Intelligence

Issued by

Executive Office of the President of the United States

liveEffective 2023-10-30EO 14110Updated September 2026
Official document →

This US presidential directive sets federal requirements for safe AI development and deployment. It includes safety reporting on the most powerful AI models, NIST standards development, and coordination across agencies.

Applies To

Developers and operators of large-scale foundation models sold or licensed in the United StatesFederal agencies and departments deploying AI systemsFederal contractors and technology vendors supplying AI-enabled products and services to the U.S. governmentCritical infrastructure operators subject to DHS oversightLife sciences and biotechnology firms using AI in research with dual-use potentialEnterprises in regulated sectors receiving follow-on agency guidance stemming from the EO

Overview

Executive Order (EO) 14110, signed by President Biden on October 30, 2023, represented the most expansive federal action on artificial intelligence governance in U.S. history at the time of issuance. The order invoked the Defense Production Act to impose reporting duties on developers of large-scale AI foundation models (general-purpose models that other AI products build on). Developers of models trained using computing power above defined thresholds had to report safety test results and other critical information to the federal government prior to public deployment. The EO directed the National Institute of Standards and Technology (NIST) to develop guidelines and standards for AI safety evaluations, red-teaming (simulated attacks), and watermarking of AI-generated content. It also assigned responsibilities to more than a dozen federal agencies to assess AI-related risks within their respective domains. These included the Department of Homeland Security, the Department of Energy, and the Department of Commerce. The order addressed algorithmic discrimination (bias in automated decisions), privacy risks from AI pooling personal data, AI's implications for critical infrastructure protection, biosecurity, and the federal AI workforce. For enterprises, the EO created immediate obligations for covered model developers and signaled a forthcoming regulatory environment that affected enterprise procurement, vendor due diligence, and internal AI development programs. EO 14110 was revoked on 20 January 2025 by Executive Order 14148. Three days later, Executive Order 14179 directed agencies to review actions taken under it. However, multiple agency rules and guidance documents initiated under EO 14110 remain in effect or are in advanced stages of rulemaking. Compliance teams should assess which downstream obligations survive the revocation.

Key Requirements

  • •Revoked on 20 January 2025 by EO 14148. The requirements below describe what the order required while it was in force.
  • •Developers of dual-use foundation models trained above defined compute thresholds (initially 10^26 FLOPs) must report to the federal government on safety testing results and red-team findings prior to deployment.
  • •NIST directed to develop a companion AI Safety Institute and publish guidelines for evaluating, red-teaming, and watermarking AI systems.
  • •Federal agencies required to designate Chief AI Officers and develop agency-specific AI governance policies aligned with OMB guidance.
  • •Commerce Department directed to issue guidance on authentication and watermarking of AI-generated synthetic content.
  • •DHS directed to assess AI risks to critical infrastructure sectors and establish an AI Safety and Security Board.
  • •HHS, CFPB, FTC, DOJ, and other regulators directed to evaluate existing authorities and issue guidance addressing AI-related harms in their domains.
  • •Federal contractors and vendors supplying AI tools to the government subject to evolving procurement standards stemming from the EO.
  • •Privacy and civil liberties protections required as part of federal AI deployment review processes.

What Your Organization Must Do

  • →Stop treating the order's compute-threshold reporting duty as current. The reporting requirement ended with the revocation.
  • →Audit all AI products and services sold or licensed to federal agencies against evolving procurement standards originating from EO 14110. Work with your government contracts team to identify contract clauses that remain operative despite the January 2025 revocation of the EO itself.
  • →Map which downstream agency rules and guidance documents initiated under EO 14110 remain in effect or in active rulemaking. Specifically track outputs from NIST's Center for AI Standards and Innovation (formerly the AI Safety Institute) and the Office of Management and Budget (OMB). Also track the Consumer Financial Protection Bureau (CFPB), Federal Trade Commission (FTC), Department of Health and Human Services (HHS), and Department of Justice (DOJ). Assign a responsible compliance owner to monitor each workstream.
  • →If your organization operates in critical infrastructure sectors, engage your Department of Homeland Security (DHS) regulatory liaison. Assess AI risk requirements flowing from the AI Safety and Security Board mandate, and confirm whether sector-specific guidance imposes new obligations on your AI systems.
  • →If your life sciences or biotechnology teams use AI in research with dual-use potential (work that could be misused to cause harm), conduct a biosecurity risk review. Coordinate with legal and biosafety officers to identify any surviving federal reporting or access-control requirements.
  • →Ensure vendor due diligence and third-party AI procurement checklists are updated before onboarding new AI suppliers, consistent with Commerce Department guidance. Checklists should require disclosure of the computing power used to train models, safety testing documentation, and practices for watermarking AI-generated content.

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Governance Controls

Operational controls that implement requirements from this regulation.

Frequently Asked Questions

Was EO 14110 revoked and do its requirements still apply?
Yes, EO 14148 revoked EO 14110 on 20 January 2025, and EO 14179 followed three days later with a review of actions taken under it. Some agency rules, guidance, and contract terms created under EO 14110 may still apply. Check each one rather than assuming all of them ended.
What is the compute threshold that triggers the mandatory safety reporting obligation under EO 14110?
The order set an initial threshold of 10^26 floating point operations (FLOPs) of training compute. Developers of dual-use foundation models trained at or above that level were required to report safety test results and red-team findings to the federal government before public deployment, invoking the Defense Production Act as legal authority.
Does EO 14110 apply to private companies or only federal agencies?
It no longer applies to anyone, because it was revoked. While in force, it covered both private developers of the largest models, through reporting duties, and federal agencies, contractors, and vendors. Obligations written into federal contracts at the time may still bind the parties.
How does EO 14110 interact with NIST AI RMF compliance obligations?
EO 14110 directed NIST to develop AI safety evaluation guidelines and establish the AI Safety Institute, building on the existing NIST AI Risk Management Framework. Organizations already aligned to the AI RMF have a head start, but EO 14110 added specific mandates around red-teaming, watermarking, and safety testing that go beyond the voluntary RMF.
What obligations does EO 14110 create for life sciences and biotech firms?
The order specifically addressed biosecurity risks from AI used in dual-use research, directing agencies to assess and mitigate threats. Life sciences and biotechnology firms using AI in research with dual-use potential should conduct a biosecurity risk review and confirm whether surviving federal reporting or access-control requirements apply to their programs.
Do federal contractor AI obligations from EO 14110 survive the January 2025 revocation?
Potentially yes. Contract clauses and procurement standards incorporated into active federal contracts before the revocation may remain operative under those agreements. Vendors supplying AI tools to federal agencies should work with their government contracts counsel to identify which specific contractual obligations remain in force.