Reasoning
The Biden-era OMB M-23-18 memo and CISA's 2024-2025 SBOM pilot for federal software only require provenance on agency-developed code, not on all email, documents, or messaging; no draft rule or appropriations rider in the FY2026 budget expands this to every federal communication by 2029. Historical base rates show only three narrow digital-authentication mandates (e.g., FIPS 201-3 PIV cards in 2005) reached full rollout within five years, while broader metadata standards such as the 2018-2022 email-authentication push took 7-9 years. Structural factors include 2026 budget caps under the Fiscal Responsibility Act and the absence of any 2025-2026 executive order or congressional hearing on provenance metadata.Key uncertainty
Whether a post-2026 administration issues a new OMB circular requiring provenance on all outbound federal communications within the 2027-2029 window.