This will likely go down the same way the original IPV6 mandate went down, before it was postponed, and before it likely will be postponed again when nobody's met the mandate.
The issue is far more complicated than the comments I see in here are giving credit for. Don't get me wrong, there's going to be delay as the PHBs get themselves wrapped around what an API even is, but they'll have the directive routed to their CIOs before that, and they will understand the requirement, and how impossible it is.
The biggest issue is that the data isn't really owned by the government entities. I mean, the data is theirs, but it's locked up in their vendor provided tools, and/or their custom, built-by-vendor products. If they're using Oracle AquaLogic (or whatever it is now) to host the majority of their portal content, they're dependent on Oracle to either come in and show them how to implement the feature (which is a significant service dollar cost) or they're going to have to wait until Oracle builds the ability for API exposure into the product if it doesn't exist yet.
If they've got custom-built portals, they'll need to consult with the vendors who wrote them or maintain them now and get them to add that in. That means that they'll have to modify the contract originally bid for the project, which is going to eat up a couple months of the timeline alone. Then they'll have to figure out what sort of things actually make it into the API, how to segment sensitive data reliably, get it through ISSO testing, etc. It's almost impossible for a project of any significance.
On top of that, they'll have to do it with a budget they don't have, and with resources allocated elsewhere. The only way the government really gets anything done is by committing large amounts of resources to it in an uninterrupted fashion. They don't have the capacity to be agile, and to some extent, that's by design.