AddToAny share buttons

Secure State AI Use: Get Ready to Use North Carolina’s AI Playbook

The N.C. Department of Information Technology is preparing to launch the statewide AI Governance Playbook, a guide that establishes a comprehensive process for the responsible use of artificial intelligence, from ideation through risk assessment, documentation, mitigation, and ongoing support.

Created by NCDIT’s Office of AI and Policy, Enterprise Security and Risk Management Office, and Privacy Office, this playbook sets minimum requirements to ensure AI use is evaluated, documented, and managed responsibly. This playbook is intended to create a more streamlined process for agencies to evaluate, implement, and monitor AI. 

The playbook will lay out a seven‑step lifecycle for agencies to responsibly implement AI:

  1. Identify potential AI use cases.
  2. Quantify risk using the AI Use Case Risk Evaluation.
  3. Complete the required assessments: the AI Use‑Case Risk Profile and a Privacy Threshold Analysis/Privacy Impact Assessment.
  4. Determine next steps with the appropriate approval and oversight.
  5. Document an inventory with quarterly submissions to Office of AI and Policy.
  6. Mitigate risks using required security, privacy, and governance controls.
  7. Continuous monitoring post‑deployment.

High‑risk use‑cases will be published to increase transparency, in line with Executive Order No. 24.

What IT, Security, and Privacy Teams Should Do Now

  • Begin by defining priority use‑cases and quantifying risk in accordance with the AI Starter Pack, sent to all AI Oversight Teams.
  • Coordinate early with cybersecurity and privacy liaisons to complete the AI Use‑Case Risk Profile and PTA/PIA and populate your AI Inventory.
  • To build workforce AI literacy, we encourage enrolling staff in the North Carolina Responsible AI for Public Professionals (InnovateUS) course.

For questions, contact NCDITAIandPolicy@nc.gov.

Related Topics: