Establishes statewide requirements for AI use, including planning, implementation, procurement, security, privacy, and governance. Applies to all Ohio state agencies and requires AI use to align with AI Council-approved solutions. Mandates agencies to define, document, and review AI use cases, test data quality, and ensure human oversight of AI outputs. Instructs agencies to provide workforce training on AI use and ethical considerations in coordination with the Ohio Department of Administrative Services. Sets procurement guidelines for AI solutions, including review of AI systems for security and privacy compliance and demands supplier disclosure of Generative AI use. Requires AI systems to implement security controls, ensure compliance with privacy laws, and guard against adversarial threats. Designates the Chief Data Officer Council to manage data governance for AI systems and mandates AI Council oversight on AI adoption impacts and framework establishment.
Paper
Full text
Ohio 2026 Administrative Policy 17 (Use of AI in State of Ohio Solutions)
ETO AGORA · U.S. state and local documents · 2023
Summary
Establishes statewide requirements for AI use, including planning, implementation, procurement, security, privacy, and governance.
Applies to all Ohio state agencies and requires AI use to align with AI Council-approved solutions.
Mandates agencies to define, document, and review AI use cases, test data quality, and ensure human oversight of AI outputs.
Instructs agencies to provide workforce training on AI use and ethical considerations in coordination with the Ohio Department of Administrative Services.
Sets procurement guidelines for AI solutions, including review of AI systems for security and privacy compliance and demands supplier disclosure of Generative AI use.
Requires AI systems to implement security controls, ensure compliance with privacy laws, and guard against adversarial threats.
Designates the Chief Data Officer Council to manage data governance for AI systems and mandates AI Council oversight on AI adoption impacts and framework establishment.
Establishes statewide AI planning, implementation, security, privacy, and governance requirements to protect data integrity in Ohio.
Purpose The purpose of this policy is to provide statewide planning, implementation, procurement, security, privacy, and governance requirements for the use of Artificial Intelligence (AI). The policy authorizes the implementation of AI, while establishing an operational framework that will assist in protecting Ohioans’ Data and the Integrity and Quality of the information delivered through AI solutions. All defined terms are capitalized and a link to the glossary of definitions is found in section IV.
States that the policy applies to all state agencies, boards, and commissions under the Governor's authority.
Scope This policy applies to all state agencies, boards, and commissions under the authority of the Governor (collectively referred to as Agency or Agencies).
Requires Ohio agencies to document, test, and monitor AI use cases, ensuring human oversight and alignment with AI principles.
Policy While AI can deliver significant business value to the State of Ohio, responsible implementation requires a deliberate and detailed approach. Agencies considering the implementation of AI must ensure that processes are in place to effectively manage the technology and achieve the desired results. This policy details the requirements for integrating AI technologies into state solutions.
AI Solution Development As part of AI planning and implementation, Agencies must follow the iterative activities outlined below:
Defining a formal process for identifying, documenting, reviewing, and approving AI use cases. Agency use cases and solutions must align with the core AI Principles. Submission of Agency approved use cases to the AI Council as appropriate (refer to section F. for additional information). Designing an approved use case pilot prior to a full production implementation. Conducting any necessary data quality testing for pilot and full production of AI deployments, including: Reviewing and testing any AI generated output for proper functionality and security. Testing the Data sets for AI Models to determine errors related to bias and variance. Testing activities must be properly documented. Defining the hand-off criteria to determine when judgment and decisions from an AI solution are transitioned to a human. Charging human operators with reviewing AI outputs for accuracy, appropriateness, privacy, and security before being acted upon or disseminated. AI outputs must not be assumed to be truthful, credible, or accurate. Ensuring that a human verification process is in place for decisions made by AI that have a legal, financial, human resources, legislative, organizational, or regulatory impact. Ongoing monitoring of AI generated output to validate that errors or Data bias are not introduced as the Model evolves.
Requires Ohio DAS and Agencies to establish AI training and mandate disclosure and approval for Generative AI use.
Workforce Requirements Agencies must ensure that the workforce understands the requirements for appropriate AI use as outlined below. To assist in this effort, the Ohio Department of Administrative Services (DAS), in coordination with Agencies, must establish AI training for the state’s workforce.
Authorization for Use: The use of Generative AI for work purposes must be approved by the Agency director or designee and must be in alignment with the requirements defined by the AI Council (refer to section III.F. for additional details).
Authorized Solutions: Only State-Managed or Governed Data Ecosystem, and AI Council approved, Generative AI solutions can be used to conduct state business.
Disclosing Use: When Generative AI is used to create a deliverable for Agency use, employees, contractors, and temporary personnel must be required to disclose this information to their Agency (e.g., written documentation, research, correspondence, and software code).
Importance of Verifying Accuracy: Review, revise, and fact check via multiple sources any output from a Generative AI solution before use. The human user is responsible for any material created with AI support.
Ethical Considerations: The training must create awareness regarding the ethical considerations surrounding the use of AI, in particular, Generative AI. AI outputs must not be used to impersonate individuals or organizations without their written permission. Material that is inappropriate for public release must not be entered as input to AI solutions unless explicitly approved by the Agency director, chief legal counsel, chief information officer or designee for the intended use case. Generative AI can make assumptions based on past stereotypes and the information provided may need to be corrected.
Secure Use: The security, privacy, and Data concerns surrounding the use of AI.
Requires agencies to review and evaluate AI procurements to meet security, privacy, and technical specifications.
AI Procurements When seeking to procure an AI solution, Agencies must adhere to the following requirements:
AI procurement solicitations offered by suppliers must align with the requirements of this policy.
All AI software services, even if they are free or part of a pilot or proof-of-concept project, must be reviewed by the Agency to ensure the software meets all necessary security and privacy requirements. This requirement applies to downloadable software, Software as a Service (SaaS), web-based services, browser plug-ins, and smartphone apps. The following elements must be captured and evaluated for any AI solution during the procurement process: Technical/design details of the AI system and algorithms How the AI system was trained (including personnel and documentation) How the AI system works (i.e., what are the inputs and outputs) Data sources (documentation of all Data sources) Audit Logging Change Management details and documentation that impact the AI system algorithms (i.e., decisions, inputs, outputs) Testing practices and results Timeframe documentation (captures time periods of testing, governance approval, deployment, and other critical milestones of the AI solution) New AI software requests must be submitted for review and possible approval to the AI Council (refer to section F.).
Agency contracts must prohibit suppliers from using State of Ohio materials or Data in Generative AI solutions, unless such use is explicitly approved by the Agency director or designee.
Procuring Agencies must ensure suppliers disclose the utilization of Generative AI when producing works owned by the state or the integration of Generative AI in products used by the state.
Procuring Agencies must submit to the AI Council the Supplier Assessment for Generative AI Solutions form, completed by the supplier, in the following circumstances: statewide contracts for Generative AI solutions; custom Generative AI solutions; public facing Generative AI solutions; and when requested by DAS.
Procuring Agencies must perform due diligence to ensure proper licensure of Model training Data for all Generative AI services using non-state Data.
All copyrightable works owned by the state that are created with the involvement of Generative AI must include an accompanying annotation sufficient to meet the requirements of the U.S. Copyright Office for Works Containing Material Generated by Artificial Intelligence (88 FR 16190). The annotation should include at least the Generative AI technology used and a description of how it was used to create the work.
Requires agencies to ensure AI solutions comply with state security and privacy laws, including specified controls.
Security and Privacy Agencies must ensure that AI solutions adhere to state IT security and privacy laws, policies, and standards. In addition, Agencies must comply with the following requirements:
Security: Agencies must implement the following security controls when designing AI solutions: Conduct a risk assessment of a proposed AI solution, including considerations of exploitation by malicious actors or inadvertent uses by authorized users. Determine appropriate security controls to mitigate against such risk. Establish controls to prevent adversarial learning attacks that try to influence or corrupt the Data Model by detecting abnormal network traffic. Ensure that authentication and authorization controls align with state and Agency policy. Confidential Data, including Personally Identifiable Information (PII) and Confidential Personal Information, must not be input into unconstrained Generative AI solutions and publicly accessible service or training Models.
Privacy: Agencies must protect the privacy of individuals when using AI solutions. This includes, but is not limited to, implementing the following privacy controls: AI Models must not be used to collect or store PII without the consent of the individual. AI solutions must only collect, use, share, and store Data in accordance with federal and state privacy and personal Data laws and policies. The AI solution must disclose to the user that they are interacting with a State of Ohio AI solution and the Data sources for the information must be provided.
Requires Ohio's CDO Council to establish AI governance, ensuring data quality, integrity, and regulatory compliance.
Data Governance The State of Ohio Chief Data Officer (CDO) Council must be responsible for establishing and maintaining statewide Data governance requirements, including those for AI solutions. The requirements must define information management controls, procedures, and processes for Data set selection, evaluation, and preparation. The controls must address, but not be limited to, the following principles:
Data Availability, Quality, and Integrity are critical for AI systems. AI systems must not be trained with Data that is biased, inaccurate, incomplete, or misleading. AI systems must only have access to the Data sources they need for the specific context. Data must be regulated through established Data sharing agreements that identify the applicable federal and state laws and policies for the AI solution use case. The agreements must outline the acceptable terms for Data use, storage, and transmission. Data sources used with AI Models must be properly parsed into multiple, randomized Data sets consisting of training, cross-validation, and test Data. Data validation procedures must be in place to select, analyze, clean, and certify the Integrity of the Data sources that will be used for AI automation solutions. Data Steward, Data Owner, and Data Custodian roles must be responsible for maintaining the Quality and Integrity of Agency AI Data Models. Every proposed Generative AI solution’s Data Model must receive Agency executive and data governance approval followed by the AI Council (refer to section F.) prior to implementation.
Directs the DAS to establish an AI Council for managing statewide Generative AI solutions and oversight activities.
AI Council DAS must establish a multi-Agency AI Council to govern the statewide use of Generative AI solutions. The AI Council must include representatives from the Governor’s Office; DAS and Agency business, human resources, information technology, security, privacy, Data analytics, and legal functional areas; and the DAS Office of Opportunity and Accessibility.
The AI Council must provide oversight for the following:
Directing the establishment of and the ongoing use of a statewide sandbox environment to safely explore the use of Generative AI to enhance the experience of the workforce and Ohioans. Examining the social, economic, and legal impacts of AI adoption on the workforce, Ohioans, and business operations. Defining the legal requirements for the use of third-party AI services, contracts, licenses, agreements, and specific AI solution use cases. Establishing the framework for evaluating and authorizing the use of AI technology (e.g., architecture frameworks, software, infrastructure, and relevant tools). Developing and maintaining a statewide central repository that captures approved Generative AI use cases. Documenting protocols and procedures for assessing and handling inquiries or incidents regarding AI system anomalies. Auditing AI current and future solutions to ensure alignment with the requirements of this policy.
Indicates capitalized defined terms reference the online IT Policy Glossary by the Department of Administrative Services.
Definitions All defined terms are capitalized within the policy and the online glossary of definitions can be found at IT Policy Glossary - Department of Administrative Services.