A2247 ARTIFICIAL INTELLIGENCE (AI) USAGE - NEW.PDF
Extracted text (via pymupdf)
18880 characters
MARICOPA COUNTY INTERNAL POLICY Policy Title: ARTIFICIAL INTELLIGENCE (AI) USAGE Policy Number: A2247 Current Adoption Date: MM-DD-YYYY Current Implementation Date: MM-DD-YYYY Approved by: BOARD OF SUPERVISORS Board Agenda Number: C-##-##-###-#-## Original Adoption Date: MM-DD-YYYY I. PURPOSE To provide information security guidelines for the use of artificial intelligence (AI) systems and to help mitigate associated risks. This is to protect the confidentiality, integrity, and availability of all data. II. APPLICATION This policy applies to all Maricopa County appointed departments, elected offices, the Flood Control District of Maricopa County, and the Maricopa County Library District (Special Districts). The Board of Supervisors is authorized to jointly adopt policies applying to the Special Districts under the Intergovernmental Agreement (IGA), C-06-18-393-6-00, approved on April 11, 2018. The Judicial Branch (Superior Court, Adult Probation, Juvenile Probation and Justice Courts) has agreed that the Judicial Branch will adhere to County information technology policies unless the Judicial Branch has an equivalent or more restrictive policy and provided County policies do not interfere or otherwise impede their ability to carry-out their required Constitutional and Statutory responsibilities nor restrict their ability to function as a separate and independent government entity. III. DEFINITIONS A. Appointing Authority: An elected official, the single administrative or executive head of a department/Special District, or the designated representative authorized to act in this capacity. B. Authorized User: An individual approved by the Appointing Authority to use County Technology Resources (CTRs). This includes County employees, temporary employees, and non-employees providing products or services to the County and/or who are given access to County data such as suppliers on contract or outside organizations with Intergovernmental Agreements (IGAs). C. Artificial Intelligence (AI): The science and engineering of making machines capable of performing tasks that are typically associated with human intelligence, such as learning and problem solving. D. Artificial Intelligence (AI) Systems: Products and services that incorporate AI hardware and software components that support machine learning, expert systems, and robust data sets to be adaptable and autonomous in providing requested solutions. E. AI Vendor or Supplier: Any entity that supplies AI services or components, such as research, development, training, implementation, deployment, maintenance, provision, or sale of AI system. F. Classic (or Non-Generative) AI: Any system that uses aspects of Artificial Intelligence to apply predefined rules to automate steps in an existing workflow. G. Chain of Reasoning: A sequence of arguments based on facts and data, each of which takes the conclusion of preceding statements as a premise in support of dynamic, or multi-step reasoning. Policy Title: ARTIFICIAL INTELLIGENCE (AI) USAGE Policy Number: A2247 Current Adoption Date: MM-DD-YYYY Page 2 of 6 H. County Technology Resource (CTR): Any computing account; device (e.g., mobile device, smartphone, tablet, computer, communications equipment, video conference, facsimile, or telephone); peripheral; software; local, wireless and wide area networks (i.e., LAN, Wi-Fi and WAN); Electronically Stored Information (ESI); website; cloud-based or internally-hosted system; or related consumable (e.g., disk space, processor time, network bandwidth) owned by, contracted with, or controlled by the County (Elected or Appointed Department) or by the Judicial Branch. I. External AI Systems: An AI model or engine that depends on infrastructure or data resources outside the immediate and complete control of the County. J. Generative AI: An AI system that learns the patterns and structures of input and trains data to generate new content. K. Large Language Model (LLM) AI: Also referred to as Foundation Model AI, this is a type of AI that uses deep learning techniques to recognize, generate, translate, or summarize vast quantities of data (usually written human language and textual data). This type of AI is adaptable for use on a range of tasks. L. InfoSec: Maricopa County Enterprise Technology Information Security team. M. Multi-Factor Authentication (MFA): an account login process that requires multiple methods of authentication from independent categories of credentials to verify a user's identity for a login or other transaction. MFA combines two or more independent credentials – what the user knows, such as a password; what the user has, such as a security token; and what the user is, by using biometric verification methods. IV. POLICY The policy of Maricopa County is to deploy and implement secure applications that drive innovation, support increased efficiencies in operations, and improve community engagement experiences. As some of these applications will employ AI, the intention is to mitigate risks posed by AI’s reliance on disparate data sets, usage, and their ability to make detailed correlations among very granular data elements. Therefore, guidelines are needed to ensure the innovative, yet ethical, use of AI while appropriately protecting CTR. The elements in this policy address factors that impact information security and Maricopa County's legal obligations to adhere to various information security standards. With such broad implications that accompany the use of AI, these policy elements will help ensure transparency, fairness, accountability, and the protection of individual rights in all AI-related activities conducted by or for Maricopa County. The intent is to help preserve the public trust, protect the County from legal liability, and ensure compliance with all applicable laws and regulations. Regular updates to this policy will ensure alignment with evolving legal requirements. A. Introduction There are two broad categories of AI usage: Organizational AI Services and External AI Systems. 1. Organizational AI services are systems internal to (or hosted for) the organization that provide services and data to employees, residents, customers, and business partners. The County may partner with third-party AI systems vendors to deliver those services. 2. External AI Systems are AI applications that are not provided by the organization, are external to the organization's enterprise network, are not subject to the organization's security controls, and are Policy Title: ARTIFICIAL INTELLIGENCE (AI) USAGE Policy Number: A2247 Current Adoption Date: MM-DD-YYYY Page 3 of 6 generally used by individual employees for specific job tasks. Examples include, but are not limited to, ChatGPT, Bard, Read.ai, Zoom.ai, and similar tools. B. Organizational (Internal) AI Services Organizational Generative AI Services shall meet the following requirements: 1. All contracted AI providers shall include in their contracts language requiring adherence to County Records Retention policy and language allowing the ability to rescind, retrieve, delete, or otherwise cleanse confidential or sensitive data that might have been input into the AI system. Contracts language will also include a data deletion schedule and procedures for destroying data. For more detailed information about confidential data, see County Policy A2244 Data Classification. 2. A human subject matter expert shall review and oversee any answers that are provided by any generative AI system. 3. Generative AI systems shall not be permitted to take any action or provide any answers that do not value human welfare, safety, and autonomy. 4. Generative AI systems shall not be permitted to take any action or provide any answers that promote illegal or unethical activity. 5. AI systems shall adhere to County nondiscrimination and data privacy policies. 6. Regarding transparency, a human subject matter expert shall be able to understand the chain of reasoning behind any Generative AI-provided answer. That is, the AI system’s general process of drawing logical conclusions from given information must be understood by a human subject matter expert so that known risks (see below) can be minimized or avoided. A Chain of Reasoning is required to meet regulatory frameworks such as HIPAA. 7. All AI-provided answers shall clearly state that they were provided by a generative AI system using County guidelines and data. 8. If the AI system interfaces with the public, methods shall be available for members of the public to inquire about, correct, and contest the results of AI-provided information. 9. The County shall not make decisions or take actions solely on AI-generated information unless it is through a tested, dedicated, purpose-built system such as classic, or non-generative, AI systems. Systems such as these are essentially automating an otherwise human-directed process (e.g., non- generative AI). C. External AI Systems Not all AI risks arise from the deliberate action of bad actors. Some AI risks arise as unintended consequences or from a lack of appropriate controls to ensure responsible AI use. To help mitigate risks associated with External AI Systems: 1. Confidential, private, or sensitive information shall not be shared in the AI interface prompts. 2. Staff must not rely on the accuracy of provided answers. 3. Ensure all policies and laws regarding copyright protections are followed as generative AI responses may be copyrighted or provided from a copyrighted source. Software source code, Policy Title: ARTIFICIAL INTELLIGENCE (AI) USAGE Policy Number: A2247 Current Adoption Date: MM-DD-YYYY Page 4 of 6 artwork, or any other answer might be owned by another entity, and anything done with that code or artwork might be considered a “derivative work.” 4. Many external AI systems known as “meeting assistants” are non-trusted and claim broad rights to collect all user meeting content. Those types of systems shall not be invited as participants in online meetings (Teams, Zoom, etc.) where confidential information is presented or discussed. Authorized users shall not subscribe to or allow AI systems of non-contracted vendors to participate in internal County meetings or applications where confidential information is presented or discussed. 5. Meetings that are considered public or where the information presented or discussed is considered “public record” are exempt from this stipulation. 6. Information entered into prompts of Generative-AI systems will most likely be used, without any controls, by the companies that power these systems. Any data that includes personally identifying information about residents, employees, contractors, vendors, or customers as well as information about critical infrastructure, security controls, source code, or means and methods could inadvertently be shared. In many cases, the input (sharing) of confidential organizational data could be illegal or considered non-compliant with federal, state, or industry regulations or standards. D. Classic AI Classic (or non-generative) AI are exempt from the stipulations in C.1 and C.2 above, as it uses purpose- built, “expert systems,” “weighted graph,” or other methods to automate otherwise human-directed processes. E. Known Risks An ETI Information Security department conducted risk assessment must be completed prior to the authorization of any purchase of a Generative-AI platform or service. The assessment must, at a minimum, include an evaluation of the known risks and examples listed below. Additional risks may also be evaluated based on data classification, business use case and other legal and regulatory requirements, or newly identified risks. 1. Risks to Human Rights: Generative AI is used to generate deepfake video and audio content, potentially damaging the reputation, relationships, and dignity of the subject. 2. Risks to Safety: An AI assistant based on LLM technology recommends a dangerous activity that it has found on the internet, without understanding or communicating the context of the website where the activity was described. The user undertakes this activity causing physical harm. 3. Risks to Fairness: An AI tool assessing creditworthiness of loan applicants is trained on incomplete or biased data, leading the company to offer loans to individuals on different terms based on characteristics like race or gender. 4. Risks to Privacy and Agency: Connected devices in the home (or office) may constantly gather data, including conversations, potentially creating a near-complete portrait of an individual's life. Privacy risks are compounded as more parties access this data. 5. Risks to Societal Wellbeing: Disinformation generated and propagated by AI could undermine access to reliable information and trust in societal institutions and processes. 6. Risks to Security: AI tools can be used to automate, accelerate, and magnify the impact of highly targeted cyber attacks, increasing the severity of the threat from malicious actors. The emergence Policy Title: ARTIFICIAL INTELLIGENCE (AI) USAGE Policy Number: A2247 Current Adoption Date: MM-DD-YYYY Page 5 of 6 of LLMs enables hackers with little technical knowledge or skill to generate phishing campaigns with malware delivery capabilities. 7. Risks to Data Leakage: AI model may disclose private information it has stored or has generated through data aggregation. 8. Copyright Infringement and Breach of License: Inclusion of a block of open-source code could force an entire project to be presented as publicly available as “open-source” due to licensing requirements that are not apparent. F. Security Implications While technical data security and privacy controls are provided and implemented to protect CTR, they cannot replace due care and due diligence towards the data under stewardship. Therefore, the following are required: 1. Any Generative-AI system will be configured in line with the County’s identity and access management standards. 2. Any identity factor that can be imitated by generative AI (e.g., voice), shall not be used as: a. digital identity verification becomes an increasingly important area to review, adapt, and update as AI capabilities improve. Proof of personhood (PoP) will be a key to robust identity access management (IAM) systems. (See the Maricopa County Enterprise Technology & Innovation Identity and Access Management (IAM) Policy and Maricopa County Enterprise Technology & Innovation Identity and Access Management (IAM) Standards documents for more information). b. data loss prevention (DLP) tools cannot be solely relied upon to help with External AI Systems because these tools may not detect protected (confidential) information going into a browser window. c. with the increased risk of malware delivery, a copy of any data provided to a Generative-AI tool shall be maintained in an offline and immutable backup library. V. AUTHORITY AND RESPONSIBILITIES A. Enterprise Technology & Innovation (ETI) General Responsibilities 1. ETI will deploy reasonable and necessary security controls, as well as deploy hardware and software, to achieve the stated policy objectives. 2. ETI shall implement logging and monitoring capabilities for audit purposes related to the usage of External AI Systems. 3. The Chief Information Officer (CIO), Chief Information Security Officer (CISO) or designee may modify the internal standards used to implement this policy to reflect changes in industry best practices, standards, legislation, technology, and processes used at the County. 4. The CIO, or designee, shall review this policy annually and maintain this policy as needed. 5. The CISO shall conduct annual audits to ensure compliance with this policy. Policy Title: ARTIFICIAL INTELLIGENCE (AI) USAGE Policy Number: A2247 Current Adoption Date: MM-DD-YYYY Page 6 of 6 6. Ensure that users receive the appropriate training. 7. Coordinate with Human Resources to ensure a mechanism exists for annual user acknowledgement of this policy. B. Specific Responsibilities 1. ETI shall provide an increased scope and frequency of security awareness training that addresses AI risks. This shall include specific scams (Spanish prisoner scam, romance scams, financial scams, social media understanding, etc.) and how to verify and validate the reality of a situation. 2. Because of the increased risk of identity spoofing and other access-compromising capabilities by AI, MFA capabilities shall be bolstered and expanded to include both external (remote) and internal (privileged) access. 3. ETI shall help provide secure enterprise resources to departments and groups that have applications that require the use of sensitive information with a Generative-AI system. C. All Authorized Users 1. Confidential or restricted data shall not be entered into any External AI System. 2. Users are responsible for performing due diligence in ensuring the output of information generated by the AI tools is accurate and appropriate for the purpose of use and that the production or use of the AI generated information does not put the County or CTR at risk. 3. Users shall consider copyright implications related to the answers received from AI Systems so as not to incur liability related to licensing and royalties. 4. If an application requires the use of sensitive information with a Generative-AI System, users shall contact InfoSec to ensure the provisioning of secure enterprise resources to enable the business process. VI. COMPLIANCE Violation of this policy may result in disciplinary actions up to and including termination. All reported violators, including non-employees, shall be referred to appropriate department executives. In addition to internal disciplinary measures, individuals found in violation of this policy may be subject to criminal prosecution, civil liability, or both. Exceptions to this are at the discretion of Appointing Authorities and their designees as deemed appropriate in activities related to legitimate use. The CISO, or designee, is authorized to initiate investigations of violations of this policy and other information technology security standards. The Maricopa County Internal Audit Department may conduct periodic audits to evaluate and ensure compliance with this policy. In some circumstances, outside technology and security auditors may perform audits of CTR and information technology operations. Revision History Version Revision Date Description of Revision 1 MM-DD-YYYY Initial version. (C-##-##-###-#-##)