A2247 ARTIFICIAL INTELLIGENCE (AI) USAGE - NEW.PDF

Maricopa County — Formal (2024-12-11)

View PDF Item 65 Meeting page

Extracted text (via pymupdf) 18880 characters
MARICOPA COUNTY INTERNAL POLICY 
 
Policy Title: 
ARTIFICIAL INTELLIGENCE (AI) USAGE 
Policy Number: 
A2247 
Current Adoption Date: 
MM-DD-YYYY 
Current Implementation Date: 
MM-DD-YYYY 
Approved by: 
BOARD OF SUPERVISORS 
Board Agenda Number: 
C-##-##-###-#-## 
Original Adoption Date: 
MM-DD-YYYY 
 
I. PURPOSE 
To provide information security guidelines for the use of artificial intelligence (AI) systems and to help 
mitigate associated risks. This is to protect the confidentiality, integrity, and availability of all data. 
II. APPLICATION 
This policy applies to all Maricopa County appointed departments, elected offices, the Flood Control District 
of Maricopa County, and the Maricopa County Library District (Special Districts). The Board of Supervisors 
is authorized to jointly adopt policies applying to the Special Districts under the Intergovernmental 
Agreement (IGA), C-06-18-393-6-00, approved on April 11, 2018. 
The Judicial Branch (Superior Court, Adult Probation, Juvenile Probation and Justice Courts) has agreed that 
the Judicial Branch will adhere to County information technology policies unless the Judicial Branch has an 
equivalent or more restrictive policy and provided County policies do not interfere or otherwise impede their 
ability to carry-out their required Constitutional and Statutory responsibilities nor restrict their ability to 
function as a separate and independent government entity. 
III. DEFINITIONS 
A. Appointing Authority: An elected official, the single administrative or executive head of a 
department/Special District, or the designated representative authorized to act in this capacity. 
B. Authorized User: An individual approved by the Appointing Authority to use County Technology 
Resources (CTRs). This includes County employees, temporary employees, and non-employees 
providing products or services to the County and/or who are given access to County data such as 
suppliers on contract or outside organizations with Intergovernmental Agreements (IGAs). 
C. Artificial Intelligence (AI): The science and engineering of making machines capable of performing 
tasks that are typically associated with human intelligence, such as learning and problem solving. 
D. Artificial Intelligence (AI) Systems: Products and services that incorporate AI hardware and software 
components that support machine learning, expert systems, and robust data sets to be adaptable and 
autonomous in providing requested solutions.  
E. AI Vendor or Supplier: Any entity that supplies AI services or components, such as research, 
development, training, implementation, deployment, maintenance, provision, or sale of AI system. 
F. Classic (or Non-Generative) AI: Any system that uses aspects of Artificial Intelligence to apply 
predefined rules to automate steps in an existing workflow. 
G. Chain of Reasoning: A sequence of arguments based on facts and data, each of which takes the 
conclusion of preceding statements as a premise in support of dynamic, or multi-step reasoning.

Policy Title: 
ARTIFICIAL INTELLIGENCE (AI) USAGE 
Policy Number: 
A2247 
Current Adoption Date: 
MM-DD-YYYY 
 
Page 2 of 6 
H. County Technology Resource (CTR): Any computing account; device (e.g., mobile device, smartphone, 
tablet, computer, communications equipment, video conference, facsimile, or telephone); peripheral; 
software; local, wireless and wide area networks (i.e., LAN, Wi-Fi and WAN); Electronically Stored 
Information (ESI); website; cloud-based or internally-hosted system; or related consumable (e.g., disk 
space, processor time, network bandwidth) owned by, contracted with, or controlled by the County 
(Elected or Appointed Department) or by the Judicial Branch. 
I. 
External AI Systems: An AI model or engine that depends on infrastructure or data resources outside 
the immediate and complete control of the County. 
J. Generative AI: An AI system that learns the patterns and structures of input and trains data to generate 
new content. 
K. Large Language Model (LLM) AI: Also referred to as Foundation Model AI, this is a type of AI that uses 
deep learning techniques to recognize, generate, translate, or summarize vast quantities of data 
(usually written human language and textual data). This type of AI is adaptable for use on a range of 
tasks. 
L. InfoSec: Maricopa County Enterprise Technology Information Security team. 
M. Multi-Factor Authentication (MFA): an account login process that requires multiple methods of 
authentication from independent categories of credentials to verify a user's identity for a login or other 
transaction. MFA combines two or more independent credentials – what the user knows, such as a 
password; what the user has, such as a security token; and what the user is, by using biometric 
verification methods. 
IV. POLICY 
The policy of Maricopa County is to deploy and implement secure applications that drive innovation, support 
increased efficiencies in operations, and improve community engagement experiences. As some of these 
applications will employ AI, the intention is to mitigate risks posed by AI’s reliance on disparate data sets, 
usage, and their ability to make detailed correlations among very granular data elements. Therefore, 
guidelines are needed to ensure the innovative, yet ethical, use of AI while appropriately protecting CTR. 
The elements in this policy address factors that impact information security and Maricopa County's legal 
obligations to adhere to various information security standards. With such broad implications that 
accompany the use of AI, these policy elements will help ensure transparency, fairness, accountability, and 
the protection of individual rights in all AI-related activities conducted by or for Maricopa County. The intent 
is to help preserve the public trust, protect the County from legal liability, and ensure compliance with all 
applicable laws and regulations. Regular updates to this policy will ensure alignment with evolving legal 
requirements. 
A. Introduction 
There are two broad categories of AI usage: Organizational AI Services and External AI Systems.  
1. 
Organizational AI services are systems internal to (or hosted for) the organization that provide 
services and data to employees, residents, customers, and business partners. The County may 
partner with third-party AI systems vendors to deliver those services.  
 
2. 
External AI Systems are AI applications that are not provided by the organization, are external to the 
organization's enterprise network, are not subject to the organization's security controls, and are

Policy Title: 
ARTIFICIAL INTELLIGENCE (AI) USAGE 
Policy Number: 
A2247 
Current Adoption Date: 
MM-DD-YYYY 
 
Page 3 of 6 
generally used by individual employees for specific job tasks. Examples include, but are not limited 
to, ChatGPT, Bard, Read.ai, Zoom.ai, and similar tools. 
B. Organizational (Internal) AI Services 
Organizational Generative AI Services shall meet the following requirements: 
1. 
All contracted AI providers shall include in their contracts language requiring adherence to County 
Records Retention policy and language allowing the ability to rescind, retrieve, delete, or otherwise 
cleanse confidential or sensitive data that might have been input into the AI system. Contracts 
language will also include a data deletion schedule and procedures for destroying data. For more 
detailed information about confidential data, see County Policy A2244 Data Classification. 
2. 
A human subject matter expert shall review and oversee any answers that are provided by any 
generative AI system. 
3. 
Generative AI systems shall not be permitted to take any action or provide any answers that do not 
value human welfare, safety, and autonomy. 
4. 
Generative AI systems shall not be permitted to take any action or provide any answers that 
promote illegal or unethical activity. 
5. 
AI systems shall adhere to County nondiscrimination and data privacy policies. 
6. 
Regarding transparency, a human subject matter expert shall be able to understand the chain of 
reasoning behind any Generative AI-provided answer. That is, the AI system’s general process of 
drawing logical conclusions from given information must be understood by a human subject matter 
expert so that known risks (see below) can be minimized or avoided.  A Chain of Reasoning is 
required to meet regulatory frameworks such as HIPAA. 
7. 
All AI-provided answers shall clearly state that they were provided by a generative AI system using 
County guidelines and data. 
8. 
If the AI system interfaces with the public, methods shall be available for members of the public to 
inquire about, correct, and contest the results of AI-provided information. 
9. 
The County shall not make decisions or take actions solely on AI-generated information unless it is 
through a tested, dedicated, purpose-built system such as classic, or non-generative, AI systems.  
Systems such as these are essentially automating an otherwise human-directed process (e.g., non-
generative AI). 
C. External AI Systems 
Not all AI risks arise from the deliberate action of bad actors. Some AI risks arise as unintended 
consequences or from a lack of appropriate controls to ensure responsible AI use. 
To help mitigate risks associated with External AI Systems: 
1. 
Confidential, private, or sensitive information shall not be shared in the AI interface prompts. 
2. 
Staff must not rely on the accuracy of provided answers. 
3. 
Ensure all policies and laws regarding copyright protections are followed as generative AI 
responses may be copyrighted or provided from a copyrighted source. Software source code,

Policy Title: 
ARTIFICIAL INTELLIGENCE (AI) USAGE 
Policy Number: 
A2247 
Current Adoption Date: 
MM-DD-YYYY 
 
Page 4 of 6 
artwork, or any other answer might be owned by another entity, and anything done with that code 
or artwork might be considered a “derivative work.”  
4. 
Many external AI systems known as “meeting assistants” are non-trusted and claim broad rights to 
collect all user meeting content.  Those types of systems shall not be invited as participants in 
online meetings (Teams, Zoom, etc.) where confidential information is presented or discussed. 
Authorized users shall not subscribe to or allow AI systems of non-contracted vendors to participate 
in internal County meetings or applications where confidential information is presented or 
discussed.  
5. 
Meetings that are considered public or where the information presented or discussed is considered 
“public record” are exempt from this stipulation. 
6. 
Information entered into prompts of Generative-AI systems will most likely be used, without any 
controls, by the companies that power these systems. Any data that includes personally identifying 
information about residents, employees, contractors, vendors, or customers as well as information 
about critical infrastructure, security controls, source code, or means and methods could 
inadvertently be shared. In many cases, the input (sharing) of confidential organizational data could 
be illegal or considered non-compliant with federal, state, or industry regulations or standards. 
D. Classic AI 
Classic (or non-generative) AI are exempt from the stipulations in C.1 and C.2 above, as it uses purpose-
built, “expert systems,” “weighted graph,” or other methods to automate otherwise human-directed 
processes. 
E. Known Risks 
An ETI Information Security department conducted risk assessment must be completed prior to the 
authorization of any purchase of a Generative-AI platform or service. The assessment must, at a 
minimum, include an evaluation of the known risks and examples listed below. Additional risks may also 
be evaluated based on data classification, business use case and other legal and regulatory 
requirements, or newly identified risks.  
1. 
Risks to Human Rights: Generative AI is used to generate deepfake video and audio content, 
potentially damaging the reputation, relationships, and dignity of the subject. 
 
2. 
Risks to Safety: An AI assistant based on LLM technology recommends a dangerous activity that it 
has found on the internet, without understanding or communicating the context of the website 
where the activity was described. The user undertakes this activity causing physical harm. 
 
3. 
Risks to Fairness: An AI tool assessing creditworthiness of loan applicants is trained on incomplete 
or biased data, leading the company to offer loans to individuals on different terms based on 
characteristics like race or gender. 
 
4. 
Risks to Privacy and Agency: Connected devices in the home (or office) may constantly gather 
data, including conversations, potentially creating a near-complete portrait of an individual's life. 
Privacy risks are compounded as more parties access this data. 
 
5. 
Risks to Societal Wellbeing: Disinformation generated and propagated by AI could undermine 
access to reliable information and trust in societal institutions and processes. 
6. 
Risks to Security: AI tools can be used to automate, accelerate, and magnify the impact of highly 
targeted cyber attacks, increasing the severity of the threat from malicious actors. The emergence

Policy Title: 
ARTIFICIAL INTELLIGENCE (AI) USAGE 
Policy Number: 
A2247 
Current Adoption Date: 
MM-DD-YYYY 
 
Page 5 of 6 
of LLMs enables hackers with little technical knowledge or skill to generate phishing campaigns 
with malware delivery capabilities. 
 
7. 
Risks to Data Leakage: AI model may disclose private information it has stored or has generated 
through data aggregation. 
 
8. 
Copyright Infringement and Breach of License: Inclusion of a block of open-source code could 
force an entire project to be presented as publicly available as “open-source” due to licensing 
requirements that are not apparent. 
F. Security Implications 
While technical data security and privacy controls are provided and implemented to protect CTR, they 
cannot replace due care and due diligence towards the data under stewardship. Therefore, the following 
are required: 
1. 
Any Generative-AI system will be configured in line with the County’s identity and access 
management standards. 
2. 
Any identity factor that can be imitated by generative AI (e.g., voice), shall not be used as: 
a. digital identity verification becomes an increasingly important area to review, adapt, and update 
as AI capabilities improve. Proof of personhood (PoP) will be a key to robust identity access 
management (IAM) systems. (See the Maricopa County Enterprise Technology & Innovation 
Identity and Access Management (IAM) Policy and Maricopa County Enterprise Technology & 
Innovation Identity and Access Management (IAM) Standards documents for more information). 
b. data loss prevention (DLP) tools cannot be solely relied upon to help with External AI Systems 
because these tools may not detect protected (confidential) information going into a browser 
window. 
c. with the increased risk of malware delivery, a copy of any data provided to a Generative-AI tool 
shall be maintained in an offline and immutable backup library. 
V. AUTHORITY AND RESPONSIBILITIES 
A. Enterprise Technology & Innovation (ETI) 
General Responsibilities 
1. 
ETI will deploy reasonable and necessary security controls, as well as deploy hardware and 
software, to achieve the stated policy objectives. 
2. 
ETI shall implement logging and monitoring capabilities for audit purposes related to the usage of 
External AI Systems. 
3. 
The Chief Information Officer (CIO), Chief Information Security Officer (CISO) or designee may 
modify the internal standards used to implement this policy to reflect changes in industry best 
practices, standards, legislation, technology, and processes used at the County.  
4. 
The CIO, or designee, shall review this policy annually and maintain this policy as needed.  
5. 
The CISO shall conduct annual audits to ensure compliance with this policy.

Policy Title: 
ARTIFICIAL INTELLIGENCE (AI) USAGE 
Policy Number: 
A2247 
Current Adoption Date: 
MM-DD-YYYY 
 
Page 6 of 6 
6. 
Ensure that users receive the appropriate training. 
7. 
Coordinate with Human Resources to ensure a mechanism exists for annual user 
acknowledgement of this policy.  
B. Specific Responsibilities 
1. 
ETI shall provide an increased scope and frequency of security awareness training that addresses 
AI risks. This shall include specific scams (Spanish prisoner scam, romance scams, financial 
scams, social media understanding, etc.) and how to verify and validate the reality of a situation. 
2. 
Because of the increased risk of identity spoofing and other access-compromising capabilities by 
AI, MFA capabilities shall be bolstered and expanded to include both external (remote) and internal 
(privileged) access. 
 
3. 
ETI shall help provide secure enterprise resources to departments and groups that have 
applications that require the use of sensitive information with a Generative-AI system.  
C. All Authorized Users 
1. 
Confidential or restricted data shall not be entered into any External AI System. 
2. 
Users are responsible for performing due diligence in ensuring the output of information generated 
by the AI tools is accurate and appropriate for the purpose of use and that the production or use of 
the AI generated information does not put the County or CTR at risk. 
3. 
Users shall consider copyright implications related to the answers received from AI Systems so as 
not to incur liability related to licensing and royalties. 
4. 
If an application requires the use of sensitive information with a Generative-AI System, users shall 
contact InfoSec to ensure the provisioning of secure enterprise resources to enable the business 
process. 
VI. COMPLIANCE 
Violation of this policy may result in disciplinary actions up to and including termination. All reported 
violators, including non-employees, shall be referred to appropriate department executives. In addition to 
internal disciplinary measures, individuals found in violation of this policy may be subject to criminal 
prosecution, civil liability, or both. Exceptions to this are at the discretion of Appointing Authorities and their 
designees as deemed appropriate in activities related to legitimate use. 
The CISO, or designee, is authorized to initiate investigations of violations of this policy and other information 
technology security standards.  
The Maricopa County Internal Audit Department may conduct periodic audits to evaluate and ensure 
compliance with this policy. In some circumstances, outside technology and security auditors may perform 
audits of CTR and information technology operations. 
Revision History 
Version 
Revision Date 
Description of Revision 
1 
MM-DD-YYYY 
Initial version. (C-##-##-###-#-##)