PUBLIC DRAFT · NOT ADOPTED POLICY

RESPONSIBLE AI · SECURITY · PUBLIC ACCOUNTABILITY

Responsible and Secure Artificial Intelligence Policy

A practical, NIST-aligned policy template for public agencies and mission-driven organizations. It permits useful experimentation while imposing stronger controls as data sensitivity, autonomy, consequence, and cyber capability increase.

v0.9discussion draft
4risk and autonomy tiers
12 mo.maximum authorization term

Important: This is an independent public reference draft. It is not legal advice, does not represent the policy of the New Mexico Office of the State Engineer or any other employer or government entity, and requires legal, privacy, records, accessibility, labor, procurement, security, and program review before adoption.

1. Purpose

This policy establishes governance for acquiring, developing, configuring, testing, deploying, operating, monitoring, and retiring artificial-intelligence systems. Its objectives are to protect people, public rights, government information, mission continuity, and public trust while enabling responsible innovation.

2. Scope

This policy applies to employees, contractors, volunteers, systems, vendors, pilots, embedded AI features, generative AI, machine learning, decision-support tools, autonomous agents, retrieval systems, models, and AI-enabled products that process organizational information or act on the organization’s behalf.

Personal use that never involves organizational data, credentials, systems, decisions, or representation remains outside scope but must comply with other applicable rules.

3. Governing principles

  1. Human accountability. A named person remains accountable for every AI system and consequential outcome.
  2. Mission before novelty. Use AI only for a defined need with an identified public or organizational benefit.
  3. Least authority. Grant the minimum data, tool, network, financial, and decision authority required.
  4. Evidence before trust. Authorization rests on testable evidence, not vendor assertions or model self-report.
  5. Transparency and contestability. People must receive appropriate notice and a meaningful path to question consequential outcomes.
  6. Data fitness. Data must be lawful, traceable, sufficiently accurate, representative, timely, and fit for the stated purpose.
  7. Secure by design. Security, privacy, accessibility, records, and resilience requirements begin during design and procurement.
  8. Continuous assurance. Approval is conditional, monitored, time-limited, and subject to suspension when conditions change.

4. Roles and accountability

RoleMinimum responsibility
Executive AI Accountable OfficerOwns enterprise AI governance, risk acceptance boundaries, reporting, and escalation.
AI Governance CouncilReviews high-impact uses; includes program, IT, security, privacy, legal, records, accessibility, procurement, data, and affected-user representation.
System OwnerDefines purpose, intended users, benefits, risks, operating limits, evidence, funding, and retirement.
Data StewardApproves data use and maintains lineage, quality, classification, retention, and correction processes.
CISO / SecuritySets technical baselines, threat models agent actions, validates controls, and leads AI incident response.
Privacy and LegalReviews lawful authority, notice, consent where applicable, data minimization, civil-rights impacts, contracts, and records obligations.
ProcurementEmbeds evidence, audit, incident, portability, subcontractor, change-notification, and exit requirements in contracts.
UsersVerify outputs, protect information, disclose material AI assistance when required, and report unsafe behavior.

5. AI inventory and classification

No in-scope AI may enter production without an inventory record. The record must identify the owner, purpose, users, vendor and model, version, hosting, datasets, connectors, identities, tools, autonomy, affected populations, decisions supported, retention, security category, authorization date, expiration, and current status.

TierUseApproval
Tier 1 · AssistBrainstorming, summarization, drafting, or analysis using public or approved low-sensitivity information; no system action.Manager-approved service and required training.
Tier 2 · RecommendUses internal information or supports operational decisions, but a qualified person independently validates the result before use.System owner, data steward, privacy/security screening.
Tier 3 · Act with approvalPrepares or initiates consequential actions, modifies records, executes code, uses privileged tools, or affects services; human approval is required at action time.Documented impact assessment, security testing, governance-council authorization.
Tier 4 · Bounded autonomyExecutes consequential activity without contemporaneous human approval.Executive authorization, independent assessment, production monitoring, tested kill switch, limited term and scope.

Classification must increase when data sensitivity, population impact, irreversibility, autonomy, cyber capability, external connectivity, scale, or uncertainty increases.

6. Prohibited uses

Unless expressly required by law and approved through an applicable formal process, the organization shall not:

  • Permit AI alone to make final decisions affecting legal rights, eligibility, employment, enforcement, liberty, access to essential services, or significant financial interests.
  • Enter restricted, confidential, regulated, privileged, export-controlled, authentication, or personal information into unapproved services.
  • Use AI output as established fact, legal interpretation, scientific finding, security evidence, or official record without qualified validation.
  • Allow an AI system to create or expand its own permissions, approve its own actions, disable monitoring, alter protected logs, or control its independent shutdown mechanism.
  • Deploy undisclosed biometric categorization, emotion inference, social scoring, deceptive impersonation, or unlawful surveillance.
  • Use AI-generated code in production without normal code review, testing, provenance, dependency scanning, and change control.
  • Use confidential organizational information to train external models without explicit written approval and contractual protection.

7. Required lifecycle controls

Before acquisition or development

  • Document mission need, alternatives, affected stakeholders, success measures, foreseeable misuse, failure consequences, and exit strategy.
  • Complete data, privacy, security, accessibility, records, civil-rights, and procurement screening proportional to risk.
  • Threat-model the complete system: model, prompts, retrieval, memory, datasets, identities, connectors, tools, code, infrastructure, network paths, operators, vendors, and recovery plane.

Before production

  • Validate performance against representative conditions and defined acceptance thresholds.
  • Test prompt injection, indirect injection, data leakage, excessive agency, privilege escalation, unsafe tool use, memory poisoning, supply-chain compromise, model substitution, denial of service, and recovery.
  • Confirm human-review design, escalation, fallback, rollback, shutdown, and continuity procedures.
  • Issue a written authorization identifying permitted uses, prohibited actions, residual risk, owners, conditions, monitoring, and expiration.

During operation

  • Monitor performance, security, data drift, bias indicators, complaints, overrides, unexpected tool calls, unauthorized destinations, and control failures.
  • Reassess after material changes to model, data, prompts, tools, permissions, hosting, vendor, use, population, law, threat, or impact.
  • Suspend operation when evidence no longer supports the authorization boundary.

8. Identity, access, and agent authority

  • Every production agent shall have a unique nonhuman identity, named human owner, documented purpose, and expiration or review date.
  • Credentials shall be short-lived where feasible, stored in approved secret-management systems, and scoped to a specific task and environment.
  • Agents shall not inherit unrestricted user sessions or share generic service accounts.
  • Network egress and tool access shall be allowlisted and enforced outside the model.
  • High-impact transactions require human confirmation or an independently enforced policy decision.
  • Financial, record-change, query-volume, execution-time, and data-export limits shall be technically enforced.
  • An authorized operator must be able to revoke access and stop execution immediately without cooperation from the model.

9. Data governance and quality

AI data shall have documented authority, source, lineage, classification, owner, purpose, retention, permitted uses, and correction path. Dataset acceptance criteria should address relevant measures of completeness, accuracy, reliability, consistency, integrity, uniqueness, coverage, lineage, traceability, timeliness, label quality, representation bias, anonymity, and confidentiality.

Retrieved documents and persistent memory shall be treated as potentially hostile input. Sources must be attributable; memory changes must be visible, auditable, reversible, and subject to retention rules.

10. Logging and evidence

High-impact systems shall maintain tamper-resistant, exportable, time-synchronized records sufficient to reconstruct consequential activity. Where technically feasible, records shall capture:

  • Model, system, prompt, policy, and configuration versions
  • Initiating identity, agent identity, authorization context, and human approvals
  • Input classification and references to retrieved evidence
  • Tool calls, queries, external destinations, affected resources, and resulting state
  • Outputs, confidence or uncertainty signals where valid, exceptions, overrides, and errors
  • Memory creation or modification, policy-enforcement decisions, and shutdown activity

Reasoning summaries or chain-of-thought shall not be the sole audit evidence. Logging shall respect applicable privacy, privilege, security, and records requirements.

11. Human oversight and public interaction

  • Human reviewers must have relevant expertise, sufficient time, source access, authority to reject the output, and protection from automation bias.
  • People materially affected by an AI-supported process shall receive appropriate notice consistent with law, security, and operational need.
  • Consequential determinations must have an accessible process for correction, appeal, or human reconsideration.
  • Public-facing AI shall identify itself as automated and shall not falsely claim human identity or official authority.
  • Accessibility shall be tested with representative users and assistive technology.

12. Procurement requirements

Contracts for AI-enabled products shall address, as applicable:

  • Model and component provenance; software and AI bills of materials
  • Training, tuning, evaluation, and customer-data use
  • Data ownership, location, isolation, return, portability, deletion, and destruction
  • Security architecture, independent tests, system cards, known limitations, and control mappings
  • Structured log access and export without punitive fees
  • Vulnerability disclosure, patch support, incident notification, forensic cooperation, and evidence preservation
  • Advance notice and customer control over material model, feature, subprocessor, or terms changes
  • Audit rights, service continuity, rollback, termination assistance, and secure retirement
  • Indemnification, warranty, insurance, and liability provisions reviewed by counsel

13. Incident response

AI incidents include unauthorized actions, harmful or materially incorrect outputs, data exposure, prompt injection, model or retrieval compromise, identity misuse, control evasion, poisoned memory, unexpected autonomy, discriminatory impact, availability loss, and failures requiring manual intervention.

Response plans shall support immediate isolation, identity revocation, connector shutdown, preservation of evidence, rollback, notification, affected-person support, legal and records review, root-cause analysis, corrective action, and documented criteria for return to service. The recovery plane and audit evidence must remain outside the agent’s control.

14. Authorization, exceptions, and enforcement

Tier 3 and Tier 4 authorizations shall expire no later than 12 months after approval and sooner when risk warrants. Material change triggers reassessment regardless of expiration date.

Exceptions must be written, time-limited, approved by the accountable authority, supported by business justification and compensating controls, and entered in the AI inventory. Violations may result in suspension of access, system shutdown, contractual remedy, or personnel action consistent with applicable law and policy.

15. Measures and reporting

The AI Governance Council should report quarterly on inventory completeness; risk-tier distribution; authorization status; incidents and near misses; overrides; unresolved findings; data-quality failures; vendor changes; training completion; time to revoke agent access; kill-switch test results; appeals; and realized mission benefits.

Success shall not be measured solely by adoption, usage, speed, or cost reduction. Measures must also address accuracy, equity, security, resilience, user outcomes, reversibility, and public trust.

16. Reference alignment

This draft is designed for tailoring alongside the NIST AI Risk Management Framework and Generative AI Profile, NIST Cybersecurity Framework 2.0, NIST SP 800‑53, NIST Secure Software Development Framework, zero-trust architecture principles, OWASP AI Security Verification Standard, applicable privacy and records requirements, emerging ISO/IEC AI logging work, and sector-specific law and guidance.

Policy maxim: an AI system shall receive no more authority than the organization can observe, interrupt, independently verify, and recover from.