Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Ai Governance topic
No spam. Unsubscribe anytime.
Indiana chief privacy officer briefs Indianapolis AI commission on state AI governance and sandboxes
Summary
Ted Cotterill, Indiana's chief privacy officer, described the state's AI review process, risk framework, and secure multi-cloud sandboxes during a briefing to the Indianapolis AI Commission.
Get email alerts on the Ai Governance topic
No spam. Unsubscribe anytime.
Ted Cotterill, chief privacy officer for the state of Indiana and general counsel for the Management Performance Hub, told the Artificial Intelligence Commission of Indianapolis Marion County that the state has built a formal review process and secure infrastructure to enable government use of artificial intelligence while managing risk.
Cotterill said the state routes AI proposals through an "AI review team" with legal, privacy, data science and governance representatives and that higher‑risk deployments undergo a NIST assessment. He said, "we're creating a fast lane for low and moderate risk proposals" and that the state is standing up multi‑cloud sandboxes with AWS Bedrock, Azure Foundry and Google Vertex to give agencies a trusted environment for testing.
The briefing laid out why the state had centralized data and privacy roles and how that work informs AI oversight. Cotterill described the Management Performance Hub's enterprise approach to data — established after the state centralized IT in 2005 and codified further in 2017 — and said it lets line agencies focus on mission work while the state provides shared infrastructure, legal templates and governance.
Cotterill reviewed several active examples: an IN.gov chatbot that he said "is still in beta," a Department of Workforce Development workforce‑recommendation model that combined wage and education data under special legal authority, and a Purdue/INDOT image analysis proof‑of‑concept that scanned road miles for asset assessment. He told commissioners roughly 60 AI proposals had been vetted by the state's review process.
On risk categorization he cited the EU AI Act and OECD guidance as influences and said the state layered a cybersecurity maturity assessment on top of NIST's AI Risk Management Framework to produce measurable readiness scores for the framework's subcategories. He identified biometrics/facial recognition, broad‑context image interpretation and AI used with children as examples of technologies or use cases the state treats as high risk.
Cotterill said the state is balancing policy with enablement: the state has adopted a cautious approach and reserves the heaviest NIST reviews for highest‑risk systems (he gave the Genesys cloud contact center as an example). To reduce data leakage risks, he said the state prefers self‑contained model instances and tighter contract language that prevents vendors from reusing state data outside the agreed scope.
He also described training and staffing steps: the state designated agency privacy officers across its more than 100 business units, contracted with the International Association of Privacy Professionals for training, and is working to make data proficiency training more widely available through the centralized State Personnel Department.
Commissioners pressed Cotterill on whether local governments could reuse the state's materials; Cotterill said the state's policy and materials are available on IN.gov/privacy and that the state shares practices with other governments through national organizations. He said the Legislative Services Agency had issued a Task Force report recommending, among other items, that the General Assembly consider a permanent interim study committee on AI.
Cotterill closed by saying the state is continuing to streamline its governance process and hopes to "unleash these sandboxes on our agencies" so they can safely prototype AI applications.
The commission followed with questions from city representatives about how to adapt the state's approach for Indianapolis, and about training for designated privacy officers and operational controls for vendor‑supplied AI services.
