Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Ai Governance topic

No spam. Unsubscribe anytime.

Indiana chief privacy officer outlines state AI governance, review process and trusted sandboxes

2391291 · February 25, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Ted Cotterill, Indiana’s chief privacy officer and general counsel for the Management Performance Hub, told the Indianapolis Artificial Intelligence Commission that the state has built an AI review process intended to balance innovation with privacy and security.

Ted Cotterill, Indiana’s chief privacy officer and general counsel for the Management Performance Hub, told the Indianapolis Artificial Intelligence Commission that the state has built an AI review process intended to balance innovation with privacy and security.

Cotterill said the state has vetted about 60 AI proposals and has created role-based review teams that include legal, privacy, data science and data governance experts to assess risk, data sources and sustainment costs. “We have some commonalities that we also look at to to understand risk—the risk posture of the proposal,” Cotterill said.

The state presentation explained why a centralized approach matters. Cotterill described the Management Performance Hub’s work to treat enterprise data as a strategic asset—centralizing governance so agencies such as the Department of Health or the Department of Child Services can focus on mission delivery while relying on enterprise infrastructure, security and legal review.

Cotterill said the review system uses a risk framework that layers the NIST AI Risk Management Framework and a cybersecurity maturity assessment, and adapts the EU AI Act’s risk profiles for state government. High‑risk systems undergo a full NIST assessment; lower‑ and moderate‑risk proposals go through an expedited “fast lane” that the state is working to automate.

The state has required each of its 100-plus business units to designate an agency privacy officer, trained some of those officers through the International Association of Privacy Professionals (IAPP), and begun issuing readiness questionnaires to collect use‑case details and regulatory obligations. Cotterill said agencies submit a readiness assessment through a web form; the AI review team then evaluates objectives, applicable law and the agency’s plan for maintenance and operation.

The review also addresses a common vendor claim in AI procurement—vendors seeking broad reuse of government data for model training. “What we’re trying to do is, Oh, that’s a—that’s data leakage that we don’t want to see,” Cotterill said. He said the state prefers self-contained instances of models and works to avoid contractual language that permits vendor use beyond the scope of the contract.

Cotterill described several state pilots and use cases: an IN.gov chatbot trained on state website content, a workforce recommendation engine in the Department of Workforce Development that combines wage and education data under legal authorities and then hands agencies a decoupled model to run, and a Purdue‑Google proof‑of‑concept for road‑asset condition assessment. He said the IN.gov chatbot is being treated as a narrow‑context system and is still in beta.

To enable experimentation while limiting risk, the state is building “trusted” AI sandboxes in multiple clouds—AWS Bedrock, Azure Foundry and Google’s Vertex—so agencies can prototype inside vetted, locked‑down environments. Cotterill said the intent is to give agencies secure compute and avoid ad hoc, shadow implementations that create long‑term technical debt.

Cotterill described Legislative Services Agency work to staff a temporary AI Task Force established by the General Assembly; that task force produced a final report recommending, among other things, the Legislature consider an ongoing study committee on AI and revisit committee assignments to ensure appropriate technical expertise. He said the executive branch did not receive prescriptive legislative directives in that first report but expects continued interim work.

On training and governance, Cotterill said the state has run multi‑day IAPP training for agency privacy officers—about 65 officers pursued CIPM certification—and pushed a broader data proficiency badge program that reached roughly 1,500 employees. He also said the Management Performance Hub now must approve external research data‑sharing agreements and provides templates for internal data sharing.

Cotterill concluded that the state is trying to avoid either an unchecked rush to adopt AI or a blanket ban that prevents beneficial uses: “Can this help us be better at what we do? Is the juice worth the squeeze?” he said, adding the state wants to enable trusted, accountable AI while identifying and mitigating harms.

What’s next: Cotterill said the state will continue to streamline reviews, automate approvals for low‑risk systems, complete NIST assessments for the highest‑risk deployments and expand sandbox availability for agencies to pilot tools.

(Reporting note: remarks and program names are taken from the commission transcript of Ted Cotterill’s presentation and subsequent Q&A.)