United States - Georgia - AI Governance Guidelines (2024)
Georgia State AI Governance and Use Guidance
United States
RAI-US-GA-GSAGUXX-2024Georgia's AI Governance Guidance establishes a framework for responsible, ethical, and secure AI use in state government, emphasizing human oversight, data privacy, and transparency.
Summary
Read full text ↗Plain English
Overview
The Georgia State AI Governance and Use Guidance, developed by the Georgia Technology Authority (GTA) and its Office of Artificial Intelligence, establishes a foundational framework for responsible and ethical AI integration across state government. It aims to enhance public services while mitigating risks like bias and data breaches. Applicable to all state employees, contractors, and third parties using AI, it emphasizes public trust and high-quality work. Built upon policies like PS-23-001 and SS-23-002, the guidance balances innovation with risk mitigation, focusing on algorithmic bias, data privacy, transparency, and accountability. A human-in-the-loop approach is mandated, ensuring human judgment remains central. Data quality, security, and privacy are paramount, requiring adherence to state laws like the GCDPA. This evolving framework, with foundational efforts in 2024 and generative AI guidelines effective mid-2025, reflects Georgia's proactive adaptation to AI advancements.
Definitions
The Georgia Technology Authority (GTA) provides an AI glossary for consistent application across state agencies. Key definitions from documents like GS-25-001 and SS-23-002 establish common language. "Artificial Intelligence" is defined as a machine-based system making predictions or decisions based on human-defined objectives. "Generative AI" (GenAI) refers to tools creating new content (text, images, video, audio) by learning from data. An "AI System" is software using AI methodologies, while an "AI Model" is an AI technology component. "Agency" typically includes executive branch departments, agencies, boards, and authorities, excluding judicial, legislative, and university system entities. These definitions ensure a shared understanding of AI technologies and the governance framework.
Governance and Institutional Framework
Georgia's AI governance is led by the Georgia Technology Authority (GTA), in collaboration with the AI Council and Office of Artificial Intelligence. GTA champions responsible AI deployment, overseeing policy, implementation, transparency, fairness, and accountability. It sets statewide technology standards, including for AI. Prior GTA authorization is required for generative AI tools used for regular organizational tasks (e.g., transcription, summarization); unauthorized use is prohibited, highlighting GTA's vetting role. Agencies must document AI tools in a State IT Inventory, with generative AI and automated decision systems requiring periodic analysis (commodity systems are exempt). The "State of Georgia: AI Roadmap and Governance Framework" includes establishing an AI Advisory Council (2024) and an AI inventory. This roadmap also details a formal governance framework integrating risk management into procurement and software approval, ensuring a structured, controlled approach to AI integration, prioritizing security, ethics, and public welfare.
Key Focus Areas
Georgia's AI Guidance is founded on core principles for responsible and ethical AI deployment in state services. These direct agencies to integrate protective measures into policies, focusing on responsible systems, ethical and fair automated decisions, data quality and privacy, transparency, and human involvement. "Implement Responsible Systems" stresses user-centered design, prioritizing user research and diverse stakeholder input to identify AI system impacts, ensuring tools benefit end-users and the public. "Ethical and Fair Use of Automated Decisions" requires adopting ethical AI principles—fairness, transparency, accountability, privacy—throughout the AI lifecycle. This includes mitigating algorithmic bias and ensuring AI systems complement human expertise, with human decision-makers retaining final responsibility. "Maintain Data Quality and Privacy" focuses on robust data governance, security, and compliance with data protection laws. "Transparency and Accountability" mandates clear records of AI system use, objectives, and roles, plus clear labeling of AI-generated content to build public trust. These focus areas form a robust ethical and operational foundation for AI in Georgia's government.
Implementation Framework
Georgia's AI implementation framework guides state employees and agencies on responsible, secure AI usage. A key directive is to "Use only pre-vetted tools" approved by the Georgia Technology Authority (GTA) via approved vendors; approvals are dynamic and require regular GTA consultation. Employees must "Record prompts," maintaining a record of AI queries and responses outside the software for accountability and transparency. Data privacy and security are paramount: employees must avoid entering personal/sensitive data into generative AI models and keep personal/work materials separate. Agencies must ensure AI tool use complies with Georgia's privacy laws (e.g., GCDPA) and implement robust security, including opting out of data collection and clearing chat histories. Specific use cases are addressed, such as prohibiting AI note-taking in Microsoft Teams meetings and requiring hosts to prevent AI bot note-takers. Agencies must ensure AI outputs supplement, not replace, human judgment, and that AI-generated content is clearly labeled and verified for accuracy and bias. The framework also includes ongoing training for staff on effective and responsible AI use.
Monitoring and Evaluation
Georgia's AI Guidance mandates continuous monitoring and evaluation for AI systems' safety, effectiveness, and ethical adherence in state operations. GTA provides oversight through ongoing evaluation and collaboration, aiming to prevent biases, mitigate risks, and promote beneficial AI solutions. Agencies must document AI tools and components in a State IT Inventory, with generative AI and automated decision systems requiring periodic analysis, enabling GTA to oversee the AI landscape. The guidance also requires regular AI system audits to identify and address ethical issues, including bias. Agencies must establish transparent and accountable policies, maintaining clear records of AI system use, objectives, and roles. The "AI Roadmap and Governance Framework" outlines strengthening AI governance by integrating risk management into procurement and software approval, with ongoing policy updates and stakeholder consultations. This iterative approach ensures the AI governance framework adapts to technological advancements and best practices, fostering responsible AI deployment and continuous improvement.
Penalties, Liability, and Appeals
Georgia's AI Governance and Use Guidance (e.g., GS-25-001, SS-23-002) outlines best practices and consequences for non-compliance. "Unauthorized use" of generative AI tools requiring GTA authorization is strictly prohibited. While specific penalties for guideline breaches aren't detailed, non-compliance by state employees or agencies falls under existing state employment, IT security (PM-04-001, PS-08-005), and broader state laws. Violations may result in internal disciplinary actions, including termination, based on severity. The guidance links AI use to legal obligations, stating it "must be consistent with Georgia's privacy laws, such as the Georgia Computer Data Privacy Act (GCDPA)." Misuse leading to data breaches or privacy violations could invoke legal repercussions under existing statutes, carrying civil or criminal penalties. AI-created meeting recordings/transcriptions become public records, subject to retention and open records laws, adding accountability. The guidance focuses on prevention, but Georgia's legal and policy framework addresses non-compliance, ensuring accountability for AI deployments and public data integrity.
Relationship to Other Instruments
Georgia's AI Governance and Use Guidance is integrated into the state's broader IT policies and legal framework. It expands upon the "Enterprise AI Responsible Use Policy (PS-23-001)" and the "AI Responsible Use Standard (SS-23-002)" issued by the Georgia Technology Authority (GTA). PS-23-001 addresses acceptable AI use and security, while SS-23-002 details AI tool deployment protocols, especially for sensitive data. The guidance documents cite authority from Georgia Code sections (e.g., O.C.G.A 50-25-4(a)(8)), granting GTA powers over state technology. It aligns with existing IT policies like PM-04-001 and PS-08-005, ensuring consistency with the state's IT governance and cybersecurity. Compliance with Georgia's privacy laws, particularly the Georgia Computer Data Privacy Act (GCDPA), is mandated, ensuring AI use respects personal data protections. This layered approach provides comprehensive oversight and legal grounding for AI implementation across state agencies.
International Alignment
Georgia's AI Governance and Use Guidance primarily regulates AI use within the state's executive branch, without explicitly detailing direct alignment with international AI frameworks or treaties. Its authority stems from Georgia state law and GTA's powers. Although "Generative AI Responsible Use (SS-25-001)" mentions alignment with "national and international best practices," specific mechanisms for international alignment are not elaborated. The focus is on establishing a robust, ethical, and secure AI ecosystem tailored to Georgia's needs and legal landscape, emphasizing internal state government operations, data protection under Georgia laws, and maintaining public trust. While responsible AI principles (transparency, fairness, accountability, privacy) are globally recognized and implicitly align with broader international discussions, the guidance does not establish formal ties or reciprocal arrangements with other national or international AI regulatory bodies. Georgia's approach is to build a strong internal governance model reflecting these universal ethical considerations, rather than explicitly engaging in cross-border cooperation or mutual recognition of AI regulations at this stage.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Enterprise AI Responsible Use Policy (PS-23-001) Effective | 2023-10-05 | Establishes acceptable use policy for AI tools in government operations. |
| Artificial Intelligence Responsible Use Guidelines (GS-23-001) Effective | 2023-12-12 | Outlines a comprehensive framework and five guiding principles for responsible AI use within state agencies. |
| Artificial Intelligence Responsible Use Standard (SS-23-002) Effective | 2024-12-01 | Delineates protocols for deployment of AI, Generative AI, Deep Learning, and Machine Learning tools, with emphasis on sensitive data. |
| Foundational AI Governance Efforts Initiated | 2024-01-01 | Establishment of an AI Advisory Council and initiation of an AI inventory to assess existing applications. |
| Generative AI Guidelines for Responsible Use (GS-25-001) Effective | 2025-07-01 | Provides specific guidelines for state entities when using Generative AI, expanding upon existing policies. |
| Procurement of AI Tools Guidelines for Responsible Use (GS-25-002) Effective | 2025-07-01 | Outlines best practices for state agencies when preparing and evaluating procurements for AI tools or solutions. |
Compliance Checklist
| Check | Required Action |
|---|---|
| Prior Authorization | Obtain prior authorization from GTA for any generative AI tools intended for regular organizational usage. |
| Vetted Tools Use | Use only AI tools that have been pre-vetted and approved by GTA with approved vendors. |
| Prompt Recording | Create and maintain a record of AI queries and responses outside of the generative AI platform for future reference. |
| Data Privacy | Do not enter personal and/or sensitive data into generative AI models. Opt out of data collection where possible. |
| Data Security | Protect all data used by AI systems from unauthorized access or breaches, including regular password changes and minimizing data retention. |
| Legal Compliance | Ensure AI tool use is consistent with Georgia's privacy laws, such as the Georgia Computer Data Privacy Act (GCDPA). |
| Transparency & Citation | Clearly label all AI-generated content (text, images, video, audio) and cite its origin. Acknowledge AI assistance openly. |
| Human-in-the-Loop | Ensure AI outputs supplement, not replace, human judgment, and human decision-makers remain responsible for final decisions. |
| Bias & Accuracy | Double-check AI-generated content for inaccuracies, AI hallucinations, or bias. Assess potential for AI to introduce or perpetuate bias. |
| AI Inventory | Document AI tools and components, including generative AI and automated decision systems, in the State IT Inventory. |
| Training & Awareness | Undergo appropriate training for responsible and ethical AI use and stay updated on AI developments, risks, and mitigation strategies. |
| Virtual Meetings | Prohibit AI note-taking tools in State of Georgia Microsoft Teams meetings and ensure compliance with data protection and IP laws for any recording/transcription. |
| Procurement | Submit all software, applications, tools, and services utilizing AI for business operations to GTA for review prior to procurement. |
Sources and References
Georgia's AI Governance and Use Guidance sets a framework for responsible, ethical, and secure artificial intelligence use across state government, applying to all state employees, contractors, and third parties.
This guidance, spearheaded by the Georgia Technology Authority (GTA), aims to integrate AI into public services while mitigating risks like bias and data breaches. It covers all state employees, contractors, and third parties using AI, specifically within executive branch departments, agencies, boards, and authorities. It does not apply to judicial, legislative, or university system entities.
Key obligations for those in scope include obtaining prior authorization from the GTA before using any generative AI tools for regular organizational tasks, as unauthorized use is strictly prohibited. Users must also never enter personal or sensitive data into generative AI models and ensure all AI tool use complies with Georgia's privacy laws, such as the Georgia Computer Data Privacy Act (GCDPA). Furthermore, AI outputs must only supplement human judgment, with human decision-makers retaining final responsibility, and all AI-generated content must be clearly labeled and verified for accuracy and bias. Finally, only AI tools that have been pre-vetted and approved by the GTA are permitted.
The framework is evolving, with foundational governance efforts initiated in January 2024. A key standard, the Artificial Intelligence Responsible Use Standard, became effective on December 1, 2024, with further generative AI and procurement guidelines set for July 1, 2025.
While the guidance itself doesn't detail specific penalties, non-compliance by state employees or agencies falls under existing state employment and IT security policies. Violations can lead to internal disciplinary actions, including termination. Misuse resulting in data breaches or privacy violations could trigger legal repercussions under existing state statutes, potentially carrying civil or criminal penalties.
A practical surprise for users is the directive to prohibit AI note-taking tools in State of Georgia Microsoft Teams meetings. Additionally, employees must record all AI queries and responses outside the AI software for accountability and transparency.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 13 marked completePlain-English obligations under United States - Georgia - AI Governance Guidelines (2024). Not legal advice — verify against the official text before relying on it.
- #1CriticalGovernance and Institutional Framework⏰ Before use
Applies to: State employees, contractors, and third parties using generative AI tools.
“Prior GTA authorization is required for generative AI tools used for regular organizational tasks; unauthorized use is prohibited.”
- #2CriticalImplementation Framework⏰ Before use
Applies to: State employees, contractors, and third parties using AI tools.
“Use only pre-vetted tools approved by the Georgia Technology Authority (GTA) via approved vendors.”
- #3CriticalImplementation Framework⏰ Continuously, during use
Applies to: State employees using generative AI models.
“employees must avoid entering personal/sensitive data into generative AI models and keep personal/work materials separate.”
- #4CriticalImplementation Framework⏰ Continuously
Applies to: Agencies using AI tools.
“Agencies must ensure AI tool use complies with Georgia's privacy laws (e.g., GCDPA).”
- #5CriticalOverview⏰ Continuously, during use
Applies to: Agencies and state employees using AI systems.
“A human-in-the-loop approach is mandated, ensuring human judgment remains central.”
- #6CriticalImplementation Framework⏰ Continuously
Applies to: State employees participating in Microsoft Teams meetings.
“prohibiting AI note-taking tools in State of Georgia Microsoft Teams meetings and requiring hosts to prevent AI bot note-takers.”
- #7CriticalGovernance and Institutional Framework⏰ Before procurement
Applies to: Agencies procuring AI tools or solutions.
“Submit all software, applications, tools, and services utilizing AI for business operations to GTA for review prior to procurement.”
- #8CriticalImplementation Framework⏰ Continuously
Applies to: Agencies using AI systems.
“Agencies must ensure AI tool use complies with Georgia's privacy laws (e.g., GCDPA) and implement robust security.”
- #9ImportantImplementation Framework⏰ Continuously, during use
Applies to: State employees using generative AI models.
“Employees must 'Record prompts,' maintaining a record of AI queries and responses outside the software for accountability and transparency.”
- #10ImportantImplementation Framework⏰ Before publication/sharing
Applies to: State employees creating content with AI.
“Agencies must ensure... that AI-generated content is clearly labeled and verified for accuracy and bias.”
- #11ImportantKey Focus Areas⏰ Before use/publication
Applies to: State employees and agencies using AI systems.
“This includes mitigating algorithmic bias and ensuring AI systems complement human expertise.”
- #12ImportantGovernance and Institutional Framework⏰ Continuously, with periodic analysis
Applies to: Agencies using AI tools.
“Agencies must document AI tools in a State IT Inventory, with generative AI and automated decision systems requiring periodic analysis.”
- #13RecommendedImplementation Framework⏰ Ongoing
Applies to: State employees using AI.
“The framework also includes ongoing training for staff on effective and responsible AI use.”
Related Regulations
FINAL REPORT OF THE SENATE STUDY COMMITTEE ON ARTIFICIAL INTELLIGENCE (SR 476)
United States94% similar
North Carolina State Government Responsible Use of Artificial Intelligence Framework
United States93% similar
Recommendations of the Judicial Council of Georgia Ad Hoc Committee on Artificial Intelligence and the Courts
United States93% similar
Buenos Aires Province Generative AI Guidelines
Argentina92% similar
Georgia Conversational Artificial Intelligence Safety Act
Georgia, United States92% similar
© Regulations.AI — created on 13-Jun-2026 using Gemini 2.5 Flash