United States - North Carolina - Responsible AI Framework

North Carolina State Government Responsible Use of Artificial Intelligence Framework

United States

RAI-US-NC-NCSGRXX-2024
Effective: August 21, 2024
In Force(In Force)
PolicyGovernance and OversightRisk ManagementData Protection and Privacy
Export PDF

The North Carolina AI Framework guides state agencies in the ethical and effective deployment of AI, fostering public trust and ensuring compliance with privacy and civil rights laws.

Overview

The North Carolina State Government Responsible Use of Artificial Intelligence Framework is a pivotal document established to guide state agencies in the responsible and ethical integration of artificial intelligence (AI) technologies into public services. This framework, developed by the N.C. Department of Information Technology (NCDIT), is designed to encourage the thoughtful exploration and application of AI, ensuring that its benefits are harnessed for the people of North Carolina while simultaneously safeguarding public trust and confidence. A core objective is to protect the state's fundamental values and ensure that all AI deployments remain in strict compliance with existing laws, particularly those concerning privacy, civil rights, and civil liberties. It functions as a comprehensive risk management strategy, offering a structured approach through a set of principles, practical guidelines, and actionable advice for agencies seeking to leverage AI's transformative potential. The NCDIT plays a crucial role in both the development and ongoing stewardship of this framework, ensuring it remains relevant and effective as AI technology evolves.

The framework applies broadly to all forms of AI utilized by State Agencies, encompassing any system that employs, or has the potential to employ, AI and could impact North Carolinians' exercise of rights, opportunities, or access to critical state-administered resources or services. This includes all AI systems that are designed, developed, acquired, or used by state agencies, unless explicitly exempted by law. The overarching goal articulated within the framework is to enhance government innovation, operations, and services in a manner that benefits citizens, builds confidence in AI, and upholds the state’s values. It underscores the importance of carefully considering potential risks associated with AI and establishing robust mechanisms for their assessment and management, thereby fostering a balanced approach to technological advancement. This living document is intended to adapt to new technological developments and societal expectations, ensuring North Carolina's leadership in responsible AI governance.

Definitions

The framework, and related state guidance, relies on a clear understanding of key terms to ensure consistent application across state agencies. Artificial Intelligence (AI) is broadly defined as an engineered system where machines learn from experience, adapt to new inputs, and are capable of performing tasks traditionally associated with human intelligence. More specifically, it is recognized as a field of computer science dedicated to simulating intelligent behavior in computers, potentially including automated decision-making processes. This foundational definition helps delineate the scope of technologies covered by the framework's principles and practices, ensuring that all relevant systems are subject to its guidelines.

Further distinctions are made for specific types and characteristics of AI. Generative AI refers to a category of artificial intelligence capable of producing new content, such as code, images, music, text (e.g., ChatGPT), simulations, or 3D objects. These systems represent a significant advancement in AI capabilities, requiring careful consideration of their ethical implications. Responsible AI is characterized as an AI system whose development and behavior are aligned with established goals and values, ensuring consistency with democratic principles. This concept emphasizes the ethical imperative in AI design and deployment. Trustworthy AI encompasses systems that exhibit specific characteristics, including being valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias effectively managed. These definitions provide a conceptual bedrock for agencies to evaluate, implement, and govern AI systems ethically and effectively, fostering public confidence in state-led AI initiatives.

Governance and Institutional Framework

North Carolina has established a robust governance structure to oversee the responsible implementation and evolution of its AI framework. A significant step in this direction was the signing of Executive Order 24 by Governor Josh Stein in September 2025, which formally launched the statewide AI framework and created several key institutional bodies. Central to this structure is the AI Leadership Council, tasked with serving as an advisory board to the Governor and state agencies on all matters related to AI use in government. This council is also responsible for developing comprehensive training programs and promoting AI literacy and fraud prevention among the public, ensuring a well-informed and secure environment for AI adoption and mitigating potential misuse.

In addition to the Council, the Executive Order also established an AI Accelerator within the N.C. Department of Information Technology (NCDIT) and mandated the creation of AI Oversight Teams within each state agency. These teams are crucial for embedding AI governance at the operational level, ensuring that agency-specific AI initiatives align with the broader state framework and its guiding principles. Furthermore, NCDIT played a foundational role in developing the framework itself and has actively recruited leadership to steer its implementation, including the appointment of I-Sah Hsieh as the first AI governance and policy executive in March 2025. This dedicated leadership ensures continuous oversight and strategic direction for the ethical, transparent, and accountable integration of AI technologies into public services, balancing innovation with rigorous risk management and public protection.

Key Focus Areas

The North Carolina AI Framework is built upon seven guiding principles that serve as a blueprint for ethical behavior and responsible AI deployment across state government. Foremost among these is the principle of Human-Centered design, which mandates human oversight for all stages of AI development, deployment, and use. This principle ensures that AI applications are designed to benefit North Carolinians and the public good, with a critical emphasis on preventing any negative impact on individuals' rights, opportunities, or access to essential state resources and services. It underscores the belief that technology, including AI, must ultimately serve and enhance human well-being, not diminish it, by prioritizing human values and control.

Other critical focus areas include Transparency and Explainability, requiring user agencies to provide clear and accessible notice to individuals potentially impacted by AI use. This notice must explain the purpose of the automated system, its contribution to outcomes affecting individuals, and include clear descriptions of the data used, the role of automation in decision-making, and mechanisms for tracing potential errors, thereby fostering public trust. Security and Resiliency are also paramount, necessitating pre-deployment testing, robust risk identification and mitigation strategies, and ongoing monitoring to ensure AI systems are safe, effective, and resilient against attacks while adhering to state and national security standards. The framework also emphasizes Data Privacy and Governance, advocating for respect for individual privacy, the adoption of Fair Information Practice Principles (FIPPs) throughout the AI lifecycle, and the embedding of privacy-by-design principles to ensure controlled data access and high data quality and integrity. Additionally, principles related to Diversity, Non-discrimination, and Fairness are integral to ensuring equitable treatment and preventing algorithmic bias, while Auditing and Accountability ensure traceable decision-making processes and clear lines of responsibility within AI systems, promoting continuous improvement and ethical compliance.

Implementation Framework

The implementation of the North Carolina State Government Responsible Use of Artificial Intelligence Framework is structured around a practical methodology that integrates principles, practices, and guidance to achieve its objectives. It provides state agencies with a clear roadmap for navigating the complexities of AI adoption, ensuring that innovation is pursued hand-in-hand with robust risk management. A cornerstone of this implementation approach is its strong alignment with the National Institute of Standards and Technology (NIST) AI Risk Management Framework (AI RMF). This alignment provides a nationally recognized standard for assessing, managing, and mitigating risks associated with AI systems, thereby enhancing the trustworthiness and reliability of state AI initiatives and fostering consistency with federal guidelines.

The framework mandates a comprehensive risk management approach that considers the entire AI lifecycle, from initial development and rigorous testing to deployment and eventual decommissioning. Agencies are encouraged to seek opportunities for designing, developing, acquiring, and using AI to improve government functions, but always with a careful consideration of potential risks and how they can be effectively assessed and managed. This includes embedding privacy into the design and architecture of IT and business practices, ensuring that data protection is a default consideration from the outset. The framework serves as a living document, signifying its dynamic nature and capacity to evolve in response to technological advancements, emerging risks, and updated best practices, thereby ensuring its continued relevance and effectiveness in guiding responsible AI use across all state operations.

Monitoring and Evaluation

Effective monitoring and evaluation are critical components of the North Carolina AI Framework, designed to ensure the continuous responsible operation and adherence to established principles by all state AI applications. The framework explicitly requires agencies to regularly test their AI applications against the seven guiding principles. This ongoing assessment is not merely a formality but a fundamental practice intended to verify that AI systems consistently perform as intended and uphold the ethical standards outlined in the framework. Such regular testing helps in proactive identification of any deviations or unintended consequences that may arise during the operational lifespan of an AI system, allowing for timely intervention.

Furthermore, the framework mandates the establishment of clear mechanisms to modify, replace, or deactivate AI applications if they fail to perform as intended or are found to violate any of the established principles. This provision ensures accountability and provides a structured response to non-compliance or system malfunctions, safeguarding against potential harms to North Carolinians and maintaining public trust. The emphasis on ongoing monitoring extends beyond initial deployment, recognizing that AI systems can evolve and their impacts may change over time, necessitating continuous vigilance. As a “living document,” the framework itself is subject to continuous review and updates, reflecting a commitment to adaptive governance that can respond to the rapid pace of AI development and societal needs, thus maintaining its efficacy and relevance in a constantly evolving technological landscape.

Penalties, Liability, and Appeals

The North Carolina State Government Responsible Use of Artificial Intelligence Framework, by its nature as a guidance document, does not establish new or specific penalties, liability provisions, or appeal mechanisms directly within its text. Instead, the framework operates under the overarching principle that the use of AI by state agencies must remain consistent with all applicable existing laws and regulations. This includes, but is not limited to, laws related to privacy, civil rights, and civil liberties, which already contain their own enforcement mechanisms, penalties for non-compliance, and avenues for redress or appeal. Therefore, agencies are expected to adhere to all existing legal obligations when deploying AI.

Any instances of non-compliance with the principles or practices outlined in the AI framework that also constitute a violation of existing state or federal law would be addressed through the established legal and regulatory frameworks. Liability for harms caused by AI systems would be determined by existing tort law, administrative law, or other relevant statutes, ensuring that individuals have recourse. Similarly, individuals seeking to appeal decisions made or influenced by AI systems would typically utilize existing administrative review processes or judicial remedies available under North Carolina law. The framework's primary role is to guide agencies in preventing such issues through responsible design and deployment, rather than to create a new punitive legal structure, thereby promoting proactive risk mitigation.

Relationship to Other Instruments

The North Carolina State Government Responsible Use of Artificial Intelligence Framework is not an isolated policy document but is strategically designed to integrate with and complement a broader landscape of existing legal and technical instruments. A cornerstone of its foundational approach is its strong alignment with the National Institute of Standards and Technology (NIST) AI Risk Management Framework (AI RMF). This alignment ensures that North Carolina's approach to AI risk management is consistent with nationally recognized best practices, promoting trustworthiness and interoperability in AI systems. The framework actively recommends using the NIST AI RMF to assess and manage risks to individuals, organizations, and society associated with AI, thereby leveraging established federal expertise.

Furthermore, the framework explicitly emphasizes its consistency with existing privacy laws and information technology (IT) policies already in force within North Carolina. This ensures that AI implementation enhances, rather than undermines, established data protection and cybersecurity protocols, creating a cohesive regulatory environment. The document also references specific state statutes, such as N.C.G.S. § 143B-1320(a)(17), for the definition of 'State Agencies,' thereby integrating itself into the existing legal lexicon of the state. It also draws inspiration from and references federal guidance, such as the White House's AI Bill of Rights, and indicates plans to implement the NIST Privacy Framework and related guidance, demonstrating a comprehensive commitment to a harmonized regulatory environment for AI that spans state and federal levels.

International Alignment

As a state-level framework, the North Carolina State Government Responsible Use of Artificial Intelligence Framework primarily focuses on governing AI within the jurisdiction of North Carolina. Therefore, it does not explicitly detail direct international alignment strategies or cross-border cooperation initiatives in the manner that a national or supra-national regulation might. However, its foundational principles and implementation approach inherently foster a degree of indirect international alignment through its adherence to globally recognized standards and best practices, contributing to a broader global understanding of responsible AI.

A key aspect of this indirect alignment stems from the framework's strong emphasis on and integration with the National Institute of Standards and Technology (NIST) AI Risk Management Framework (AI RMF). NIST standards are widely respected and adopted by various countries and international bodies as benchmarks for technological development and risk management. By aligning with the NIST AI RMF, North Carolina's framework benefits from a globally recognized methodology for building trustworthy and responsible AI systems, which facilitates future interoperability and collaboration. This commitment to robust, standardized risk management and ethical principles contributes to a broader global dialogue on responsible AI governance, even if its immediate scope is confined to state operations, by promoting universal best practices.

Implementation Timeline

MilestoneDateNotes
Initial Publication of Framework (Version 1.0)2024-08-21The North Carolina State Government Responsible Use of Artificial Intelligence Framework was first published, establishing the initial principles and guidance for state agencies.
AI Governance and Policy Executive Appointed2025-03-31I-Sah Hsieh began his role as the first AI governance and policy executive for the N.C. Department of Information Technology (NCDIT), tasked with overseeing AI governance frameworks and policies.
Framework Revised (Version 1.1)2025-08-22The North Carolina State Government Responsible Use of Artificial Intelligence Framework underwent a revision, updating its content to Version 1.1.
Executive Order 24 Signed by Governor2025-09-03Governor Josh Stein signed Executive Order 24, formally launching the statewide AI framework and establishing key governance structures, including the AI Leadership Council, AI Accelerator, and agency-level AI Oversight Teams.

Compliance Checklist

CheckRequired Action
Human OversightEnsure human oversight is maintained for all stages of AI development, deployment, and use within state agencies.
Public Benefit AlignmentVerify that AI use consistently benefits North Carolinians and serves the public good, aligning with agency missions.
Rights ProtectionConfirm that AI use does not negatively impact North Carolinians' exercise of rights, opportunities, or access to critical resources or services.
Transparency & NoticeProvide clear, accessible, and plain-language notice to individuals who may be impacted by the use of an automated system.
ExplainabilityExplain why AI is used, how it contributes to outcomes, describe data, the role of automation, and ability to trace errors.
Pre-deployment TestingConduct rigorous pre-deployment testing, risk identification, and mitigation for all AI systems.
Ongoing MonitoringImplement ongoing monitoring to demonstrate that AI systems are safe, effective, resilient, and adhere to security standards.
Data Privacy & FIPPsMaintain respect for individuals' privacy and adopt Fair Information Practice Principles (FIPPs) throughout the AI lifecycle.
Privacy by DesignEmbed privacy into the design and architecture of IT and business practices involving AI, ensuring controlled data access.
Data Quality & IntegrityEnsure individuals developing or deploying AI systems are conscious of the quality and integrity of data used by those systems.
Principle Adherence TestingRegularly test AI applications against the seven guiding principles established in the framework.
Modification/Deactivation MechanismsEstablish mechanisms to modify, replace, or deactivate AI applications that do not perform as intended or violate principles.

Sources and References

SourceType
N.C. State Government Responsible Use of Artificial Intelligence Framework (PDF)official
AI Framework for Responsible Use | NCDIT - NC.govgovernment
Principles for Responsible Use of AI | NCDIT - NC.govgovernment
NIST AI Risk Management Frameworkgovernment
Blueprint for an AI Bill of Rights | OSTP - White Housegovernment
Plain English

The North Carolina State Government Responsible Use of Artificial Intelligence Framework guides all state agencies on the ethical and effective deployment of AI. This policy applies broadly to any AI system designed, developed, acquired, or used by state agencies that could impact North Carolinians' rights, opportunities, or access to critical state-administered resources or services.

The framework, initially published on August 21, 2024, and formalized by Governor Josh Stein's Executive Order 24 in September 2025, aims to foster public trust and ensure compliance with existing privacy and civil rights laws. It establishes a comprehensive risk management strategy built on seven guiding principles. Among the most important obligations for agencies are:

  • **Human-Centered Design:** Ensuring human oversight at all stages, designing AI to benefit the public, and preventing negative impacts on individuals' rights or access to services.
  • **Transparency and Explainability:** Providing clear, accessible notice to individuals potentially affected by AI, explaining the system's purpose, data used, and how decisions are made, with mechanisms to trace errors.
  • **Data Privacy and Governance:** Respecting individual privacy, adopting Fair Information Practice Principles (FIPPs), and embedding privacy-by-design from the outset, while ensuring high data quality and integrity.
  • **Security and Resiliency:** Conducting rigorous pre-deployment testing, identifying and mitigating risks, and continuously monitoring AI systems to ensure they are safe, effective, and resilient against attacks.

Crucially, this framework does not establish new penalties or liability provisions. Instead, any non-compliance that also violates existing state or federal laws (such as those concerning privacy or civil rights) will be addressed through those established legal and regulatory channels. Agencies are required to regularly test their AI applications against the guiding principles and must have mechanisms to modify, replace, or deactivate systems that fail to perform as intended or violate principles.

A practical pitfall for product managers and team leads is understanding that while the framework offers robust guidance, its enforcement power stems from existing legal obligations. This means agencies must proactively integrate the framework's principles with all current legal requirements, rather than viewing it as a standalone set of rules. The framework is also a "living document," meaning it will evolve, requiring continuous adaptation from agencies.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 12 marked complete

Plain-English obligations under United States - North Carolina - Responsible AI Framework. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalKey Focus AreasContinuously

    Applies to: State agencies

    mandates human oversight for all stages of AI development, deployment, and use.
  2. #2CriticalKey Focus AreasBefore deployment, Continuously

    Applies to: State agencies

    preventing any negative impact on individuals' rights, opportunities, or access to essential state resources or services.
  3. #3CriticalKey Focus AreasBefore deployment

    Applies to: User agencies

    requiring user agencies to provide clear and accessible notice to individuals potentially impacted by AI use.
  4. #4CriticalKey Focus AreasBefore deployment

    Applies to: User agencies

    This notice must explain the purpose of the automated system, its contribution to outcomes affecting individuals, and include clear descriptions of the data used...
  5. #5CriticalKey Focus AreasBefore deployment

    Applies to: State agencies

    necessitating pre-deployment testing, robust risk identification and mitigation strategies, and ongoing monitoring
  6. #6CriticalKey Focus AreasContinuously

    Applies to: State agencies

    ongoing monitoring to ensure AI systems are safe, effective, resilient, and adhere to security standards.
  7. #7CriticalKey Focus AreasBefore deployment, Continuously

    Applies to: State agencies

    integral to ensuring equitable treatment and preventing algorithmic bias
  8. #8CriticalImplementation FrameworkBefore deployment, Continuously

    Applies to: State agencies

    The framework mandates a comprehensive risk management approach that considers the entire AI lifecycle
  9. #9CriticalMonitoring and EvaluationContinuously

    Applies to: State agencies

    The framework explicitly requires agencies to regularly test their AI applications against the seven guiding principles.
  10. #10CriticalMonitoring and EvaluationBefore deployment, Continuously

    Applies to: State agencies

    mandates the establishment of clear mechanisms to modify, replace, or deactivate AI applications if they fail to perform as intended or are found to violate any of the established principles.
  11. #11ImportantKey Focus AreasContinuously

    Applies to: State agencies

    adoption of Fair Information Practice Principles (FIPPs) throughout the AI lifecycle
  12. #12ImportantKey Focus AreasBefore deployment

    Applies to: State agencies

    embedding of privacy-by-design principles to ensure controlled data access and high data quality and integrity.

© Regulations.AI — created on 06-Jan-2026 using Gemini 2.5 Flash