Governing AI use responsibly across Indiana State Government
In February 2024, Indiana implemented an enterprise-level policy governing the use of Artificial Intelligence (AI) within state government. The State of Indiana AI Policy is issued and monitored by the Office of the Chief Data Officer (OCDO), with support from the Chief Privacy Officer (CPO) and the Management Performance Hub (MPH).
While AI offers significant potential to enhance government services for Hoosiers, it also presents unique challenges requiring careful management. State leadership and employees must understand the benefits and risks of AI, including bias, privacy and security concerns.
The policy uses the National Institute of Standards and Technology’s AI Risk Management Framework (NIST AI RMF) to guide ethical, efficient and secure AI use, while balancing innovation with responsibility. To complement the AI Policy, the OCDO issued the AI Systems Standard that requires agencies to complete a Readiness Assessment before deploying any AI tools.
AI Request Process

As of August 2026, the Readiness Assessment process has been merged with the Indiana Office of Technology’s (IOT) intake process into a single, unified request mechanism via ServiceNow. This streamlined approach benefits both requestors and reviewers by:
- Requiring only one form for both IOT and MPH/OCDO submissions
- Providing clear visibility into submission progress throughout the review process
- Allowing requestors to monitor submission status in ServiceNow at any time
AI Request Forms in ServiceNow
AI Helper: Determine Your Path
You will sign-in via SSO to access this form on ServiceNow
Open the AI HelperAI Helper: Determine Your Path
Triage your request to determine which form is most appropriate for your situation. The AI Helper: Determine Your Path is your logic starting point if you're not sure how to begin.
AI Out of Scope
Affirm your agency’s intention and ability to block, disable, and/or not implement AI tools/ features of a system or software.
AI Readiness Assessment
You will sign-in via SSO to access this form on ServiceNow
Open the AI Readiness AssessmentAI Readiness Assessment
Submit a request to utilize an AI system that has not yet been approved for use by another State of Indiana agency.
AI Use Case Questionnaire
You will sign-in via SSO to access this form on ServiceNow
Open the AI Use Case QuestionnaireAI Use Case Questionnaire
Submit a request to utilize an AI system that has been approved for use by another State of Indiana agency and is included on the AI Systems Inventory list.
Click the image to view larger version.
Review and Approval
After obtaining approval from the requesting agency's Agency Privacy Officer (APO), submissions are reviewed by:
- The MPH (OCDO) AI Review Team
- The IOT AI Technical Team
- The IOT Security and Compliance Team
This review ensures ethical, privacy and technical security standards are considered prior to deployment. Once reviewed and approved, the submission results in a State of Indiana AI Policy Exception Grant issued by the CPO, authorizing the agency's use of the AI tool or system.
Click the image to view larger version.
Frequently Asked Questions
Policy & Definitions
State employees may use only AI systems that have been reviewed and approved by the Office of the Chief Data Officer (OCDO). Any unapproved AI use is prohibited. The policy applies to all AI systems, regardless of whether they are open‑source, third‑party, internally built, or purchased.
Under this policy and in accordance with the NIST AI Risk Management Framework, an AI System is defined as an engineered or machine-based system that can generate outputs such as predictions, recommendations, or decisions influencing real or virtual environments for a given set of objectives. AI Systems are designed to operate with varying levels of autonomy.
The Agency Privacy Officer (APO) is responsible for ensuring compliance with the AI policy in your agency. This individual is designated under the State of Indiana Policy: Information Privacy and appointed by your agency.
For state employees, it may lead to removal from relevant AI Implementation Activities and a review of their access. It may also constitute employee misconduct.
The policy applies to all AI systems, including those that have already been implemented. For existing systems, the agency should submit the appropriate form determined by the AI Helper survey on ServiceNow.
No. AI tools on personal devices cannot meet State security, privacy, auditing, and data-protection requirements. Additionally, AI on personal devices for State purposes significantly increases the risks of data leakage and inaccurate or unreliable outputs.
Submission Process
The AI Helper: Determine Your Path triage questionnaire is the best place to begin an AI request.
There are 3 AI request forms in ServiceNow:
- AI Readiness Assessment – this form collects information on an AI system that has not yet been approved for State of Indiana use. This form’s questions are outlined [LINK TO RESOURCE].
- AI Use Case Questionnaire – this form collects information about an agency’s use case for an AI solution listed in the AI Systems Inventory.
- AI Out of Scope Form – this form documents an agency’s affirmation that they do not intend to utilize AI features of a particular system and collects proof that the AI tools may be disabled, blocked, or not made available to agency users.
An agency that does not intend to utilize the AI features or capabilities of a system may submit an AI Out of Scope form IF any of the following requirements are met AND proof is documented:
- AI features may be disabled at the administrator-level (i.e. not individual users)
- Specific URLs may be blocked by IOT
- No AI features or capabilities are included in the agency’s purchase of the system
If documentation is not available and/or none of the above requirements are met, the AI Out of Scope form is not applicable, and the agency should use the AI Helper to determine whether an AI Readiness Assessment or AI Use Case Questionnaire is more appropriate for their system.
It is at the discretion of the Agency as to who is able to submit an AI request. All forms require the submitter to identify the Agency Privacy Officer (APO) as they are responsible for ensuring the agency is compliant with the State of Indiana AI Policy. The APO is notified of the submission and must enter their approval in ServiceNow for the submission to move forward.
Yes, once a form is approved by both the MPH/ OCDO team and the IOT AI Technical Team, a notification is sent to the submitter alerting them that a Software Authorization Request must be submitted via Archer before the IOT Security Team begins their review.
Assessment Process
The review team needs a clear explanation of what the AI system will do, what data it will use, who will use it, and how it will operate. They are looking for risks that may be introduced by the tool in order to prescribe controls to mitigate them.
AI Systems are classified into three risk levels: High-Risk, Moderate-Risk, and Low-Risk. The classification is based on the system’s potential impact and scope of application.
- High-Risk systems generally have broad-context applicability or may impact fundamental rights, safety, or critical sectors.
- ‘Broad-context’ means a system that operates across diverse domains and/or impacts individuals in unpredictable ways.
- Moderate-Risk systems typically have narrow-context applicability or are deployed in less sensitive contexts.
- ‘Narrow-context’ means a system that operates in a specific domain and/or conducts well-defined tasks with limited scope.
- Low-Risk systems have very limited ability to cause harm and the risks are easily mitigated.
The NIST AI RMF is a widely-used framework adopted by the State of Indiana for managing risks associated with AI systems. It is important because it provides a structured approach to identify, assess and mitigate risks related to AI implementation.
Post-Implementation
Yes, notice improves user trust by clearly showing when AI is being used, turning hidden automation into transparent, understandable interaction. Please reach out to ResponsibleData@mph.in.gov for guidance on how to provide appropriate notice for your AI system/ system outputs.
AI Policy Exceptions must be reviewed following major system changes or annually, whichever comes first. Major changes include new policies, mergers, stakeholder shifts, accessibility or processing updates, changes in information type, or significant output modifications. The agency using the AI system is responsible for identifying and reporting these changes. MPH handles annual reviews with a self-report form for agencies.
No. The only AI tools that are allowable for use by state employees are those with accompanying AI Policy exceptions.
If a vendor pushes an update that includes an AI tool, the agency should report it to IOT immediately.
Yes, the AI Systems Inventory is available to State employees in Archer.
- Note: An AI system’s inclusion in the Inventory does not mean it has been approved for use by all agencies. Use cases must be submitted for OCDO/MPH and IOT review prior to implementation.

