AI Request Process

As of August 2026, the Readiness Assessment process has been merged with the Indiana Office of Technology’s (IOT) intake process into a single, unified request mechanism via ServiceNow. This streamlined approach benefits both requestors and reviewers by:
- Requiring only one form for both IOT and MPH/OCDO submissions
- Providing clear visibility into submission progress throughout the review process
- Allowing requestors to monitor submission status in ServiceNow at any time
Frequently Asked Questions
Policy & Definitions
- What is allowed by the State of Indiana Artificial Intelligence (AI) Policy?
State employees may use only AI systems that have been reviewed and approved by the Office of the Chief Data Officer (OCDO). Any unapproved AI use is prohibited. The policy applies to all AI systems, regardless of whether they are open‑source, third‑party, internally built, or purchased.
- What is considered an AI system under the State of Indiana AI Policy?
Under this policy and in accordance with the NIST AI Risk Management Framework, an AI System is defined as an engineered or machine-based system that can generate outputs such as predictions, recommendations, or decisions influencing real or virtual environments for a given set of objectives. AI Systems are designed to operate with varying levels of autonomy.
- Who is responsible for ensuring compliance with the AI policy in my agency?
The Agency Privacy Officer (APO) is responsible for ensuring compliance with the AI policy in your agency. This individual is designated under the State of Indiana Policy: Information Privacy and appointed by your agency.
- What happens if there’s a violation of the AI policy?
For state employees, it may lead to removal from relevant AI Implementation Activities and a review of their access. It may also constitute employee misconduct.
- How does this policy affect AI systems we’ve already implemented?
The policy applies to all AI systems, including those that have already been implemented. For existing systems, the agency should submit the appropriate form determined by the AI Helper survey on ServiceNow.
- Am I able to use AI on my personal device for State purposes?
No. AI tools on personal devices cannot meet State security, privacy, auditing, and data-protection requirements. Additionally, AI on personal devices for State purposes significantly increases the risks of data leakage and inaccurate or unreliable outputs.
Submission Process
- How do I know which form to use?
The AI Helper: Determine Your Path triage questionnaire is the best place to begin an AI request.
There are 3 AI request forms in ServiceNow:
- AI Readiness Assessment – this form collects information on an AI system that has not yet been approved for State of Indiana use. This form’s questions are outlined [LINK TO RESOURCE].
- AI Use Case Questionnaire – this form collects information about an agency’s use case for an AI solution listed in the AI Systems Inventory.
- AI Out of Scope Form – this form documents an agency’s affirmation that they do not intend to utilize AI features of a particular system and collects proof that the AI tools may be disabled, blocked, or not made available to agency users.
- What if a system has AI features or capabilities that I do not intend to use?
An agency that does not intend to utilize the AI features or capabilities of a system may submit an AI Out of Scope form IF any of the following requirements are met AND proof is documented:
- AI features may be disabled at the administrator-level (i.e. not individual users)
- Specific URLs may be blocked by IOT
- No AI features or capabilities are included in the agency’s purchase of the system
If documentation is not available and/or none of the above requirements are met, the AI Out of Scope form is not applicable, and the agency should use the AI Helper to determine whether an AI Readiness Assessment or AI Use Case Questionnaire is more appropriate for their system.
- Who is able to submit an AI request?
It is at the discretion of the Agency as to who is able to submit an AI request. All forms require the submitter to identify the Agency Privacy Officer (APO) as they are responsible for ensuring the agency is compliant with the State of Indiana AI Policy. The APO is notified of the submission and must enter their approval in ServiceNow for the submission to move forward.
- Is an IOT Software Authorization Request still required?
Yes, once a form is approved by both the MPH/ OCDO team and the IOT AI Technical Team, a notification is sent to the submitter alerting them that a Software Authorization Request must be submitted via Archer before the IOT Security Team begins their review.
Assessment Process
- What does the OCDO/ MPH AI Review Team need to understand about an agency’s AI use case?
The review team needs a clear explanation of what the AI system will do, what data it will use, who will use it, and how it will operate. They are looking for risks that may be introduced by the tool in order to prescribe controls to mitigate them.
- How does OCDO/ MPH classify the risk level of an AI system?
AI Systems are classified into three risk levels: High-Risk, Moderate-Risk, and Low-Risk. The classification is based on the system’s potential impact and scope of application.
- High-Risk systems generally have broad-context applicability or may impact fundamental rights, safety, or critical sectors.
- ‘Broad-context’ means a system that operates across diverse domains and/or impacts individuals in unpredictable ways.
- Moderate-Risk systems typically have narrow-context applicability or are deployed in less sensitive contexts.
- ‘Narrow-context’ means a system that operates in a specific domain and/or conducts well-defined tasks with limited scope.
- Low-Risk systems have very limited ability to cause harm and the risks are easily mitigated.
- High-Risk systems generally have broad-context applicability or may impact fundamental rights, safety, or critical sectors.
- What is the NIST AI Risk Management Framework and why is it important?
The NIST AI RMF is a widely-used framework adopted by the State of Indiana for managing risks associated with AI systems. It is important because it provides a structured approach to identify, assess and mitigate risks related to AI implementation.
Post-Implementation
- Do we need to provide notice to individuals when using an AI system?
Yes, notice improves user trust by clearly showing when AI is being used, turning hidden automation into transparent, understandable interaction. Please reach out to ResponsibleData@mph.in.gov for guidance on how to provide appropriate notice for your AI system/ system outputs.
- How often are AI Policy Exceptions reviewed?
AI Policy Exceptions must be reviewed following major system changes or annually, whichever comes first. Major changes include new policies, mergers, stakeholder shifts, accessibility or processing updates, changes in information type, or significant output modifications. The agency using the AI system is responsible for identifying and reporting these changes. MPH handles annual reviews with a self-report form for agencies.
- If an AI tool is accessible, (i.e. not blocked by IOT) am I allowed to use it? Are we allowed to use integrated AI tools pushed through in updates by vendors to existing systems?
No. The only AI tools that are allowable for use by state employees are those with accompanying AI Policy exceptions.
If a vendor pushes an update that includes an AI tool, the agency should report it to IOT immediately.
- Is there a list of approved AI tools available?
Yes, the AI Systems Inventory is available to State employees in Archer.
- Note: An AI system’s inclusion in the Inventory does not mean it has been approved for use by all agencies. Use cases must be submitted for OCDO/MPH and IOT review prior to implementation.


