====== Public Records and AI Template ====== Use this template to document how an organization manages public-records, retention, transparency, disclosure, and documentation responsibilities related to AI-assisted work. ===== Records and AI Profile ===== **Organization:** [Organization Name] **Policy or Guidance Name:** [Public Records and AI Guidance] **Concept ID:** [namespace:public_records_ai] **Policy Owner:** [Department, Clerk, Legal, Records Manager, or IT] **Audience:** Staff, managers, legal counsel, records officers, AI users **Status:** Draft **Last Reviewed:** [Month Year] ===== Purpose ===== Explain how the organization will identify, preserve, review, disclose, and manage records created through or connected to AI-enabled systems. ===== Scope ===== This guidance may apply to: * AI-generated drafts * Prompts entered by staff * Uploaded documents * Chat histories * AI-assisted reports * Public-facing chatbot interactions * Vendor audit logs * System-generated recommendations * AI-related approval records * AI incident records ===== Core Principles ===== * AI use does not remove records-management obligations. * Staff remain responsible for preserving required records. * Records should be maintained according to applicable retention rules. * Sensitive information should not be entered into unapproved AI systems. * Public-facing AI interactions may require additional review and retention controls. * Vendor contracts should support export, retention, deletion, and audit needs. ===== Record Categories ===== ^ Record Type ^ Example ^ Retention or Handling Requirement ^ | Prompt | Staff request entered into an AI tool | [Requirement] | | Output | AI-generated draft memo or response | [Requirement] | | Uploaded File | Policy, spreadsheet, or public document uploaded to AI tool | [Requirement] | | Chat History | User interaction with an internal or public AI assistant | [Requirement] | | Approval Record | Decision approving AI use case or vendor | [Requirement] | | Audit Log | System access or AI activity record | [Requirement] | | Incident Record | Harmful output, data issue, or misuse report | [Requirement] | ===== Staff Responsibilities ===== Staff should: * Use only approved AI tools for agency work. * Avoid entering confidential, protected, or restricted information into unapproved systems. * Preserve work products when required. * Follow department retention schedules. * Escalate uncertain records questions to records-management, legal, or supervisory staff. * Review AI-generated content before relying on or releasing it. ===== AI Tool Review Questions ===== * Does the platform retain prompts, uploaded files, or outputs? * Can records be exported? * Can records be searched and retrieved? * Can data be deleted according to retention rules? * Are audit logs available? * Does the vendor use organizational data for model training? * Can the organization respond to a records request involving AI use? * Are public-facing AI interactions captured and retained? ===== Public-Facing AI Requirements ===== For public-facing AI assistants, document: * The purpose of the assistant * The information sources used * Human review requirements * Disclaimer language * Escalation paths * Record-retention approach * Accessibility expectations * Monitoring and quality-review practices ===== Required Documentation ===== * Approved AI use case * Data categories involved * Retention guidance * Vendor contract terms * Audit-log availability * Approval records * Incident procedures * Staff training materials * Review schedule ===== Related OKF Resources ===== * [[government:public_records|Example: Public Records and AI]] * [[government:ai_governance|Example: AI Governance]] * [[government:ai_procurement|Example: AI Procurement]] * [[templates:ai_governance|AI Governance Template]] * [[templates:vendor_evaluation|Vendor Evaluation Template]] * [[templates:start|Return to OKF Templates]] ===== Revision History ===== ^ Version ^ Date ^ Change ^ Owner ^ | 0.1 | [Month Year] | Initial draft | [Name or role] |