Public Records and AI Template
Use this template to document how an organization manages public-records, retention, transparency, disclosure, and documentation responsibilities related to AI-assisted work.
Records and AI Profile
Organization: [Organization Name] Policy or Guidance Name: [Public Records and AI Guidance] Concept ID: [namespace:public_records_ai] Policy Owner: [Department, Clerk, Legal, Records Manager, or IT] Audience: Staff, managers, legal counsel, records officers, AI users Status: Draft Last Reviewed: [Month Year]
Purpose
Explain how the organization will identify, preserve, review, disclose, and manage records created through or connected to AI-enabled systems.
Scope
This guidance may apply to:
- AI-generated drafts
- Prompts entered by staff
- Uploaded documents
- Chat histories
- AI-assisted reports
- Public-facing chatbot interactions
- Vendor audit logs
- System-generated recommendations
- AI-related approval records
- AI incident records
Core Principles
- AI use does not remove records-management obligations.
- Staff remain responsible for preserving required records.
- Records should be maintained according to applicable retention rules.
- Sensitive information should not be entered into unapproved AI systems.
- Public-facing AI interactions may require additional review and retention controls.
- Vendor contracts should support export, retention, deletion, and audit needs.
Record Categories
| Record Type | Example | Retention or Handling Requirement |
|---|---|---|
| Prompt | Staff request entered into an AI tool | [Requirement] |
| Output | AI-generated draft memo or response | [Requirement] |
| Uploaded File | Policy, spreadsheet, or public document uploaded to AI tool | [Requirement] |
| Chat History | User interaction with an internal or public AI assistant | [Requirement] |
| Approval Record | Decision approving AI use case or vendor | [Requirement] |
| Audit Log | System access or AI activity record | [Requirement] |
| Incident Record | Harmful output, data issue, or misuse report | [Requirement] |
Staff Responsibilities
Staff should:
- Use only approved AI tools for agency work.
- Avoid entering confidential, protected, or restricted information into unapproved systems.
- Preserve work products when required.
- Follow department retention schedules.
- Escalate uncertain records questions to records-management, legal, or supervisory staff.
- Review AI-generated content before relying on or releasing it.
AI Tool Review Questions
- Does the platform retain prompts, uploaded files, or outputs?
- Can records be exported?
- Can records be searched and retrieved?
- Can data be deleted according to retention rules?
- Are audit logs available?
- Does the vendor use organizational data for model training?
- Can the organization respond to a records request involving AI use?
- Are public-facing AI interactions captured and retained?
Public-Facing AI Requirements
For public-facing AI assistants, document:
- The purpose of the assistant
- The information sources used
- Human review requirements
- Disclaimer language
- Escalation paths
- Record-retention approach
- Accessibility expectations
- Monitoring and quality-review practices
Required Documentation
- Approved AI use case
- Data categories involved
- Retention guidance
- Vendor contract terms
- Audit-log availability
- Approval records
- Incident procedures
- Staff training materials
- Review schedule
Related OKF Resources
Revision History
| Version | Date | Change | Owner |
|---|---|---|---|
| 0.1 | [Month Year] | Initial draft | [Name or role] |