{"data":{"id":"us-ky/krs-42.731","jurisdiction":"us-ky","citation":"KRS 42.731","heading":"Duties of Artificial Intelligence Governance Committee -- Duties of","body":"Commonwealth Office of Technology regarding artificial intelligence systems -\n- Establishment of policies and operating standards on use of artificial\nintelligence by state agencies -- Report -- Administrative regulations.\n(1) The Commonwealth Office of Technology shall create an Artificial Intelligence\nGovernance Committee to govern the use of artificial intelligence systems by state\ndepartments, state agencies, and state administrative bodies by:\n(a) Developing policy standards and guiding principles to mitigate risks and\nprotect data and privacy of Kentucky citizens and businesses that adhere to\nthe latest version of Standard ISO/IEC 42001 of the International\nOrganization for Standardization;\n(b) Establishing technology standards to provide protocols and requirements for\nthe use of generative artificial intelligence and high -risk artificial intelligence\nsystems;\n(c) Ensuring transparency in the use of artificial intelligence systems;\n(d) Maintaining a centralized registry to include current inventory of generative\nartificial intelligence systems and high-risk artificial intelligence systems; and\n(e) Developing an approval process to include a registry of application, use case,\nand decision rationale aimed at mitigation of risks.\n(2) The Artificial Intelligence Governance Committee shall develop policies and\nprocedures to ensure that any department, program, cabinet, agency, or\nadministrative body that utilizes and accesses the Com monwealth's information\ntechnology and technology infrastructure shall:\n(a) Verify the use and development of generative artificial intelligence systems\nand high-risk artificial intelligence systems; and\n(b) Act in compliance with responsible, ethical, and  transparent procedures to\nimplement the use of artificial intelligence technologies by:\n1. Ensuring artificial intelligence models have comprehensive and\ncomplete documentation that is available for review and inspection;\n2. Requiring review and intervention by humans dependent on the use case\nand potential risk for all outcomes from generative and high -risk\nartificial intelligence systems; and\n3. Ensuring the use of generative artificial intelligence and high -risk\nartificial intelligence systems are resilient, accountable, and explainable.\n(3) The Commonwealth Office of Technology shall prioritize personal privacy and the\nprotection of the data of individuals and businesses as the state develops,\nimplements, employs, and procu res artificial intelligence systems, generative\nartificial intelligence systems, and high -risk artificial intelligence systems by\nensuring all departments, agencies, and administrative bodies:\n(a) Allow only the use of necessary data in artificial intelligence systems;\n(b) Do not allow unrestricted access to personal data controlled by the\nCommonwealth; and\n(c) Secure all data and implement a timeframe for data retention.\n(4) To maintain and secure the technology infrastructure, information technology,\ninformation resources, and personal information, all departments, agencies, and\nadministrative bodies shall be subject to review of generative artificial intelligence\nsystems or high-risk artificial intelligence systems.\n(5) At a minimum, the executive directo r of the Commonwealth Office of Technology\nshall consider and document:\n(a) How the artificial intelligence system will not result in unlawful\ndiscrimination against any individual or group of individuals;\n(b) How the use of generative artificial intellige nce or other artificial intelligence\ncapabilities will benefit the citizens of the Commonwealth and serve the\nobjectives of the department or agency;\n(c) To what extent oversight and human interaction of the artificial intelligence\nsystem should be required;\n(d) The potential risks, including cybersecurity, data protection and privacy, and\nhealth and safety of individuals and businesses, and a mitigation strategy to\nany identified or potential risk; and\n(e) The proper control and management for all data pos sessed by the\nCommonwealth to maintain security and data quality.\n(6) (a) A department, agency, or administrative body shall disclose to the public,\nthrough a clear and conspicuous disclaimer, when generative artificial\nintelligence, artificial intelligenc e systems, or other artificial intelligence -\nrelated capabilities are used:\n1. To render any decision regarding individual citizens or businesses\nwithin the state;\n2. In any process, or to produce materials used by the system or humans, to\ninform a decision or create an output; or\n3. To produce information or outputs accessible by citizens and businesses.\n(b) When an artificial intelligence system makes external decisions related to\ncitizens of the Commonwealth, a department, agency, or administrative body\nshall:\n1. Disclose how artificial intelligence is used in the decision -making\nprocess;\n2. Provide the extent of human involvement in validating and oversight of\nany decision made; and\n3. Make readily available options for individuals to appeal a consequenti al\ndecision that involves artificial intelligence.\n(c) Any disclaimer under paragraph (a) of this subsection shall also provide\ninformation regarding third -party artificial intelligence products or programs,\nincluding but not limited to information as to h ow the high -risk artificial\nintelligence system or generative artificial intelligence system works, such as\nsystem cards or other documented information provided by developers.\n(7) The Commonwealth Office of Technology shall establish policies to encompass\nlegal and ethical frameworks to ensure that any artificial intelligence systems shall\nalign with existing laws, administrative regulations, and guidelines, which shall be\nupdated at least annually to maintain compliance as technology and industry best\npractices evolve.\n(8) (a) Operating standards for utilization of high -risk artificial intelligence systems\nshall prohibit the use of a high -risk artificial intelligence system to render a\nconsequential decision without the design and implementation of a risk\nmanagement policy and program for high -risk artificial intelligence systems.\nThe risk management policy shall:\n1. Specify principles, process, and personnel that shall be utilized to\nmaintain the risk management program; and\n2. Identify, mitigate, and document any bias or potential bias that is a\npotential consequence of use in making a consequential decision.\n(b) Each risk management policy designed and implemented shall at a minimum\nadhere to the latest version of Standard ISO/ IEC 42001 of the International\nOrganization for Standardization or another national or internationally\nrecognized risk management framework for artificial intelligence systems,\nand consider the:\n1. Size and complexity of the deployer;\n2. Nature, scope, and  intended use of the high -risk artificial intelligence\nsystem and its deployer; and\n3. Sensitivity and volume of data processed.\n(9) This section and KRS 42.722 and 42.726 shall not be construed to require the\ndisclosure of trade secrets, confidential or p roprietary information about the design\nor use of an artificial intelligence system, or any information which would create a\nsecurity risk.\n(10) The Commonwealth Office of Technology shall provide education and training of\nemployees about the benefits and risks of artificial intelligence and allowable use\npolicies.\n(11) (a) The Commonwealth Office of Technology shall transmit reports to the\nLegislative Research Commission and the Interim Joint Committee on State\nGovernment by December 1, 2025, and annually every year thereafter. The\nreports shall include:\n1. The artificial intelligence registry, which shall include the current\ninventory and use case of artificial intelligence utilized in state\ngovernment;\n2. Applications received for use of artificial intell igence, including the\ndecision and rationale in approving or disapproving a request in\ncompliance with subsection (5)(c) of this section; and\n3. Third-party artificial intelligence developers, system administrators,\nproviders, and contractors submitted for  review in compliance with\nsubsection (5) of this section.\n(b) To facilitate the report in paragraph (a) of this subsection, the Commonwealth\nOffice of Technology shall receive from each department, agency, and\nadministrative body a report examining and id entifying potential use cases for\nthe deployment of generative artificial intelligence systems and high -risk\nartificial intelligence systems, including a description of the benefits and risks\nto individuals, communities, government, and government employees.\n(12) The Commonwealth Office of Technology shall promulgate administrative\nregulations in accordance with KRS Chapter 13A to implement this section and\nKRS 42.726 by December 1, 2025.","path":["KRS Chapter 42"],"source_url":"https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=55895","current_through":"Includes enactments through the 2026 Regular Session","vintage":"09/05/2026","retrieved_at":"2026-09-05T20:49:03Z","sha256":"4072f5e9c9b399320373c41571cf6a093f3f8dc63914e710d36abed8e36c81ac","source_id":"us-ky","stale":false,"prev":"us-ky/krs-42.730","next":"us-ky/krs-42.732"},"notice":"GroundRules: Original legal text. Not legal advice."}
