Loading...
HomeMy WebLinkAbout051926 email - AI Policy NotesALERT: BE CAUTIOUS This email originated outside the organization. Do not open attachments or click on links if you are not expecting them. Good evening Commissioners-- Here are some preliminary written comments on some portions of the AI policy. I think it will be much easier to understand the policy (and spot things about it which don't make sense) once it has been edited for grammar and formatting and once staff have addressed some of the things discussed at the workshop . . . so you can expect additional comments following the next workshop. * Sections 4, 5, 7, and 8 (there is no section 6) of the adopting resolution refer to the resolution as an ordinance. * Section 4 of the adopting resolution says that the ordinance "controls over any other ordinance, resolution or policy on the same topic." However, section (2)E (page 1 of the policy) says that the purpose of the policy is to "[e]nsure the compliance of AI systems with all applicable federal, state, and local laws and regulations as well as existing the County policies." I believe the intent is to have this policy control over other County policies and regulations, as stated in the resolution--but I read section (2)E as suggesting that the policy is subordinate to any existing laws, regulations or policies in existence at the time of adoption. * In section (3) (pages 2-3), I think the "We expect" language is still odd. I take the point that the County can't defensibly pin itself to "We will" language. I suppose "We expect" is intended to convey that the County expects that all AI users will abide by the guidelines, but to me, it sounds more like "We think" or "We believe that AI will . . ." and puts the onus on AI tools and their developers while minimizing the County's responsibility. Perhaps a more appropriate wording would be something along the lines of "We will endeavor to . . ." or "We will aspire to . . ." * The subparts of section (5)(d) (page 8) are joined by an "and" that I believe should be an "or". * In section (8) (page 11), I think there should be some statement about records retention. Based on the discussion at the workshop, I expect that one of the main uses of AI at the County is and will continue to be drafting documents. Although many draft documents are transitory and fall under DAN GS2016-004, that record series specifically excludes drafts that are "needed as evidence . . . that the agency practiced due diligence in the drafting process". I think this section should describe under what circumstances an AI-drafted document or prompt needs to be retained for evidence of due diligence. It seems like it would be overkill to retain all AI-generated draft documents . . . but perhaps that is what is suggested by sections: * (3)(a) and (e) (page 2); * (10)(e)(ii) (page 13); * (11)(e) (page 14); and * (12) (pages 16-18. * * Section (10)(c)(ii) (page 12) allows the County Administrator to decide "whether to allow AI use cases which involve substantial risks of harm or other negative consequences." "Substantial risk of harm" is not defined in the policy, but if a use case did involve a substantial risk of harm as that phrase might reasonably be understood, I don't see what circumstances would make it appropriate for the County Administrator to allow such a use. (I do think it's important to not forget that while AI may be becoming more prevalent and important to government, the traditional functions of government have historically all been done without AI.) Unless I am missing an obvious foreseeable reason to allow AI use cases involving substantial risks of harm, I would recommend pulling this section and replacing it with a section elsewhere in this policy (likely section (7)) which explicitly prohibits "AI use cases which involve substantial risks of harm" (as defined by the Central Services Director pursuant to section (11)(b)(i) (page 14)). * Section (11)(h)(i) (page 15) stipulates that "vendors and other third parties who provide or interact with AI systems shall be required to comply" with the AI policy. But in subsection (iii), the policy goes on to say that "preference in procurement decisions shall be given to vendors which can effectively provide transparency into their AI systems and practices to both the County and the public." If vendors must comply with the policy, and the policy requires transparency in the use of AI systems and practices, I don't see how one of two vendors who are both compliant could be given preference over the other, unless the implication is that certain vendors or contractors may have policies which are more transparent than the County's. If that is what this section contemplates, and the County will be evaluating those policies during procurement, then I would recommend that the any time a vendor is given preference under this section, the rationale behind that preference be communicated to the AI Review Committee for consideration for incorporation into the County's policy. * Section (11)(i) (page 16) requires AI-generated content to be labeled if it is presented to the public. There was some discussion about how extensive labeling requirements could be unduly burdensome with little benefit, and I think that there is some merit to that argument. Still, I think there is some benefit to having labeling requirements for content not intended for public dissemination so that (1) employees know whether they are working with AI content and (2) (County-generated) records which are requested through public records requests are labeled as AI-generated. There is probably some middle ground between labeling everything and only labeling documents intended for public dissemination. Note also that section (12)(a) (page 16) requires attribution (i.e., labeling) in what appears to be all cases where AI systems are used. Section (11)(i) should probably be rolled into section (12)(a), as this labeling requirement is procedural. * I would recommend removing subsections (12)(c)(iii)(A)-(C) (page 17) from the policy and instead including them in the AI User Guide. * I believe Mr. Thiersch's comment about NDAs was in part also related to section (12)(f) (page 18): "Responsibilities for protecting County information do not end at the termination of employment. These responsibilities continue until the information is reclassified to be public." * Appendix C (page 23) is blank. Perhaps relocate subsections (7)(e)(vi)(A)-(I) (pages 10-11) to this appendix, supplement it, and call it a list of common PRA and other statute exemptions. Additionally, I will note that I still do not grasp what exactly DarwinAI's role is in all of this. Monday's brief explanation answered some questions while raising others. (Admittedly, I have not looked into it at all on my own.) Because DarwinAI seems to be central to the implementation of the policy, I wonder if it might not be helpful to include something in the policy explaining its role (maybe as an appendix or part of section (11)). To the extent that doing so is feasible, it might also be illuminating to have Shawn provide a demo to the Board at the next workshop to demonstrate what DarwinAI does and why it is necessary. Thank you, Kincaid