{"resourceId":"nc-ai-governance-playbook-prelaunch-20260902","versions":[{"version":"external-00b9daec92508b706ff611e9b585b52e453f7e71623d602d8c254b0e5ad511eb","resource":{"id":"nc-ai-governance-playbook-prelaunch-20260902","title":"North Carolina prepares lifecycle AI oversight with inventories and continuing monitoring","organization":"North Carolina Department of Information Technology","sector":"State government","geography":"North Carolina, United States","publishedAt":"September 2, 2026","publicationDate":"2026-09-02","eventDate":null,"sourceName":"NCDIT","sourceLabel":"Official forthcoming governance guidance","sourceUrl":"https://it.nc.gov/blog/2026/09/02/secure-state-ai-use-get-ready-use-north-carolinas-ai-playbook","evidenceClass":"standards-guidance","outcomeClass":"emerging","topics":["governance-procurement","data-security","accessibility-workforce","operating-model"],"finding":"NCDIT announces preparation for an AI Governance Playbook spanning assessment, approval, inventory, mitigation and monitoring; it does not report implementation results.","sledRelevance":"Direct state-agency preparation signal. The September 2 notice is newly archived, not a new September 10 launch.","evidence":"The notice specifies quarterly inventory submissions and planned publication of high-risk uses, alongside risk and privacy assessments. It provides no completed assessment sample, compliance rate, baseline or measured efficiency result.","architectureImplications":"Interpretation: link inventory entries to actual deployments, data flows and versions; guidance does not prescribe infrastructure sizing or an agent architecture.","governanceImplications":"Interpretation: make approval gates executable in operating processes and retain evidence of reviews.","securityPrivacyImplications":"Interpretation: connect privacy assessment findings to testable controls rather than filing assessments separately.","caveats":"Prelaunch notice, not the complete playbook or proof that agencies comply. Exact launch date is unknown; no independent outcome evaluation.","streamIds":["state-government"],"roles":{"sales":"Interpretation: Engage agency AI oversight teams, security, privacy and program leadership around the work needed to prepare reviewable use cases. Ask whether inventories match deployed tools, who can provide data-flow evidence, and how teams decide which uses merit escalation. A bounded readiness engagement could assemble one complete assessment package and identify missing dependencies. The value hypothesis is fewer avoidable review gaps, not proven faster approval. Keep any commercial proposal contingent on confirmed playbook availability and agency scope. Do not describe the announcement as a completed statewide rollout, certification program or evidence that buying a particular platform satisfies the process.","engineering":"Interpretation: Fit is an evidence workflow around existing AI systems rather than a new model deployment. Connect use-case identifiers to model versions, input classes, integrations, permissions and monitoring records. Prerequisites include authoritative system ownership and access to configuration evidence. Test whether an unapproved scope change can be detected and routed to the responsible reviewer. A proof of value could reconcile one inventory entry against its running configuration and demonstrate retrieval of approval evidence. The notice does not specify retention periods or technical thresholds, so confirm these locally. Treat autonomous write actions and benefits decisions as separate risk questions rather than assuming copilot approval covers them.","delivery":"Interpretation: The agency oversight lead should own readiness, supported by privacy and security liaisons and a program owner who understands service consequences. Establish an intake form, evidence checklist, inventory reconciliation and review calendar. Train contributors with representative cases and a route for uncertain classifications. Proposed acceptance criteria: every scoped deployment has an accountable owner, review status and traceable risk disposition; a sampled configuration change triggers the agreed review process. These are proposed measures, not state-reported achievements. Dependencies include staff time and central instructions. Risks include stale entries, duplicative paperwork and a monitoring obligation without anyone assigned to act on alerts."},"retrievedAt":"2026-09-11T03:00:45Z","enrichedAt":"2026-09-11T03:02:34Z","enrichmentBasis":"retrieved source","accessibilityWorkforceImplications":"The notice encourages responsible-AI training. Interpretation: assess practical competence and accessible participation, not attendance alone.","procurementImplications":"Interpretation: obtain vendor evidence early enough to inform risk review; do not infer new binding contract terms from this announcement.","operatingModelImplications":"Interpretation: assign agency inventory owners and a central reconciliation process.","updateExplanation":"URL and related Playbook finding absent from full archive and targeted search. September 2 preparation notice newly inspected for lifecycle details; no subsequent launch asserted.","sourceVerification":{"openedUrl":"https://it.nc.gov/blog/2026/09/02/secure-state-ai-use-get-ready-use-north-carolinas-ai-playbook","referenceExcerpt":"Continuous monitoring post‑deployment.","promptVersion":"sled-research-v3.1","model":null,"basis":"agent-reported inspection"}}}]}