What happened
On September 2, 2026 (confirmed via page metadata), NCDIT published a blog post previewing an upcoming statewide AI Governance Playbook that will establish a mandatory seven-step lifecycle for state agencies: use-case risk evaluation, risk/privacy assessments, approval and oversight, quarterly inventory submission, required security/privacy/governance controls, and continuous post-deployment monitoring. The full playbook document itself has not yet been released — this is a preview/announcement of forthcoming guidance, not the final published standard.
Why it matters
This is an operational (not merely aspirational) AI governance pattern requiring accountable owners, auditable assessment evidence, and ongoing monitoring — a template other state/local governments may follow. Blast radius is currently limited to North Carolina state agencies, and the underlying document is not yet public, so its authoritative content and enforcement mechanics cannot yet be fully verified.
Action needed
Public-sector AI/security teams (especially other US state IT agencies) should watch for the full playbook release and benchmark its lifecycle/control requirements against existing internal AI risk processes.