Guidelines  ·  2026-09-04

North Carolina previews statewide AI Governance Playbook with mandated security/risk lifecycle for state agencies

GuidelinesMedium impactGlobal
On September 2, 2026 (confirmed via page metadata), NCDIT published a blog post previewing an upcoming statewide AI Governance Playbook that will establish a mandatory seven-step lifecycle for state agencies: use-case risk evaluation, risk/privacy assessments, approval and oversight, quarterly inventory submission, required security/privacy/governance controls, and continuous post-deployment monitoring. The full playbook document itself has not yet been released — this is a preview/announcement of forthcoming guidance, not the final published standard.
This is an operational (not merely aspirational) AI governance pattern requiring accountable owners, auditable assessment evidence, and ongoing monitoring — a template other state/local governments may follow. Blast radius is currently limited to North Carolina state agencies, and the underlying document is not yet public, so its authoritative content and enforcement mechanics cannot yet be fully verified.
Public-sector AI/security teams (especially other US state IT agencies) should watch for the full playbook release and benchmark its lifecycle/control requirements against existing internal AI risk processes.
NCDIT blog — Secure State AI Use: Get Ready to Use North Carolina's AI Playbook
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →