Skip to main content

Oregon State Flag An official website of the State of Oregon »

Artificial Intelligence

Artificial Intelligence

Oregon’s Artificial Intelligence (AI) program provides the foundation for responsible AI use across state government. The foundation for this work is the statewide Responsible AI Usage Policy. Current program efforts prioritize low risk applications and the development of AI tools to support agencies.  

What is the Responsible AI Usage Policy? 

Oregon’s Responsible AI Usage policy establishes enterprise-wide governance for generative and agentic AI across the executive branch. The main purpose of the policy is the creation of a robust governance structure that instills confidence and trust in the use of AI at the state. The policy has the following objectives: 

  • Establish enterprise governance: create a governance structure for AI policy and oversight that can keep pace with rapidly evolving technology and standards. 
  • Identify and address risks: establish a risk management model to identify and address potential issues related to bias, fairness, privacy, safety, and security. 
  • Ensure accountability: mandate clear lines of human responsibility for all AI systems. 
  • Foster transparency: require mechanisms for internal and public transparency regarding the state's use of AI. 
  • Empower the workforce: build AI literacy and technical competency across the state workforce. 
  • Monitor progress: establish systems for monitoring and reporting AI use. 

The policy applies to both generative and agentic AI systems, standalone or embedded, used for state business by executive branch agencies, boards, and commissions. 

How Do State Agencies Comply with the AI policy? 

Agencies must follow these core requirements: 

  • Develop an Agency AI Adoption Plan: Agencies are directed to develop and maintain an AI adoption plan that is aligned with the agencies strategic plan, IT strategic plan, and data governance plan. A plan template is available to help. 
  • Seek Approval for AI uses: For proposed new uses of AI, agencies must evaluate risks and submit the AI Use Form as part of the IT Investment process (ITI).  
  • Follow key standards on human review, disclosure and user feedback: All specified in the AI policy attachments.  
  • Use Approved Tools: Microsoft Copilot Chat, M365 Copilot, and Teams Premium are approved tools for widespread use by state employees. All other tools require separate approval.  
Document
Description
Responsible AI Usage Policy Statewide requirements for responsible AI governance, oversight, and transparency.
Responsible AI Usage Policy – Supporting Attachments Agency AI Adoption Strategy Template and Instructions
AI Risk Management Framework
AI Use Form
Use Disclosure
User Feedback
Human in the Loop Documentation
Higher-risk Use Cases Requirements
Responsible AI Usage Procedure Steps agencies must follow to implement the AI policy.
Copilot General Usage Policy Policy for using Microsoft Copilot Chat, M365 Copilot and Teams Premium.
Copilot Usage Procedure Agency steps for implementing the Copilot General Usage policy.



Training and Collaboration Tools for State Employees

*Requires M365 Profiles and Workday access

Enterprise AI Advisory Committee 

A statewide committee appointed by the State CIO to provide guidance and recommendations on AI governance, policy, and responsible use across state agencies. More information and the full charter will be posted soon. 







Frequently Asked Questions about AI for State Agencies and Employees

This FAQ provides guidance to help agencies understand requirements and expectations for responsible AI and data use.

Answer:
Microsoft Copilot Chat is the recommended tool for use by state employees and it is available to all staff through M365. An enhanced version of Copilot called M365 Copilot is also approved and available with an additional agency-approved license and train​ing.

Answer:
No. Copilot does not give anyone new access; it follows the same permissions and protections as Teams, Outlook, and SharePoint.​

Answer:
You may use these tools for normal web searching. Do not enter non-public state data (Level 2+) or use them for writing, editing, or summarization for work.Only approved tools like Copilot should be used for that.​

Answer:
Currently Copilot is the recommended and approved GenAI tool for general use by state employees and should be considered first. Other tools may only be used if they have gone through the Information Technology Investment (ITI) process and have been approved by EIS.

Answer:
Yes. Any AI tool used for state business (other than web search engine use as noted) must be approved through the appropriate IT and EIS review, regardless of data level.​

Answer:
New AI features, even in an existing tool, must be reviewed via the information technology investment (ITI) process and approved by EIS before use.​

Answer:
Generally, yes. If they document state business or support decisions, they are public records and must follow normal records management and retention rules.​

Answer:
No. AI output must always be reviewed by a human and must not be the sole basis for official decisions or statements.​

Answer:
For external documents, disclosure is recommended (for example, a note or footnote). Your agency may set more specific rules.​

Answer:
The “AI for Public Professionals” course in Workday is the recommended baseline. Additional Copilot training is available through the M365 training library and Microsoft scenario examples.​

Answer:
State employees with an M365 Copilot license must complete AI for Public Professionals (or another EIS-approved course). Others are encouraged but not currently required.​

Answer:
Only Level 1 (“Published”) and Level 2 (“Limited”) data are allowed. Level 3 (“Restricted”), Level 4 (“Critical”), and regulated data must not be used.  Please see the latest guidence and policy on data usage on the EIS Polices, Procedures, and Guidenec page.

Answer:
Yes. Classify your inputs first and only use Level 1–2. Treat and label GenAI outputs at the highest sensitivity level of the input data.​

Answer:

AI tools and services must go through the information technology investment (ITI) process and normal procurement review, including security, privacy, and data handling terms in contracts. “Built-in” AI features are treated as a change in risk and must be reviewed and approved before use.​