Department of Corrections and Rehabilitation - Operations Manual

Chapter 4 – Information Technology

Article 40 – Generative Artificial Intelligence Policy

View All Sections >

47130.4 Policy Directives

  • The department shall ensure:

    • All content used to directly communicate with a person regarding government services and benefits that is created or substantially altered by GenAI must have a specified disclosure that the content is generated or substantially altered using GenAI.

    • All GenAI proof of concepts must be first tested in a CDT approved “sandbox” environment, in accordance with State Administrative Manual (SAMState Administrative Manual) Section 4986.6, or its subsequent iteration. Testing shall include, but not be limited to:

      • evaluation for model bias,

      • hallucinations,

      • bad actors,

      • equity,

      • data quality issues,

      • privacy, and

      • security concerns.

    • Prior to any potential use of, or solicitation for, technologies that involve GenAI components, the technologies undergo a formal review to assess risk and verify alignment with official business goals per State procurement and policy requirements specific to GenAI.

    • All potential use of, or solicitation for, GenAI and related technologies must be approved by the department’s Chief Information Officer (CIO) prior to use by department personnel. Only uses of GenAI that are for official department purposes shall be considered for approval.t involve GenAI components, the technologies undergo a formal review to assess risk and verify alignment with official business goals per State procurement and policy requirements specific to GenAI.

    • All GenAI input and output data shall be reviewed to prevent biases and misuse. The review must be supplemented with human verification of accuracy and factuality of the input and output data to prevent misinformation.

    • All GenAI applications, tools, and systems including those deemed “high-risk automated decisions systems” pursuant to Government Code (GCGovernment Code) Section 11546.45.5, subdivision (a)(5), and those deemed “high-risk” pursuant to the required risk assessment in State Information Management Manual (SIMM) 5305-F, shall be documented and inventoried.

    • Prior to their involvement in any potential use or use of GenAI that may utilize department data and information assets, all personnel shall undergo appropriate GenAI training according to their roles and responsibilities.

    • All GenAI and related technologies are implemented with documented and appropriate security controls, as determined by the CIO.

    • Individuals consuming processes or services utilizing GenAI applications, tools, and systems shall have access to a non-GenAI alternative that ensures the ability to opt out of automated systems in favor of a non-GenAI alternative where appropriate.

    • Access to human review and remedy through a fallback and escalation process when an individual contests or appeals a GenAI-assisted outcome.

  • In accordance with SAMState Administrative Manual Section 4986.12, the department shall ensure:

    • Users only use State approved or provided accounts on State approved or provided equipment for State work.

    • Users are prohibited from entering confidential and sensitive State data into commercially available GenAI.

    • Users may employ GenAI to enhance the efficiency and effectiveness of public services.

    • Users must review and verify GenAI output for relevance before use to ensure it aligns with its intended purpose and to mitigate risks such as hallucinations, misinformation and bias.

    • Users must not infringe on any copyright or intellectual property laws and must comply with open-source licenses as applicable.

    • Users must use the “opt-out” option on data collection and model training features that GenAI might offer if available. (e.g. ChatGPT).

    • Users waive all rights of ownership to GenAI outputs that are created on behalf of California and used for public related services to California.

    • Users must not use State email or other State identifying information to register unsupported tools.

    • Users must not label content created from GenAI as their own.

    • Users must report the unauthorized use or disclosure of confidential and sensitive State data in GenAI to the Information Security Officer (ISOInformation Security Officer).