As mandated by Governor Youngkin’s Executive Order 30 on Artificial Intelligence (AI), the Commonwealth has issued a comprehensive Artificial Intelligence (AI) Utilization Policy and an Artificial Intelligence Standard under VITA’s governance framework. These policies define how agencies must responsibly adopt, manage, and oversee AI; whether standalone, embedded, generative, or vendor-provided; across the enterprise.
Agencies are required to register all internal and external AI systems via the AI registry (currently in the Archer application), and secure approvals through the CTP Planview application, ensuring alignment with VITA, agency head, and Secretary-level governance teams. The AI Standard mandates ethical and transparent AI use, covering data protection, human oversight, fairness, and disclosure; it applies to both new and existing AI deployments.
This FAQ is designed to guide Commonwealth agencies through:
- The AI registration and approval process, including definitions of scope and exemptions
- Policy and technical standards that govern AI procurement, deployment, and operation
- Risk management best practices, such as data privacy, vendor oversight, and audit readiness
- Enterprise documentation requirements, including inventory and architecture reporting via Ardoq
For a full set of policy documents, technical standards, and AI governance resources, please see VITA's Artificial Intelligence page.
AI frequently asked questions (FAQ)
Getting Started with AI
All agencies, including executive branch, higher education, and independent agencies may start with the VITA AI webpage, which you are currently visiting; the VITA AI Policy & Technology Standards, their Agency AI Portfolio Owner, and/or the VITA Commonwealth Enterprise Architecture (EA) team.
For questions beyond this FAQ, please contact your VITA Commonwealth technology strategic partner (CTSP), or the VITA EA team.
Additional questions may also be sent to: vccc@vita.virginia.gov.
For technical questions regarding specific AI technologies, please reach out to your assigned VITA enterprise architect.
AI capabilities are rapidly becoming standard features in software and services across the IT landscape, including many products your agency already uses. As vendors expand or update their offerings, agencies should stay alert to new AI components or functionality introduced into existing tools.
Agencies should carefully monitor product updates within their portfolios to identify when AI features are added. It is equally important to evaluate vendor claims critically, because some providers may exaggerate or misrepresent the presence or effectiveness of AI in their products, which is a practice commonly referred to as “AI washing.” Staying vigilant helps agencies make informed decisions and ensures compliance with AI governance requirements.
AI systems typically learn from data, make predictions, generate content, or automate decision making. If the system performs tasks that normally require human judgment or reasoning, it may contain AI.
When in doubt, ask your solution owner or vendor.
The AI Registry only applies when the AI is actively modifying the data you provide or making decisions, predictions, recommendations, or generating content. Simply having an AI capability embedded in a product is not enough to trigger registration. What matters is whether your agency is actually using that AI function.
For example, Archer includes an AI module, but the Commonwealth does not enable or use it, and end users cannot access it. Therefore, it does not require registration.
The AI Registry is concerned with registering technologies when the AI is: A) making alterations to inputted data, or B) making outbound decisions.
When an AI component influences outputs or decisions, it must be evaluated.
If you're unsure whether a product’s AI capabilities need to be registered, contact your agency’s AI Portfolio Owner.
AI Registration and Approval Requirements
Per the Artificial Intelligence (AI) Utilization Policy, all executive branch agencies (as defined in EO 30) shall register their use of internal and external AI systems for oversight and approval to ensure the trusted, safe, and secure use of such systems.
Artificial Intelligence Registration and Approval is currently a multistep process that requires use-case registration in the Archer application, that once approved, also requires input into VITA's Planview CTP application for necessary approvals (e.g., your agency head and your secretary (external AI only)).
If you have questions about how to register your AI technology in the Archer application, please contact your agency assigned EA who will be happy to assist. If you have questions about CTP/Planview, contact your agency assigned ITIMD analyst.
While there is no exemption in EO 30 for already existing uses of AI, not all uses need to be captured in the registry. When in doubt, ask your agency assigned EA.
- If the AI solution meets all three of the following criteria, registration is not required:
- Internally facing
- Does not use people data
- Not incorporated in a production system (examples of non-production systems are sandbox, development and test systems only using synthetic or publicly available data)
- If the AI solution meets any of the following conditions, registration is required:
- Externally facing
- Uses people data
- Utilized in a production system
- Supports agency mission essential or business critical processes
- Includes sensitive data as defined in SEC530 Information Security Standard
- Requires review for the evaluation of cloud services
Yes.
Any use of AI for official Commonwealth business, even widely available, free tools, must go through the formal registration and approval process defined in the AI Standards and EO‑30. Without official approval, employees may not download, access, or use these products on state devices or for agency work.
This requirement exists because freely available AI tools pose the same risks as paid or enterprise solutions. EO‑30 and the AI Standards ensure that all AI use protects citizen data, avoids biased or harmful outputs, and supports a valid business purpose. Recent public reporting has shown that some free AI tools may produce inaccurate or biased results, underscoring the need for careful evaluation before any agency use.
The AI policies, standards, and registry requirements do not apply in the following situations:
- AI used for defense or Commonwealth security systems, such as cybersecurity tools, HVAC controls, or SCADA systems.
- AI embedded in common commercial products where the Commonwealth does not control the software or the data it uses. Examples include consumer devices like an Apple Watch or iPhone, commercial desktop software such as Adobe Photoshop, or managed SaaS applications where the underlying AI cannot be accessed or invoked independently by the user.
- AI used in research and development (R&D) or instructional programs at public institutions of higher education.
While AI used for research, experimentation, or instructional purposes at public institutions of higher education is generally exempt, AI used for administrative, operational, or business functions involving Commonwealth data is not exempt. Any system that influences real‑world decisions, manages institutional operations, or handles regulated or sensitive data must follow the AI policies, standards, and Registry requirements. Examples include:
- AI used in student admissions, including systems that screen, score, or rank applicants.
- AI used to determine scholarships, grants, or financial aid, or to automate eligibility decisions.
- AI used in personnel management, including tools for hiring, evaluating staff, or supporting performance management.
- AI used to run core business operations, such as financial management, procurement, real estate administration, facilities oversight, or IT service processes.
- AI that accesses or processes sensitive institutional data, including data protected under HIPAA, FERPA, IRS regulations, or other federal and state requirements.
In short, any AI system tied to operational decisions, institutional governance, or regulated data falls within the scope of EO‑30 and must be registered and approved before use.
The AI Registration and Approval process and COV RAMP serve related but distinct purposes, and they occur in a specific order to protect agencies from unnecessary cost and effort.
The AI Registration and Approval process evaluates the intent to use a specific AI technology for a particular business purpose. It ensures the proposed use aligns with EO‑30 and the AI Utilization Policy; covering issues such as ethical use, data protection, bias mitigation, and business justification.
COV RAMP, on the other hand, assesses the operational viability of the vendor and the Commonwealth’s ability to procure and safely use the product. It focuses on vendor security, financial stability, contractual obligations, and risk posture.
Submitting to AI Registration and Approval first helps agencies avoid unnecessary COV RAMP charges. If an AI proposal is denied at the policy level by VITA or the Secretariat, the agency will not need to initiate COV RAMP screening; saving time and avoiding costs. Once a proposed AI use is approved, the agency can proceed to COV RAMP with confidence that the investment is appropriate, justified, and compliant.
It depends.
The AI Registry is designed to promote transparency around the Commonwealth’s use of AI, consistent with the AI Utilization Policy’s requirements for disclosures and mandatory disclaimers. As a result, information in the registry is generally subject to the Virginia Freedom of Information Act (FOIA).
However, FOIA includes cybersecurity and sensitive‑information exemptions that may apply to certain portions of a registry entry. These exemptions, such as those outlined in Va. Code § 2.2‑3705.2(2) and (14), allow agencies to withhold or redact information that, if released, could expose security risks or protected data. FOIA also provides mechanisms for redacting specific fields or extracting only releasable portions of a record (see Va. Code §§ 2.2‑3704(G) and 2.2‑3704.01).
If an agency submits information to the AI Registry that may be sensitive or confidential, it should clearly mark that information when entering it. Doing so helps ensure that, if a FOIA request is received, reviewers can efficiently determine what must be disclosed and what qualifies for exemption or redaction.
No.
The COV Artificial Intelligence Technology Roadmap is intended to highlight AI solutions that have already been reviewed and to point agencies toward technologies they may want to explore.
If an AI product does not appear on the Roadmap, your agency may still pursue it by submitting the proposed use through the AI Registration and Oversight Approval process. Every AI use, whether or not it is listed on the Roadmap, must go through the same registration and evaluation steps outlined in the AI Utilization Policy and AI Standard.
In short, absence from the Roadmap does not prohibit use. It simply means the technology has not yet been evaluated or included, and your agency must submit it through the normal approval process.
It depends.
How is the supplier using the AI and does that use affect the Commonwealth?
If a supplier uses AI strictly for internal, non‑Commonwealth purposes, for example, an employee using an AI tool like Claude to analyze an email that does not involve Commonwealth data or services, then no disclosure or registration is required.
However, registration is required when a supplier’s AI use directly supports a Commonwealth business process, affects an agency mission, or has public‑facing implications. This includes any AI functionality that influences decisions, processes, data handling, or services delivered to the Commonwealth or its citizens.
Responsibility for registration also depends on how the AI use originates:
If VITA requests or requires the supplier to use a particular AI capability, then VITA is responsible for ensuring the AI use case is entered into the Registry. If the supplier proposes using AI as part of delivering services to VITA or any agency, then the supplier must initiate the registration process and work with VITA to complete it.
In short, any supplier AI use that touches Commonwealth data, systems, or business functions must be registered, regardless of whether it is supplier‑initiated or VITA‑directed.
Not necessarily.
Some internal, low‑risk uses of generative AI do not require registration. In general, registration is not required when the AI use:
- is internal‑facing and only supports informal research or idea generation,
- does not produce decisions, policies, or outputs that guide official actions,
- does not use Commonwealth data or people data,
- is not connected to core agency business processes,
- is not integrated into a production system or workflow.
If generative AI is used strictly for brainstorming, summarizing public information, exploring ideas, or supporting learning without touching Commonwealth data or affecting mission‑critical work, registration is not required.
If you’re unsure whether your intended use meets these conditions, contact your agency’s AI Portfolio Owner for guidance.
AI used strictly for research, experimentation, or teaching and learning at public institutions of higher education is exempt from the Commonwealth’s AI policies, standards, and registration requirements. These uses support academic exploration and do not involve operational decision‑making or Commonwealth business processes. Examples include:
- AI used in research initiatives, such as tools that help people perform tasks or support the study of human behavior.
- AI‑assisted exploration of academic topics, where AI is used to review, summarize, or analyze bodies of knowledge.
- AI‑enabled analysis of research data, including experimentation with models, datasets, or methodologies.
- Research focused on AI itself, such as developing or evaluating algorithms, methods, or emerging technologies.
- Classroom use of generative AI by students, including assignments where students use AI tools to assist with writing, coding, or problem‑solving.
- Instructional use by faculty, such as grading, evaluating student work, or demonstrating AI systems as part of coursework.
VITA recommends that AI used in research involving human subjects be overseen through the institution’s Institutional Review Board (IRB) to ensure ethical treatment, responsible data practices, and protection of participant privacy.
For instructional uses, VITA recommends following the guidance of the Virginia Department of Education (for K–12) and the State Council of Higher Education for Virginia (SCHEV) (for colleges and universities).
Ardoq Documentation Requirements
Under the AI Policy, agencies are required to “document where and how AI is used across their IT portfolio” as part of governance responsibilities.
Ardoq is the designated platform for maintaining a centralized, standardized agency portfolio, enabling VITA and the Commonwealth-CIO to monitor usage, assess risks, and ensure compliance across the Commonwealth.
Any AI system used or procured by an executive branch agency, including stand-alone, embedded, or generative AI must be registered in both.
Documentation in Ardoq should begin during the planning phase, before ITIM submission. Early documentation ensures:
- Alignment with enterprise architecture standards
- Inclusion in the risk review process
- Visibility to VITA and assigned Enterprise Architects
Subsequently, updates must be made throughout the lifecycle from procurement to deployment and decommissioning.
Agencies should include:
Sufficient information in all requested fields to completely define the use case being submitted for approval.
No field should be left blank.
Agencies must register new AI systems in the COV AI Registry and submit details via Ardoq prior to deployment.
Updates occur annually to document any changes and ensure continuing alignment with COV policies and standards.
The Agency IT Representative (AITR) and Information Security Officer (ISO) are responsible for:
- Ensuring entries are complete and current,
- Tracking and reporting usage metrics,
- Coordinating any updates or changes with VITA and the CIO.
Agencies must also appoint an AI data governance official to oversee documentation and maintain annual audits.
Agencies must conduct annual audits of high-risk AI systems to confirm:
- Data minimization practices
- Consent management
- Logs and access tracking
- Compliance with de‑identification, bias mitigation, and security protocols
Audit results must be submitted to VITA and the Secretary of Administration.
1. At milestone gates such as pre-planning, procurement, and go-live
2. Whenever key attributes change: owner, data classification, lifecycle status
3. During ITIM quarterly updates, to ensure accurate architecture and compliance
Sandbox, test, or AI using only synthetic/public data is exempt from formal registration/documentation. But if the system:
- Is planned for production use, or
- Supports mission-critical processes, or
- Requires cloud service review
Then registration in CTP/Archer and documentation in Ardoq is required.
Not entirely on its own. Per policy, AI systems must also be:
- Registered in CTP/Planview
- Logged in Archer for risk inventory
- Approved by agency head (and Secretary, if external AI) and reflected in both CTP and Archer
- Documented in Ardoq as part of enterprise-level architecture governance
Ardoq documentation complements but doesn’t replace these steps.
Data Protection, Privacy, and Responsible Use
If your AI solution involves any form of people data such as personal, sensitive, or identifiable information, your agency must be able to clearly explain how that data is collected, used, protected, and governed. At a minimum, your documentation and approval request should include:
-
A description of the data being used. Identify the specific data elements involved, why each is needed, and the value the AI system is expected to produce from them.
-
How the data will be secured and who can access it. Describe storage protections, access controls, encryption, retention practices, and the roles or individuals authorized to view or use the data.
-
How the AI model operates on the data. Explain how the dataset will be processed, how the model generates its outputs, and any known risks related to bias, inference, or misuse.
-
How outputs will be anonymized or protected. Document how the results will be de‑identified, filtered, or safeguarded to prevent exposure of personal information.
-
A critical limitation: People data must not be used to train new AI models unless expressly permitted, which includes all safeguards under the AI Utilization Policy and applicable law.
Note: Any use of people data significantly increases oversight requirements, and agencies must ensure compliance with EO‑30, VITA’s AI standards, privacy laws, and data governance expectations.
Any AI solution developed by a Commonwealth agency must clearly demonstrate that it has permission to use every dataset involved in training, including data sourced from publicly available sources. Agencies must be able to identify and document all datasets used, explain why each dataset is appropriate, and describe how the data contributes to the operation and outputs of the AI system.
All datasets used for AI development, training, or AI solutions in general must be documented in the Commonwealth’s Enterprise Architecture tool. This documentation ensures traceability, supports transparency, and enables oversight throughout the lifecycle of the AI solution.
Before using any data to train an AI model, especially data that may include personal, sensitive, intellectual property-protected, or copyrighted information, agencies should consult their legal counsel or the Office of the Attorney General. These reviews help confirm that the agency has proper authorization, that intellectual property and licensing requirements are met, and that no prohibited data is used in model training.
In short, agencies may only use data they are explicitly permitted to use, and they must fully document, justify, and govern that data throughout the AI system’s development.
Yes.
AI‑generated code may be used, but only with strict human oversight. Any code produced by an AI tool must be thoroughly reviewed, validated, and tested before it is incorporated into an agency system.
A qualified developer must examine the AI‑generated code prior to adding it to any development branch, ensuring it meets security, quality, and architectural requirements. The resulting solution must undergo full testing, including security scans, functional verification, and performance evaluation before it is released to production.
In short, AI can assist with code generation, but people must remain fully accountable for reviewing, approving, and validating any code before deployment.
Registration Currency and Ongoing Maintenance
Registry currency means that the Commonwealth’s AI Registry must always reflect an accurate, up‑to‑date inventory of every AI system an agency uses, including newly deployed solutions, long‑standing legacy systems, embedded capabilities, and generative tools. It is a living record that mirrors the agency’s real IT portfolio at all times.
Why:
Because the AI Utilization Policy requires complete documentation of how AI is used across agencies, ensuring transparency, oversight, human validation, and ethical deployment. A current registry is fundamental to these obligations.
No.
Any existing AI system supporting mission‑essential or business‑critical functions, processing citizen/business data, or requiring cloud review must be registered, even if deployed years ago.
Why:
The approval process applies to any internal or external AI system, and the policy specifies that agencies must document where and how AI is used across their IT portfolio, with no exception for older technologies.
Updates must occur continuously, whenever an AI system is identified, modified, replaced, or newly used.
Why:
Agency governance requirements mandate that registry entries remain complete and current, and annual audits depend on accurate documentation. Continuous maintenance prevents gaps that could weaken oversight.
Limiting registration to net‑new systems leaves embedded, inherited, or legacy AI untracked. This creates blind spots in compliance, human‑oversight review, risk management, and citizen transparency.
Why:
The policy emphasizes documenting all AI use, ensuring responsible, ethical deployment regardless of when the system originated. AI responsibilities apply equally to standalone, embedded, or generative AI.
Register it promptly in the AI Registry, complete the required approvals, and update associated governance documentation.
Why:
All AI systems must go through the approval workflow and be recorded so VITA and Secretariat reviewers can evaluate fairness, human oversight, data stewardship, and risks.
Agency IT Representatives (AITRs), Information Security Officers (ISOs), designated agency governance personnel, and VITA’s Enterprise Architecture division all play shared roles in discovering, documenting, reviewing, and maintaining AI entries.
Why:
The policy assigns agencies responsibility for documenting AI use, completing approvals, and keeping registry entries current, while VITA maintains records and provides oversight.
Audits verify that registry entries are accurate, complete, and consistent with actual system usage. Findings help identify gaps and ensure governance materials are up‑to‑date.
Why:
Annual audits for high‑risk systems and ongoing agency governance reviews depend on complete registry entries, and results must be submitted to VITA and the Secretary of Administration.
Yes, but only when the system is strictly non‑production (sandbox, development, or test) and uses synthetic or publicly available data.
Why:
The approval exemption for “AI embedded in standard commercial products” does not extend to systems actively used in production. Governance requirements still mandate inventory awareness even when registration is not required.
Registry currency ensures agencies meet EO‑30’s requirement for mandatory registration and approval of each AI use, including existing ones, enabling consistent statewide oversight and ethical deployment.
Why:
EO‑30 requires transparency and comprehensive documentation of all AI, and the policy’s approval workflow operationalizes these obligations.
- Perform a full scan of systems and applications to identify embedded or legacy AI.
- Distinguish production vs. non‑production uses.
- Register all production AI systems.
- Complete Planview CTP approvals.
- Conduct periodic internal reviews and annual audits.
- Maintain documentation required under agency governance.
Why:
These actions align with policy sections on documentation, approval workflows, audits, and governance requirements.
It ensures statewide consistency, ethical use, transparency in citizen‑facing systems, and uniform compliance with the AI Utilization Policy.
Why:
The policy requires agencies to document where and how AI is used and to make governance materials available to VITA. Current registry entries support responsible, consistent statewide oversight.
Agencies do not need to submit registry approval for AI embedded in standard commercial products. However, agencies must still maintain awareness of embedded AI through inventory practices.
Why:
The approval process explicitly exempts embedded AI in standard commercial software, but inventory management of third‑party resources is still required.
A current registry helps agencies track where third‑party AI is used so they can assess vendor testing, documentation, warranties, data‑use restrictions, and security safeguards.
Why:
The policy mandates vendor vetting, testing reviews, contract requirements, and inventory management to mitigate third‑party risks.
It helps agencies identify all AI systems that process Commonwealth data, enabling compliance with the Government Data Collection and Dissemination Practices Act, data minimization, retention limits, and security metrics.
Why:
The policy requires strict privacy and data‑protection measures and annual audits of high‑risk systems, both of which depend on knowing exactly which AI systems exist.
It enables agencies to meet disclosure requirements by clearly identifying which systems generate decisions, public‑facing content, or automated outputs that impact citizens.
Why:
The policy requires public disclosure, content labeling, pre‑use notices, and transparency for external AI systems that affect citizens. Accurate registry entries support these obligations.
Yes. Agencies must know which systems use AI so they can apply the correct mandatory disclaimer language to outputs, decisions, and content.
Why:
The policy mandates specific disclaimer language and transparency rules whenever AI is used to generate or assist output. Accurate registry awareness is essential.
Up‑to‑date registry entries allow agencies and reviewers to evaluate each AI system for human validation, oversight, and explainability, preventing unmonitored “black‑box” decision‑making.
Why:
The policy prohibits unexplained decision‑logic and requires human oversight to validate outcomes and address unintended consequences.
It ensures that every AI system, including older ones, has a clearly stated purpose, public benefit, and supporting documentation (including RIA review), consistent with modern standards.
Why:
The policy requires each AI system to justify its value to citizens and document alternatives evaluated during the business‑case process.
Maintaining complete registry entries reduces coordination gaps by creating a unified, authoritative dataset of AI systems across agencies.
Why:
Agency governance requirements emphasize clear documentation, up‑to‑date tracking, and availability of records to VITA, all of which mitigate fragmentation.
A complete registry ensures agencies can meet audit requirements, demonstrate compliance with policy standards, and provide accurate governance materials to VITA and policy leadership.
Why:
Agencies must conduct annual audits of high‑risk systems, track AI usage, maintain documentation, and submit results to VITA and the Secretary of Administration, which are all dependent on registry accuracy.