As mandated by Governor Youngkin’s Executive Order 30 on Artificial Intelligence (AI), the Commonwealth has issued a comprehensive Artificial Intelligence (AI) Utilization Policy and an Artificial Intelligence Standard under VITA’s governance framework. These policies define how agencies must responsibly adopt, manage, and oversee AI; whether standalone, embedded, generative, or vendor-provided; across the enterprise.

Agencies are required to register all internal and external AI systems via the AI registry (currently in the Archer application), and secure approvals through the CTP Planview application, ensuring alignment with VITA, agency head, and Secretary-level governance teams. The AI Standard mandates ethical and transparent AI use, covering data protection, human oversight, fairness, and disclosure; it applies to both new and existing AI deployments.

This FAQ is designed to guide Commonwealth agencies through:

  • The AI registration and approval process, including definitions of scope and exemptions
  • Policy and technical standards that govern AI procurement, deployment, and operation
  • Risk management best practices, such as data privacy, vendor oversight, and audit readiness
  • Enterprise documentation requirements, including inventory and architecture reporting via Ardoq

For a full set of policy documents, technical standards, and AI governance resources, please see VITA's Artificial Intelligence page.

AI frequently asked questions (FAQ)

Getting Started with AI

AI Registration and Approval Requirements

Ardoq Documentation Requirements

Data Protection, Privacy, and Responsible Use

Registration Currency and Ongoing Maintenance