Artificial Intelligence Use and Risk Management Policy

Artificial Intelligence (AI) Use and Risk Management Policy

Article 1. Policy

Artificial Intelligence (“AI”) can improve the ability of a cultural institution to achieve its mission. For this reason, Sally Ploof Hunter Memorial Library (SPHML) will not avoid the use of AI. However, it is well-established that untrustworthy AI poses risks to

individuals, institutions, governments, and society. To ensure that the Library is making the benefits of AI available while managing associated risks, the Library adopts the following policy and procedures.

Article 2. Definitions

2.1 “AI,” or an “artificial intelligence model,” is an engineered or machine-based system that can, for a given set of objectives, generate outputs such as predictions, recommendations, or decisions influencing real or virtual environments.

2.2 “Generative AI” is the class of AI that emulates the structure and characteristics of input data in order to generate derived synthetic content. This can include images, videos, audio, text, and other digital content.

2.3 “Artificial Narrow Intelligence,” or “ANI,” is AI designed to accomplish a specific problem-solving or reasoning task.

2.4 “Trustworthy” AI systems have been evaluated by the Library and determined to be: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.

2.5 An “AI tool,” as referred to in this policy, refers to a software product using an artificial intelligence model.

Article 3. Scope

This policy addresses the Library’s ethical considerations, policies, and practices with respect to AI and:

· Procurement

· Sustainability

· Operations: Board

· Operations: Executive Director

· Operations: personnel

· Accessibility

· Grants, Sponsored Programs, Donations

· Generation of institutional records

· Public Relations

· Assisting members and the public with library utilization as impacted by AI

· All other uses

Article 4. AI and Procurement

4.1 The Library purchases (either outright or via temporary licensing) goods and services that may consist of or incorporate AI.

For example, if the Library purchases a smartphone for general use, the smartphone may have AI embedded on it as a default application or function.

For another example, if the Library licenses an e-resource, the e-resource or a manner of accessing it may have an AI component.

4.2 Procurement for products that may consist of or incorporate AI shall be evaluated per current National Institute of Standards and Technology (“NIST”) standards for artificial intelligence risk management prior to finalization of a purchase or contract.

This shall include, but not be limited to, assessing if the AI meets the standard of being trustworthy [per the current standards of trustworthiness as articulated by NIST or another appropriate standard]:

· valid and reliable;

· safe;

· secure and resilient;

· accountable and transparent;

· explainable and interpretable;

· privacy enhanced; and

· fair with harmful bias managed;

4.3 To ensure such considerations are raised early in the purchasing process, all requests for information (“RFI’s”) and requests for proposals (“RFP’s”), together with sole source purchases and any other contracts for products or services involving artificial intelligence, shall be evaluated per this policy.

4.4 A copy of the evaluation, based on appropriate standards, shall accompany the RFP, RFI, purchase order, sole source justification, or other documentation submitted with the authorization for purchasing.

A sample “AI Risk Evaluation Form” is included with this policy as “A,” but it is understood that such evaluation will vary based on the technology and governing standards at the time of purchase.

Article 5. Operations: Board

5.1 With respect to all policy development and decision-making, the Board shall evaluate all strategic plans, budgets, policies and other governing documents to ensure all of the Library’s uses of AI follow this Policy.

In particular, the Board shall ensure the budget and strategic planning process do not contemplate using AI to substitute for the routine services, final judgement, or decision-making of paid employees.

Article 6. Operations: Director

6.1 With respect to day-to-day leadership and decision-making, the Executive Director shall evaluate all actions to ensure all purchases and/or decisions to use AI by the Library are preceded by an evaluation such as the one in “A.”

Article 7. Operations: Personnel

7.1 The Library depends on the skills and services of its personnel. Any Library personnel using AI to fulfill job duties or to provide services to the public in their professional capacity shall do so only using AI that meets the Library’s standards as outlined in the risk management plan, and with the affirmative awareness and consent of leadership.

For example: Employees shall not submit written reports, emails, or other content generated by AI without prior disclosure and consent of their supervisor, and the final result shall be reviewed by the employee for quality and substance.

Article 8. Accessibility

8.1 Based on specific circumstances, use of AI may be part of a “reasonable accommodation” per the Americans with Disabilities Act of 1990 (the “ADA”).

When AI is used as a reasonable accommodation, in addition to NIST guidelines, the evaluation and use of the AI for ADA purposes shall consider the latest input from the “Job Accommodation Network” or other applicable guidance.

Article 9. Grants, Sponsored Programs, Donations

9.1 All contracts and agreements for grants, sponsored programs, and donations that involve use of AI shall include the requirement that all use of AI shall follow this policy.

Article 10. Generation of institutional records

10.1 When AI is used to generate or in any way manage a Library record, such utilization shall only be performed on duly approved AI, and such utilization shall be noted in the metadata and the published presentation of the record. In addition, AI tools shall be utilized in a manner that assures institutional ownership of the copyright (requiring human authorship).

For example: if AI is used to generate the metadata accompanying an archive of letters that have been scanned, this metadata shall note the use of such AI in the generation of the metadata.

For another example, if AI is used to generate a summary of an annual report to the community, the annual report summary shall contain a note that AI was used to generate the summary.

10.2 To ensure compliance with this requirement, every year the Library shall confirm a list of AI found to be trustworthy and appropriate for generating institutional records and shall note the scope and limits of such use.

Article 11. Public Relations

11.1 It is important that the Library’s public relations be credible and trustworthy.

11.2 When AI is used to generate or in any way manage the Library’s public relations content, such utilization shall be noted in the published content and a human shall review such content before publication.

11.3 To ensure compliance with this requirement, every year, the Library shall confirm a list of AI found to be appropriate for use for public relations, or, if none is chosen, shall state, “Sally Ploof Hunter Memorial Library does not currently use AI for public relations.”

Article 12. Assisting patrons with library utilization as impacted by AI

12.1 At all times, the Library shall maintain an awareness of the latest risk management practices maintained by NIST (or other confirmed authority) and from time to time, employees shall be trained on this policy and how to assist members OR patrons whose

experience of using library services may be impacted by AI.

12.2 The Library shall review annually and confirm a list of AI products and services used by the Library. Such list shall expressly state it is not a product endorsement but rather was reviewed per appropriate criteria.

Article 13. All other uses of AI

13.1 No policy can name all possible uses of AI by SPHML.

13.2 At all times, the Library shall avoid use of a particular AI until that AI is documented by the Library as trustworthy based on the

following criteria set by NIST:

· valid and reliable

· safe

· secure and resilient

· accountable and transparent

· explainable and interpretable

· privacy enhanced, and

· fair with harmful bias managed

For example, if a patron asks an employee for help with a resume and an AI tool is available, the employee shall not use the tool until the AI is documented by the Library as being trustworthy.

For another example, if a patron asks if an AI tool is good to use, an employee can share whether the Library’s evaluation of the AI tool finds it trustworthy (bearing in mind that trustworthiness in part depends on what the AI tool is being used for).

For another example, if a patron is using an AI tool on a library computer and does not ask an employee for input or assistance, the employee shall not comment on nor limit access based on trustworthiness, unless such use is a violation of another policy (for example, a policy barring use of a particular AI tool on a library computer for security reasons).

AI Risk Evaluation Form used by Sally Ploof Hunter Memorial Library available upon request.  

Approve By the Board of Trustees on: 26 May 2026