AI Policy

What you need to know

What we’ll cover:

  • What AI is
  • Examples of AI in your life
  • How AI works (conceptually)
  • ETDD’s Policy (what and why)
  • Examples of how to put this information into action

Goals for this Presentation

  • Understand at a basic level what AI is
  • Understand that there are different kinds of AI models
  • Understand different AI models are appropriate for different tasks
  • Be able to apply this information to using AI or writing an AI policy
  • Understand how ETDD’s policy addresses potential issues and be able to adapt for your organization
  • Have a basis for further learning

What Is AI?

How would you define AI?

“AI is whatever hasn’t been done yet.” — Tesler’s Theorem1

Defining AI

  • How do you define “Intelligence”?
  • Academic definitions differ and are not always helpful for practical use
AI Definition Overview2
Human-based Ideal Rationality
Reasoning-based Systems that think like humans Systems that think rationally
Behavior-based Systems that act like humans Systems that act rationally

Defining AI

AI is “an engineered or machine-based system that can, for a given set of objectives, generate outputs such as predictions, recommendations, or decisions influencing real or virtual environments. AI systems are designed to operate with varying levels of autonomy”3

Defining AI

Questions to help determine if it’s AI:

  • Does the technology use data to provide predictions, recommendations, insights, or decisions?
  • Does the technology augment or replace human decision-making?
  • Does the company use words such as “personalized”, “tailored”, and “adaptive” in its marketing?
  • Would it be difficult or impossible to write out how a program does what it does, either because the process is opaque or because it is mathematically complex? 4

Examples of AI

What are some examples of AI you interact with on a regular basis?

Optical Character Recognition

Video Games5

Spam Filters6

How AI Works Conceptually

  • Understanding the different kinds can help you know when and how to use AI

G AI AI Logistic Logistic AI->Logistic NonLogistic NonLogistic AI->NonLogistic Probabilistic Probabilistic NonLogistic->Probabilistic Neurocomputational Neurocomputational NonLogistic->Neurocomputational

Lets say you need an AI to help organize some recipes:

Logicist AI

Probabilistic AI

Neurocomputational AI

Real Life Examples of Each Kind of AI

Logicist

Probabilistic

Neurocomputational

Optical Character Recognition

Video Games7

Spam Filters8

AI Model Type Overview
Logicist Probabilistic Neurocomputational
good for: clearly defined logic clear factors No clear process
bad at: handling uncertainty operating with limited /bad data or assumptions Truth; Explainability
example: email inbox rules (some) population forecasting chatGPT

Quick Clarifications

  • AI is not just Large Language Models9
  • AI is not new10
  • It is still valuable to learn new skills

Quick Advice for Using AI

  • Don’t use AI search results without verifying them
  • If you use chat bots:
    • Give them context in your prompt
    • Try different prompting strategies (e.g. say “you are an X”, be nice)
  • Don’t forget the sunk cost fallacy11
  • Sometimes older methods are better

Think about any potential questions:

  1. Any questions you have about AI
  2. Why an AI Policy is important
  3. Anything specific you’re not sure how to handle

Why an AI policy is imporant

  • More people want to use AI
  • Many people don’t know how to responsibly use AI
  • Some AI is cutting edge technology treated as traditional software
  • Rapid changes in legal and technical realms
  • A well-written policy can save you time and headaches later

ETDD’s Policy Outline

  • Introduction
  • Guiding Principles
  • Roles And Responsibilities
  • Definitions
  • General Information (and special notes)
  • Processes to review AI requests, sunset tools
  • Enforcement

Rapid Changes

Policy Considerations

  • Legal12
  • Technical
    • Unique hacking vectors13
    • Coding14
  • Consumer-Facing

Rapid Changes

ETDD’s Policy

  • Guiding Principles
  • Focus on flexible processes and risk assessments
  • Specific as needed (e.g. AI Note takers, generating code)
  • Separate Generative AI Policy
  • Updating regularly

Lack of Accessible Information

Policy Considerations

  • Most information is very polarized
  • Most tools don’t tell you how they work15
  • Difficult to know if something will do what it says
  • Difficult to know if something has unstated risks
  • Lots of start ups

Lack of Accessible Information

ETDD’s Policy

  • Guiding Principles help indicate how and why
  • AI Training is required
  • AI Request process
  • Risk Assessments
  • Transparency

Public Opinion

Policy Considerations

  • Public opinion divided16
  • Difficult to know potential consequences on relationships
  • Plagiarism17

Public Opinion

ETDD’s Policy

  • Proactively disclose our use of generative AI
  • Cite usage as appropriate
  • Avoid certain high-risk use cases
  • Most Risk Assessments consider this

Privacy and Data Concerns

Policy Considerations

  • AI Note Takers18
  • Data leaks
  • Sensitive Information leaks19
  • FOIA

Privacy and Data Concerns

ETDD’s Policy

  • Don’t put information not ready for public in generative AI
  • Always ask for consent before using an AI Note Taker

Lack of Resources Tailored for Development Districts

Policy Considerations

  • Difficult to find relevant trainings
  • Difficult to find resources on AI policies
    • Most is aimed at people who are developing AI
  • Time sink

Lack of Resources Tailored for Development Districts

ETDD’s Policy

  • Hire a nerd
    • (Who will include helpful resources at the end of this presentation)

Putting Guiding Principles into Policy

Policy Considerations

  • Translating Guiding Principles into policy is hard

Putting Guiding Principles into Policy

ETDD’s Policy

Example using Effectiveness:

  • AI is a tool not the tool
    • No data analysis with generative AI
  • Automation Bias20
  • Resource Use21

Practical Advice for Policies

  • Be prepared for technical issues
  • Adapt for your organization
  • Consider how this might fit with other policies
  • AI is not always traditional software
  • Try to provide alternatives

Putting It In Action / Hypotheticals

Let’s say you want to create an AI policy, and you just want to have the bare minimum to prevent likely issues. What do you think some of the content you would want in the policy would be? What would be the pros and cons of doing it this way?

Potential Content:

  • What AI can be used for
  • How tools are approved
  • How (or if) you will cite your usage of AI
  • How you will handle certain high-risk use cases
  • Other content?

Let’s say you want to create an AI policy, and you just want to have the bare minimum to prevent likely issues. What do you think some of the content you would want in the policy would be? What would be the pros and cons of doing it this way?

Pros:

  • Might be easier to write and follow
  • Allow for staff more freedom to choose how/if to use AI
  • Clearer instructions
  • Might need to be updated less frequently
  • Other pros?

Let’s say you want to create an AI policy, and you just want to have the bare minimum to prevent likely issues. What do you think some of the content you would want in the policy would be? What would be the pros and cons of doing it this way?

Cons:

  • Might not cover everything you need
  • Might need to be updated more frequently
  • Might not provide enough guidance
  • Might increase the risk of misuse of AI
  • Other cons?

Let’s say you wrote in your AI policy that you only had to approve each tool once, and then it was fine to use for everyone. What are some potential risks with this approach?

  • Approving tools for inappropriate use cases
  • Not approving specialized tools
  • Inaccurately assessing risks of a tool
  • Scrambling if there is a change in a tool
  • Other risks?

Let’s say a grant writer uses generative AI like Copilot to write a grant. How might they decide to use it?

Let’s say the grant was not funded, and the community is upset. If you had an AI policy that outlined how you used AI, how could that protect you? If you did not have an AI policy, what might you be vulnerable to?

They might use it by:

  • Editing their work
  • Asking it for statistics
  • Creating a sample of the grant
  • Creating an outline
  • Create the grant and not edit it
  • Other potential uses?

Let’s say a grant writer uses generative AI like Copilot to write a grant. How might they decide to use it?

Let’s say the grant was not funded, and the community is upset. If you had an AI policy that outlined how you used AI, how could that protect you? If you did not have an AI policy, what might you be vulnerable to?

A policy could protect you by:

  • Ensuring applications maintain a certain level of staff involvement
  • Preventing the use of statistics from unreliable sources
  • Helping staff use AI effectively and ethically
  • Other potential ways it could protect you?

Let’s say a grant writer uses generative AI like Copilot to write a grant. How might they decide to use it?

Let’s say the grant was not funded, and the community is upset. If you had an AI policy that outlined how you used AI, how could that protect you? If you did not have an AI policy, what might you be vulnerable to?

Not having a policy could make you more vulnerable to:

  • Using AI inappropriately
  • Accusations of using AI in ways that might be unethical or illegal
  • Relationship issues
  • Other potential ways it could make you vulnerable?

Resources (Policy)

Resources (Learning more)

Introductory:

Advanced but Accessible:

In Depth:

Resources (ETDD’s Policy)

Questions?

Thank you

References

2025. https://news.bloomberglaw.com/litigation/wiretap-suits-pit-old-privacy-laws-against-new-ai-technology.
n.d. https://commons.wikimedia.org/wiki/File:Email-spam-sample_(cropped).png.
n.d. https://www.microsoft.com/en-us/ai/ai-101/generative-ai-vs-other-types-of-ai.
n.d. https://owasp.org/www-project-top-10-for-large-language-model-applications/.
n.d. https://owasp.org/www-project-citizen-development-top10-security-risks/content/2022/en/CD-SEC-01-Blind-Trust.html.
n.d. https://crfm.stanford.edu/fmti/December-2025/index.html.
n.d. https://natlawreview.com/article/2026-outlook-artificial-intelligence.
n.d. https://teachingcommons.stanford.edu/teaching-guides/artificial-intelligence-teaching-guide/understanding-ai-literacy.
n.d. https://www.3blue1brown.com/3blue1brown.com.
In Center for Security and Emerging Technology. n.d. https://cset.georgetown.edu/publication/cybersecurity-risks-of-ai-generated-code/.
In Computerworld. n.d. https://www.computerworld.com/article/4041849/enterprise-note-taking-apps-face-legal-scrutiny-as-otter-hit-with-privacy-suit.html.
In Crash Course. n.d. https://thecrashcourse.com/topic/ai/.
In Google Workspace Blog. n.d. https://workspace.google.com/blog/productivity-collaboration/everyday-ai-beyond-spell-check-how-google-docs-is-smart-enough-to-correct-grammar,.
In Investopedia. n.d. https://www.investopedia.com/terms/s/sunkcost.asp.
In MIT News | Massachusetts Institute of Technology. 2025. https://news.mit.edu/2025/explained-generative-ai-environmental-impact-0117.
In MIT Schwarzman College of Computing. n.d. https://computing.mit.edu/research/ai-policy-briefs/.
In Mozilla Foundation. n.d. https://www.mozillafoundation.org/en/research/library/ai-transparency-in-practice/ai-transparency-in-practice/.
In NVIDIA Technical Blog. 2025. https://developer.nvidia.com/blog/how-code-execution-drives-key-risks-in-agentic-ai-systems/.
In Proton. 2025. https://proton.me/blog/llm.
In TensorFlow. n.d. https://www.tensorflow.org/resources/learn-ml.
Brenndoerfer, Michael. Backpropagation - Training Deep Neural Networks. 2025. https://mbrenndoerfer.com/writing/history-backpropagation-deep-learning-training.
Bringsjord, Selmer, and Naveen Sundar Govindarajulu. Artificial Intelligence.” In The Stanford Encyclopedia of Philosophy, Spring 2025, edited by Edward N. Zalta and Uri Nodelman. Https://plato.stanford.edu/archives/spr2025/entries/artificial-intelligence/; Metaphysics Research Lab, Stanford University, 2025.
Chan, Cecilia Ka Yuk. “Students’ Perceptions of ‘AI-Giarism’: Investigating Changes in Understandings of Academic Misconduct.” Education and Information Technologies 30, no. 6 (2025): 8087–108. https://doi.org/10.1007/s10639-024-13151-7.
Chugani, Vinod. “AI Winter: Understanding the Cycles of AI Development.” In Data Camp. 2025. https://www.datacamp.com/blog/ai-winter.
Gabrielsson, Rickard Brüel. MIT FUTURE OF AI. n.d. https://www.futureofai.mit.edu/.
“Initiatives.” In OWASP Gen AI Security Project. n.d. https://genai.owasp.org/initiatives/.
Namco. English: Pac-Man Approaching a Row of Three Dots. 2024. https://commons.wikimedia.org/wiki/File:Pac-Man_eating_dots.svg.
Pasquini, Brian Kennedy, Colleen McClain, and Giancarlo. “How the u.s. Public and AI Experts View Artificial Intelligence.” In Pew Research Center. 2025. https://www.pewresearch.org/internet/2025/04/03/how-the-us-public-and-ai-experts-view-artificial-intelligence/.
Programmers at Work: Interviews Wit 19 Programmers Who Shaped the Computer Industry. Repr. with new additions. Microsoft Pr, 1989.
published, Craig Hale. “Microsoft Admits an Office Bug Exposed Confidential User Emails to Copilot.” In TechRadar. 2026. https://www.techradar.com/pro/security/microsoft-admits-an-office-bug-exposed-confidential-user-emails-to-copilot.
Romeo, Giuseppe, and Daniela Conti. “Exploring Automation Bias in Human–AI Collaboration: A Review and Implications for Explainable AI.” AI & SOCIETY 41, no. 1 (2026): 259–78. https://doi.org/10.1007/s00146-025-02422-7.
Rudko, Ihor, and Aysan Bashirpour Bonab. “ChatGPT Is Incredible (at Being Average).” Ethics and Information Technology 27, no. 3 (2025): 36. https://doi.org/10.1007/s10676-025-09845-2.
Russell, Stuart J., and Peter Norvig. Artificial Intelligence: A Modern Approach. Fourth edition, global edition. Prentice Hall Series in Artificial Intelligence. Pearson, 2022.
San José’s Information Technology Department: Digital Privacy Office, City of. AI Handbook. 2024. https://www.sanjoseca.gov/home/showpublisheddocument/109904/638463850657330000.
Tabassi, Elham. Artificial Intelligence Risk Management Framework (AI RMF 1.0). National Institute of Standards; Technology (U.S.), 2023. https://doi.org/10.6028/NIST.AI.100-1.
team, CLRN. “Is Spell Check AI?” In California Learning Resource Network. 2025. https://www.clrn.org/is-spell-check-ai/.
“Tesler’s Theorem and Other Adages and Coinages.” In Larry Tesler. n.d. https://www.nomodes.com/larry-tesler-consulting/adages-and-coinages.

Footnotes

  1. According to Tesler, he originally said “Intelligence is whatever machines haven’t done yet”, however Tesler’s Theorem is more well known (source: “Tesler’s Theorem and Other Adages and Coinages,” in Larry Tesler, n.d., https://www.nomodes.com/larry-tesler-consulting/adages-and-coinages.)

  2. Selmer Bringsjord and Naveen Sundar Govindarajulu Artificial Intelligence,” in The Stanford Encyclopedia of Philosophy, Spring 2025, ed. Edward N. Zalta and Uri Nodelman (https://plato.stanford.edu/archives/spr2025/entries/artificial-intelligence/; Metaphysics Research Lab, Stanford University, 2025).

  3. Elham Tabassi Artificial Intelligence Risk Management Framework (AI RMF 1.0) (National Institute of Standards; Technology (U.S.), 2023), NIST AI 100–1, https://doi.org/10.6028/NIST.AI.100-1.

  4. City of San José’s Information Technology Department: Digital Privacy Office AI Handbook (2024), https://www.sanjoseca.gov/home/showpublisheddocument/109904/638463850657330000.

  5. Programmers at Work: Interviews Wit 19 Programmers Who Shaped the Computer Industry, Repr. with new additions (Microsoft Pr, 1989)., see page 266. Image from: Namco English: Pac-Man Approaching a Row of Three Dots. (2024), https://commons.wikimedia.org/wiki/File:Pac-Man_eating_dots.svg.

  6. Image from: n.d., https://commons.wikimedia.org/wiki/File:Email-spam-sample_(cropped).png.

  7. Namco English.

  8. Image from:

  9. n.d., https://www.microsoft.com/en-us/ai/ai-101/generative-ai-vs-other-types-of-ai.

  10. Vinod Chugani “AI Winter: Understanding the Cycles of AI Development,” in Data Camp, 2025, https://www.datacamp.com/blog/ai-winter.

  11. in Investopedia, n.d., https://www.investopedia.com/terms/s/sunkcost.asp.

  12. in Computerworld, n.d., https://www.computerworld.com/article/4041849/enterprise-note-taking-apps-face-legal-scrutiny-as-otter-hit-with-privacy-suit.html., 2025, https://news.bloomberglaw.com/litigation/wiretap-suits-pit-old-privacy-laws-against-new-ai-technology.

  13. n.d., https://owasp.org/www-project-top-10-for-large-language-model-applications/.

  14. n.d., https://owasp.org/www-project-citizen-development-top10-security-risks/content/2022/en/CD-SEC-01-Blind-Trust.html.; in NVIDIA Technical Blog, 2025, https://developer.nvidia.com/blog/how-code-execution-drives-key-risks-in-agentic-ai-systems/.

  15. CLRN team “Is Spell Check AI?” in California Learning Resource Network, 2025, https://www.clrn.org/is-spell-check-ai/.; in Google Workspace Blog, n.d., https://workspace.google.com/blog/productivity-collaboration/everyday-ai-beyond-spell-check-how-google-docs-is-smart-enough-to-correct-grammar,.; in Mozilla Foundation, n.d., https://www.mozillafoundation.org/en/research/library/ai-transparency-in-practice/ai-transparency-in-practice/.; n.d., https://crfm.stanford.edu/fmti/December-2025/index.html.;

  16. Brian Kennedy Pasquini Colleen McClain and Giancarlo “How the u.s. Public and AI Experts View Artificial Intelligence,” in Pew Research Center, 2025, https://www.pewresearch.org/internet/2025/04/03/how-the-us-public-and-ai-experts-view-artificial-intelligence/.

  17. Most of the studies right now are focused on academia, but we can extrapolate from these studies that what is or is not plagiarism with regards to AI is not settled. Here is one study Cecilia Ka Yuk Chan “Students’ Perceptions of ‘AI-Giarism’: Investigating Changes in Understandings of Academic Misconduct,” Education and Information Technologies 30, no. 6 (2025): 8087–108, https://doi.org/10.1007/s10639-024-13151-7.

  18. Craig Hale published “Microsoft Admits an Office Bug Exposed Confidential User Emails to Copilot,” in TechRadar, 2026, https://www.techradar.com/pro/security/microsoft-admits-an-office-bug-exposed-confidential-user-emails-to-copilot.

  19. Giuseppe Romeo and Daniela Conti “Exploring Automation Bias in Human–AI Collaboration: A Review and Implications for Explainable AI,” AI & SOCIETY 41, no. 1 (2026): 259–78, https://doi.org/10.1007/s00146-025-02422-7.

  20. in MIT News | Massachusetts Institute of Technology, 2025, https://news.mit.edu/2025/explained-generative-ai-environmental-impact-0117.

  21. Their website is https://www.sanjoseca.gov/your-government/departments-offices/information-technology/ai-reviews-algorithm-register/govai-coalition

  22. https://www.tn.gov/finance/ai-council.html; https://www.tn.gov/content/dam/tn/finance/aicouncil/documents/STS%20Roadmap%20for%20AI.pdf

  23. Stuart J. Russell and Peter Norvig Artificial Intelligence: A Modern Approach, Fourth edition, global edition, Prentice Hall Series in Artificial Intelligence (Pearson, 2022).