Article 1. Policy
Artificial Intelligence (“AI”) can improve the ability of a cultural institution to achieve its mission. For this reason, Ogdensburg Public Library will not avoid the use of AI. However, it is well-established that untrustworthy AI poses risks to individuals, institutions, governments, and society. To ensure that the Library is making the benefits of AI available while managing associated risks, the Library adopts the following policy and procedures.
Article 2. Definitions
“AI,” or an “artificial intelligence model,” is an engineered or machine-based system that can, for a given set of objectives, generate outputs such as predictions, recommendations, or decisions influencing real or virtual environments.
“Generative AI” is the class of AI that emulates the structure and characteristics of input data in order to generate derived synthetic content. This can include images, videos, audio, text, and other digital content.
“Artificial Narrow Intelligence,” or “ANI,” is AI designed to accomplish a specific problem-solving or reasoning task.
“Trustworthy” AI systems have been evaluated by the Library and determined to be: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.
An “AI tool,” as referred to in this policy, refers to a software product using an artificial intelligence model.
Article 3. Scope
This policy addresses the Library’s ethical considerations, policies, and practices with respect to AI and:
- Procurement
- Sustainability
- Operations: Board
- Operations: Executive Director
- Operations: personnel
- Accessibility
- Grants, Sponsored Programs, Donations
- Generation of institutional records
- Public Relations
- Assisting members and the public with library utilization as impacted by AI
- All other uses
Article 4. AI and Procurement
The Library purchases (either outright or via temporary licensing) goods and services that may consist of or incorporate AI.
For example, if the Library purchases a smartphone for general use, the smartphone may have AI embedded on it as a default application or function.
For another example, if the Library licenses an e-resource, the e-resource or a manner of accessing it may have an AI component.
Procurement for products that may consist of or incorporate AI shall be evaluated per current National Institute of Standards and Technology (“NIST”) standards for artificial intelligence risk management prior to finalization of a purchase or contract.
This shall include, but not be limited to, assessing if the AI meets the standard of being trustworthy [per the current standards of trustworthiness as articulated by NIST or another appropriate standard]:
- valid and reliable;
- safe;
- secure and resilient;
- accountable and transparent;
- explainable and interpretable;
- privacy enhanced; and
fair with harmful bias managed;
To ensure such considerations are raised early in the purchasing process, all requests for information (“RFI’s”) and requests for proposals (“RFP’s”), together with sole source purchases and any other contracts for products or services involving artificial intelligence, shall be evaluated per this policy.
A copy of the evaluation, based on appropriate standards, shall accompany the RFP, RFI, purchase order, sole source justification, or other documentation submitted with the authorization for purchasing.
A sample “AI Risk Evaluation Form” is included with this policy as “A,” but it is understood that such evaluation will vary based on the technology and governing standards at the time of purchase.
A copy of this policy shall be annexed to the procurement policy to ensure compliance.
Article 5. Operations: Board
With respect to all policy development and decision-making, the Board shall evaluate all strategic plans, budgets, policies and other governing documents to ensure all of the Library’s uses of AI follow this Policy.
In particular, the Board shall ensure the budget and strategic planning process do not contemplate using AI to substitute for the routine services, final judgement, or decision-making of paid employees.
Article 6. Operations: Executive Director
With respect to day-to-day leadership and decision-making, the Executive Director shall evaluate all actions to ensure all purchases and/or decisions to use AI by the Library are preceded by an evaluation such as the one in “A.”
Article 7. Operations: Personnel
The Library depends on the skills and services of its personnel. Any Library personnel using AI to fulfill job duties or to provide services to the public in their professional capacity shall do so only using AI that meets the Library’s standards as outlined in the risk management plan, and with the affirmative awareness and consent of leadership.
For example: Employees shall not submit written reports, emails, or other content generated by AI without prior disclosure and consent of their supervisor, and the final result shall be reviewed by the employee for quality and substance.
Article 8. Accessibility
Based on specific circumstances, use of AI may be part of a “reasonable accommodation” per the Americans with Disabilities Act of 1990 (the “ADA”).
When AI is used as a reasonable accommodation, in addition to NIST guidelines, the evaluation and use of the AI for ADA purposes shall consider the latest input from the “Job Accommodation Network” or other applicable guidance.
Article 9. Grants, Sponsored Programs, Donations
All contracts and agreements for grants, sponsored programs, and donations that involve use of AI shall include the requirement that all use of AI shall follow this policy.
Article 10. Generation of institutional records
When AI is used to generate or in any way manage a Library record, such utilization shall only be performed on duly approved AI, and such utilization shall be noted in the metadata and the published presentation of the record. In addition, AI tools shall be utilized in a manner that assures institutional ownership of the copyright (requiring human authorship).
For example: if AI is used to generate the metadata accompanying an archive of letters that have been scanned, this metadata shall note the use of such AI in the generation of the metadata.
For another example, if AI is used to generate a summary of an annual report to the community, the annual report summary shall contain a note that AI was used to generate the summary.
To ensure compliance with this requirement, every year the Library shall confirm a list of AI found to be trustworthy and appropriate for generating institutional records and shall note the scope and limits of such use.
Article 11. Public Relations
It is important that the Library’s public relations be credible and trustworthy.
When AI is used to generate or in any way manage the Library’s public relations content, such utilization shall be noted in the published content and a human shall review such content before publication.
To ensure compliance with this requirement, every year, the Library shall confirm a list of AI found to be appropriate for use for public relations, or, if none is chosen, shall state, “Ogdensburg Public Library does not currently use AI for public relations.”
Article 12. Assisting patrons with library utilization as impacted by AI
At all times, the Library shall maintain an awareness of the latest risk management practices maintained by NIST (or other confirmed authority) and from time to time, employees shall be trained on this policy and how to assist members OR patrons whose experience of using library services may be impacted by AI.
The Library shall review annually and confirm a list of AI products and services used by the Library. Such list shall expressly state it is not a product endorsement but rather was reviewed per appropriate criteria.
Article 13. All other uses of AI
No policy can name all possible uses of AI by Ogdensburg Public Library.
At all times, the Library shall avoid use of a particular AI until that AI is documented by the Library as trustworthy based on the following criteria set by NIST:
- valid and reliable
- safe
- secure and resilient
- accountable and transparent
- explainable and interpretable
- privacy enhanced, and
- fair with harmful bias managed
For example, if a patron asks an employee for help with a resume and an AI tool is available, the employee shall not use the tool until the AI is documented by the Library as being trustworthy.
For another example, if a patron asks if an AI tool is good to use, an employee can share whether the Library’s evaluation of the AI tool finds it trustworthy (bearing in mind that trustworthiness in part depends on what the AI tool is being used for).
For another example, if a patron is using an AI tool on a library computer and does not ask an employee for input or assistance, the employee shall not comment on nor limit access based on trustworthiness, unless such use is a violation of another policy (for example, a policy barring use of a particular AI tool on a library computer for security reasons).
Approve By the Board of Trustees on: February 4, 2026
Ogdensburg Public Library
AI Risk Evaluation Form
I. Preliminary Information Date of evaluation: ___________
| Product to be evaluated: | |
| How product uses or incorporates AI: | |
| How product will be used: | |
| Anticipated users of product: | |
| Any NIST, ALA, or other prevailing standards for evaluating this AI? | If yes, attach standards. |
| Ethics & Privacy: will the product have access to library user information? | |
| Dependency: To what degree will critical operations depend on this AI? | |
| For institutions with sustainability targets: Does the vendor track and report its energy use? Is the energy use reported consistent with your library’s policy with respect to sustainability? | |
| Person preparing evaluation: |
II. AI Risk Analysis
| TRUSTWORTHINESS FACTORS | ANSWER |
| 1. Is the AI “valid and reliable?” Is there objective evidence that the requirements for the specific use have been met? Please attach. Is there a documented third-party confirmation that the product will perform as required without failure? Please attach. | |
| 2. Is the AI “safe?” What are the risks posed by the AI failing to work as intended? Does the AI allow for shutdown, immediate notice, override, or other safety measures to reduce harm? | |
| 3. Is the AI “secure and resilient?? How does the AI prevent unauthorized access and use? How does the AI empower the user to address unauthorized access and use? | |
| 4. Is the AI “accountable and transparent?” Transparency reflects the extent to which information about the AI and its outputs is available to individuals interacting with the AI. Transparency is often needed to redress AI system outputs that are incorrect or otherwise risky (allowing it to be “accountable”). How does this AI use transparency to enable the user to promptly address a concern? | |
| 5. Is the AI “explainable and interpretable?” “Explainability” is being able to articulate how the AI works, and “interpretability” refers to meaningful understanding of the AI’s output. Will the primary users at the INSTITUTION/LIBRARY NAME be able to explain how the AI works and accurately interpret the output? | |
| 6. Is the AI “privacy-enhanced?” Privacy is a key library value. “Privacy-enhanced” means that use of the AI will proactively protect privacy. How will the AI use privacy-enhancing techniques (anonymity, confidentiality, data sparsity, etc.) to proactively protect privacy? | |
| 7. Is the AI “fair, with harmful bias managed?” How will this AI impact the experience of library users, employees, or work that will drive resources and business decisions (for instance, generating a summary of utilization)? Considering that impact, how is the risk of bias managed by the product and/or the operator? In the alternative, show how this is a neutral/irrelevant factor. | |
| 8. Miscellaneous What other risks posed by this AI have been identified, and how are they to be managed? | |
| 9. Benefits If this analysis shows heightened risk related to a factor, what beneficial functions of the AI merit the Ogdensburg Public Library taking on that heightened risk? | |
| Overall trustworthiness Please review the answers and summarize whether the documentation and analysis show that risks of using the product are minimal or can be managed. | |
| Decision and limits of use On this basis, is the product recommended for purchase? What use is it limited to? |
III. Determination by decision-maker
| Does the above analysis show that the AI has been documented as sufficiently trustworthy for the purpose it is being acquired to fulfill? | |
| Has this analysis been submitted prior to the purchasing decision? | |
| Does the trustworthiness documented support moving forward with the purchase? | |
| If the purchase is denied due to this analysis, what aspects must be addressed prior to reconsideration? | |
| Date and signature of decision-maker | DATE: SIGNATURE: PRINT NAME: |
THIS COMPLETED FORM WILL BE RETAINED FOR SIX YEARS AFTER THE EXPIRATION OF THE CONTRACT OR DISCONTINUANCE OF USE OF THE AI, WHICHEVER IS LATER.