The Gap Between State and Territorial AI Policies and Public Health Practice
August 18, 2026 | Greg Papillion, Andrea King
A recent wave of government AI policy is sweeping across states, territories, and localities. ASTHO’s AI in Public Health Rees, and action plans covering 33 jurisdictions — from Tennessee and Idaho to Guam and Alameda County, CA — and a review of these documents shows striking agreement about how states, territories, and localities are approaching AI governance
These are jurisdiction-wide policies set by the government as a whole, not the agency-specific AI policies some health authorities maintain separately. Several states have instituted health department-specific AI policies, but those are not yet public and are not included here. Data from the 2025 ASTHO Profile of State and Territorial Public Health complements the resource library. Together, they illuminate both the terrain health agencies are navigating and the questions they will have to answer.
The Policy Landscape
Most state and territorial health agencies are not developing AI policy from scratch. Those operating under a statewide policy, or drafting their own, are typically working within a broader jurisdictional framework, informed by other states and often at least partly set by someone outside of public health. Understanding what that framework contains can help health department leaders direct their own policies
Many of the reviewed policies draw from similar reference documents: the National Institute of Standards and Technology’s AI Risk Management Framework, the since rescinded White House AI Bill of Rights, and in some cases the European Union AI Act. The result is a set of common provisions that appear across jurisdictions with some consistency
Data Protection is the Most Common Focus
Data governance, privacy, and security are addressed in 32 of the 33 reviewed jurisdictions. Tennessee’s Enterprise AI Policy prohibits entering “confidential or privileged information or communications,” personally identifiable information, and protected health information into AI tools not approved for state use. Illinois’ DoIT AI Policy goes further, requiring written authorization from the agency head before any AI system may access protected data and barring those data from becoming part of a public model or dataset in any form. Some policies — Kentucky and Kansas among them — also prohibit vendors from using government data to train proprietary models. Health agencies that handle sensitive patient and population data face this issue acutely, and the reviewed policies generally treat health-related data as among the highest-risk categories.
“Human in the Loop” Oversight is Widespread
In 24 of the 33 reviewed jurisdictions, a human must be the ultimate decision-maker when AI is used in any process with legal, financial, or rights-affecting consequences. Illinois’ DoIT policy states that “AI Systems must have a ‘human in the loop’ to ensure that all decisions are, ultimately, made by humans.” Colorado’s statewide generative AI policy specifies that “a human must be the ultimate decision-maker as part of the workflow” for benefit determinations or adverse actions. Pennsylvania’s AI policy identifies benefits eligibility, health, safety, and welfare decisions as categories subject to audit when AI is involved. In public health terms, this bears directly on AI used for disease case management, benefits eligibility, or resource allocation — areas where some agencies are beginning to experiment, even as most high-stakes applications remain in early stages.
Transparency and Disclosure Are Widely Expected
Reviewed policies generally require that AI-created content in public communications should be labeled, and citizens interacting with AI-powered services should be told so. New Jersey’s interim guidanceasks employees to “label content created with generative AI” and specify the model, prompts, and methods used. New York City’s preliminary guidance recommends that agencies “always label AI-Generated Content as such, even if it has been edited by personnel.” Idaho’s AI Governance Policy goes further, providing specific required disclaimer language for public-facing AI outputs. Even so, transparency and explainability requirements are not yet universal across the reviewed policies.
Procurement Controls Extend to Free Tools
The 23 jurisdictions that address procurement add AI-specific vendor requirements, including disclosure of training data sources, known limitations, or bias testing results. A smaller number close a related loophole: in six of the 33 reviewed jurisdictions, procurement or governance rules extend the same review requirements to free or personal-account AI use. Iowa’s Enterprise Generative AI Policy prohibits agencies and staff from using freely available AI tools without prior written approval. Idaho’s governance policy similarly states that “all AI systems (including pilots or free tools) must be reviewed and approved.” This approach raises an important consideration for agencies using consumer generative AI tools without going through a formal review process.
Commonly Prohibited Uses
Across multiple policies, certain AI applications are off-limits. San José’s AI Policy, Washington County, Oregon’s AI Acceptable Use Policy, and Maryland’s Responsible AI Policy all explicitly prohibit real-time and covert biometric identification, emotion analysis, social scoring, fully automated consequential decisions without meaningful human oversight, and cognitive behavioral manipulation. Idaho’s governance policy prohibits fully autonomous decision-making affecting individual rights, benefits, or services. Health agencies considering any AI application that touches on identity, monitoring, or automated decision-making should be aware that these may already be prohibited under statewide policy.
What the Reviewed Policies Leave Unaddressed
The reviewed policies are primarily IT governance documents. They establish rules for data handling, procurement, vendor contracts, and prohibited uses. They do not typically address what AI tools are appropriate for disease surveillance, how to evaluate an AI-assisted outbreak detection system, or how to train an epidemiologist to use AI responsibly in case investigation. That public-health-specific guidance is largely absent from the reviewed policies, leaving a gap in which health agencies develop their own standards.
Two factors compound this gap. First, training: mandatory AI training appears in just nine of the 33 reviewed jurisdictions — California’s GenAI guidelines requires it of only executives and procurement staff, while Idaho’s AI Governance Policy requires tiered training for executives, designated agency officials, general users, and technical staff. A gap between statewide and agency-level policies may mean that health department staff are subject to training mandates they aren’t fully aware of.
Second, data access: nearly every policy that addresses data classification draws a hard line between what consumer tools and enterprise environments may process. Minnesota’s Public AI Services Security Standard limits publicly available AI services to data classified as “Low,” meaning information already intended for public release. Nebraska’s AI policy prohibits using public AI tools with High or Moderate Impact data, or any data containing personal elements. Under most policies, agencies using consumer tools are authorized to use only information already in the public domain — a significant constraint for work involving exactly the sensitive data those policies restrict.
Tradeoffs the Policies Surface but May Not Resolve
One tension runs through the policy landscape: formal governance versus informal AI use
Strict approval processes and vendor review requirements serve real purposes, including protecting sensitive data, preventing discriminatory outputs, and ensuring accountability. But the more cumbersome the official pathway, the more pressure there may be for staff to use personal accounts, free consumer tools, or workarounds that fall outside any governance structure and capacity of an agency to monitor use. Iowa and Idaho address this directly by prohibiting the use of personal accounts or free tools to conduct government business with AI. But prohibition alone does not resolve the underlying pressure that drives informal use, particularly amid ongoing workforce skills gaps and limited public-health-specific AI guidance.
The bias and equity gap also warrants honest assessment. Oregon’s AI Advisory Council Action Plan calls for formal equity impact assessments, standardized templates for consent and opt-out processes, and periodic equity audits. Connecticut’s Responsible AI Policy Framework requires an impact assessment before implementing any system to guard against unlawful discrimination. But these are outliers. Most reviewed policies acknowledge bias risk without specifying how to measure it, which demographic groups must be included in fairness testing, or what constitutes an acceptable result. For health agencies serving populations that have historically faced discrimination in health care delivery and data collection, that gap is not abstract.
Closing the Gaps Together
No single agency should have to close these gaps alone. Figuring out how to evaluate an AI-assisted outbreak detection system, determining which populations belong in a bias audit, or building approval pathways that protect data without pushing staff toward workarounds — these are hard questions, but they are not unique questions. Nearly every health department is facing them at once, and the work of answering them can be shared and facilitated through professional organizations and cross-jurisdictional networks. ASTHO’s AI in Public Health topic page, AI in Public Health Resource Library, technical assistance, and the Informatics and Data Modernization Network, along with efforts like the PubHealthAI Collaborative Network, give agencies spaces to compare notes, learn from each other’s pilots and mistakes, and turn broad IT-governance rules into guidance that actually fits public health work. Statewide AI policy is moving faster than public health agencies can keep up. Until that changes, agencies will get further by solving these problems together than separately.
Reviewed by Tabatha Offutt-Powell, Vice President, Public Health Data Modernization and Informatics; Rachel Joseph, Vice President, Strategic Business Development; and Lindsey Myers, Vice President, Public Health Workforce and Infrastructure


