⚡ Quick Summary
Published by the Virginia Joint Commission on Technology and Science (JCOTS), this report analyses the use of artificial intelligence by public bodies in the Commonwealth of Virginia and explores potential regulatory frameworks. It fulfils the expectation set out in SB 487, which directed JCOTS to report findings and recommendations to specified House and Senate committees by 1 December 2024 and to assess the creation of a Commission on Artificial Intelligence.
The report opens with an overview of AI, covering supervised and unsupervised machine learning, deep learning and neural networks, generative AI as probabilistic next-word prediction, the "black box" problem, and applications from healthcare and disability support to hiring, surveillance and creative work. It then summarises AI policymaking: the White House Blueprint for an AI Bill of Rights, the NIST AI Risk Management Framework with its trustworthiness characteristics and Govern, Map, Measure and Manage functions, Executive Order 14110, the OMB policy memorandum, and congressional bills. Enacted laws in Colorado, Maryland, Utah and Vermont's task force report follow as comparators.
Virginia's position is reviewed through VITA's six-standard AI Utilization Policy, the AI Enterprise Solutions Architecture, Executive Order 30, the Virginia Consumer Data Protection Act, and bills referred to JCOTS in 2024. The report concludes with four legislative recommendations and an appendix of AI definitions.
🧩 What’s Covered
- Overview of artificial intelligence: defines AI broadly, explains supervised machine learning with a cat-and-dog training example, unsupervised machine learning and feature weighting, deep learning and neural networks, and generative AI, and lists applications in healthcare, disability support, education, hiring, insurance, surveillance and creative fields.
- AI policymaking: sets out the regulatory problem of no comprehensive federal legislation, then summarises the White House Blueprint for an AI Bill of Rights' five principles, the NIST AI Risk Management Framework (risk measurement, tolerance and prioritisation; trustworthiness characteristics; four core functions), Executive Order 14110's eight priorities, the 2024 OMB policy memorandum's governance, innovation and risk-management practices, and pending congressional bills.
- Other states' AI policy: covers Colorado SB24-205 with developer and deployer duties, consequential decisions and high-risk AI; Maryland SB541, the Online Data Privacy Act; Maryland SB818, the AI Governance Act, with inventories of high-risk AI and the AI Subcabinet; Maryland Executive Order 01.01.2024.02; Utah SB149, including the Office of AI Policy and AI Learning Laboratory Program; and Vermont's AI Task Force final report.
- Virginia AI policy: presents VITA's definition of AI and its six standards, the AI Enterprise Solutions Architecture, Executive Order 30, the Virginia Consumer Data Protection Act, bills referred to JCOTS (SB164, HB249, HB251, SB487, HB697 and SB571, HB747), and law enforcement AI use.
- Future of AI policy in Virginia: describes a patchwork of state regulation and lists considerations including data privacy, civil rights, deepfakes, intellectual property and environmental effects.
- Legislative recommendations: four options - codifying VITA's AI Utilization Policy, establishing an advisory committee, regulating AI use by private and public entities through a risk-based approach, and strengthening data privacy through an opt-in mechanism.
- Appendix A: definitions of AI: definitions from the OECD, the European Union, NIST, OMB, Executive Order 14110, several US states and VITA.
💡 Why it matters?
For legislators, regulators and public-sector technology teams, the report assembles in one place the federal guidance, state statutes and Virginia executive actions that shape government AI use. It shows how an existing state IT policy - VITA's mandatory approval process, disclaimers and third-party vetting - corresponds to the NIST AI Risk Management Framework, and how Colorado SB24-205 allocates disclosure, impact assessment and reporting duties between developers and deployers. The four recommendations give assessable options: codification of current standards, an advisory committee, risk-based regulation, and opt-in data privacy, each with fiscal estimates from the 2024 bills.
❓ What’s Missing
The report is tied to Virginia and to the 2024 legislative session: HB747 and SB487 are described as introduced or substituted rather than enacted, and the proposed Commission on AI would expire in July 2027 if created. Comparator states are limited to Colorado, Maryland, Utah and Vermont; the EU AI Act appears only in the definitions appendix and a comparison with Colorado's definition. The recommendations carry no implementation timelines, and the technical overview does not cover evaluation metrics, security testing methods or procurement contract language.
👥 Best For
State legislators and committee staff drafting AI statutes; public-sector CIOs, IT agencies and procurement teams implementing or overseeing AI policies; and policy or compliance analysts who need a consolidated comparison of US federal guidance, state AI laws and one state's executive-branch measures.
📄 Source Details
Artificial Intelligence: Policy and Practice, a report of the Virginia Joint Commission on Technology and Science (JCOTS), dated November 2024. The report author is listed as Gates Palissery; Jodi Kuhn is the Executive Director, and Delegate C.E. Cliff Hayes, Jr. chairs the commission. The document runs to 38 pages in the supplied PDF, including Appendix A, definitions of AI. Language is English. No URL for the report itself is printed; other sources are cited by link text. The full 38-page text extraction was available.