Navigating AI Disclosure and Data Privacy in Michigan Government
As artificial intelligence (AI) continues to integrate into public sector operations, the State of Michigan is actively developing frameworks to balance innovation with security and transparency. While Michigan does not yet have a single, comprehensive “AI Privacy Act,” the state manages AI adoption through a combination of existing data protection statutes, internal governance guidelines, and emerging legislative proposals.
The State of Michigan’s AI Governance Framework
The Michigan Department of Technology, Management, and Budget (DTMB) serves as the primary authority for state-level technology policy. In August 2025, the state released formal guidelines titled Adoption and Usage of Artificial Intelligence: Guidelines and Responsibilities. These guidelines are designed to serve as a “conversation starter” for state agencies, emphasizing that AI tools must align with existing security standards rather than supersede them.
Data Classification and Security
Central to Michigan’s approach is the Data Classification Standard, which mirrors Federal Information Processing Standards (FIPS) 199. Agencies are required to categorize data before using it in any AI tool:
* Public: Non-sensitive information (e.g., executive budgets, non-exempt FOIA documents).
* Internal: Information for agency operations (e.g., internal directories, driver history records).
* Confidential: Sensitive information requiring protection (e.g., Social Security numbers, health records).
* Restricted: Highly sensitive data where disclosure could cause extreme harm (e.g., law enforcement data, critical infrastructure plans).
Any external AI tool processing State of Michigan (SOM) proprietary data must undergo the Michigan Security Accreditation Process (MiSAP) to receive an Authority to Operate (ATO).
Legislative Landscape and Privacy Laws
While Michigan lacks a general consumer privacy law, it maintains robust protections through specific statutes. The Identity Theft Protection Act (Act 452 of 2004) remains the cornerstone of data breach notification requirements in the state. Additionally, the Student Online Personal Information Protection Act (SB 510), enacted in 2016, provides specific safeguards for student data, a critical area as AI-driven educational tools become more prevalent.
Legislative momentum is building. Recent proposals, such as HB 4537, seek to prohibit the use of AI as the sole basis for medical decision-making, reflecting a broader national trend toward regulating “high-risk” AI applications. Furthermore, Michigan law (MCL 169.259) includes provisions regarding political advertisements, requiring transparency for content that may be generated or distributed via digital platforms.
Regional Context and Demographics
Michigan’s approach to AI is influenced by its diverse economic landscape, which spans from the high-tech automotive corridors of Southeast Michigan to the agricultural and tourism-heavy regions of the Upper Peninsula. With a population of approximately 10 million, the state faces the challenge of ensuring that AI-driven government services remain accessible and equitable across both urban centers like Detroit and rural communities. The Michigan Department of Education (MDE) is actively working to support school districts with quality AI resources, ensuring that the next generation of Michigan residents is prepared for an AI-integrated workforce.
Practical Resources for Residents and Agencies
For those seeking to understand or comply with Michigan’s AI and data policies, the following resources are essential:
* DTMB Agency Services: The primary point of contact for state agencies looking to implement AI tools.
* Michigan Attorney General’s Office: The primary regulator for consumer protection and data privacy enforcement.
* Michigan Legislature Website: The official source for tracking pending bills, including those related to AI transparency and algorithmic accountability.
* MiSAP Training: The state offers a 90-minute course on Data Classification and Security Categorization for personnel involved in information management.
Conclusion
Michigan is currently in a phase of “responsible exploration.” By leveraging existing frameworks like the Data Classification Standard and emphasizing the “human-in-the-loop” (HITL) principle, the state aims to mitigate risks such as bias and data leakage. As the legal landscape evolves, residents and businesses are encouraged to monitor the Michigan Legislature for updates on privacy and AI-specific disclosure requirements.
