Idaho buyer guide
Outsourcing software development from Idaho
An Idaho buyer guide to international software and AI: six-factor risk tiers, high-water data, human review, records, incidents, accessibility, cost, and exit.

Idaho outsourcing at a glance
| Proposed work | Default passport lane | Evidence before access or release |
|---|---|---|
| Ordinary application, integration, infrastructure, or test automation | Buyer-owned engineering lane | Named entity and people, architecture, repository, environments, data boundary, dependencies, secure-development evidence, acceptance, runbook, complete cost, and exit |
| GenAI drafting or code assistance using public/synthetic material | Approved Tier 1 candidate lane | Approved tool and State-business account where applicable, use case, prompt data class, source rights, human review, content identification, significant-output log, tests, retention, and inventory record |
| AI using Restricted information, broader scope, lower transparency, or reduced human oversight | Tier 2 or higher review lane | Six-factor assessment, high-water data class, Information Owner, privacy impact, security controls, fairness evaluation, vendor assessment, monitoring plan, human mechanism, approvals, and change triggers |
| High-impact, high-autonomy, opaque, large-scale, novel, or Critical-data AI | Default stop and Tier 3 authority lane | Detailed model and limitations, enhanced security, risk mitigation, AI-specific incident plan, mandatory committee consultations, leadership/ITS approvals, controlled environment, recovery, and exit |
| Level 4 Critical State data | No international remote-access lane by default | Current Information Owner and qualified authority determination, exact governing source, approved system and people, no supplier inference from an AI approval, and a separated eligible-artifact plan |
| Public-facing State AI content or service | Human-release, disclosure, and accessibility lane | Exact accepted version, human verification, disclosure/attribution, source and validation record, correction path, WCAG evidence, assistive-technology checks, owner approval, and record treatment |
| State record in a supplier or AI platform | Records-custody lane | Public-record determination, custodian, classification, exemptions and segregation, native/available export, search, metadata, retention, hold, production, and tested platform exit |
| Private or public covered personal-information incident | Immediate factual relay with separate authority branches | Discovery time, owner/licensee or maintainer role, misuse facts, affected data and residents, preservation, containment, public-agency 24-hour route if applicable, resident decision owner, recovery, and updates |
| State digital product or service procurement | Solicitation-activated accessibility and vendor lane | Exact solicitation and contract, vendor accessibility assessment, WCAG 2.1 AA evidence where applicable, known exceptions, remediation ownership, acceptance tests, and ongoing regression plan |
No row authorizes another. An AI tool approved for public data is not approved for Critical data. A technical review does not transfer the Information Owner’s authority. A private company is not subject to every State committee path. A supplier’s accessibility statement is not acceptance evidence. The passport keeps those boundaries visible.
The core decision: can the buyer issue a complete risk passport?
An outsourcing statement such as “build a citizen chatbot” or “automate our document review” hides the facts that determine control. What information enters? Does the system recommend or decide? Can it act without a person? Can a nontechnical stakeholder understand it? How many people does it affect? Is the technique proven in this setting? Where will prompts, logs, embeddings, and backups live? Who can stop it? Who owns the record?
The high-water approval passport is a versioned evidence packet for one implementation and release. It should contain:
- Outcome and excluded uses. Define the permitted service, user, decision, business or public purpose, acceptance result, and prohibited adjacent uses.
- System boundary. List interfaces, repositories, datasets, models, retrieval collections, agents, plugins, connectors, environments, clouds, devices, networks, regions, subprocessors, and downstream actions.
- Information high-water mark. Identify each data source and classification and set the system floor at the highest impact level until an Information Owner records a different approved architecture.
- Six-factor AI assessment. Score personal-data sensitivity, decision impact, autonomy, transparency, scope and scale, and novelty and complexity with evidence and justification.
- Governance tier. Record Tier 1, 2, or 3, the calculation/version, approvers and advisors, open conditions, expiration, and reassessment triggers.
- People and places. Name the contracting entity, contributors, supervisors, employment or subcontract chain, cities, devices, working zones, support routes, and approved replacement process.
- Authority. Separate read, propose, write, train, fine-tune, merge, deploy, communicate, decide, purchase, delete, and change-access permissions. Name the U.S. buyer owner for each consequential gate.
- Evaluation. Define functional, factual, security, privacy, fairness, accessibility, rights, performance, cost, and failure-mode tests appropriate to the risk.
- Transparency and records. State how AI assistance is identified, what prompt/output/review evidence is retained, what may be a public record, where it is searchable, and which retention and segregation rules apply.
- Incident and recovery. Identify detection, immediate relay, safe containment, public-agency and private branches, evidence protection, rollback, restoration, reconciliation, and communication authority.
- Change control. Reassess new data, model, autonomy, connector, purpose, population, supplier, country, terms, incident, or operational context before the old passport is reused.
- Exit. Prove source, configurations, data, records, evaluations, accounts, credentials, documentation, deletion or return, and replacement-team operation.
Attach the passport ID to the work order, access group, model configuration, deployment artifact, approval, invoice, and exit register. A supplier can help assemble the packet, but the accountable buyer roles must own the classification, tier, release, record, incident, and acceptance decisions.
Score all six AI factors, not only the data
The Idaho AI standard requires a multi-factor model with four ratings—Low, Medium, High, and Very High—across six dimensions. The weighted result places the implementation in one of three governance tiers. The exact State tool and current approvals govern covered work; a supplier-created spreadsheet is not a substitute. The dimensions nevertheless provide a precise diligence model for any Idaho buyer that adopts them deliberately.
| Dimension | Passport question | Evidence that prevents understatement |
|---|---|---|
| Personal data sensitivity | What is the highest class the system reads, derives, stores, exposes, or can retrieve? | Field/source inventory, owner, classification, lineage, prompt/retrieval/log path, copies, regions, retention, and test data |
| Decision impact | How can an output affect a person’s rights, benefits, services, safety, finances, employment, access, or public interaction? | Decision map, consequence and appeal path, baseline, error costs, affected roles, human authority, and correction test |
| Autonomy level | Can the system only draft, or can it choose tools, take actions, and continue without confirmation? | Action allowlist, credential scope, approval gates, budget and volume limits, traces, stop test, rollback, and incident drill |
| Transparency | Can affected users, reviewers, and nontechnical owners understand the relevant logic, inputs, limitations, and result? | Fact sheet, sources, reason or explanation record, user disclosure, reviewer display, limitation notice, and contest route |
| Scope and scale | Is this a narrow pilot or a broad service affecting many people, agencies, sites, or transactions? | Audience and population estimate, deployment boundary, concurrency and volume, expansion plan, monitoring, and blast-radius test |
| Novelty and complexity | Is the method established for this use or an untested combination with uncertain behavior? | Architecture, model/version, prior evidence, integration and dependency map, adversarial tests, fallback, and staged rollout |
Risk does not average away. Low-sensitivity public data does not make a fully autonomous public-benefit decision low risk. Strong human review does not make Critical information safe in an unapproved remote system. A narrow pilot does not eliminate prompt injection. Record each dimension, and keep the high one visible even if the weighted total is lower.
For generative AI, the standard adds hallucination or factual inaccuracy, prompt injection, data poisoning, copyright and intellectual-property implications, and misuse or unintended outputs. Test these against the real proposed retrieval sources, tools, people, and action boundary. A generic vendor benchmark does not prove the Idaho use case.
Apply the high-water mark to the whole system
The Idaho standard tells Information Owners to classify AI systems using the “high water mark”—the highest impact level of the associated information. This prevents a team from labeling an application Low because its public interface looks harmless while its retrieval store, administrator log, or support workflow contains Restricted or Critical information.
The current classification guide describes four levels:
| Level | Practical meaning in the State guide | Outside-U.S. default for covered work |
|---|---|---|
| Level 1 — Unrestricted/Public | Public information associated with State conduct or administration and typically created for public consumption | Eligible for an approved work lane after source, integrity, rights, tool, and release checks |
| Level 2 — Limited/Internal | Sensitive internal information that may or may not be protected from public disclosure | Authenticated buyer-controlled lane; approved people, purpose, system, transfer, review, and retention; do not equate possible disclosure with public posting |
| Level 3 — Restricted | Confidential agency-use information, often with federal or other stronger handling requirements | Protected enterprise lane; encryption and named access, approved remote path if any, strong identity, no informal messages or ordinary file transfer, monitored processing, and exit proof |
| Level 4 — Critical | Highly sensitive information whose disclosure could create significant harm, including potential injury, disability, or loss of life | Default deny for international remote access; keep in approved systems with approved users and resolve exact authority before any AI use |
The guide’s handling table is unusually operational. It prohibits remote access for Level 4, restricts Level 4 to approved systems and users, disallows websites and hard-copy production for that level, and requires encryption and access controls. Level 3 remote access is described as necessary-only with VPN and MFA. Do not reduce those controls to “our provider is secure.” The work package must match the permitted transfer, device, identity, environment, communication, printing, website, and disposal route.
Create an eligible-artifact bridge. Keep protected source data and consequential production systems inside the approved enclosure. Let an international team work on public specifications, synthetic fixtures, minimized interfaces, isolated components, test harnesses, accessibility corrections, documentation, and other artifacts that do not require restricted access. A buyer-side integration owner can move an accepted artifact through security and release gates without exporting the protected information.
Synthetic data requires proof. Show that it exercises the relevant formats, edge cases, distributions, access rules, and failure paths without reconstructing real protected facts. If a bug cannot be reproduced without actual data, create a narrowly approved diagnostic path instead of granting the entire provider standing access.
Resolve the Critical-data GenAI stop gate explicitly
The current Idaho AI package contains two statements a covered team must reconcile rather than reinterpret. Its AI data-management and general-use sections say Critical data must not be processed with GenAI without explicit authorization for high-risk deployments, including AI Executive Committee review and robust safeguards. Its prohibited-use section separately says GenAI tools must not process or generate content involving data classified as Critical. The data-classification guide also prohibits remote access for Level 4.
The safe outsourcing response is a stop gate:
- do not put Critical data into a GenAI tool or international remote session;
- identify the exact proposed data, transformation, system, person, country, and output;
- route the apparent conflict to the Information Owner, designated agency role, ITS, security, privacy, legal, records, and the stated governance authorities as appropriate;
- obtain a current written determination that cites the controlling document, scope, version, conditions, and expiration;
- preserve stricter agency, federal, contract, CUI, safety, and sector requirements; and
- if the answer is not explicit, keep the data in the non-GenAI approved enclave and use the eligible-artifact bridge.
An approval to use an AI product with Level 1–3 data is not an implied Level 4 exception. A committee consultation is not permission for an overseas engineer to view the data. A private company’s own criticality label does not automatically invoke Idaho’s State policy, but the company should still resolve safety-critical and high-consequence processing through its applicable standards and qualified owners.
Route each tier to the correct approval path
The Idaho standard sets tier-specific review:
- Tier 1 / Low Risk: ITS and agency or department IT leader approval; the AI Innovation Team receives inventory notification.
- Tier 2 / Medium Risk: ITS and agency or department leadership approval, with advisory input from the AI Innovation Team and Technical Review Board; Information Owners manage sharing agreements and security controls.
- Tier 3 / High Risk: ITS and agency or department leadership approval, with mandatory consultation from the Ethics Committee, Technical Review Board, and Executive Committee; Information Owners maintain enhanced oversight for Critical data controls.
Treat this as a route, not a badge. Record who reviewed which passport version, evidence, limitations, conditions, and release. If the implementation changes after approval, reassess annually and when functionality, data sources, or operational context changes, as the standard requires. Useful additional triggers include a new model, plugin, action, supplier, country, audience, autonomy level, interface, terms, or incident.
Every tier needs basic documentation: concept brief, classification assessment and approval, data sources and handling, performance metrics and evaluation criteria, user guidance, AI fact sheet, human oversight, shared-responsibility assignments, deviations and justification, contacts, and leadership/ITS signatures. Tier 2 adds the privacy impact, security controls, fairness evaluation, monitoring, and vendor assessment. Tier 3 adds detailed model architecture/training/limitations, enhanced AI security, risk mitigation, and AI-specific incident procedures.
Do not let the provider declare the tier in its proposal and proceed. The buyer’s applicable State roles own the classification and approval. The supplier’s responsibility is to disclose enough architecture, data, testing, people, locations, terms, and controls for those roles to decide.
Turn shared responsibility into named operations
“Shared responsibility” can hide gaps unless every activity has one accountable owner. Build a responsibility matrix for:
- concept and mission fit;
- data and system classification;
- risk-factor scoring and tier approval;
- provider and subprocessor assessment;
- architecture, secure development, threat modeling, and data separation;
- privacy impact, information sharing, rights, retention, and records;
- fairness, accessibility, human oversight, transparency, and user recourse;
- model, prompt, retrieval, output, and agent evaluation;
- deployment authority, monitoring, change review, incident response, recovery, and communication; and
- decommissioning, export, deletion or return, credential revocation, and continuity.
Use four explicit states: Responsible, Accountable, Consulted, and Informed, plus an evidence link and fallback owner. A provider may be Responsible for a test while the agency Information Owner remains Accountable for classification. The Technical Review Board may be Consulted, but a named release owner still approves deployment. A security team can isolate an incident immediately without owning the resident notice decision.
Identify the person—not “the business”—for every approval. Include vacation, turnover, and after-hours fallback. If the responsible supplier role changes, reassess access, training, confidentiality, country, schedule, and knowledge transfer before substitution.
Control GenAI prompts, outputs, and public content
For covered State work, the Idaho standard requires human review of GenAI outputs used for official purposes, clear identification of AI-generated content when distributed internally and externally, registration of tools in agency/software and State AI inventories, and logs for significant content including prompts and human-review status. It calls for documented prompt libraries, interaction logging, input validation against prompt injection, content filtering, and public-facing review.
Build a significant-output record with:
- passport and work-object ID;
- approved tool, account, model/version, connector set, region, and configuration;
- prompt or instruction version and restricted pointer to material input where needed;
- retrieved source identifiers, rights, freshness, and integrity checks;
- raw output or controlled reference, detected risks, edits, tests, and rejected variants;
- named reviewer, evidence seen, validation, corrections, accepted content, and final authority;
- disclosure/attribution text and exact placement;
- record class, retention, access, hold, publication, correction, and disposition; and
- cost, latency, failures, incident linkage, and change trigger.
Do not dump protected prompts into a broad analytics service merely to satisfy logging. Use classification-appropriate storage and access; a pointer, hash, or protected evidence vault can preserve linkage. Likewise, do not keep every experiment forever. The applicable owner and custodian should decide which prompt/output evidence supports an official decision, public content, accepted release, audit, investigation, or legal hold.
The State’s published disclosure language is a current implementation signal, not a universal private-company safe harbor. Covered teams should use the approved language and agency process where applicable. Private buyers should determine their own accurate disclosure from product, audience, law, contract, risk, and user expectation.
Preserve public records outside the supplier’s interface
Idaho’s Public Records Law and Attorney General manual define and explain public records, custody, examination and copying, exemptions, segregation, and request handling. For State and local public work, the buyer should decide whether prompts, model outputs, chats, evaluations, work papers, tickets, source files, action logs, and approvals are public records based on the actual definition and facts—not the vendor’s product category.
Create a record-custody map:
- which public agency and custodian owns the decision;
- which supplier, platform, model, ticket, repository, chat, email, log, backup, and subprocessor can possess the record;
- which portions may be exempt and how exempt and nonexempt material can be separated;
- how the record is searched by topic, date, owner, user, model, prompt, action, and release;
- which native or available export includes content, metadata, attachments, relationships, edits, and timestamps;
- which retention, litigation or disputed-record hold, and disposition path applies; and
- how the buyer retrieves and protects the records during suspension, provider failure, or exit.
An export that converts every interaction into an image without searchable text, model identity, or timestamps is weak. A platform that deletes the only prompt trace when a user account is disabled is weak. Test retrieval before signing and during the pilot.
Public record does not mean every field is publicly disclosed. Exempt and confidential information still needs protection and segregation. Conversely, a supplier confidentiality clause cannot erase a public agency’s statutory duties. Contract for both retrievability and protection.
Private buyers need business records too, but should not label ordinary corporate evidence an Idaho public record. Apply actual tax, employment, quality, security, insurance, litigation, contract, and retention requirements.
Build the incident fork before access
Idaho Code title 28, chapter 51 covers its defined personal-information breach path for agencies, individuals, and commercial entities. The current Attorney General page makes an important scope distinction: an Idaho public agency must notify the Attorney General within 24 hours after discovering a security-system breach; a commercial entity may report to that office but is not required to do so under this general chapter. Other sector, federal, contract, and jurisdiction-specific routes may still apply.
The chapter distinguishes owner/licensee from maintainer. The owner or licensee conducts a good-faith reasonable and prompt misuse investigation and, when misuse occurred or is reasonably likely, handles the resident-notice path. A maintainer must notify and cooperate with the owner or licensee immediately after discovery when the statutory misuse condition is met. A supplier should contract to alert earlier on any credible event so the buyer can investigate the condition rather than waiting for the provider’s legal conclusion.
Use one evidence stream with separate authority forks:
| Fork | Trigger owner | Operational design |
|---|---|---|
| Credible security or AI event | Supplier and buyer security roles | Immediate factual alert, safe containment, preserved systems and logs, frequent updates, no premature public conclusion |
| Covered public-agency security-system breach | Agency’s designated authority | 24-hour Attorney General route from discovery plus applicable State IT reporting; supplier evidence arrives well before the outside deadline |
| Covered private owner/licensee misuse decision | Named business/legal/privacy owner | Prompt reasonable investigation, affected Idaho resident decision, lawful delay analysis, recovery, communication, and documentation |
| Covered maintainer event | Supplier/maintainer and owner/licensee | Immediate notice and cooperation, field/record population, acquisition and misuse facts, system integrity, update cadence, and evidence handoff |
| AI-specific failure | Passport incident owner | Prompt injection, data poisoning, harmful or deceptive output, unapproved autonomy, model drift, discrimination, disclosure, cost runaway, or unsafe action containment and correction |
The first packet should identify discovery time, detecting person/system, affected services and passport, entities, people, countries, models, agents, tools, identities, credentials, data classes and fields, residents/populations, encryption, acquisition and misuse evidence, containment, preserved material, recovery, downstream effects, known unknowns, and next update. Preserve the distinction between fact, hypothesis, and legal determination.
Exercise the 24-hour public-agency path using a much shorter internal target. Inject a prompt-injection attempt, a compromised overseas credential, a provider-region change, an inaccessible public record, and a harmful output that reached a staging queue. Measure stop time, owner notification, evidence completeness, classification, records protection, recovery, user correction, and revoked access.
Include accessibility in State digital delivery
Idaho Division of Purchasing’s current vendor resources state that vendors providing digital products or services on behalf of the State must comply with the specified WCAG 2.1 AA digital-accessibility requirements and complete the referenced vendor assessment for solicitation responses and contracts. Apply the exact solicitation, contract, date, scope, and exception process; do not turn a procurement resource into a universal rule for every private website.
For activated State work, accessibility belongs in the work package and passport:
- semantic structure, landmarks, headings, names, roles, states, and relationships;
- keyboard operation, visible focus, logical order, escape and dismissal, and no keyboard trap;
- text alternatives, captions, transcripts, audio description where applicable, and meaningful link/control labels;
- contrast, zoom, reflow, orientation, target size, motion, timing, and error prevention;
- form instructions, validation, status announcements, authentication, and no-JavaScript or service fallback where appropriate;
- accessible documents, exports, charts, tables, generated content, and AI disclosures;
- supported browser, screen reader, magnifier, voice, switch, and mobile combinations based on the actual audience; and
- regression tests, defect ownership, remediation timing, evidence, acceptance, and post-release monitoring.
An automated scan is useful but incomplete. Combine static analysis with keyboard use, zoom/reflow, screen-reader inspection, content review, and representative user testing proportional to risk. Store findings, versions, exceptions, fixes, retests, and acceptance in buyer-owned systems.
AI can create accessibility defects at scale: unlabeled controls, incorrect alt text, unstable focus, inaccessible charts, invented headings, misleading summaries, or voice interactions without an equivalent path. Evaluate the final rendered experience, not only the source prompt.
Engineer Pacific and Mountain authority windows
Idaho spans Pacific and Mountain time. The current Idaho Fish and Game publication, for example, distinguishes Pacific-time Panhandle and Clearwater regional offices from Mountain-time offices elsewhere. Do not put “Idaho time” in a work order or incident plan. Record the buyer’s actual city or operational site, its IANA zone, contributor cities and zones, engagement dates, holidays, and clock-transition test dates.
Use three operating lanes:
- Working overlap: a sustainable recurring period for clarification, pairing, accessibility review, and ordinary approval.
- Decision relay: a written packet with purpose, version, high-water class, risk tier, evidence, questions, limits, and next safe action for asynchronous progress.
- Urgent authority: a 24-hour route appropriate to risk, with named security and business owners, immediate stop permission, protected evidence location, and public/private incident fork.
A Boise schedule does not automatically work for a Coeur d’Alene or Lewiston operation. A provider sales team may quote Mountain overlap while the actual buyer owner is in the Pacific lane. Calculate the exact site and date.
Avoid permanent night work. Fatigue undermines code review, content verification, security decisions, accessibility inspection, and incident response. Use short high-value overlap, clear asynchronous packets, rotating exceptional coverage, compensation, and backup authority.
Select providers by the passport they can prove
Compare named provider teams and operating facts:
- legal contracting entity, operational ownership, beneficial ownership where relevant, insurance, and dispute path;
- named contributors, supervisors, employment or subcontract chain, cities, facilities, devices, networks, and replacement rules;
- skill evidence for the actual architecture, data, model, accessibility, security, and domain work;
- repositories, build systems, cloud tenants, model services, data regions, logging, support, backups, subprocessors, and change notification;
- secure-development, dependency, provenance, vulnerability, evaluation, deployment, monitoring, incident, recovery, and exit evidence;
- data classes, purpose limits, training use, model rights, retention, deletion, and support for public records or resident rights where activated;
- intellectual-property assignment and contributor flow-down, pre-existing material, open source, commercial components, training data, generated material, and destination-country formalities;
- current sanctions, export, sector, CUI, procurement, engagement, employment, tax, and destination constraints reviewed for the actual work; and
- sustainable Pacific/Mountain overlap, asynchronous discipline, urgent coverage, complete price, attrition response, and continuity.
The buyer should control repositories, cloud and identity accounts, domains, deployment, production keys, data, model and prompt configurations, passports, evaluations, records, logs, runbooks, and recovery artifacts. The provider can operate them under bounded access. A broad IP clause does not help if the buyer cannot build, search, deploy, or recover the system.
Do not publish provider, partner, customer, tool-vendor, compliance, or past-company relationship claims without evidence and permission. Using a tool is not a partnership. A supplier’s prior employee experience is not a customer reference for a new company.
Compare complete cost and downside
Normalize each proposal to the same outcome, passport, risk tier, period, and acceptance evidence. Include:
- discovery, concept brief, architecture, data mapping, classification, risk assessment, privacy, security, fairness, accessibility, records, procurement, and legal review;
- product, design, engineering, data work, model evaluation, testing, DevOps, documentation, training, support, and buyer management;
- model, retrieval, embedding, storage, observability, safety, evaluation, egress, and tool-call consumption;
- cloud, repositories, identity, managed devices, assurance, insurance, connectivity, and travel;
- recruiting, onboarding, background checks where appropriate, role training, replacement, attrition, and knowledge distribution;
- currency, tax, international engagement, contract administration, sanctions/export review, and dispute handling;
- rework, hallucination, prompt injection, model drift, accessibility remediation, public-record production, incident investigation, recovery, resident support, and communication; and
- transition, export, decommissioning, deletion or return, credential rotation, replacement operation, and stranded-platform cost.
Price a material change. What happens when the model version changes, a connector adds new data, a Level 3 source becomes Level 4, the system grows from a pilot to an agency-wide service, a supplier adds a country, a public record cannot be exported, or an accessibility regression blocks a user? Include reassessment and corrective work.
Price failure and exit. A low hourly rate is not a saving if the buyer must recreate the risk assessment, extract unreadable records, remediate an inaccessible interface, or replace the only person who knows how the model is deployed.
Run a high-water passport pilot
Choose one real, reversible outcome using public, synthetic, or expressly approved nonproduction data. Use the actual proposed people, tools, model, location, and buyer approvers. Include one AI-assisted output or decision-support feature only if the team can exercise the full passport.
Before access, require:
- concept brief, work boundary, excluded uses, named users, affected population, and acceptance evidence;
- data/system inventory, high-water classification, transformations, retention, records, and eligible-artifact boundary;
- all six factor ratings, GenAI-specific risks, resulting tier, approval route, conditions, and change triggers;
- provider entity, contributors, cities, systems, models, accounts, regions, plugins, subprocessors, and rights chain;
- human-review and release design, disclosure, significant-output logging, accessibility, incident, recovery, and exit plans; and
- exact Pacific or Mountain decision window, written handoff packet, urgent route, and unavailable-owner fallback.
During the pilot:
- Have the team deliver one accepted feature or artifact through buyer-owned systems.
- Introduce a new data source that raises the high-water mark and verify that the old passport stops.
- Reduce human oversight or add a tool action and verify reassessment of autonomy and tier.
- Place a malicious instruction in retrieved content and verify input isolation and action limits.
- Generate a factual error or inaccessible output and verify human detection, correction, disclosure, and retest.
- Request the material prompt/output/approval record and verify search, export, protection, and segregation.
- Simulate a credential incident and exercise the public/private authority fork without waiting for a final conclusion.
- Roll back, restore, revoke all supplier and machine access, export the packet, and transfer operation to another qualified person.
Score delivered outcome, factor evidence, classification, approval accuracy, human review, security, fairness, accessibility, records, incident speed, schedule sustainability, complete cost, recovery, and exit. Do not scale when the provider cannot explain why the tier is correct or what makes the system portable.
Contract the passport and high-water boundary
The work order and master terms should address:
- exact entities, named or controlled team, approved countries/locations, facilities, devices, employment/subcontract chain, training, replacement, and change notice;
- outcome, excluded uses, deliverables, dependencies, acceptance evidence, service levels, remedies, change control, and order of precedence;
- data and system inventory, classifications, purpose, collection, minimization, transfer, regions, access, retention, records, holds, return, deletion, and evidence;
- six-factor AI assessment, high-water system rule, tier, approval conditions, tool/model/agent inventory, reassessment, and decommissioning;
- privacy, security, fairness, accessibility, human oversight, transparency, prompt/output logging, evaluation, monitoring, and user correction;
- secure development, dependencies, source and build provenance, vulnerability response, buyer release, rollback, restoration, and continuity;
- immediate incident relay, safe containment, public-agency and commercial branches, evidence custody, update cadence, investigation cooperation, and buyer-controlled notices and communications;
- public-record identification, search, metadata, export, exemption segregation, retention, hold, production, and transition where activated;
- IP assignment and contributor flow-down, pre-existing material, open source, commercial licenses, model and data rights, destination-country formalities, and moral-rights treatment where relevant;
- pricing, consumption limits, invoices, currency, taxes, insurance, liability, suspension, termination, transition assistance, and unresolved claims; and
- buyer control of repositories, accounts, domains, configurations, passports, evaluations, credentials, logs, records, documentation, backups, and recovery artifacts.
Test the contract as a workflow. Who stops a Level 4 export? Who rescans the six factors after an autonomy change? Who identifies significant AI content? Which person reviews accessibility? Which system preserves a public record when an account closes? Who calls the agency 24-hour route? Can the replacement team deploy from buyer-held material?
Idaho outsourcing red flags
Pause or reject a proposal when:
- “Idaho compliant” appears without the exact entity, operation, source, scope, date, and qualified reviewer;
- State AI, data, records, incident, or procurement policy is presented as a universal private-company rule;
- a provider scores only data sensitivity and ignores decision impact, autonomy, transparency, scale, or novelty;
- the weighted tier hides a Very High dimension or the high-water information class;
- an AI product approval is presented as unrestricted approval for every data class, action, and country;
- Level 4 Critical data is proposed for overseas remote access despite the current handling guide;
- a supplier resolves the current Critical-data GenAI tension through sales language instead of written authority;
- Tier 2 or 3 work lacks the added privacy, security, fairness, monitoring, vendor, model, mitigation, or incident evidence;
- “human in the loop” does not name the person, evidence, authority, time, stop, and correction path;
- significant prompts, outputs, reviews, decisions, and actions disappear inside the provider’s interface;
- public-record export is unsearchable, incomplete, unsegregated, or dependent on an active supplier account;
- the supplier waits for a final misuse or legal decision before reporting a credible event;
- commercial-entity voluntary AG reporting and public-agency 24-hour reporting are collapsed into one rule;
- an accessibility badge replaces the actual solicitation, WCAG evidence, assistive-technology test, remediation, and acceptance;
- “Idaho time” replaces an actual Pacific or Mountain site, IANA zone, date, and named authority owner;
- price excludes governance, model consumption, accessibility, records, incidents, recovery, or exit; or
- the provider controls the only repository, cloud account, model configuration, passport, evaluation, logs, records, credentials, or runbook.
Frequently asked questions
Can an Idaho company outsource software development outside the United States?
Potentially. Define the work, entities, people, data, systems, models, tools, countries, authority, law and contracts, destination requirements, sanctions/export constraints, tax and engagement issues, security, cost, continuity, and exit. Keep protected data and consequential production authority separated when the international team does not need them.
Do Idaho’s State AI policies apply to every private business?
No. The cited package governs State data, systems, agencies, personnel, contractors, subcontractors, and business partners within its stated scope. Private buyers may adopt the risk model, but should not label it a universal private-sector mandate.
What are Idaho’s six AI risk factors?
They are personal-data sensitivity, decision impact, autonomy level, transparency, scope and scale, and novelty and complexity. Covered implementations use the State’s weighted classification tool and approval process; a provider should supply evidence for every factor.
What does the high-water mark mean?
The system is classified from the highest-impact associated information, not its least sensitive screen or average dataset. Include retrieval, prompts, outputs, logs, support, backups, derived data, credentials, and integrations when identifying the high-water mark.
Can an overseas team remotely access Level 4 Critical State data?
The current Idaho handling guide lists remote access as prohibited for Level 4. Default to no. Route any proposed exception or different interpretation through the actual Information Owner and authorized State, security, legal, privacy, and contractual process; a supplier cannot infer permission.
Can Critical State data be processed with generative AI after committee review?
Do not assume so. The current AI package contains an explicit high-risk authorization statement and a separate prohibited-use statement, while the handling guide prohibits Level 4 remote access. Treat this as a stop gate and obtain a current written authoritative determination for the exact operation.
Must official State GenAI output receive human review?
The current standard requires human review before GenAI outputs used for official purposes are finalized or distributed. Make the review meaningful: name the reviewer, evidence, checks, corrections, authority, and accepted version.
Can an AI prompt or output be an Idaho public record?
Potentially, depending on the actual public agency, content, custody, use, and statutory definition and exemptions. The public entity should decide, preserve, protect, search, segregate, retain, and produce the applicable record; the vendor platform does not decide the law.
Does every Idaho business have to notify the Attorney General within 24 hours of a breach?
No. The current Attorney General page identifies the 24-hour requirement for an Idaho public agency. It says commercial reporting to that office is voluntary under this general chapter. Other sector, federal, contractual, and jurisdictional duties may apply.
How fast should an international supplier report a possible event?
Immediately under the operating contract. Early facts let the buyer classify the event, preserve evidence, investigate misuse, meet any public-agency 24-hour route, handle resident or other notices, and recover. Do not wait for a final legal conclusion.
Is Idaho entirely in Mountain time?
No. Idaho uses Pacific and Mountain time. Record the buyer’s actual city or site and IANA identifier and calculate overlap for the engagement dates; do not use “Idaho time.”
Which delivery country is best for an Idaho buyer?
There is no universal best country. Compare named teams and locations for capability, sustainable overlap, data and authority boundary, current destination constraints, IP chain, evidence, complete cost, incident response, continuity, and exit.
What should the first pilot prove?
It should prove a real accepted outcome, high-water classification, all six risk factors, correct approval route, human release, prompt-injection containment, accessibility, records retrieval, immediate incident relay, rollback, revoked access, and replacement-team operation.
Is Outsourcing.ai located in Idaho?
No local presence is claimed. This is an online buyer guide, not an Idaho office, local-business listing, or representation of local employees, customers, State authorization, procurement eligibility, or completed local work.
Buyer checklist
- Define the outcome, excluded uses, acceptance evidence, consequence, engagement model, budget, and buyer owner.
- Identify the exact Idaho buyer city/site, IANA zone, contributor cities, dates, overlap, handoff, and urgent authority.
- Inventory data, records, code, prompts, retrieval, models, tools, connectors, systems, credentials, actions, outputs, logs, backups, and subprocessors.
- Assign the Information Owner, classification, handling, retention, and high-water system level for each work package.
- Score data sensitivity, decision impact, autonomy, transparency, scope/scale, and novelty/complexity with evidence.
- Evaluate hallucination, prompt injection, data poisoning, copyright/IP, misuse, and unintended-output risks for GenAI.
- Record the Tier 1, 2, or 3 route, current assessment tool/version, approvers and advisors, conditions, expiry, and reassessment triggers.
- Keep Level 4 Critical State data outside international remote access and GenAI until current authorized owners resolve every applicable restriction.
- Build an eligible-artifact bridge for international engineering that does not require protected data or production authority.
- Separate human and workload identities; bound read, propose, write, merge, deploy, communicate, decide, purchase, delete, and access-change actions.
- Register approved tools where applicable; preserve significant prompts, outputs, human-review status, disclosures, evaluations, and accepted versions.
- Define meaningful human gates, evidence shown, time to decide, stop authority, correction, rollback, and recovery.
- Map public records across every supplier and AI platform; test search, export, metadata, exemption segregation, retention, holds, and exit.
- Activate exact State digital-accessibility requirements from the solicitation/contract; combine automated and human testing.
- Contract for immediate factual incident relay and test the public-agency 24-hour, maintainer, owner/licensee, resident, AI-failure, and recovery branches that actually apply.
- Verify provider entities, people, countries, destinations, sanctions/export limits, IP chain, insurance, subprocessors, and change notice.
- Compare complete cost and material-change/downside cases with identical assumptions.
- Run the representative pilot with the actual proposed team, tools, data boundary, buyer approvers, and replacement operator.
- Obtain current legal, privacy, records, procurement, accessibility, security, tax, employment, export, and intellectual-property advice where applicable.
- Record named human content, source, visual, and legal approval before production publication.
The exit test
Before scale, prove the buyer can continue without the supplier. Retrieve and validate:
- repositories, branches, accepted artifacts, build definitions, dependencies, source and model provenance, evaluation suites, release history, rollback packages, defects, and licenses;
- concept briefs, six-factor assessments, GenAI-specific risks, high-water classes, tiers, approvals, conditions, significant changes, fact sheets, shared-responsibility assignments, and current owners;
- data and records inventory, sources, lineage, transformations, prompts, outputs, reviews, actions, logs, replicas, backups, retention, holds, exemptions, segregation, authorized deletion or return, and residuals;
- provider entities, contributors, employment or subcontract chain, locations, devices, networks, accounts, model services, regions, connectors, subprocessors, confidentiality, and IP flow-down;
- privacy impacts, security controls, fairness and accessibility evaluations, vendor assessments, monitoring, incidents, limitations, corrections, disclosure, and user support;
- architecture, environments, infrastructure, domains, identity, credentials, access history, monitoring, runbooks, restoration results, risks, decisions, and support history;
- incident evidence, discovery and update timeline, classification, agency/private decisions, notices, communications, remediation, recovery, and protected investigation material;
- public-record indexes, native or available exports, search, metadata, attachments, relationships, retention, production, and custody transfer for activated public work;
- invoices, cloud/model consumption, acceptance, service levels, insurance, transition duties, returned property, deletion evidence, holds, and unresolved claims; and
- revoked human and machine access across repositories, clouds, identity providers, model tools, support systems, endpoints, networks, secrets stores, and subprocessors.
Have a replacement team reproduce a build, explain the high-water level and one factor score, run the evaluation suite, locate and export a material record, remediate one accessibility defect, rotate a credential, contain a simulated AI event, restore a failed component, and execute a controlled release from buyer-held systems. Reconcile all residual data and authority.
The durable Idaho outsourcing model is a high-water approval passport. It shows the data floor, six risk dimensions, tier and approval route, exact people and places, bounded action, meaningful human review, accessible public experience, searchable records, immediate incident fork, recovery, and exit. If the proposed team can prove that packet and operate through a representative pilot, international delivery can expand capability without hiding State or private authority inside a provider label. If it cannot, do not scale the engagement.
Evidence ledger
Sources used on this page
- Artificial Intelligence Governance Policy, Standard, and Guideline, version 1.0 — Idaho Information Technology Services. Supports: Current August 2025 State package for six-factor AI risk classification, three governance tiers, tier-specific approval, the high-water information rule, documentation, GenAI controls, tool inventory, human review, content identification, prompt and output logging, procurement, incidents, lifecycle monitoring, and shared responsibility. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- AI Help Center — Idaho Information Technology Services. Supports: Current State implementation hub for the risk-based AI framework, approved public disclosure language, agency approval intake, leadership, user, and innovator resources, and the warning that sensitive information may be subject to the Idaho Public Records Act. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Guide to Data and System Classification — Idaho Information Technology Services. Supports: Current November 2025 handling guide for Level 1 Unrestricted, Level 2 Limited, Level 3 Restricted, and Level 4 Critical information and systems, including marking, transfer, storage, copying, remote-access, website, printing, and CUI controls. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Idaho Public Records Law Manual — Idaho Office of the Attorney General. Supports: Official July 2026 manual reproducing and explaining Idaho Code sections 74-101 through 74-127, including public-record definitions, custody, inspection and copying, request handling, segregating exempt from nonexempt material, and retention of disputed records. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Security Breaches — Idaho Office of the Attorney General. Supports: Current official explanation that title 28, chapter 51 governs covered Idaho breaches, that a public agency must notify the Attorney General within 24 hours of discovery, and that commercial-entity Attorney General reporting is voluntary under this general chapter. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Idaho Code, title 28, chapter 51 — Identity Theft — Idaho State Legislature. Supports: Official statutory chapter for covered personal-information definitions, reasonable and prompt misuse investigation, resident notice, the public-agency 24-hour Attorney General path, immediate maintainer-to-owner cooperation, alternative compliance, and enforcement. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- S6010 — Cybersecurity Incident and Breach Response Management and Reporting — Idaho Technology Authority. Supports: Current State incident-response handbook connecting incident handling, classification, reporting, evidence, agency roles, and Idaho Code sections 28-51-104 through 28-51-107 for covered State operations. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Vendor resources — Idaho Division of Purchasing. Supports: Current State vendor resources stating that vendors providing digital products or services on behalf of the State must meet the specified WCAG 2.1 AA digital-accessibility requirements and complete the referenced vendor assessment for solicitation responses and contracts. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- 2026 Big Game Seasons and Rules — Idaho Department of Fish and Game. Supports: Current official State publication distinguishing Pacific-time Panhandle and Clearwater regional offices from Mountain-time offices elsewhere, supporting location-specific Idaho scheduling rather than one statewide time label. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Artificial Intelligence Risk Management Framework — National Institute of Standards and Technology. Supports: Maintained federal methodology for governing, mapping, measuring, and managing AI risks across design, development, deployment, use, evaluation, and retirement. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Secure Software Development Framework — National Institute of Standards and Technology. Supports: Maintained secure-development methodology for organizational preparation, protected software and build environments, well-secured releases, provenance, and vulnerability response. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- IANA Time Zone Database — Internet Assigned Numbers Authority. Supports: Maintained time-zone identifiers and transition rules for calculating dated overlap between specific Idaho buyer sites and proposed international delivery cities. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Directory of Intellectual Property Offices — World Intellectual Property Organization. Supports: Official destination-country intellectual-property office links for researching software, invention, copyright, design, model, and contributor-rights questions without assuming one Idaho contract resolves every jurisdiction. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
Next scheduled review: October 15, 2026. Corrections: hello@outsourcing.ai.
