New Mexico buyer guide
Outsourcing software development from New Mexico
A New Mexico buyer guide to international software and AI delivery: data classification, prompt custody, human review, records, incidents, cost, and exit.

New Mexico outsourcing at a glance
| Proposed work | Default containment lane | Evidence required before access or release |
|---|---|---|
| Ordinary application, integration, infrastructure, or automation | Buyer-owned software workspace with least privilege | Named entity and people, architecture, repository, environments, dependency record, tests, approvals, security evidence, runbook, complete cost, and exit package |
| Generative-AI drafting or coding with public or synthetic material | Approved prompt lane | Tool, account, model/version, purpose, prompt class, allowed sources, settings, output, reviewer, fact and security checks, disclosure decision, accepted version, and deletion/retention treatment |
| Non-public, customer, employee, research, operational, or regulated information | Classified-data stop gate before any AI or supplier access | Owner/steward, exact fields, classification, purpose, legal and contract basis, region, tool license, security review, authorization, access, retention, human review, incident route, and exit |
| New Mexico executive-agency Gen-AI implementation | Agency governance and authorization lane | NIST-based assessment, agency policy, DoIT/OCS participation, roles, classification and sensitivity labels, security review, written authorization when required, testing, human fact-check, disclosure, monitoring, audit, and records handling |
| Public-facing AI-generated state content | Human-review and disclosure lane | Prompt and sources, factual and bias review, named reviewer/editor, copyright and attribution review, accepted content, disclosure text, publication authority, correction route, and record classification |
| State electronic records or record-producing systems | Records-custody lane | Custodian and schedule, record/non-record determination, native or approved format, metadata, retrieval, reliability, accuracy, security, confidentiality, migration, preservation, disposition authority, and export test |
| Private-business processing of New Mexico resident identifying information | Contracted safeguard and incident lane | Data inventory, reasonable safeguards, service-provider security clause, role ownership, discovery relay, preserved facts, risk determination, applicable notices, recovery, disposal, and evidence custody |
| Laboratory, national-security, federally funded, CUI, export-controlled, or otherwise restricted work | Separate qualified-authority enclave | Exact governing instrument, category and marking, approved entities, countries, persons, systems, cloud regions, access rules, flow-downs, release authority, incident route, records, and exit; do not infer permission from this guide |
New Mexico does not create one universal rule for all eight rows. The practical advantage of a containment zone is that it prevents a provider from treating a permissive low-risk lane as authorization for a restricted one. An ordinary test harness can be international while a sensitive dataset, production credential, controlled specification, official record, or consequential decision remains in a different environment and authority path.
The core decision: can the buyer contain the transformation?
Outsourcing changes more than the person writing code. It changes who can see input, where a transformation runs, which platform stores prompts and logs, who reviews an output, what becomes a business or public record, who can release it, and whether the buyer can reconstruct the result after the supplier leaves. A master services agreement cannot answer those questions without an operating record.
For every material transformation, the buyer should be able to draw this chain:
- Purpose. The allowed business or public purpose and the uses that are excluded.
- Input. The exact data, code, documents, images, instructions, credentials, or physical-system signals presented to a person or tool.
- Classification. The buyer’s sensitivity category, applicable legal or contract restrictions, and the authority needed for access.
- Place and processor. The legal entities, people, systems, model providers, plugins, regions, and subprocessors that can receive or retain the input.
- Transformation. The source, prompt, configuration, model or software version, retrieval collection, build, test, and human work that produced the result.
- Output. The actual code, content, model, recommendation, dataset, record, or action returned.
- Review. The person accountable for factual, functional, safety, security, rights, bias, accessibility, and policy checks appropriate to the use.
- Release. The authorized person who can merge, deploy, publish, submit, communicate, or act on the output.
- Record. The evidence retained, its custodian, classification, retrieval method, schedule, litigation or audit hold, and authorized disposition.
- Exit. The export, knowledge, credentials, deletion or return evidence, and continuity test that place the buyer back in control.
The zone fails if any material link is implicit. “Our developers use AI responsibly” does not identify the provider account, retention setting, prompt data, output reviewer, or record. “The platform is secure” does not identify the buyer’s allowed region, people, plugins, or incident relay. “The agency owns the data” does not prove the overseas team is permitted to receive it.
Use the State data classes as an operational model, not a universal law
The March 2026 New Mexico Data Policy applies to employees, contractors, and agents of executive-branch agencies within its scope. It is not a blanket private-sector statute. Its classification logic is nevertheless a concrete operating reference for covered agency work and a useful design prompt for other buyers that adopt it deliberately.
The policy describes four levels:
| State policy level | Operational meaning in the policy | Outsourcing default for covered work |
|---|---|---|
| Level 1 — Published | Not protected from disclosure and not subject to redaction; intended public material is a stated example | May enter an approved delivery lane after source integrity, rights, purpose, and tool checks; “published” is not permission to ignore copyright, contract, export, or platform terms |
| Level 2 — Internal | Not legally protected from disclosure but restricted for management or organizational purposes | Keep in authenticated systems; require manager-level release treatment where applicable; do not paste into public Gen-AI merely because it might be disclosable under some process |
| Level 3 — Sensitive | Mix of legally protected and unprotected information; release generally requires legal review and redaction | Stop before international or AI access until fields, permissions, redaction, region, security, authorization, and reviewer are approved |
| Level 4 — Restricted | Wholly protected or designated confidential; release is prohibited except through strict legal parameters | Default deny; place only in an expressly approved enclave with qualified authority, exact personnel and system boundaries, logging, monitoring, incident handling, and exit |
Classification should attach to the object, not the Jira ticket or project name. A single feature can involve a Level 1 public specification, Level 2 operating notes, Level 3 test records, and Level 4 legal or medical material. Store the class in the data or artifact register, propagate it into access groups and pipeline rules, and re-evaluate it when the object is enriched, joined, inferred, exported, or prepared for publication.
Derived information matters. Removing a direct identifier does not necessarily make a dataset safe if combinations, small populations, model outputs, embeddings, logs, or external sources can reconnect a person or protected fact. The State policy calls for disclosure-avoidance techniques beyond removing identifiers, including suppression, perturbation, aggregation, generalization, de-identification, and pseudonymization. A buyer should select and test a method for the actual use instead of calling every modified dataset “anonymous.”
The State policy also connects classification to permission structures. For an outsourced system, record the group, role, or attribute that grants access; the approving owner; the exact repositories and environments; the expiration; the last review; and the removal evidence. Country restrictions alone are too coarse. A permitted country does not make every person, device, account, model, or subprocessor appropriate.
Build a prompt-to-record ledger
The prompt-to-record ledger is the index for the containment zone. It does not need to copy secrets into a broad governance database. It can point to restricted objects while preserving enough metadata to prove the chain.
| Ledger field | Question | Minimum evidence |
|---|---|---|
| Work object | What is being built, analyzed, summarized, generated, or decided? | Stable ID, owner, purpose, consequence class, intended audience, prohibited uses |
| Input manifest | What entered the human or machine process? | Sources, fields, file or dataset versions, rights, classification, integrity, minimization, approved transformations |
| Supplier path | Who and what can receive it? | Contracting entity, named team, employment/subcontract chain, locations, systems, tools, model providers, regions, plugins, subprocessors |
| Authorization | Why is each access allowed? | Work order, data-owner decision, steward and security approval, applicable license, agency authorization, expiration, exception |
| Transformation identity | How was the output produced? | Repository commit, build, model/version, prompt or instruction version, retrieval sources, parameters, account, timestamps, human changes |
| Evaluation | Is the result fit for the stated use? | Acceptance criteria, tests, source checking, baseline, rights review, security review, bias or accessibility checks where relevant, limitations |
| Human accountability | Who reviewed and who can release? | Named reviewer, evidence seen, corrections, decision owner, approval, conditions, override or escalation route |
| Disclosure and record | Must the use be labeled or retained? | Disclosure decision and text, record/non-record decision, custodian, class, schedule, location, hold, disposition authority |
| Incident | What happens if confidentiality, integrity, availability, or provenance fails? | Immediate contact route, containment authority, preserved logs and objects, owner/maintainer roles, legal and regulator decision owners, recovery proof |
| Exit | Can the buyer continue and prove closure? | Source and data export, configuration, model and dependency manifest, credentials, runbook, record transfer, verified return/deletion, replacement test |
Make the ledger machine-checkable where possible. A deployment policy can reject a release when a production dataset has no owner, a model identifier is missing, an approved region changed, a prompt path accepts restricted material, a human reviewer is absent, or an export test expired. Use human judgment for classification, legal scope, risk, and acceptance; use automation to catch drift from decisions already made.
Do not preserve every experimental prompt forever. Retention should follow the applicable business, records, legal, security, and audit decision. Preserve the prompt and source context when it materially supports an accepted public output, consequential action, model, release, investigation, or required record. Dispose of transient copies when authorized. Keeping everything can expand risk just as surely as keeping nothing destroys accountability.
Separate public AI tools from licensed, reviewed systems
The New Mexico Generative AI policy draws a meaningful boundary around non-public information. State personnel may not place non-public data into a publicly available Gen-AI system for which DoIT or the agency lacks a current license agreement. It further says an agency shall not procure or deploy Gen-AI, or use publicly available Gen-AI to process non-public data, unless the solution has completed security review, sensitivity labeling and data classification have been applied, and prior written authorization has been received from OCS and DoIT.
A license is therefore not the end of diligence. It is one fact in the path. Before approval, determine:
- which legal entity contracts for the service and which provider entity processes data;
- whether the account is consumer, team, enterprise, API, embedded, or supplier-owned;
- what the provider may retain, inspect, train on, improve with, or disclose;
- model, region, hosting, encryption, identity, logging, plugin, connector, and subprocessor behavior;
- whether prompts, outputs, files, embeddings, telemetry, abuse-monitoring samples, and backups follow the same rules;
- how deleted data, disabled accounts, expired projects, and legal holds behave;
- whether the buyer can export the prompt, configuration, evaluation, and accepted output evidence it needs;
- whether provider or model changes trigger new testing and authorization; and
- which buyer and supplier personnel can administer, use, review, monitor, and revoke the service.
For private buyers, adopt an equivalent rule in the work order if it suits the risk: no project data in personal or public AI accounts; approved enterprise or API services only; an explicit list of permitted data classes and purposes; no hidden training or improvement use; logged identity; human review; and incident and exit duties. This is a contractual control, not a claim that the State policy directly governs the company.
Shadow AI is often a workflow problem. If the approved route is slow or unusable, people will paste into another tool. Give the team a usable public/synthetic sandbox, a governed internal lane, a fast stop-and-ask channel, approved redaction or synthetic-data methods, and examples for code, documents, screenshots, logs, designs, recordings, and customer support. Test the route with realistic tasks before production access.
Preserve meaningful human review and public-facing disclosure
The State Gen-AI policy requires agency outputs to be reviewed and fact-checked by accountable personnel. It directs personnel to check for inaccurate, private, outdated, harmful, or offensive material. It also calls for public-facing generated content to be clearly labeled and for details of review and editing—how and by whom—to be provided.
Meaningful review is not a checkbox after publication. The reviewer needs:
- the original purpose and audience;
- the material sources and prompt or instruction context;
- an independently usable way to verify facts, calculations, citations, code, and permissions;
- known limitations, uncertainty, security findings, and failed tests;
- authority and time to reject or correct the result;
- a record of the edits and accepted version; and
- a correction, escalation, or human-assistance route after release.
For generated code, require the engineer to understand the behavior, dependencies, licenses, vulnerabilities, failure modes, and operating assumptions before merge. Run the normal review, test, security, and deployment path. An AI assistant does not become the authorizer of a production change.
For resident-facing chat or automated support, preserve a visible human escalation route. Test ambiguous language, accessibility, language switching, unsupported requests, account authentication, sensitive disclosures, emergency statements, prompt injection, hallucinated policy, refusal, and escalation. Do not advertise a human path that is not staffed or cannot receive the context needed to help.
For public content, keep the disclosure accurate to the accepted object. A generic footer saying “AI may be used” does not explain which material was generated, the human role, or how the content was checked. At the same time, do not publish a sensitive prompt or restricted source merely to demonstrate transparency. The reviewer and records owner should determine a useful public statement and preserve restricted supporting evidence in the appropriate system.
Treat state records as custody, retrieval, and migration work
Prompts, generated databases, outputs, edits, reviews, and approvals can become public records in covered agency use. The State Gen-AI policy tells agencies to consult legal counsel and records custodians. The Data Policy points to State Commission of Public Records schedules. The electronic-records rule emphasizes reliability, accuracy, security, accessibility, confidentiality, retention, and the ability to preserve or migrate electronic records as technology changes.
An outsourcing contract should translate those needs into system behavior:
- identify the record custodian and the person who decides whether an object is a record or non-record;
- map record series and trigger events to the applicable current schedule rather than inventing one project-wide retention period;
- preserve native or approved formats, metadata, relationships, versions, approvals, and search fields needed to retrieve a transaction;
- prevent supplier chat, ticket, model, or repository settings from deleting required records before transfer;
- distinguish authoritative records from convenience copies so the buyer does not create uncontrolled archives;
- carry confidentiality and access restrictions into exports, backups, migrations, and replacement systems;
- document the system and procedures that establish record reliability, accuracy, security, and process integrity;
- test export and restore before the supplier becomes the sole practical custodian;
- suspend ordinary disposition for a valid audit, investigation, public-records request, litigation hold, or other applicable preservation duty; and
- require authorized, evidenced disposition after retention is satisfied.
Avoid PDF-only evidence dumps when the records depend on structured relationships, searchable fields, audit trails, or machine-readable data. Require an export dictionary, stable identifiers, integrity checks, timestamps, access history where needed, and a reconstruction exercise. A folder of screenshots may show that screens existed without preserving the transactions they represented.
Technology migration belongs in the initial design. If a model platform, hosted repository, work-management tool, or proprietary file format changes, the buyer should know which current and historical objects must move, how integrity will be checked, what becomes human-readable, and who approves disposal of the old copy. Test one migration-shaped exit during the pilot rather than waiting for a platform shutdown.
Keep private-business breach duties in their own lane
New Mexico’s Data Breach Notification Act and the executive-agency policies have different scopes. The enacted Act expressly exempts the State of New Mexico and its political subdivisions. A private company or other person should have qualified counsel determine whether and how the Act applies to its facts, regulated-sector exemptions, information, role, and incident.
For a covered private path, the final enacted text includes several outsourcing-relevant controls. A person that owns or licenses covered personal identifying information must maintain reasonable security procedures appropriate to the information. A person disclosing such information under a service-provider contract must require the provider by contract to maintain appropriate security. The Act also creates notification paths for owners or maintainers, includes an investigation and significant-risk determination, specifies outside timing and notice content, and provides an Attorney General and consumer-reporting-agency path at the stated threshold.
Do not turn the statutory outside limit into the supplier’s initial alert deadline. The buyer needs facts early enough to contain the event, determine scope, assess risk, coordinate counsel and insurers, preserve evidence, restore service, and make any required notices. A strong supplier clause requires immediate escalation of a credible event or loss of control, followed by staged evidence.
| Incident stage | Supplier output | Buyer-owned decision |
|---|---|---|
| Credible signal | Discovery time, reporter, affected service, safe containment already taken, known access or acquisition facts, and urgent support contact | Activate response, preserve systems, authorize containment, separate speculation from confirmed facts |
| Initial boundary | Owner/maintainer role, systems, accounts, people, locations, data classes and readability, logs, provider and subprocessor involvement | Set investigation scope, protect evidence, decide service isolation and business continuity |
| Decision packet | Timeline, affected New Mexico residents where relevant, personal identifying information elements, acquisition and misuse evidence, encryption or redaction facts, risk analysis inputs, remedial actions, gaps | Qualified owner makes the legal risk, notice, regulator, law-enforcement, insurer, customer, and communications decisions |
| Recovery and closure | Restored versions, credential and key actions, monitoring, root-cause evidence, corrective work, validation, residual risk, retained artifacts | Approve restoration, notification completion, lessons, control changes, retention, and authorized closure |
The supplier should not announce that “no breach occurred” unless it owns that decision under applicable law and the contract. It can provide a technical assessment and supporting facts. Preserve dissent, uncertainty, unavailable logs, and changes in the conclusion. A fast, incomplete record is useful when it is clearly labeled; a confident but unsupported conclusion is not.
Put restricted research and government-contractor work behind a separate enclave
New Mexico is home to significant research, energy, aerospace, public-sector, and federal activity, but location alone does not tell a buyer whether a particular project is controlled, classified, export restricted, CUI, subject to a federal clause, or eligible for non-U.S. performance. Do not use local industry identity as authorization.
For a potentially restricted work package, stop before sharing specifications or sample data. Identify the exact contract, award, agency direction, classification guide, data category, marking, license, regulation, flow-down, security requirement, cloud authorization, person restriction, location restriction, or release procedure that applies. Obtain a decision from the buyer’s qualified contracting, security, export, legal, and program owners.
Then split the architecture:
- Open commercial lane: work deliberately cleared for an eligible international team, using sanitized requirements, public standards, synthetic data, isolated interfaces, and buyer-defined acceptance tests.
- Controlled enclave: restricted artifacts, identities, systems, production data, credentials, operations, and decisions accessible only to approved entities, persons, locations, and devices.
- Evidence bridge: allowed schemas, interface contracts, tests, signed artifacts, findings, and release packets that can cross after review without carrying restricted context.
- Buyer authority: the person or board that approves each transfer, exception, deployment, and change in scope.
Do not “sanitize” by renaming a file. Prove that requirements, metadata, screenshots, logs, models, comments, test fixtures, issue histories, and combinations cannot reveal the restricted information. Maintain a return route for findings that cannot safely cross. Record why a package was cleared and which version that decision covered.
Schedule the actual New Mexico location and delivery city
Most New Mexico buyer locations use the IANA America/Denver zone. Recurring schedules must still be calculated with maintained time-zone data because daylight-saving transitions can change the offset relative to countries or regions that change clocks on different dates or do not change them.
Do not promise “Mountain Time overlap” without dates. Ask each provider for the legal entity, named delivery city, maintained IANA zone, normal local working hours, holidays, on-call path, and any seasonal schedule. Generate a dated overlap table for the pilot and the next two clock changes.
Use three operating windows:
- Build window. The international team can implement, test, document, and prepare questions without release authority.
- Decision window. Named New Mexico owners and the provider’s leads review risks, resolve ambiguity, accept work, and authorize controlled actions.
- Emergency window. A tested, always-current route for incidents, credential compromise, unsafe operations, material data loss, or urgent service recovery.
Limited overlap is workable when the handoff is complete. Each packet should state the accepted baseline, work performed, evidence, open questions, blocked items, environment and data used, tests, risks, proposed next action, and exact decision needed. The next person should not reconstruct intent from chat fragments.
Pilot one clock transition if the relationship is material. Verify calendar invitations, pager routing, maintenance windows, release freezes, staffing, and customer promises. A provider’s sales office zone is irrelevant if the people doing or approving the work are elsewhere.
Compare countries only after defining the containment zone
Country selection should follow work classification. Otherwise the buyer compares generic hourly rates for teams that may not be allowed to perform the same work.
Build a named-team, named-city shortlist using at least these dimensions:
| Dimension | Evidence to compare |
|---|---|
| Eligibility | Sanctions and export review, contract restrictions, data and cloud location, customer commitments, government or funding clauses, and actual people and systems |
| Capability | Demonstrated comparable work, code or design exercise, architecture judgment, domain knowledge, communication, testing, security, and references the buyer can verify |
| Data and AI path | Approved tools and accounts, model providers, data classes, regions, retention and training settings, prompt controls, logs, human review, and subprocessor chain |
| Collaboration | Delivery city and zone, dated overlap, written handoff quality, decision cadence, holidays, escalation, travel assumptions, and backup ownership |
| Rights | Contracting entity, worker and subcontractor agreements, pre-existing material, open-source and dataset governance, destination-country rules, transfer and license terms |
| Reliability | Key-person coverage, infrastructure, connectivity, geopolitical and weather scenarios, recovery, financial continuity, access revocation, and replacement plan |
| Cost | Loaded labor, management, security, tools, model usage, cloud, tax advice, travel, compliance, rework, transition, and expected incident or delay cost |
| Exit | Buyer-controlled repository and accounts, portable formats, documentation, credentials, model and data export, knowledge transfer, deletion/return, and tested replacement |
Nearshore teams can increase live overlap and travel convenience. Offshore teams can offer deeper specialist pools or follow-the-sun capacity. Neither label proves quality, security, affordability, or eligibility. Score the proposed entity and people against the contained work.
Use WIPO’s directory and qualified destination-country counsel for intellectual-property questions. A New Mexico assignment clause does not automatically resolve contributor, employer, moral-rights, invention, software, database, model, or subcontractor issues in every country. Preserve the rights chain for the actual team and artifacts.
Normalize complete cost instead of comparing rates
Compare a common unit such as cost per accepted pilot outcome, stable release, supported workflow, or quarter of operated service. A low hourly rate can be expensive when the buyer supplies heavy supervision, repeats requirements, rebuilds insecure work, or cannot exit.
Use this planning equation:
complete cost = supplier fees + buyer management + tooling and infrastructure + AI/model usage + security and compliance + tax and legal review + travel + expected rework + delay exposure + transition and exit
Document the units and uncertainty. Separate one-time transition from recurring delivery. Model a base, favorable, and adverse case. Include usage-driven model and cloud spend, foreign-exchange assumptions where relevant, senior reviewer time, overlap premiums, vendor-management work, accessibility and security testing, record export, and replacement assistance.
Do not treat a range on this page as a quote. Ask finalists to price the same work package, evidence set, staffing assumptions, environments, AI policy, incident obligations, support window, acceptance criteria, and exit exercise. Reject proposals that omit buyer work while advertising “fully managed” delivery.
Run a paid containment-zone pilot
Choose a work package that exercises the risky boundary without exposing production or restricted information. Good candidates include a synthetic-data integration, isolated service, evaluation harness, accessibility remediation, migration prototype, public-data workflow, or internal tool with representative but non-sensitive fixtures.
The pilot should last long enough to test ordinary flow, a difficult decision, a denied request, an incident drill, and an exit. Define outcomes rather than staff activity.
Pilot acceptance gates
- Identity gate: every person, entity, country, city, system, tool, model provider, and subprocessor matches the approved path.
- Classification gate: the team correctly recognizes public, internal, sensitive, restricted, synthetic, and unclear material and follows the stop route.
- Transformation gate: source, prompt or instruction, configuration, dependencies, tests, human edits, and accepted output remain reconstructable.
- Human-review gate: the named reviewer can independently verify, reject, correct, and explain the work.
- Security gate: least privilege, secrets, dependencies, logging, vulnerabilities, backups, and recovery meet the work order.
- Record gate: required evidence is retrievable in the approved format and transient material follows the authorized retention path.
- Incident gate: an exercise delivers a staged, decision-ready packet through the correct urgent contacts without unauthorized public communication.
- Clock gate: the team completes one ordinary handoff and one urgent escalation in the dated operating model.
- Exit gate: a buyer or replacement operator builds, tests, runs, and understands the result from exported artifacts after supplier access is revoked.
Fail the pilot for hidden personal AI accounts, undisclosed workers, unexplained model or region changes, sensitive prompt data, buyer-inaccessible evidence, supplier-only production credentials, fabricated tests, unreviewed public content, or an export that cannot recreate the accepted result.
Put the controls in the RFP, contract, and work order
The RFP should request evidence without asking providers to expose another customer’s confidential material. Ask for redacted samples, live demonstrations, policies, architecture, tool and subprocessor inventories, incident exercises, and the named proposed team.
Require the contract and work order to address:
- exact legal entities, countries, delivery locations, named or role-bound people, subcontract approval, and change notice;
- work packages, prohibited uses, classification, data fields, systems, environments, regions, and production boundaries;
- approved AI tools, account types, models, retention and improvement settings, plugins, connectors, logging, and provider-change review;
- security, access, device, identity, dependency, secret, vulnerability, backup, monitoring, and recovery controls proportionate to the work;
- human review, acceptance, disclosure, release, correction, and escalation authority;
- source and data provenance, pre-existing material, third-party components, destination-country rights, transfer, license, and reuse restrictions;
- record ownership, custody, schedules, formats, metadata, retrieval, preservation, migration, hold, and authorized disposition where applicable;
- immediate incident escalation, safe containment, preserved evidence, staged updates, investigation cooperation, recovery, and buyer-owned notification decisions;
- service levels for decisions and evidence, not only server uptime;
- complete pricing, usage charges, pass-throughs, travel, support, transition, and rate-change rules; and
- termination assistance, export specifications, credential transfer, knowledge transfer, access revocation, verified return/deletion, and survival terms.
Avoid a clause that says the supplier may use “industry-standard AI” at its discretion. The provider, model, account, region, settings, data, and purpose can materially change the path. Create a lightweight approval route for low-risk changes and a full review route for material ones.
Design exit before access
An exit packet is not a final zip file. Keep it current throughout delivery:
- buyer-controlled repositories, domains, cloud tenants, model or API accounts where practical, and billing visibility;
- source, build and deployment definitions, dependency locks, infrastructure code, schemas, tests, fixtures, architecture decisions, and runbooks;
- data dictionary, provenance, classification, transformation history, authoritative exports, integrity checks, and retention treatment;
- model/provider identity, prompts or instruction templates, retrieval configuration, evaluation sets and results, limitations, monitoring, and rollback;
- inventory of supplier and subprocessor identities, accounts, credentials, tokens, keys, devices, environments, and access groups;
- accepted releases, public disclosures, human approvals, incidents, corrective work, unresolved risks, and applicable records;
- licenses, rights schedules, third-party terms, attribution, assignments, and exclusions; and
- return, deletion, backup expiry, account closure, credential rotation, record transfer, and continuing obligations.
Exercise exit with a replacement person who did not build the system. They should reproduce the build, deploy to an isolated environment, restore representative data, find a decision record, rotate a credential, handle a simulated failure, and explain the next safe release. Score missing knowledge as a deliverable defect.
For a hosted AI or proprietary platform, test an alternative that matches the business need, not necessarily every internal feature. Export source inputs, accepted outputs, configurations, evaluations, prompts where required, embeddings or indexes where portable and authorized, and enough lineage to assess replacement behavior. Record dependencies that cannot be exported and the buyer’s chosen contingency.
Frequently asked questions
Can a New Mexico company outsource software development outside the United States?
Yes, when its contracts, customer commitments, data, export and sanctions review, funding or government terms, security requirements, rights chain, and operating risk allow the actual entity, people, countries, systems, and work. New Mexico location alone neither prohibits nor authorizes international delivery.
Does the New Mexico executive-agency AI policy apply to every private company?
No. The cited policy governs the executive-agency context described in the document. A private buyer can voluntarily use its containment logic, but it should not present the State policy as a universal private-sector mandate.
Can State personnel put non-public information into a public generative-AI tool?
The State policy says agency personnel shall not place non-public information into publicly available Gen-AI systems for which DoIT or the agency lacks a current license agreement. It also conditions non-public-data processing on security review, classification and sensitivity labels, and prior written authorization from OCS and DoIT. The covered agency must apply the complete current policy to its facts.
Is a paid enterprise AI account automatically approved for sensitive data?
No. A license does not settle classification, purpose, security review, region, retention, provider use, plugins, subprocessors, authorization, records, human review, or exit. Approval should identify the exact service and allowed data path.
Are prompts and AI outputs public records?
They can be in covered government use. The State policy says a Gen-AI solution may record prompts, create databases, or produce outputs that constitute public records. The agency’s counsel and records custodian should classify the objects and apply the correct schedule and preservation path.
Must public-facing state AI content be reviewed and disclosed?
The cited State policy requires accountable human review and fact-checking of Gen-AI outputs and says public-facing generated content must be clearly labeled with review and editing details. The agency should preserve a useful disclosure without exposing protected prompt or source material.
Does New Mexico have one data classification for all organizations?
No. The four-level Published, Internal, Sensitive, and Restricted framework comes from the cited executive-branch Data Policy. Other organizations need their own authoritative classification mapped to their laws, contracts, customers, systems, and risk.
What should a supplier do first after a possible personal-information incident?
Use the contracted urgent route, take only pre-authorized safe containment, preserve volatile evidence, identify the affected service and role, and give the buyer a clearly labeled initial fact packet. Do not delay the first alert until every legal conclusion is final.
Is the New Mexico Data Breach Notification Act the same as the State agency incident path?
No. The enacted Act has its own private-person scope and expressly exempts the State and political subdivisions. State agencies follow their applicable cybersecurity, data, records, and incident authorities. Qualified owners should map each event to the correct path.
Is an overseas team appropriate for laboratory or federal-contractor work?
Only after qualified owners determine the exact work is eligible for those entities, persons, locations, systems, and tools. Split open commercial work from controlled work and use a reviewed evidence bridge; do not infer eligibility from the buyer’s industry or from this guide.
Which country is best for a New Mexico software team?
There is no universal answer. Define the work and containment zone, then compare eligible named teams on capability, city-specific overlap, security, AI and data path, rights, complete cost, continuity, and exit. Nearshore and offshore are sourcing patterns, not quality grades.
What is the best first project?
A bounded, paid project with representative complexity and synthetic, public, or otherwise approved data is best. It should test classification, AI-tool discipline, human review, written handoffs, incident escalation, record export, and replacement operation—not merely produce a demo.
Recommended next step
Write a one-page containment brief before requesting proposals. Name the outcome, excluded uses, data and artifact classes, supplier locations, systems, AI tools, decision owners, records, incident route, clock window, acceptance evidence, budget unit, and exit test. Use it to shortlist eligible teams, then run the paid pilot against the same gates. If the provider cannot make the transformation and custody path visible before access, the work is not ready to outsource.
Evidence ledger
Sources used on this page
- State of New Mexico Generative AI Use Guidelines Policy, version 1.0 — New Mexico Department of Information Technology. Supports: Current June 2025 executive-agency guidance for NIST-based assessment, human fact-checking, public-facing disclosure, non-public data restrictions, records, governance, monitoring, training, security review, classification, and prior written authorization. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Generative AI Use Guidelines Policy Quick Guide — New Mexico Department of Information Technology. Supports: Official scenario guidance for state personnel covering human review, sensitive information in prompts, code understanding, audiovisual publication review, and human escalation for resident-facing automation. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- State of New Mexico Data Policy, version 1.0 — New Mexico Department of Information Technology. Supports: Current March 2026 executive-branch policy for data quality, minimization, stewardship, source attribution, reconstructable methods, retention, access control, security review, and the four-level Published, Internal, Sensitive, and Restricted classification framework. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- New Mexico Administrative Code 1.13.3 — Management of Electronic Records — New Mexico State Records Center and Archives. Supports: Official electronic-records rule addressing reliability, accuracy, security, retrieval, confidentiality, retention, preservation, custody, media and technology migration, and documented evidence about record-producing systems. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Functional Retention and Disposition Schedules — New Mexico State Records Center and Archives. Supports: Official State resource explaining that retention schedules are filed as rules, that 1.21.2 NMAC is the functional schedule, and that custodians and legal counsel participate in classifying retention and disposition. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- House Bill 15 final — Data Breach Notification Act — New Mexico Legislature. Supports: Official final enacted text for secure disposal, reasonable safeguards, service-provider contract requirements, resident and owner-or-licensee notification, risk determination, timing, content, regulator threshold, enforcement, exemptions, and the State and political-subdivision exemption. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- 2017 Regular Session HB 15 legislative history — New Mexico Legislature. Supports: Official history confirming that HB 15 was signed, chaptered as Chapter 36, and is not merely a proposal. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Artificial Intelligence Risk Management Framework — National Institute of Standards and Technology. Supports: Maintained federal methodology for governing, mapping, measuring, and managing AI risks across design, development, deployment, use, evaluation, and retirement. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Secure Software Development Framework — National Institute of Standards and Technology. Supports: Maintained secure-development methodology for organizational preparation, protected software and environments, well-secured releases, provenance, vulnerability response, and evidence shared between producers and acquirers. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- IANA Time Zone Database — Internet Assigned Numbers Authority. Supports: Maintained time-zone identifiers and transition rules for calculating dated overlap between New Mexico buyer locations and proposed international delivery cities. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Directory of Intellectual Property Offices — World Intellectual Property Organization. Supports: Official destination-country intellectual-property office links for researching software, invention, copyright, design, model, and contributor-rights questions without assuming a New Mexico contract resolves every jurisdiction. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
Next scheduled review: October 15, 2026. Corrections: hello@outsourcing.ai.
