← AI Safety & Governance
SCAIO Policy Brief

Intentional by Design

Five AI guardrails worth building before you need them — for South Carolina legislators, agencies, and boards.

June 2026 · AI Safety & Governance series
Bottom line up front

The most effective AI guardrails are cheap, boring, and installed before they're needed — and almost none of them require new legislation. The five below are governance moves any agency or board can adopt now, using authority it already has. They reduce the risks that are actually reachable at the state and local level, and they cost far less to build in advance than to retrofit after a public failure.

South Carolina is adopting AI across its agencies, schools, courts, and companies. The question is not whether to use it — that's settled — but whether the use is intentional: designed, with the predictable failure points addressed up front, or improvised, with the failures discovered in production.

This brief is deliberately modest. It doesn't propose a sweeping AI law or a new regulatory body. It lists five guardrails that work at the level a state or local decision-maker actually controls — procurement, process, and accountability — and that hold up whether or not the General Assembly passes anything. (For where legislation stands, see SCAIO's Policy Tracker.)

The five guardrails

In rough order of leverage per dollar.

1

A human signs off on consequential decisions

Why: The single highest-stakes failure mode is an automated system denying someone a benefit, a job, a placement, or a claim with no human in the loop. AI is a capable assistant and an unaccountable decider.

In practice: Require that any decision materially affecting a person's rights, benefits, or money be reviewed and owned by a named human before it takes effect — and that the human has the information and time to actually review, not rubber-stamp.

2

Keep an AI inventory — and disclose use

Why: You cannot govern what you cannot see. Most organizations don't know how many AI tools are already in use, on what data, by whom. Disclosure to affected people is the cheapest trust-builder there is.

In practice: Maintain a living list of every AI system in use — tool, vendor, purpose, data touched. Tell the public when an AI system is materially involved in a decision or interaction affecting them. SC's Center of Excellence already models the intake side of this.

3

Evaluate for the actual use — before you switch it on

Why: A model that performs well in a demo can fail badly on your specific population and task. Evaluation is most of the deployment job; skipping it is just hoping. Leading AI research tools have shown hallucination rates of 17–33% on factual questions — the binding constraint is testing, not vendor promises.

In practice: Before deployment, test the system against realistic cases from your own context, including edge cases and the populations most at risk of error. Document the result. Re-test after major model updates.

4

Put the requirements in the contract

Why: Procurement is the most underused safety lever government has. What you forget to require at contract time, you cannot demand later. The leverage is highest before you sign.

In practice: Bake into vendor contracts: accuracy/performance certification for your use, audit and documentation rights, data-use limits (no training on your data without consent), incident notification, and an exit path. See the checklist below.

5

Name an owner and give people an appeal path

Why: Accountability doesn't disappear because a decision was AI-assisted — it tends to evaporate unless someone is explicitly assigned it. And a person on the wrong end of an automated error needs a real way to contest it.

In practice: For each significant AI deployment, designate an accountable official, and publish a plain, usable channel for people to flag and appeal an AI-influenced decision. Track what comes in — appeals are your cheapest early-warning system.

Five questions to ask any AI vendor — before signing
  • What exactly was this evaluated on, and how does that match how we'll use it?
  • What are its known failure modes, and how does it fail — loudly, or silently?
  • What happens to our data? Is it used to train your models? Can we turn that off?
  • What audit and documentation rights do we get if we need to investigate a bad output?
  • If we leave, what do we keep, and how hard is it to switch?

Why "before you need them"

Every one of these is cheaper to install in advance than to retrofit after something goes wrong. A human-review requirement written into a workflow at design time costs a line in a procedure document; added after a wrongful-denial story breaks, it costs a crisis, a clean-up, and the public trust that's hardest to rebuild. Intentional implementation isn't caution for its own sake — it's the lower-cost path, and it's the one that lets a state capture AI's benefits without absorbing the avoidable harms.

About this brief: Part of SCAIO's AI Safety & Governance series, which champions AI's benefits while taking its risks seriously. The guardrails reflect widely-recommended governance practice (NIST AI Risk Management Framework; OMB M-24-10; state procurement guidance) adapted for South Carolina's state and local context. Reliability figures from Magesh et al. (2025, JELS). Pairs with the founding editorial, Between Doom and Denial, and SCAIO's Policy Tracker. SCAIO welcomes correction and adaptation for specific agencies or boards.