SIGEN Sets Controls for the Use of AI in the Public Sector
The guidelines establish controls for the responsible use of AI in the public sector, focusing on risk management, human oversight, and accountability.
The General Audit Office (SIGEN) has issued the Artificial Intelligence Controls Guide, which sets out guidelines for managing the risks associated with the use of artificial intelligence tools and systems by entities of the federal public sector. The guide adopts a risk-based approach and seeks to align AI initiatives with institutional objectives; compliance with applicable regulations; and the principles of integrity, transparency, and accountability in public administration. Its provisions complement the General Internal Control Standards for the National Public Sector and the Internal Control Standards for Information Technology, approved through SIGEN Resolutions 172/2014 and 87/2022.
One of the document’s core principles is that while AI may help in the execution of certain tasks, responsibility for decisions and their outcomes cannot be delegated. Such responsibility remains with the public officials and organizational structures implementing the technology. Accordingly, the guide contemplates the implementation of formal accountability mechanisms, traceability of automated decisions, and effective human oversight.
The guide distinguishes between two categories of AI use. The first one encompasses generative AI tools used individually by employees of the public sector, such as ChatGPT, Copilot, Gemini, or DALL·E, without integration into institutional systems. In these cases, the guide recommends adopting institutional usage policies, evaluating the tools with the involvement of technology and legal departments, reviewing their terms and conditions, preventing the use of unauthorized applications, and training personnel on their risks and limitations.
It also requires implementing controls to prevent the input of non-public, confidential, or personal information, including anonymization guidelines and measures to ensure compliance with the Personal Data Protection Law 25326. Where AI is used to support significant decisions, its output must remain subject to human review. In addition, the guide considers it a good practice to disclose when content has been generated or produced with AI.
The second category covers AI systems embedded in organizational processes, applications, or decision-making activities, for which a prior assessment of feasibility and suitability must be conducted. Public entities must also justify the appropriateness of using AI; identify those responsible for the project; and verify the quality, representativeness, integrity, and provenance of the data used. They are also required to prevent bias, protect personal data and intellectual property rights, conduct testing in secure environments, and periodically monitor the model to ensure that its performance does not deteriorate over time.
These systems must maintain records that enable the reconstruction of operations, identification of responsible parties, and monitoring of configuration changes. The guide also requires outputs to be transparent and explainable, particularly where individuals may be affected, and states that public officials must review critical decisions.
In addition, the guide includes measures to prevent attacks through malicious data inputs, regulate the procurement of cloud services and other external providers, and record technical or ethical incidents. Agreements with third parties must incorporate the security, auditability, and control requirements established by each agency.
Through these measures, SIGEN incorporates the use of AI into the internal control framework of the federal public sector and establishes a reference framework for future audits. The objective is to promote innovation and improve public sector efficiency without compromising security, information protection, transparency, or the accountability of public authorities.
This insight is a brief comment on legal news in Argentina; it does not purport to be an exhaustive analysis or to provide legal advice.