Skip to main content
Gain AmericaGet in touch

Government AI Deployment in North Carolina: Contracts & Staffing

Government AI deployment in North Carolina: NCDIT procurement, the state's Responsible Use Framework, GovRAMP path, Research Triangle talent, and staffing public-sector AI.

By Gain America, Enterprise AI Advisory · Updated 2026-07-28

Government AI deployment in North Carolina runs through two gates that have nothing to do with the model: procurement administered by the NCDIT Statewide IT Procurement Office, and a governance regime — the state's Responsible Use of Artificial Intelligence Framework — that applies to any system capable of affecting North Carolinians' rights, opportunities, or access to services.

North Carolina has moved faster than most states to build the plumbing for public-sector AI. The Department of Information Technology (NCDIT) published a formal Responsible Use of AI Framework in August 2024, Governor Josh Stein signed Executive Order 24 in September 2025 to stand up an AI Leadership Council and a centralized NC AI Accelerator, and the state sits atop one of the deepest AI talent pools in the country in the Research Triangle. For agencies and the integrators serving them, the model is the easy part; procurement, authorization, and staffing are where programs stall. Gain America closes the last of those gaps — we staff and deploy the forward-deployed engineers, MLOps teams, and public-sector-ready delivery talent that get North Carolina AI systems into production without the frontier-lab salary load the state cannot carry.

The North Carolina state AI landscape: NCDIT, the AI Accelerator, and the Responsible Use Framework

North Carolina's AI apparatus is centralized under NCDIT in a way many states have not achieved. NCDIT sets statewide technology and security standards, runs the Statewide IT Procurement Office, and owns the state's AI governance framework. In August 2024 it published the North Carolina State Government Responsible Use of Artificial Intelligence Framework — a set of principles, practices, and guidance for agencies deploying AI while protecting the sensitive data North Carolinians hand to the state. The framework explicitly applies to "all systems that use, or have the potential to use, AI and have the potential to impact North Carolinians' exercise of rights, opportunities, or access to critical resources or services."

That scope statement matters. It means a benefits-eligibility model, a DMV chatbot, and a fraud-scoring system all fall inside the same governance envelope, and any government AI deployment in the state has to be designed to the published framework from day one rather than retrofitted to it after a pilot works.

Governor Stein's Executive Order 24 (September 2025) hardened this into institutional structure. It formally launched the statewide framework, created an AI Leadership Council to advise the Governor and agencies, and established the North Carolina AI Accelerator inside NCDIT as the state's centralized hub for AI governance, research, partnership, development, implementation, and training. For a delivery team, the Accelerator is the room where architecture, risk review, and standards converge — and building to what comes out of it is far cheaper than rebuilding after it.

North Carolina made AI governance a design input, not a post-deployment audit. The Responsible Use Framework reaches any system that could affect a resident's access to services — so responsible-AI review belongs in the architecture from the first sprint, not the last.

NC's responsible-AI guidance for state agencies

The framework rests on seven guiding principles that form a blueprint for ethical AI use across state government. Critically, they are operational, not aspirational: agencies must regularly test their AI applications against the principles, and if an application does not perform as intended or violates them, mechanisms must exist to modify, replace, or deactivate it. That "modify, replace, or deactivate" requirement is an engineering mandate — it presupposes evaluation harnesses, monitoring, and rollback paths that most pilots never build. Standing them up is where agent evaluations in production and disciplined AgentOps observability stop being nice-to-haves and become procurement-relevant deliverables.

North Carolina also maintains a distinct policy for publicly available generative AI. It gives employees clear expectations on legal, responsible, and ethical use: personal information may not be entered into public GenAI tools, and disclosure is required when publicly available generative AI creates substantive content — including a citation naming the system, model type, and version. For an agency building on top of commercial models, that policy shapes both data handling and the audit trail a system must produce.

The through-line across all of it is the NIST AI Risk Management Framework, which North Carolina's guidance echoes. Govern, map, measure, and manage is the vocabulary reviewers speak, and a system documented in those terms clears review faster than one that treats governance as paperwork bolted on at the end. This is also why so many NC AI programs favor human-in-the-loop AI agents: a reviewable decision point is the cleanest way to satisfy the framework's accountability principle in a benefits or enforcement context.

NCDIT procurement: statewide contracts, RFPs, and AI-specific terms

North Carolina buys IT — and increasingly AI — through statewide IT term contracts administered by the NCDIT Statewide IT Procurement Office, transacted through NC eProcurement, and governed alongside the Department of Administration's Purchase & Contract division for non-IT categories. Statewide term contracts let agencies, community colleges, universities, and many local governments aggregate demand and buy against pre-negotiated terms, and they are the fastest legal path onto a state system for a qualified vendor.

Two developments make North Carolina an unusually workable market right now. First, NCDIT has been developing standard AI language for RFPs, contract terms and conditions, and generative-AI vendor questionnaires — so transparency and accountability travel with the contract wherever AI touches a vendor product. Second, streamlined procurement procedures have cut the average time to complete a state-agency RFP from roughly 256 days to 62 days. That compression changes the economics of delivery: the gate is no longer the contract, it is whether you can field cleared, qualified engineers the moment the vehicle is in place.

For vendors, the practical routes onto a North Carolina program are three: hold a relevant statewide IT term contract, respond to an agency RFP built on NCDIT's standardized language, or subcontract to a prime already holding a vehicle. Each demands a delivery bench, and staffing that bench is exactly where programs slip. The mechanics of qualifying and pricing are covered in our government AI procurement guide; the talent question is treated below and in our analysis of AI staffing for government contractors and primes.

GovRAMP and the compliance path for NC agency AI

North Carolina does not impose a single blanket statute requiring GovRAMP for every AI system, but the framework — StateRAMP, rebranded to GovRAMP in early 2025 — is the recognized way to demonstrate cloud security to state and local buyers, and NCDIT sets statewide security standards any AI system must satisfy. GovRAMP now covers state, local, tribal, and education buyers under a whole-of-state model, and it has been adopted in some form across more than two dozen states, so a GovRAMP-authorized cloud baseline is the most portable security posture a vendor can bring to North Carolina.

The realistic compliance stack for an NC agency AI system layers three things: a GovRAMP-authorized cloud baseline for the hosting environment, alignment to the NIST AI Risk Management Framework for the model and its decisions, and conformance to NCDIT's Responsible Use Framework for governance and accountability. Where a system touches criminal-justice data — a public-safety or courts use case — the CJIS-compliant AI security policy adds its own controls on top. We map how these frameworks stack, overlap, and translate into engineering work in our deep dive on StateRAMP/GovRAMP AI compliance.

The trap to avoid is treating any of these as a certificate you buy at the end. Continuous monitoring, evidence generation, and re-authorization are ongoing engineering commitments — which is why compliance and staffing are the same conversation. A system that no one can keep authorized is a system that gets switched off.

High-value NC use cases: benefits, DMV, revenue, and public safety

North Carolina's best AI opportunities share a profile: high transaction volume, real backlog, and rule-bound decisions where AI accelerates work while a human stays accountable for the outcome.

  • Benefits and case processing. NC DHHS and the NC FAST eligibility platform handle Medicaid, food and nutrition, and child-welfare casework at enormous scale. Retrieval-grounded assistants over policy manuals and case files — see government RAG knowledge assistants — help caseworkers find the right rule and cut backlog without removing human judgment from an eligibility decision.
  • DMV and licensing modernization. NCDOT and the Division of Motor Vehicles are perennial constituent-experience pressure points. Constituent-service assistants over legacy records, appointment and document triage, and form-completion help are high-visibility wins that citizens feel immediately.
  • Revenue and tax processing. The North Carolina Department of Revenue processes returns and payments at volume and carries a clear fraud-detection and anomaly-scoring mission — a classic pattern where AI flags cases for human review rather than deciding them.
  • Public safety and emergency management. Records search, computer-aided dispatch support, and emergency-management situational tools are high-value, but they carry the heaviest governance load and, where criminal-justice data is involved, CJIS obligations.

Across all four, the pattern that survives NC's responsible-use review is the same: public-sector agentic AI with a human decision point, full audit logging, and an evaluation harness that can prove the system behaves — the difference, in practice, between a pilot and a production program. Many state AI efforts stall precisely here; our analysis of why government AI projects fail traces most of those failures to missing delivery capacity rather than missing technology.

Research Triangle: North Carolina's AI-delivery talent hub

North Carolina's structural advantage over almost every peer state is talent. The Research Triangle — anchored by NC State, Duke, and UNC-Chapel Hill, all within an hour of each other and clustered around Research Triangle Park — is one of the deepest technology talent pipelines in the country. The universities help draw roughly $3 billion in federal R&D funding a year and seed a startup ecosystem, and the regional tech workforce has grown into the tens of thousands, with employers from IBM/Red Hat and SAS to Cisco and specialized AI firms competing for engineers.

That depth cuts two ways. It means the raw talent to deliver public-sector AI exists locally — engineers who understand ML, data engineering, and production systems and who already live near Raleigh, Durham, and Chapel Hill. But it also means a fierce talent war: Raleigh software-engineer compensation now averages well into the six figures, and agencies competing for the same people on state pay scales lose every time. This is the core of the enterprise AI talent gap as it lands on government — the skills are in the market, but not at the price or on the employment terms a state agency can offer.

The answer is not to out-bid the Triangle labor market on permanent salaries — it is to access that talent through an engagement model instead of a headcount model, the staff augmentation versus hiring tradeoff that decides whether a program ships this fiscal year or waits for a req to clear.

Staffing AI delivery for North Carolina government

This is where Gain America fits. Most North Carolina agencies — and many of the integrators holding statewide vehicles — cannot hire frontier-grade AI engineers on state pay scales, and even prime contractors struggle to keep a bench idle between task orders. The gap is closed with forward-deployed engineers and staff augmentation embedded directly into agency or prime-contractor teams.

Gain America staffs public-sector-ready forward-deployed engineers for government, MLOps specialists, and data engineers into North Carolina agencies and the contractors serving them, drawing on the Research Triangle's NC State, Duke, and UNC talent base. The forward-deployed engineer model is a particularly good fit for NC's environment: an FDE sits inside the agency's constraints — its data, its security posture, its responsible-use obligations — and ships working systems against them rather than lobbing a demo over the wall. That embedded posture is exactly what NCDIT's framework, GovRAMP monitoring, and the state's evaluation-and-deactivation mandate all require, because each is a continuous engineering commitment rather than a one-time build.

The states shipping public-sector AI are not the ones with the best models. They are the ones that solved staffing — cleared, qualified engineers embedded where the data and the governance live, available at an engagement rate rather than a permanent salary load.

For agencies, the model converts a hiring problem the state cannot win into a delivery decision it can. For primes and integrators, it means a bench that scales with task orders instead of a fixed cost carried between them — the pattern we detail in our guide to government AI staffing firms. Either way, North Carolina has already built the procurement plumbing and the governance framework; what remains is the talent to deliver against them, on terms the state can actually sustain.

Frequently asked questions

How does North Carolina state government buy AI systems and services?

North Carolina agencies buy AI through statewide IT term contracts and RFPs administered by the NCDIT Statewide IT Procurement Office, with NC eProcurement as the transactional layer. NCDIT has been standardizing AI-specific RFP language, contract terms, and generative-AI vendor questionnaires so that transparency and accountability are built into every procurement where the technology touches a vendor product. Streamlined procedures have cut average RFP completion time for state agencies from roughly 256 days to 62 days, so buying vehicles are no longer the main bottleneck — governance and staffing are.

What is North Carolina's AI governance framework and who runs it?

North Carolina's AI governance is led by NCDIT through the state's Responsible Use of Artificial Intelligence Framework, published in August 2024, and reinforced by Governor Josh Stein's Executive Order 24 (September 2025), which created an AI Leadership Council and the NC AI Accelerator. The framework sets seven guiding principles and applies to any system that could affect North Carolinians' rights, opportunities, or access to critical services. A separate policy governs employee use of publicly available generative AI, prohibiting entry of personal data and requiring disclosure when GenAI produces substantive content.

Does North Carolina require StateRAMP or GovRAMP for agency AI systems?

North Carolina does not impose a single blanket statute mandating GovRAMP for all AI, but GovRAMP — the framework formerly named StateRAMP, rebranded in 2025 — is the recognized way to demonstrate cloud security to state and local buyers, and NCDIT sets statewide security standards any AI system must meet. For an AI system handling constituent data, a GovRAMP-authorized cloud baseline plus alignment to the NIST AI Risk Management Framework and NCDIT's Responsible Use Framework is the practical route to an authorization to operate.

What are the highest-value AI use cases for North Carolina government?

The highest-value North Carolina public-sector AI use cases are benefits and case processing across health and human services (NC DHHS and NC FAST), DMV and licensing modernization at NCDOT, revenue and tax processing plus fraud detection at the Department of Revenue, and public-safety and emergency-management workflows. Each pairs high volume and backlog with rule-bound decisions where AI accelerates work while a human stays in the loop and the state's responsible-use principles govern the design.

How do you staff AI delivery for North Carolina state and local agencies?

Most North Carolina agencies cannot hire frontier-lab AI engineers on state pay scales, so they close the gap with forward-deployed engineers and staff augmentation embedded into agency or prime-contractor teams. Gain America staffs public-sector-ready FDEs, MLOps, and data engineers into NC agencies and the integrators holding statewide vehicles, drawing on the Research Triangle's NC State, Duke, and UNC talent base to deliver capacity at an engagement rate rather than a permanent salary load.

Build it with Gain America

Gain America staffs and deploys the engineers behind enterprise AI — from data center teams to forward deployed engineers.

Talk to our team