Executive Briefing Series

Robin Hastings

Executive Briefing Series

Practical guidance for library boards making technology decisions.

Technology decisions affect the library's ability to serve its community, protect privacy, and use public resources responsibly. These short briefings give trustees a starting point for conversations with their director: what matters, what questions to ask, and what a useful next step could look like.

Use a briefing before a budget discussion, policy review, or vendor decision. Read it together, choose the questions that fit your library, and ask what evidence would help you make the decision.

Briefing 01

What Boards Need to Know About AI

Use AI policy to protect library values, support staff judgment, and guide patron education. Understand the Human–AI–Human workflow and the board's role in setting boundaries, supporting training, and reviewing policy.

Read Briefing 01 online

Download Briefing 01 (PDF, 1 page)
Briefing 01

What Boards Need to Know About AI

The decision facing the board

What guidance will help staff use AI responsibly while protecting the library's values and keeping people accountable for the work?

What boards need to know

AI policy gives staff a shared basis for deciding whether and how to use AI. It should connect everyday decisions to privacy, intellectual freedom, equitable access, transparency, and professional responsibility. A template can help start the conversation, but the library needs to adapt it to its staff, services, and community.

The MPLA/NM presentation centers a Human–AI–Human workflow: a person defines the task, AI assists, and a person reviews the output and takes responsibility for it. Approval to use a tool does not remove the need to verify its work. The source policy template also keeps final employment, discipline, and evaluation decisions with people and excludes confidential patron or staff information from unapproved tools.

Implementation needs attention alongside policy language. Staff need usable examples, a clear tool-approval process, training, and someone to ask when they are unsure. Patron education matters too: helping people understand AI's limitations, recognize privacy risks, and evaluate its output is part of the approach presented in these sessions.

The board can focus its discussion on values, boundaries, resources, and review. Operational detail can live in procedures where that fits the library's governance structure. Set a review schedule and make sure the policy connects to existing privacy, technology-use, collection, and vendor practices.

Source: Robin Hastings, Thinking Through AI Policy for your Library, MPLA/NM presentation: Guiding Principles, Human–AI–Human Workflow, Prohibited Uses, Tool Approval, Staff Training, Patron Education, Living Document, and AI in Other Policies.

Questions to ask

  • What are staff and patrons already doing with AI, and where is guidance unclear?
  • Which uses would we permit, restrict, or prohibit, and why?
  • How will staff verify AI-assisted work and protect confidential information?
  • Who approves tools, answers questions, and recommends policy changes?
  • What time and support will staff need for training and patron education?

A practical next step

Ask the director to bring a short policy summary and two realistic examples to a board discussion. Use them to test the proposed boundaries before reviewing the full policy. Agree on responsibility for implementation and a review schedule.

Illustrative discussion: AI helps draft a program description from public information. A staff member checks the details, language, and accessibility before using it. Contrast that with asking AI to make a final personnel evaluation: the source template keeps that judgment with people. What guidance would help staff recognize the difference?

Download Briefing 01 (PDF) · Back to series overview

Briefing 02

Library Technology Risk

The decision facing the board

What level of service disruption can the library tolerate, and what resources will it commit to reducing that risk?

What boards need to know

Start with a service: checking out materials, providing public internet access, or paying staff. Ask what happens if the technology supporting it becomes unavailable. This makes a technical discussion concrete enough to connect to the library's priorities.

NIST's Cybersecurity Framework treats governance as part of managing cybersecurity risk. Its small-organization guide recommends identifying critical systems, assigning responsibility, maintaining safeguards, testing backups, and preparing response and recovery plans. The framework is voluntary guidance, not a certification that a library is secure. Source: NIST SP 1300, overview and Govern through Recover sections.

For a board discussion, ask the director to translate the most significant risks into service consequences and funding choices. A useful report explains what is already addressed, what remains unresolved, and which decisions require board action. Detailed technical work can remain with the people responsible for operating the systems.

Questions to ask

  • Which interrupted service would cause the greatest difficulty for our community?
  • What could staff continue doing while that service is unavailable?
  • When was recovery last tested, and what did the test reveal?
  • Where does responsibility sit with the library, its parent institution, a consortium, or a contractor?
  • Which unresolved risk needs a policy or budget decision from us?

A practical next step

Request a one-page discussion paper covering three priority service risks. For each, include the likely consequence, current protection, responsible role, proposed improvement, and decision needed. Agree with the director on when to revisit it.

Illustrative discussion: If the catalog is unavailable for two days, how will patrons borrow materials, what information will staff record, and how will normal service resume? Work through that scenario before deciding what recovery investment is adequate.

Download Briefing 02 (PDF) · Back to series overview

Briefing 03

AI Privacy

The decision facing the board

What information may staff use with AI, for which purposes, and under whose approval?

What boards need to know

An AI policy needs examples staff can apply during ordinary work. Drafting a program announcement from public information and summarizing an identifiable patron's reference conversation should not receive the same automatic approval.

NIST's Generative AI Profile identifies privacy risks including unauthorized disclosure and the possibility of connecting data back to individuals. It recommends evaluating third-party AI risks and monitoring generated content for sensitive information. These risks warrant reviewing the particular use, data, and product rather than treating every AI tool as equivalent. Source: NIST AI 600-1, section 2 and actions GV-6.1-009 and MP-4.1-001.

ALA's vendor guidance recommends collecting only the user data needed for a specific task and addressing retention and permitted use in agreements. Apply those questions when reviewing AI services. Source: ALA, Data Integrity and Security and Agreements sections.

Questions to ask

  • Which uses are approved, and how will staff recognize an unapproved use?
  • Could an uploaded document or connected account expose information beyond the intended task?
  • What do the applicable terms say about storage, human access, model training, and deletion?
  • Who checks the output and handles a suspected disclosure?
  • Can staff accomplish the task with public or fictional information, or without AI?

A practical next step

Ask the director to bring three ordinary workflows to a policy discussion: one suitable for approved AI assistance, one requiring further review, and one that should remain outside the tool. Document the reason for each boundary and who can authorize a change.

Illustrative discussion: A staff member wants help responding to a reference question. A proposed safer starting point is to create a fictional example that captures the research need without copying the patron's correspondence. Removing a name alone should not be treated as proof that the original message is safe to share.

Download Briefing 03 (PDF) · Back to series overview

Briefing 04

Vendor Evaluation

The decision facing the board

Does the proposed service solve a defined library problem well enough to justify its cost, obligations, and risks?

What boards need to know

Begin the discussion with the need. A demonstration can show appealing features without establishing that the service fits the library's staffing, community, or budget. Ask for a comparison that includes continuing the current approach, improving an existing service, and purchasing something new.

For privacy, ALA recommends including requirements in the purchasing process and addressing data use, retention, ownership, security, and incident response in vendor agreements. Its guidance also addresses deleting user data when the relationship ends. Source: ALA, Choosing a Third-Party Vendor, Agreements, and Ending the Library-Vendor Relationship sections.

Those provisions are one part of the decision. The board also needs a clear account of who will implement the service, what success will look like, and what the library will do if the service disappoints.

Questions to ask

  • What specific service problem are we trying to solve, and how will we recognize improvement?
  • Has staff tested the proposed workflow, including accessibility needs, with representative tasks?
  • What will implementation, training, ongoing support, and eventual migration cost?
  • Which important promises appear in the written agreement, and which remain sales statements?
  • What happens if pricing, ownership, or product features change?
  • Can we obtain usable data and continue service if we leave?

A practical next step

Request a short comparison of the realistic options, with evidence for each major claim. Set the library's essential requirements before scoring attractive features. Where an essential requirement remains unresolved, identify the evidence or contract change needed before proceeding.

Illustrative discussion: A proposed service costs less than the current one but requires substantial staff cleanup after migration. Ask staff to include that work in the comparison and explain what other service would be delayed. The subscription price alone does not answer the purchasing question.

Download Briefing 04 (PDF) · Back to series overview

Robin Hastings · Executive Briefing Series · October 2026