MA Public Records Search
← Back to Search

Gerhardson, Jonathan v. Executive Office of Technology Services and Security (SPR 20260890)

Massachusetts Public Records Appeal · Public records appeal decision · Filed 03-13-2026

OpenAppeal

SPR 20260890 is a Massachusetts Public Records Law appeal filed by Gerhardson, Jonathan concerning records held by Executive Office of Technology Services and Security, opened 03-13-2026. Type: Appeal. Status: Open.

Case Details

Case Number
20260890
Case Type
Appeal
Status
Open
Requester
Gerhardson, Jonathan
Custodian
Executive Office of Technology Services and Security
Date Opened
03-13-2026
Date Closed
03-26-2026

PDF Document

Extracted Text (searchable & copyable)

The Commonwealth of Massachusetts William Francis Galvin, Secretary of the Commonwealth Public Records Division Manza Arthur Supervisor of Records March 26, 2026 SPR26/0890 Luke Ferreira, Esq. Assistant General Counsel Executive Office of Technology Services & Security 1 Ashburton Place, 8th Floor Boston, MA 02108 Dear Attorney Ferreira: I have received the petition of Jonathan Gerhardson appealing the response of the Executive Office of Technology Services & Security (Office) to a request for public records. See G. L. c. 66, § 10A; see also 950 C.M.R. 32.08(1). On September 29, 2025, Mr. Gerhardson requested nine categories of records, and on January 19, 2026, Mr. Gerhardson modified his request as follows: 1. Use cases, approval policies All records describing the specific AI use cases that have been developed, are currently being tested, or have been approved for testing within the AI Sandbox, and any internal policies your office may rely on when making these decisions. 2. Agency requests for approval (Other state agency initiated) All notifications and requests for approval submitted by Commonwealth Agencies and Offices to the Commonwealth CTO to procure Generative AI software or services, as required by Section 5.5 of the policy, and any records showing the CTO’s decision. 3. System Architecture & Logging Definitions To better understand the structure of the data you described, and to verify compliance with IS. 022, “Logging and Event Monitoring Standard” and Section 3.8 of the previously provided EOTSS AI Sandbox Terms and Conditions, I request: - Schema Definitions: Used to define the structure of the access logs mentioned in your previous correspondence. (I am requesting the field names/column headers only—e.g., user_id, service_name, timestamp—not the row data). These might include Copies of the AWS Glue Data Catalog Table Definitions, Athena DDL One Ashburton Place, Room 1719, Boston, Massachusetts 02108 • (617) 727-2832 • Fax: (617) 727-5914 sec.state.ma.us/pre • pre@sec.state.ma.us

Luke Ferreira, Esq. SPR26/0890 Page 2 March 26, 2026 (Data Definition Language) statements, or JSON Schemas. - Retention Policies: Records sufficient to show the data retention settings for the Sandbox environments, specifically S3 Lifecycle Configuration rules or CloudWatch Log Group retention settings that dictate how long these logs are preserved before deletion. - Operational Procedures: Any “standard operating procedures” or “audit and accountability” documentation maintained by EOTSS to comply with Policy IS.022 regarding the definition and review of audit events for the AI Sandbox. 4. AWS Cost and Usage Reports (CUR) I request the financial usage records for the AI Sandbox (both “Higher Ed” and “Internal”). As these are generated automatically by AWS for billing, providing them does not constitute creating a record. - Format: A copy of the AWS Cost and Usage Report (CUR), Reseller Billing Extract (e.g., CloudHealth, CloudCheckr exports), or equivalent granular billing export (CSV or Parquet converted to CSV) for the relevant time period. - Required Fields: Please ensure the export includes the lineItem/ ProductCode, lineItem/UsageType, lineItem/Operation, and lineItem/UsageAmount columns. - Scope: Please include all usage types associated with the Sandbox environments (e.g., standard model inference, model customization, storage, or provisioned throughput) so that I may understand the full extent of the tools being utilized. 5. Amazon Bedrock Configuration & Audit Status Regarding the specific use of generative AI models via Amazon Bedrock, I request: - Logging Status: A record showing the current configuration status of “Model Invocation Logging” for the Bedrock service. This may be satisfied by providing the JSON output of the aws bedrock getmodel- invocation-logging-configuration command or a screenshot of the Bedrock Settings console. - Change History: A copy of the most recent CloudTrail Management Event with the event name PutModelInvocationLoggingConfiguration or DeleteModelInvocationLoggingConfiguration. - Context: This specific record is requested to verify the timeline of when audit logging was enabled or disabled. - Guardrails: A copy of the configuration details for any “Bedrock Guardrails” applied to the Sandbox, specifically the “Content Filters” and “Denied Topics” settings. 6. GenAI Catalog The current version of the “GenAI Catalog” listing each GenAI solution approved for use within the Commonwealth, as referenced in Section 5.6 of the policy. 7. Reports, presentations, etc. Any reports, summaries, presentations, or analyses created by or for EOTSS regarding the usage, performance, outcomes, or risks identified within the AI

Luke Ferreira, Esq. SPR26/0890 Page 3 March 26, 2026 Sandbox program. Previous Petition This request was the subject of a previous petition from the Office. See SPR25/3005 Determination of the Supervisor of Records (October 17, 2025). In my October 17th determination, I found that the Office may assess fees for segregation and redaction of the responsive records. Subsequently, the Office responded multiple times from November 20, 2025 through March 11, 2026, providing numerous responsive records. Unsatisfied with the Office’s responses, Mr. Gerhardson petitioned this office, and this appeal, SPR26/0890, was opened as a result. Subsequent to the opening of this appeal, the Office provided a further response to this office and Mr. Gerhardson on March 20, 2026, and Mr. Gerhardson reiterated his objections to the Offices responses on March 23, 2026. The Public Records Law The Public Records Law strongly favors disclosure by creating a presumption that all governmental records are public records. G. L. c. 66, § 10A(d); 950 C.M.R. 32.03(4). “Public records” is broadly defined to include all documentary materials or data, regardless of physical form or characteristics, made or received by any officer or employee of any agency or municipality of the Commonwealth, unless falling within a statutory exemption. G. L. c. 4, § 7(26). It is the burden of the records custodian to demonstrate the application of an exemption in order to withhold a requested record. G. L. c. 66, § 10(b)(iv); 950 C.M.R. 32.06(3); see also Dist. Attorney for the Norfolk Dist. v. Flatley, 419 Mass. 507, 511 (1995) (custodian has the burden of establishing the applicability of an exemption). To meet the specificity requirement a custodian must not only cite an exemption, but must also state why the exemption applies to the withheld or redacted portion of the responsive record. If there are any fees associated with a response, a written good faith estimate must be provided. G. L. c. 66, § 10(b)(viii); see also 950 C.M.R. 32.07(2). Once fees are paid, a records custodian must provide the responsive records. Current Appeal In his appeal petition, Mr. Gerhardson requests the following of this office: 1. Order EOTSS to produce the unredacted AI_COE_submission spreadsheet, with any redactions limited to specifically identified deliberative content justified on a field-by-field basis, limited only to those redactions required by law. 2. Order EOTSS to produce without delay the approximately 39 risk assessment and approval records, with redactions limited to only specifically identified security-sensitive technical details consistent with the framework set forth in PETA, 477 Mass. At 286–91.

Luke Ferreira, Esq. SPR26/0890 Page 4 March 26, 2026 3. Order EOTSS to produce access and activity logs for the AI Sandbox environments, with only genuinely security-sensitive fields redacted as may be required by law, and for any such redactions provide sufficient factual heft for the withholding; and to do so without delay 4. Order EOTSS to respond to outstanding Items 3, 4, and 5 of my amended request without delay. Upon a review of the appeal petition, I understand Mr. Gerhardson objects only to the withholding and redaction of the records described above in his appeal petition. The Office’s Responses In multiple responses from November 20, 2025 through March 11, 2026, the Office provided numerous responsive records, and cited Exemptions (c), (d), and (n) of the Public Records Law for withholding and redacting records. See G. L. c. 4, § 7(26)(c), (d), (n). In its March 20, 2026 response, the Office indicates that it possesses records responsive to Items 3, 4 and 5 of the request, and cites Exemptions (d) and (n) of the Public Records Law for withholding the records described in Mr. Gerhardson’s appeal petition. Exemption (d) Exemption (d) allows the withholding of: inter-agency or intra-agency memoranda or letters relating to policy positions being developed by the agency; but this subclause shall not apply to reasonably completed factual studies or reports on which the development of such policy positions has been or may be based G. L. c. 4, § 7(26)(d). Exemption (d) is intended to avoid premature release of materials that could taint the deliberative process if disclosed. Its application is limited to recommendations on legal and policy matters found within an ongoing deliberative process. See Babets v. Sec’y of the Exec. Office of Human Servs., 403 Mass. 230, 237 n.8 (1988). Factual reports which are reasonably complete and inferences which can be drawn from factual investigations, even if labeled as opinions or conclusions, are not exempt as deliberative or policy making materials. G. L. c. 4, § 7(26)(d); see also Envtl. Prot. Agency v. Mink, 410 U.S. 73, 89 (1973) (purely factual matters used in the development of government policy are subject to disclosure).

Luke Ferreira, Esq. SPR26/0890 Page 5 March 26, 2026 Exemption (n) Exemption (n) applies to: records, including, but not limited to, blueprints, plans, policies, procedures and schematic drawings, which relate to internal layout and structural elements, security measures, emergency preparedness, threat or vulnerability assessments, or any other records relating to the security or safety of persons or buildings, structures, facilities, utilities, transportation, cyber security or other infrastructure located within the commonwealth, the disclosure of which, in the reasonable judgment of the record custodian, subject to review by the supervisor of public records under subsection (c) of section 10 of chapter 66, is likely to jeopardize public safety or cyber security. G. L. c. 4, § 7(26)(n). Exemption (n) allows for the withholding of certain records which if released would jeopardize public safety. The first prong of Exemption (n) examines “whether, and to what degree, the record sought resembles the records listed as examples in the statute;” specifically, the “inquiry is whether, and to what degree, the record is one a terrorist ‘would find useful to maximize damage.’” People for the Ethical Treatment of Animals (PETA) v. Dep’t of Agric. Res., 477 Mass. 280, 289-90 (2017). The second prong of Exemption (n) examines “the factual and contextual support for the proposition that disclosure of the record is ‘likely to jeopardize public safety.’” Id. at 289-90. The PETA decision further provides that “[b]ecause the records custodian must exercise ‘reasonable judgment’ in making that determination, the primary focus on review is whether the custodian has provided sufficient factual heft for the supervisor of public records or the reviewing court to conclude that a reasonable person would agree with the custodian’s determination given the context of the particular case.” Id. PETA also provides that “[t]hese two prongs of exemption (n) must be analyzed together, because there is an inverse correlation between them. That is, the more the record sought resembles the records enumerated in exemption (n), the lower the custodian’s burden in demonstrating ‘reasonable judgment’ and vice versa.” PETA, at 290. In its March 20th response, under Exemptions (d) and (n), the Office argues the following: Issue (1): AI center for excellence submission spreadsheet. The AI Center of Excellence is a group composed of EOTSS subject matter experts who assess the legal, security and operational risks of proposed AI programs, products and development. The purpose of the AI COE is to provide guidance on emerging technology to support commonwealth agencies’ adoption and deployment of AI. EOTSS has provided a redacted version of this document to Mr. Gerhardson.

Luke Ferreira, Esq. SPR26/0890 Page 6 March 26, 2026 EOTSS redacted details related to proposals that are in a pre-production, and a pre-procurement state. EOTSS is withholding these records under exemption (d). The ability for EOTSS personnel to provide candid, comprehensive feedback to project proposals will be significantly chilled if they become concerned that their preliminary assessment might become subject to disclosure before a concept is fully developed. Further, some of the redacted details that Mr. Gerhardson is challenging as being “factual,” such as project names, are not purely factual and should be redacted, as they reveal descriptive information about the nature and progress of a developing project and may change as the project evolves. EOTSS believes it is inappropriate to disclose such information prior to project completion and while the deliberative process is still ongoing and therefor this information sits squarely within the exemption. Issue (2): Risk assessment proposals. These records are related to the spreadsheet discussed in Issue (1) insofar as they represent the underlying records from which the summary data in the “AI_COE_Submissions.xlsx” spreadsheet were collected. To the extent that these records include information that has been captured in the “AI_COE_Submissions.xlsx” spreadsheet and is subject to disclosure, they have already been provided to Mr. Gerhardson as part of the spreadsheet file. To the extent that these records contain information related to proposals that are still under development, EOTSS believes that they are subject to exemption (d). To the extent that these records contain more specific details related to IT infrastructure security (such as the locations of EOTSS cloud repositories or other sensitive data), EOTSS has withheld them under exemption (n). Issue (3): Access and Activity logs. Mr. Gerhardson initially requested per-user log data for all AI-related activities within EOTSS’ “AI Centers of Excellence” sandbox environments. EOTSS informed Mr. Gerhardson that EOTSS’s sandbox environments, which are housed within EOTSS’s tenant on Amazon Web Services “S3” service, do create log data. Those logs, however, are created across EOTSS’ entire tenant, which houses many application and service environments beyond the “AI Centers of Excellence” sandbox environments. These data are quite large (on the order of gigabytes of information), and are not readily sortable in the specific way that Mr. Gerhardson had requested (per-user data for specific AI-related applications). Additionally, EOTSS is unwilling to provide Mr. Gerhardson with the entire log file as that represents and unacceptable security risk. Issue (4): Failure to Respond to Outstanding Items. Due to the specificity of Mr. Gerhardson’s requests, input was required from EOTSS technical, privacy, legal and security specialists. In addition to the log data that Mr. Gerhardson has requested, he also requested that EOTSS provide additional details about its AWS tenant configuration. EOTSS’ AWS S3 tenant is a secure, isolated, cloud environment that contains sensitive configuration and operational data. Mr. Gerhardson has again relied upon a generative AI tool to produce specific

Luke Ferreira, Esq. SPR26/0890 Page 7 March 26, 2026 command lines intended to be run in AWS’ administrative tools in order to create custom reporting. Having now received feedback from EOTSS’ subject matter experts, EOTSS is prepared to respond to each of these items here: - Item 3 (system architecture and logging definitions, including schema definitions, retention policies, and IS.022 operational procedures) EOTSS’ Enterprise Information Security policies are already available online at: [a specified website]. Providing application-specific architecture, definitions, and schema would constitute a clear and substantial risk to EOTSS’ IT security posture. These data would contain information that could assist black-hat operators in gaining unauthorized access to Commonwealth infrastructure. EOTSS therefore withholds this information under exemption (n) to the definition of public records. - Item 4 (AWS Cost and Usage Reports for the Sandbox environments) Information about EOTSS’ contractual agreements with both AWS and OpenAI are available to the public on CommBuys.com. EOTSS has already provided Mr. Gerhardson with direct links to contract records for EOTSS’ procurement of services from OpenAI. “AWS CURs” (Amazon Web Services Cost and Usage Reports) are records created by the AWS S3 tenant administrative tools that track application usage and billing. According to Amazon’s own guidance materials, “AWS Cost and Usage Reports (AWS CUR) contains the most comprehensive set of cost and usage data available.” (see e.g., [a specified website]) They contain significant amounts of highly sensitive data. Providing records requesters with CURs would be equivalent to providing them administrator level knowledge of EOTSS’ AWS S3 tenant. EOTSS therefore withholds this information under exemption (n) to the definition of public records. - Item 5 (Amazon Bedrock configuration and audit status, including model invocation logging, CloudTrail change history, and guardrail configurations) These requests reference specific configuration settings that would be selected on a per-project basis within the COE Sandbox Environment for specific GenAI projects. Much like the architectural information in Item 1 above, these details would provide useful information for bad actors seeking to gain unauthorized access to EOTSS IT infrastructure, and EOTSS is therefore withholding this information under exemption (n) to the definition of public records. In Camera Inspection In order to facilitate a determination as to the applicability of the Exemption (d) and (n) claims made by the Office to redact and withhold the responsive records, the Office must provide this office with un-redacted copies of a representative sample of the responsive records for in camera inspection. See 950 C.M.R. 32.08(4). After I complete my review of the records, I will

Luke Ferreira, Esq. SPR26/0890 Page 8 March 26, 2026 return the records to the Office’s custody and issue an opinion on the public or exempt nature of the records. The authority to require the submission of records for an in camera inspection emanates from the Code of Massachusetts Regulations. 950 C.M.R. 32.08(4); see also G. L. c. 66, § 1. This office interprets the in camera inspection process to be analogous to that utilized by the judicial system. See Rock v. Mass. Comm’n Against Discrimination, 384 Mass. 198, 206 (1981) (administrative agency entitled deference in the interpretation of its own regulations). Records are not voluntarily submitted, but rather are submitted pursuant to an order by this office that an in camera inspection is necessary to make a proper finding. Records are submitted for the limited purpose of review. This office is not the custodian of records examined in camera, therefore, any request made to this office for records being reviewed in camera will be denied. See 950 C.M.R. 32.08(4)(c). This office has a long history of cooperation with governmental agencies with respect to in camera inspection. Custodians submit copies of the relevant records to this office upon a promise of confidentiality. This office does not release records reviewed in camera to anyone under any circumstances. Upon a determination of the public record status, records reviewed in camera are promptly returned to the custodian. To operate in any other fashion would seriously impede our ability to function and would certainly affect our credibility within the legal community. Please be aware, any cover letter submitted to accompany the relevant records may be subject to disclosure. Order Accordingly, the Office is ordered to provide this office with un-redacted copies of a representative sample of the responsive records for in camera inspection without delay. Sincerely, Manza Arthur Supervisor of Records cc: Jonathan Gerhardson