Most AI governance frameworks are written for organizations with a compliance department. Local public health does not have one. In NACCHO's 2024 Public Health Informatics Profile, more than 60% of local health departments reported having no staff dedicated to informatics at all.

So the goal is not a 40-page document. The goal is governance you can actually run with the people already on payroll.

Here is the useful part: you already know how to do this. AI governance is population health practice pointed at your own operations.

Five mappings from public health practice to AI governance. Disease surveillance becomes AI tool inventory. Risk stratification becomes high-impact tiering. Targeted intervention becomes pre-deployment review. Ongoing monitoring becomes quarterly performance check. Program officer oversight becomes named human accountability.

You survey to find out what is happening. You stratify by risk. You intervene where risk is highest. You monitor for drift. You name someone accountable. Same five moves, new subject.

Assign three hats, hire no one

The accountable executive — your health officer or director. Roughly two hours a month. Sets the agency's risk tolerance, approves high-impact uses, and represents AI activity to the board of health.

The AI reviewer — an informatics lead, senior epidemiologist, or operations lead. Two to three hours a week. Runs the intake form, clears routine requests, and conducts pre-deployment reviews.

The outside check — county IT, shared counsel, or a peer health department. One quarterly conversation. Audits a sample of workflows against policy, verifies data handling, and looks for performance drift.

The outside check matters more than its time commitment suggests. It is the only one of the three that has no incentive to approve.

Sort uses by consequence, not by technology

The question is never "is this AI?" It is "what happens to a resident if this is wrong?"

Four impact tiers and who signs off. Tier 1 assistive, low risk: drafting, formatting, plain-language rewrites, approved by a program manager. Tier 2 operational, medium risk: aggregated non-identifiable analysis, approved by the AI reviewer. Tier 3 consequential, high risk: allocation, triage, advice to the public, approved by the accountable executive. Tier 4 off-limits, critical risk: autonomous denials and PHI in free tools, prohibited.

Tier 1, assistive. Drafting, formatting, summarizing, internal translation. Plain-language advisory rewrites, administrative memos. Program manager clears it, and staff do not wait.

Tier 2, operational. Internal data cleaning and aggregated trend analysis on non-identifiable data. Community health assessment sorting, budget summaries. AI reviewer signs off with a documented data check.

Tier 3, consequential. Anything informing resource allocation, triage, outreach prioritization, or advice to the public. Inspection prioritization models, resident-facing chatbots. Accountable executive approves, after a full review.

Tier 4, off-limits. Fully autonomous benefit denials, enforcement without human review, PHI pasted into unvetted consumer tools. Not a request to evaluate. A process to redesign.

Fast-tracking Tier 1 is what makes the rest credible. If every use goes through the same queue, staff route around the queue, and you are back to shadow AI with a policy on the shelf.

Seven questions before anything consequential ships

The AI reviewer documents answers to these before a Tier 3 system touches operations:

  1. Who is affected, and were members of that community consulted while it was being designed?
  2. Is the data representative of your jurisdiction across language, race, rurality, and disability?
  3. Has accuracy been tested by subgroup, so you would notice if performance degraded for a smaller population?
  4. Do people receive notice and a plain explanation that AI was involved?
  5. Is there an accessible human appeal path that works without hiring a lawyer?
  6. Which named role is accountable for the system's decisions?
  7. What is the schedule for re-checking performance and fairness over time?

Question 3 is the one most often skipped, and it is where the documented health care failures have concentrated. Aggregate accuracy can look strong while the model performs badly for exactly the population your program exists to reach.

The 90 days

A ninety-day roadmap in three phases. Days 1 to 30, see it: run a no-penalty internal AI census, assign the three hats to existing staff, check for a county or state umbrella policy. Days 31 to 60, set it: adopt a one-page acceptable use policy, stand up a five-question intake form, provision enterprise accounts as the safe lane. Days 61 to 90, show it: publish the AI tool inventory, assign baseline responsible-AI training, brief the board on one completed review.

Days 1–30: see it. Run an internal AI census with an explicit no-penalty guarantee, and mean it — the census is worthless if staff have a reason to under-report. Assign the three hats. Check whether your county or state already has an umbrella AI policy you can adopt by reference instead of writing your own.

Days 31–60: set it. Adopt a one-page acceptable use policy. The GovAI Coalition's templates, built by government staff for government staff and aligned to the NIST AI Risk Management Framework, are free and designed to be edited rather than admired. Stand up a five-question intake form. Then provision enterprise accounts, because a safe lane is the only thing that reliably reduces shadow AI — prohibition alone moves the activity, it does not stop it.

Days 61–90: show it. Publish your AI tool inventory. Assign baseline responsible-AI training to all staff. Complete one high-impact review end to end and brief the board of health on it. One finished example does more for institutional confidence than a policy nobody has tested.

Why this order

Ninety days is not enough to govern AI well. It is enough to stop governing it by accident.

Departments that start here move from the ban-and-ignore cycle — where policy prohibits what practice already does — to something they can describe out loud to an auditor, a board, or a reporter. That is the outcome worth having. Public trust is not built by having the strictest policy. It is built by being able to answer the question.

Ready to start? Darwin's Policy Wizard turns your agency's risk posture and existing documents into a tailored AI policy in minutes. And Darwin Govern gives agencies the visibility layer behind step one: what AI is actually in use, including the tools nobody reported.

Interested in Learning More?