More than 60% of local health departments have no dedicated informatics staff, so AI governance has to run on the people already on payroll. Three roles, four impact tiers, and 90 days to get there.
.png)
Most AI governance frameworks are written for organizations with a compliance department. Local public health does not have one. In NACCHO's 2024 Public Health Informatics Profile, more than 60% of local health departments reported having no staff dedicated to informatics at all.
So the goal is not a 40-page document. The goal is governance you can actually run with the people already on payroll.
Here is the useful part: you already know how to do this. AI governance is population health practice pointed at your own operations.

You survey to find out what is happening. You stratify by risk. You intervene where risk is highest. You monitor for drift. You name someone accountable. Same five moves, new subject.
The accountable executive — your health officer or director. Roughly two hours a month. Sets the agency's risk tolerance, approves high-impact uses, and represents AI activity to the board of health.
The AI reviewer — an informatics lead, senior epidemiologist, or operations lead. Two to three hours a week. Runs the intake form, clears routine requests, and conducts pre-deployment reviews.
The outside check — county IT, shared counsel, or a peer health department. One quarterly conversation. Audits a sample of workflows against policy, verifies data handling, and looks for performance drift.
The outside check matters more than its time commitment suggests. It is the only one of the three that has no incentive to approve.
The question is never "is this AI?" It is "what happens to a resident if this is wrong?"

Tier 1, assistive. Drafting, formatting, summarizing, internal translation. Plain-language advisory rewrites, administrative memos. Program manager clears it, and staff do not wait.
Tier 2, operational. Internal data cleaning and aggregated trend analysis on non-identifiable data. Community health assessment sorting, budget summaries. AI reviewer signs off with a documented data check.
Tier 3, consequential. Anything informing resource allocation, triage, outreach prioritization, or advice to the public. Inspection prioritization models, resident-facing chatbots. Accountable executive approves, after a full review.
Tier 4, off-limits. Fully autonomous benefit denials, enforcement without human review, PHI pasted into unvetted consumer tools. Not a request to evaluate. A process to redesign.
Fast-tracking Tier 1 is what makes the rest credible. If every use goes through the same queue, staff route around the queue, and you are back to shadow AI with a policy on the shelf.
The AI reviewer documents answers to these before a Tier 3 system touches operations:
Question 3 is the one most often skipped, and it is where the documented health care failures have concentrated. Aggregate accuracy can look strong while the model performs badly for exactly the population your program exists to reach.

Days 1–30: see it. Run an internal AI census with an explicit no-penalty guarantee, and mean it — the census is worthless if staff have a reason to under-report. Assign the three hats. Check whether your county or state already has an umbrella AI policy you can adopt by reference instead of writing your own.
Days 31–60: set it. Adopt a one-page acceptable use policy. The GovAI Coalition's templates, built by government staff for government staff and aligned to the NIST AI Risk Management Framework, are free and designed to be edited rather than admired. Stand up a five-question intake form. Then provision enterprise accounts, because a safe lane is the only thing that reliably reduces shadow AI — prohibition alone moves the activity, it does not stop it.
Days 61–90: show it. Publish your AI tool inventory. Assign baseline responsible-AI training to all staff. Complete one high-impact review end to end and brief the board of health on it. One finished example does more for institutional confidence than a policy nobody has tested.
Ninety days is not enough to govern AI well. It is enough to stop governing it by accident.
Departments that start here move from the ban-and-ignore cycle — where policy prohibits what practice already does — to something they can describe out loud to an auditor, a board, or a reporter. That is the outcome worth having. Public trust is not built by having the strictest policy. It is built by being able to answer the question.
Ready to start? Darwin's Policy Wizard turns your agency's risk posture and existing documents into a tailored AI policy in minutes. And Darwin Govern gives agencies the visibility layer behind step one: what AI is actually in use, including the tools nobody reported.