More than half of government organizations now use AI, but fewer than half have a formal AI policy. Here's the legal and security case for closing that gap and how to write an AI policy your agency will actually follow.
.png)
Here's an uncomfortable exercise for any city manager, county administrator, or agency IT director: ask yourself how many AI tools are in use across your organization right now. Not how many you've approved, but how many are actually in use.
If you're like most agencies, the honest answer is "I have no idea." And the numbers say the gap between AI use and AI governance in government is wide, and widening.
According to the 2026 State of Digital Government report, 55.7% of government organizations now use AI, but only 42.9% have formal AI policies in place. And adoption is accelerating: in a recent survey of government leaders, 72% said they expect to expand their AI use in the next 12–18 months.
The states have moved fastest on paper; NASCIO's 2025 State CIO Survey found 88% of states have responsible-use policies or guardrails in place. But policy on paper isn't the same as governance in practice: a 2025 Pew/NCSL report found only 24% of state CIOs had actually implemented data governance frameworks for generative AI. And at the city and county level, where IT teams are smaller and AI arrived through the side door, the gap is bigger still.
Because that's how AI entered your agency, not through a procurement process, but through individual choices. A communications officer using ChatGPT to draft press releases. A planner summarizing public comments with Copilot. A clerk asking an AI assistant to clean up meeting minutes. The security industry has a name for this: shadow AI. One 2025 study found 68% of employees use free-tier AI tools through personal accounts, and 57% of them input sensitive data. Another found 38% of employees admit to sharing sensitive work information with AI tools without authorization. Agencies that survey their own workforce tend to reach the same humbling conclusion: adoption is already widespread, across departments and use cases leadership never anticipated. The only difference between agencies with a shadow-AI problem and agencies without one is which ones have looked.
And it's not just the tools employees choose. AI is now embedded in the software agencies already run: meeting transcribers, document assistants, features quietly added to platforms in routine updates. Your organization can be "using AI" in a dozen places without a single person having decided to adopt it.
Every organization has reasons to govern AI use. Public agencies have legal ones that private companies don't, and they're no longer hypothetical.
In Washington state, journalists recently obtained city officials' ChatGPT conversation logs through public records requests, and the cities produced them, treating AI prompts and outputs as disclosable records. Legal analysts expect the same logic to apply under other states' records laws, like the California Public Records Act, whose definition of a "record" is broad enough to reach content used in agency business even when it's stored on a third-party vendor's servers. If your employees are using AI today, ask yourself: could your agency even locate those records to respond to a request? For ungoverned personal accounts, the answer is no, which is its own compliance problem.
As the UNC School of Government has flagged, when an AI tool transcribes a meeting, it may have created a record subject to disclosure, including for conversations that were never required to be public in the first place. A sensitive internal discussion becomes a disclosable transcript because someone clicked "enable transcription." Without a policy, nobody in your agency has even been told this is a risk.
Tax records, health information, case files, permit applications residents don't choose whether to hand this to their government. When an employee pastes a resident's information into a public chatbot to "help draft a response," that data leaves your control, potentially into a system that stores or trains on it. Research on enterprise AI use found 40% of file uploads into generative AI tools contain PII or payment data. IBM's 2025 Cost of a Data Breach report found one in five organizations has already experienced a breach linked to unsanctioned AI. For an agency, that's not just a security incident; it's a betrayal of a trust residents never opted into.
More than 1,000 AI-related bills were introduced in state legislatures in 2025, over twice the 2024 count, and every state considered AI legislation. Government use of AI has been one of the dominant categories from the start. Whatever your state has enacted or will enact, one thing is predictable: agencies will be asked to show that their AI use was deliberate, documented, and governed. An agency without a policy has no defensible answer to the questions that are coming from auditors, councils, and journalists alike.
Faced with all this, agencies tend to reach for one of two responses, and both backfire.
The first is the ban. Prohibit AI use until the risks are understood. It feels safe, but it doesn't stop usage; it relocates it. Staff move to personal devices and personal accounts, and the agency trades visible, governable AI use for invisible, ungovernable AI use the exact accounts that public records officers can't search, and IT can't see. The risk doesn't shrink. It just goes dark.
The second is the binder: a sprawling, 40-page policy that tries to anticipate every scenario. Nobody reads it, nobody remembers it, and within months it exists mainly to be cited after something goes wrong. Employees who can't tell what's allowed default to either not using AI (losing real productivity) or using it quietly (same shadow problem as the ban).
The agencies getting this right chose a third path; the City of Hopkinsville, KY is one worth reading about, a deliberately lean policy anchored in a few core principles. Keep sensitive information out of public AI tools. Keep a human in the loop before anything AI-assisted is published or acted on. Use sanctioned tools. Guardrails, not gates. A policy like that can actually be read, remembered, and followed, which is the entire point.
You don't need forty pages. You need clear answers to a handful of questions:
That's a framework an agency can adopt in weeks, not quarters. It won't answer every question, no first policy does, but it converts AI from an unmanaged liability into a governed program, and it gives your staff the thing they actually want: permission to use these tools, with clarity about how.
This is exactly why we built the Policy Wizard and why it's free. Answer a short series of questions about your agency, and it generates a customized AI policy as a PDF, built on the lean, enforceable principles above. No sales call, no strings. Five minutes, and your agency has a real starting point.
A written policy is step one, not the finish line. A policy can set expectations, but it can't see which tools are in use or whether citizen data is staying where it belongs. That's the governance layer, and it's what Darwin was built for. But every agency that's gotten AI governance right started in the same place: they wrote down the rules.
Your staff are already using AI. Give them the guardrails. Generate your agency's AI policy →
Already have a policy? The wizard can benchmark it against similar public sector organizations instead