Here's an uncomfortable exercise for any city manager, county administrator, or agency IT director: ask yourself how many AI tools are in use across your organization right now. Not how many you've approved, but how many are actually in use.

If you're like most agencies, the honest answer is "I have no idea." And the numbers say the gap between AI use and AI governance in government is wide, and widening.

AI adoption outpaces AI policy in government

According to the 2026 State of Digital Government report, 55.7% of government organizations now use AI, but only 42.9% have formal AI policies in place. And adoption is accelerating: in a recent survey of government leaders, 72% said they expect to expand their AI use in the next 12–18 months.

The states have moved fastest on paper; NASCIO's 2025 State CIO Survey found 88% of states have responsible-use policies or guardrails in place. But policy on paper isn't the same as governance in practice: a 2025 Pew/NCSL report found only 24% of state CIOs had actually implemented data governance frameworks for generative AI. And at the city and county level, where IT teams are smaller and AI arrived through the side door, the gap is bigger still.

Because that's how AI entered your agency, not through a procurement process, but through individual choices. A communications officer using ChatGPT to draft press releases. A planner summarizing public comments with Copilot. A clerk asking an AI assistant to clean up meeting minutes. The security industry has a name for this: shadow AI. One 2025 study found 68% of employees use free-tier AI tools through personal accounts, and 57% of them input sensitive data. Another found 38% of employees admit to sharing sensitive work information with AI tools without authorization. Agencies that survey their own workforce tend to reach the same humbling conclusion: adoption is already widespread, across departments and use cases leadership never anticipated. The only difference between agencies with a shadow-AI problem and agencies without one is which ones have looked.

And it's not just the tools employees choose. AI is now embedded in the software agencies already run: meeting transcribers, document assistants, features quietly added to platforms in routine updates. Your organization can be "using AI" in a dozen places without a single person having decided to adopt it.

The legal risks of operating without an AI policy

Every organization has reasons to govern AI use. Public agencies have legal ones that private companies don't, and they're no longer hypothetical.

Your staff's AI chats may be public records

In Washington state, journalists recently obtained city officials' ChatGPT conversation logs through public records requests, and the cities produced them, treating AI prompts and outputs as disclosable records. Legal analysts expect the same logic to apply under other states' records laws, like the California Public Records Act, whose definition of a "record" is broad enough to reach content used in agency business even when it's stored on a third-party vendor's servers. If your employees are using AI today, ask yourself: could your agency even locate those records to respond to a request? For ungoverned personal accounts, the answer is no, which is its own compliance problem.

AI tools quietly create records you didn't mean to create

As the UNC School of Government has flagged, when an AI tool transcribes a meeting, it may have created a record subject to disclosure, including for conversations that were never required to be public in the first place. A sensitive internal discussion becomes a disclosable transcript because someone clicked "enable transcription." Without a policy, nobody in your agency has even been told this is a risk.

Citizen data isn't yours to expose

Tax records, health information, case files, permit applications residents don't choose whether to hand this to their government. When an employee pastes a resident's information into a public chatbot to "help draft a response," that data leaves your control, potentially into a system that stores or trains on it. Research on enterprise AI use found 40% of file uploads into generative AI tools contain PII or payment data. IBM's 2025 Cost of a Data Breach report found one in five organizations has already experienced a breach linked to unsanctioned AI. For an agency, that's not just a security incident; it's a betrayal of a trust residents never opted into.

Legislatures are moving faster than agencies

More than 1,000 AI-related bills were introduced in state legislatures in 2025, over twice the 2024 count, and every state considered AI legislation. Government use of AI has been one of the dominant categories from the start. Whatever your state has enacted or will enact, one thing is predictable: agencies will be asked to show that their AI use was deliberate, documented, and governed. An agency without a policy has no defensible answer to the questions that are coming from auditors, councils, and journalists alike.

Why most government AI policies fail: The ban and the binder

Faced with all this, agencies tend to reach for one of two responses, and both backfire.

The first is the ban. Prohibit AI use until the risks are understood. It feels safe, but it doesn't stop usage; it relocates it. Staff move to personal devices and personal accounts, and the agency trades visible, governable AI use for invisible, ungovernable AI use the exact accounts that public records officers can't search, and IT can't see. The risk doesn't shrink. It just goes dark.

The second is the binder: a sprawling, 40-page policy that tries to anticipate every scenario. Nobody reads it, nobody remembers it, and within months it exists mainly to be cited after something goes wrong. Employees who can't tell what's allowed default to either not using AI (losing real productivity) or using it quietly (same shadow problem as the ban).

The agencies getting this right chose a third path; the City of Hopkinsville, KY is one worth reading about, a deliberately lean policy anchored in a few core principles. Keep sensitive information out of public AI tools. Keep a human in the loop before anything AI-assisted is published or acted on. Use sanctioned tools. Guardrails, not gates. A policy like that can actually be read, remembered, and followed, which is the entire point.

What a government AI policy should include

You don't need forty pages. You need clear answers to a handful of questions:

  • What data can never go into public AI tools — PII, health information, records covered by confidentiality requirements, anything a resident entrusted to you
  • Which tools are sanctioned, and what the path is for requesting a new one
  • Where human review is mandatory — before publication, before decisions that affect residents, before anything enters the official record
  • How AI use intersects your records obligations — what may be disclosable, what must be retained, and where AI-generated content lives
  • Who owns the policy — the person or board that answers questions, handles exceptions, and updates it as the technology and the law move

That's a framework an agency can adopt in weeks, not quarters. It won't answer every question, no first policy does, but it converts AI from an unmanaged liability into a governed program, and it gives your staff the thing they actually want: permission to use these tools, with clarity about how.

How to create an AI policy for your agency in five minutes

This is exactly why we built the Policy Wizard and why it's free. Answer a short series of questions about your agency, and it generates a customized AI policy as a PDF, built on the lean, enforceable principles above. No sales call, no strings. Five minutes, and your agency has a real starting point.

A written policy is step one, not the finish line. A policy can set expectations, but it can't see which tools are in use or whether citizen data is staying where it belongs. That's the governance layer, and it's what Darwin was built for. But every agency that's gotten AI governance right started in the same place: they wrote down the rules.

Your staff are already using AI. Give them the guardrails. Generate your agency's AI policy →

Already have a policy? The wizard can benchmark it against similar public sector organizations instead

Interested in Learning More?