AI governance has to tell government who can decide what

Local governments need clear decision rights for AI, with rules that let low-risk uses move quickly and give higher-risk applications the scrutiny they require.

Joe Hamilton
·
August 11, 2026

Every time a government employee chooses an AI tool, enters information into it or uses its output to complete public work, someone is making a governance decision.

Pinellas County recognizes that reality in its current procurement for an enterprise-wide AI Strategic Roadmap and Governance Framework. Its scope includes responsible-use policies, oversight roles, intake and approval processes, accountability, transparency and reporting.

Those requirements go well beyond writing an AI policy.

A policy might tell an employee that sensitive information cannot be entered into an unapproved AI model. Governance determines which models are approved, who makes that determination, how an employee requests an exception and who responds when a new tool appears that nobody contemplated when the policy was written.

As AI use spreads, local governments need clear decision rights.

At the Artificial Intelligence Center of Excellence, I would organize those rights around five functions.

Authority. Government needs to establish who can approve AI uses and when approval is required. A communications employee using an approved model to brainstorm headlines presents a different level of institutional risk than a department deploying AI to evaluate permit applications. The approval process should recognize that difference.

Data rules. Employees need practical guidance about what information can be used with which systems. Public information, internal government information, personally identifiable information and legally protected records require different treatment. Those rules need to be understandable enough to guide an employee during actual work.

Human oversight. Governments should determine where people remain responsible for reviewing AI output. The required oversight should increase with the consequence of the application. Drafting an internal meeting summary and influencing an eligibility determination should never travel through identical review processes.

Documentation. Significant AI systems need an institutional record. Government should know what model or system is being used, its purpose, the data involved, who owns the application and how its performance is evaluated. Documentation becomes particularly important as models and vendors change.

Accountability. Every deployed system needs a human owner. Someone must be responsible for performance, errors, evaluation and decisions about whether the application should continue operating.

The challenge is implementing these controls without creating an approval process so cumbersome that employees work around it.

A risk-tiered system offers a practical approach.

Low-risk applications can operate under standing rules using approved tools. Employees should not need a committee meeting every time they use AI to summarize a public document or improve routine internal writing.

Moderate-risk applications can require departmental review, documentation and periodic evaluation.

High-risk applications involving sensitive data, consequential decisions, public-facing interactions or significant automation should receive deeper technical, legal, security and operational review before deployment.

This structure allows governance to scale with consequence.

It also gives employees a clearer path for experimentation. Someone with a promising idea knows where to take it and what review will be required. Department leaders know what they can authorize. Technology and legal teams can concentrate their attention on applications where mistakes carry greater consequences.

Without that structure, early adopters inevitably create their own rules. One department permits a practice another prohibits. Employees make individual judgments about appropriate data. Useful experiments remain hidden because nobody knows how to get them approved. Risk accumulates without giving leadership a reliable picture of where AI is operating.

Governance should create enough consistency that AI can become an institutional capability.

That requires rules people can understand, authority people can identify and review proportional to the consequences of the application.

The next challenge is deciding which AI opportunities deserve government attention in the first place.

A Practical Model for Civic AI Governance

Assign decision rights. Define who can approve AI uses at the employee, department and enterprise levels.

Set operating rules. Establish clear requirements for data, approved systems, human oversight, documentation and accountability.

Classify by risk. Create tiers that allow routine low-risk uses to proceed while escalating applications with greater public, legal, privacy or operational consequences.

Maintain visibility. Keep an inventory of significant AI systems, responsible owners, evaluations and changes so leadership knows where AI is operating across government.

Share this insight
get aicoe news to your inbox
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
© 2026 AICOE - ALL RIGHTS RESERVED
Powered By The
St Petersburg Foundation