
Most organizations can tell you which software vendors they use. Far fewer can tell you which AI models are operating inside those applications.
That distinction is becoming increasingly important.
Microsoft Copilot may rely on different models depending on the task. Other vendors regularly introduce new AI capabilities, replace underlying models or add autonomous agents without requiring customers to purchase an entirely new product. A city may approve a software platform only to discover months later that its AI capabilities look very different from the ones it originally evaluated.
The software hasn't changed.
The intelligence inside it has.
Most AI governance policies focus on employee behavior. They establish expectations around privacy, public records, acceptable use and human oversight. Those policies remain essential, but they answer a different question.
How should employees use AI?
City leaders also need to answer another question.
What AI is actually operating inside our organization today?
That is where a model registry becomes indispensable.
Think of it as the source of truth for every AI model approved to perform work on behalf of the organization. Instead of maintaining a simple list of vendors, the registry documents the intelligence behind those products and how it is being used.
For each model, the registry might identify the provider, model version, approved uses, prohibited uses, connected systems, data classifications, evaluation results, department owner, review schedule and the individual responsible for ongoing oversight.
That information should never become a static spreadsheet.
It should be a living system.
As vendors release new models, retire existing ones or introduce new agent capabilities, the registry should identify those changes automatically and alert the appropriate people to review them. If a permitting application suddenly gains an AI agent capable of completing tasks instead of simply answering questions, that change deserves a governance review. If a financial platform begins using a different reasoning model, leaders should understand what changed before it becomes part of daily operations.
The registry should also uncover AI that arrives through software the organization has owned for years.
Nearly every major software company is embedding AI into existing products. Microsoft, Adobe, Salesforce, Esri, Oracle and countless others continue expanding AI capabilities through routine updates. Those changes often happen gradually, making them easy to overlook.
An effective AI operating system should continuously discover those capabilities instead of relying on someone to notice a product announcement or release note.
That visibility creates better decisions across the organization.
Technology leaders gain a current inventory of AI assets.
Department directors understand which systems are using AI and why.
Legal and records teams can evaluate new capabilities before they become routine practice.
Procurement staff have a historical record of how products have evolved since they were purchased.
Executives gain confidence that governance keeps pace with technology.
The same information also becomes the foundation for future transparency.
A public AI registry is only credible if the organization first maintains an accurate internal record. Without a trusted source of truth, transparency becomes an exercise in manually collecting information that is already out of date.
That is why I see the model registry as one of the foundational components of an AI operating system.
It gives cities a continuously updated picture of the intelligence already working across their organization. From that foundation, every other governance function becomes easier to build.
A Practical Model for Building a Model Registry
Record every model. Track the AI models operating across every application, not just the software vendors that provide them.
Capture operational details. Document approved uses, data access, connected tools, responsible owner, evaluation results and review dates for every model.
Monitor continuously. Detect model updates, new AI capabilities and agent features as vendors release them so governance keeps pace with technology.
Make it the source of truth. Use the registry to support executive oversight, procurement, audits, compliance and future public transparency.
