
AI Governance for State & Local Government
A practical framework for safe, scalable AI adoption in the public sector.
Artificial intelligence is already entering state agencies, local governments, K-12 school systems, colleges, universities, and the private companies that serve them.
The important question is no longer whether these organizations will use AI. It is whether they can use it safely, responsibly, and at scale without governance becoming an obstacle to innovation.
For state, local, and education (SLED) organizations, that balance matters more than almost anywhere else. These institutions manage public records, student information, citizen data, financial information, operational systems, and decisions that can directly affect people's lives.
Fortunately, public agencies do not have to build an AI governance model from scratch.
The U.S. Department of State's July 2026 Generative AI Playbook provides a useful real-world example of what responsible enterprise AI adoption can look like. The Department developed StateChat, an enterprise generative AI assistant approved for Sensitive But Unclassified information, and moved it from experimentation to widespread deployment. By June 2026, StateChat had grown to more than 62,000 users.
That number matters. It demonstrates something every state CIO, local government technology leader, superintendent, university administrator, and public-sector technology partner should recognize:
AI governance and AI adoption do not have to work against each other. Done correctly, governance is what makes adoption possible.
What Government Agencies Can Learn From the State Department's AI Rollout
The State Department did not begin by giving tens of thousands of employees an AI tool and hoping for the best. Its journey was staged — the Department began with experimentation and small-scale testing, expanded into beta deployment, moved into production, drove adoption, and then focused on more advanced AI capabilities.
That progression provides a useful model for SLED agencies:
Lay the groundwork → prove it is possible → prove it is useful → launch → scale → measure impact.
The underlying lesson is simple. Do not begin an AI program with the question, "Which AI product should we buy?" Begin with: "What problem are we solving, what information will the AI encounter, what could go wrong, and what controls should exist before we scale it?"
That changes AI governance from a policy exercise into an operating model.
Safe AI Governance Starts Before the AI Tool
One of the biggest mistakes organizations can make is treating AI governance as a document created after technology has already been selected. Effective AI governance begins earlier. Before deploying an AI system, SLED organizations should understand at least five things.
1. What data can the AI access?
Agencies need clear boundaries around public, internal, confidential, regulated, student, personnel, and other sensitive information. Employees should not have to guess whether information can be entered into an AI system.
2. Who is accountable for the system?
AI cannot become "IT's problem." Governance should include technology, cybersecurity, privacy, legal, procurement, data leadership, operational stakeholders, and the people who will actually use the system.
3. What decisions can AI influence?
Drafting an internal email is different from evaluating a benefits application. Summarizing meeting notes is different from recommending disciplinary action involving a student. Risk should therefore be tied to the use case, not simply to whether something contains AI.
4. How will outputs be verified?
Generative AI can produce convincing information that is incomplete or incorrect. Human review needs to be designed into workflows where accuracy matters. The goal is not merely "human in the loop" — agencies should define where human judgment is required and who owns that judgment.
5. How will the agency know whether AI is actually working?
AI adoption should eventually produce measurable public value. The State Department provides an excellent example: a survey of regular StateChat users found that 90% reported saving time, with reported savings averaging approximately 1.6 hours per week per task.
Those are the kinds of measurements public agencies should pursue. Not logins. Not licenses purchased. Not prompts submitted. Outcomes.
Use a Risk-Based AI Governance Framework
Government organizations do not need to invent entirely new terminology for managing AI risk. The National Institute of Standards and Technology's AI Risk Management Framework organizes AI risk management around four straightforward functions, developed through an open, collaborative process involving more than 240 contributing organizations across government, private industry, academia, and civil society.
For a SLED organization, those four functions can become practical questions:
- GOVERN — Who owns AI policy, accountability, oversight, procurement, and acceptable use?
- MAP — Where is AI being used, what data does it touch, who could be affected, and what risks exist?
- MEASURE — How will accuracy, security, privacy, bias, reliability, and operational value be evaluated?
- MANAGE — What happens when risk is discovered, the technology changes, or the system performs differently than expected?
The result should not be a 100-page AI policy that employees never read. It should be a repeatable system for making good decisions.
Start Small — But Build for Scale
Another lesson from the State Department's approach is the importance of controlled experimentation. A pilot allows an organization to discover problems while the blast radius is small.
A SLED agency might begin with lower-risk internal applications such as:
- summarizing non-sensitive documents
- assisting with internal research
- drafting communications
- searching approved internal knowledge
- helping employees navigate policies
- generating first drafts of routine administrative material
The agency can then evaluate usefulness, accuracy, employee behavior, security requirements, and unexpected risks before expanding access. This creates something extremely valuable: evidence. Instead of debating AI hypothetically, leaders can make decisions based on how AI actually performs inside their organization.
Private Companies Have a Responsibility Too
Safe government AI cannot be the responsibility of government alone. Private companies selling AI platforms, consulting services, integrations, data products, and applications into the public sector should be able to reciprocate the governance expectations being placed on agencies.
If a vendor asks a government customer to trust its AI system, that vendor should be prepared to help the customer answer basic governance questions:
- What data enters the system, and where does that data go?
- Is customer data used for model training?
- How long is information retained?
- Which models and subprocessors are involved?
- What security controls protect the environment?
- Can administrators control access and permissions?
- Are system activities logged?
- How are model or product changes communicated?
- Can AI-generated actions be reviewed or reversed?
- What happens to agency data when the contract ends?
These questions should not require weeks of escalation through a vendor's legal and engineering teams. Governance readiness should become part of product readiness.
Vendors Should Provide an AI Governance Packet
One practical way private companies can reciprocate is by creating a standardized AI Governance Packet for public-sector customers. Instead of forcing every agency to independently discover how a product works, vendors could proactively provide:
- Data Flow Documentation — what information enters the system, where it is processed, what third parties receive it, where it is stored, and when it is deleted.
- AI System Card — the models being used, intended uses, known limitations, major risks, and important configuration options.
- Security Documentation — relevant security controls, access controls, encryption practices, logging capabilities, incident processes, and independent assessments where appropriate.
- Privacy and Training Commitments — clear language describing whether customer prompts, files, outputs, or metadata can be used to train or improve models.
- Human Oversight Guidance — specific recommendations for when outputs should require human verification.
- Change Management Policy — how customers will be informed when underlying models, capabilities, subprocessors, or material system behavior changes.
- Testing and Evaluation Results — evidence showing how the system has been evaluated for accuracy, reliability, security, and other risks relevant to its intended use.
That does more than make procurement easier. It creates a common governance language between the public and private sectors.
Procurement Is Becoming Part of AI Governance
This may ultimately be one of the biggest changes AI brings to SLED technology. Traditionally, agencies might evaluate software primarily around functionality, security, accessibility, integration, price, and contractual terms. AI introduces another layer: how does this system behave?
Two products offering nearly identical functionality could create dramatically different levels of AI risk depending on their models, data architecture, permissions, retention policies, autonomous capabilities, and human oversight.
That means AI governance needs to reach procurement. Requests for proposals, vendor evaluations, security assessments, contracts, and renewal processes should increasingly include AI-specific requirements. Private companies that prepare for those questions now will have an advantage.
Governance Should Make Safe AI Easier to Use
There is another side to this discussion that government leaders should not overlook: overly restrictive governance can create its own risk. If approved AI systems are difficult to access, significantly less capable than consumer alternatives, or buried beneath complicated approval processes, employees may look for easier alternatives.
Good governance therefore needs both guardrails and a paved road. Tell employees what they cannot do — but equally importantly, give them an approved way to do what they can do.
The State Department's StateChat experience demonstrates the potential of that approach: create an enterprise environment designed around government requirements, provide employees with useful capabilities, learn from real usage, and expand from there.
SLED AI Governance Checklist
Use this checklist before deploying any AI system in a state, local, or education environment:
- Define what data the AI can access — public, internal, confidential, student, and personnel.
- Assign clear ownership across IT, security, privacy, legal, and end users.
- Classify each use case by risk (drafting vs. deciding).
- Require human review wherever outputs affect real decisions.
- Set measurable goals tied to public value, not just usage.
- Apply the NIST AI RMF: Govern, Map, Measure, Manage.
- Start with a low-risk pilot before scaling access.
- Request an AI Governance Packet from every AI vendor.
- Add AI-specific requirements to procurement and RFPs.
- Revisit governance as models, vendors, and use cases change.
Measure Public Value, Not AI Adoption
The most important question at the end of an AI initiative is not "How many people used AI?" It is "What became better because they did?"
For a local government, that might mean reducing the time required to respond to citizen inquiries. For a state agency, it might mean helping employees find information across thousands of pages of policy documentation. For a school district, it might mean reducing administrative workload so educators have more time for students. For a university, it might mean accelerating research administration or improving student services.
AI metrics should connect technology to mission outcomes. The State Department's reported time-savings data is valuable precisely because it moves the conversation from AI experimentation toward measurable organizational impact.
The Public and Private Sectors Need a Shared AI Governance Model
Government agencies cannot safely scale AI without cooperation from the companies building and providing these systems. And private companies cannot successfully serve government customers if every organization develops completely different expectations around AI.
The opportunity is to meet in the middle. Public agencies can establish clear governance, risk tiers, acceptable-use policies, evaluation standards, and procurement requirements. Private companies can provide transparency, documentation, controls, testing evidence, data protections, and ongoing accountability that allow agencies to satisfy those requirements.
Frameworks such as the NIST AI Risk Management Framework give both sides a common starting point. The State Department's Generative AI Playbook gives agencies something equally valuable: evidence that responsible governance can coexist with meaningful adoption.
More than 62,000 users did not happen by avoiding governance. Scale became possible because the organization built the foundation required to support it.
That may be the most important lesson for state, local, and education organizations approaching AI today. The goal of AI governance should not be to slow innovation down. It should be to create the conditions that allow organizations to move faster without losing control — and the companies serving government should be prepared to help them do exactly that.
Frequently asked questions
What is AI governance for state and local government?
AI governance for state and local government (SLED) is the set of policies, ownership structures, and controls that determine how public agencies, school districts, and universities use AI safely — covering what data AI systems can access, who is accountable, which decisions AI can influence, how outputs are verified, and how success is measured.
Why does AI governance matter for SLED organizations specifically?
SLED organizations manage public records, student information, citizen data, and decisions that directly affect people's lives, so the stakes of unmanaged AI use are higher than in many private-sector contexts. Strong governance lets these organizations adopt AI at scale without it becoming a source of risk or an obstacle to innovation.
What is the NIST AI Risk Management Framework?
The NIST AI Risk Management Framework (AI RMF) is a voluntary framework, developed with input from more than 240 organizations, that organizes AI risk management into four functions — Govern, Map, Measure, and Manage — giving public agencies and vendors a shared, practical vocabulary for AI governance.
What can government agencies learn from the State Department's Generative AI Playbook?
The State Department's July 2026 Generative AI Playbook shows that AI governance and AI adoption can reinforce each other. Its enterprise assistant, StateChat, grew to more than 62,000 users by moving through staged phases — experimentation, beta, production, adoption, and expanded capability — rather than deploying AI broadly before governance was in place.
What questions should a government agency ask an AI vendor?
At minimum, agencies should ask what data the system can access, whether customer data trains the vendor's models, how long data is retained, which models and subprocessors are involved, what security controls exist, whether AI-generated actions can be reviewed or reversed, and what happens to agency data when the contract ends.
How should a SLED organization start using AI safely?
Start with a low-risk, internal pilot — such as summarizing non-sensitive documents or drafting routine communications — before expanding access. This produces real evidence about accuracy, security, and employee behavior, so later decisions are based on how AI actually performs inside the organization rather than hypothetical risk.
What is the difference between AI governance and AI adoption?
AI adoption measures how many people are using an AI tool; AI governance is the framework of accountability, risk controls, and verification that determines whether that use is safe. The State Department's experience shows governance is what makes large-scale adoption possible, not a barrier that slows it down.