AI in City Hall: Why an Enterprise License Is Not a Governance Program
Generative AI is already in local government, drafting agendas, summarizing public comments, screening applications, assisting with records requests, and answering constituent questions. Those uses can save staff time and improve service. They can also create records the agency cannot retrieve, expose information through an unapproved account, or influence a decision that can be difficult to reconstruct.
An enterprise license is not an AI governance program. Local agencies need an operating governance system covering approved platforms, assigned owners, usable records controls, defined data restrictions, proportionate review, vendor obligations, and evidence that those controls function in practice.
No single federal statute governs every public entity’s procurement, deployment, and use of AI. Existing privacy, public records, civil rights, employment, procurement, cybersecurity, accessibility, and administrative law requirements continue to apply, while states are adding AI-specific rules and guidance unevenly. President Trump’s December 11, 2025 executive order seeks a minimally burdensome national framework and directs federal challenges to selected state laws, but it does not itself displace those laws. Local agencies should govern under the requirements presently applicable to them rather than wait for a national standard that Congress has not enacted.
States have taken different approaches. The Texas Responsible Artificial Intelligence Governance Act (“TRAIGA”) applies directly to Texas governmental entities, including political subdivisions, although it excludes hospital districts and public institutions of higher education. TRAIGA requires disclosures for specified AI interactions and restricts governmental social scoring and certain biometric identification uses. Separately, Texas requires state agencies and local governments to adopt minimum risk management and governance standards for heightened scrutiny AI systems and an AI code of ethics, both established by the Department of Information Resources. Tex. Gov't Code §§ 2054.702-.703. Maryland, Connecticut, Kentucky, California, and Washington have adopted inventory, procurement, risk assessment, or governance requirements principally directed to state agencies. Those programs do not automatically govern local entities, but they do offer useful models for local policy and procurement.
Florida illustrates the records issue. Chapter 119 defines public records broadly, regardless of physical form or means of transmission. Florida courts apply the functional test articulated in Shevin v. Byron, Harless, Schaffer, Reid & Associates, Inc., asking whether material made or received in connection with official business was intended to perpetuate, communicate, or formalize knowledge. Depending on their content, purpose, and use, AI prompts, outputs, chat histories, and supporting logs may qualify as public records, although public record status, retention, and disclosure remain separate questions.
Enterprise agreements and platform selection
An enterprise or government agreement can give an agency access to controls such as single sign-on, role-based access, administrative logging, retention configuration, data location commitments, and negotiated restrictions on whether and how agency data, prompts, outputs, feedback, telemetry, and derived information may be used for training, product improvement, or other vendor purposes. The agency should verify which capabilities are included and how they are configured rather than merely infer them from the “enterprise” label. Selection should follow the agency’s existing cloud and records environment rather than brand preference.
Diligence should typically include permitted data categories; training and product improvement restrictions; retention and deletion settings; administrator access; storage location and authorized subprocessors; searchable export and legal hold capability; incident notification; model and material feature changes; accessibility; audit or verification rights; offboarding; and post-termination return or deletion. Using an existing enterprise environment can reduce identity, records, security, and administrative fragmentation, but only if the incumbent tool and contract satisfy the agency’s requirements. Marketing material is not a control. The contract and incorporated terms define the vendor’s obligations; configuration, administration, monitoring, and evidence determine whether those protections operate in practice.
What a defensible policy covers
AI use in local government will continue expanding. The legal framework surrounding that use will remain distributed across public records, privacy, civil rights, employment, procurement, cybersecurity, accessibility, and administrative law requirements. Using AI does not, by itself, displace those obligations.
The agencies best positioned are those that can identify which systems are in use, what information and decisions those systems affect, who is responsible for them, under what terms they operate, where their records reside, and who can restrict or stop them.
An enterprise license can support that work. It cannot perform it.
The Jones Walker Privacy, Data Strategy and Artificial Intelligence team advises public agencies and organizations on AI governance and acceptable use policies, tool inventories, enterprise and vendor contracting, public records and retention compliance, employment-related AI use, incident response, and the evolving state and federal regulatory landscape. Stay tuned and subscribe for continued insights from the AI Law and Policy Navigator.
