Jones Walker Logo
  • News & Insights
  • Professionals
  • Services
  • News & Insights
  • Professionals
  • Services

  • Firm
  • Offices
  • Careers
  • Events
  • Media Center
  • Blogs
  • Contact

  • text

AI Law and Policy Navigator

AI in City Hall: Why an Enterprise License Is Not a Governance Program

By Nick Primrose, Christina Baptista, Jason M. Loring
October 6, 2026

AI in City Hall: Why an Enterprise License Is Not a Governance Program

Generative AI is already in local government, drafting agendas, summarizing public comments, screening applications, assisting with records requests, and answering constituent questions. Those uses can save staff time and improve service. They can also create records the agency cannot retrieve, expose information through an unapproved account, or influence a decision that can be difficult to reconstruct.

An enterprise license is not an AI governance program. Local agencies need an operating governance system covering approved platforms, assigned owners, usable records controls, defined data restrictions, proportionate review, vendor obligations, and evidence that those controls function in practice.

No single federal statute governs every public entity’s procurement, deployment, and use of AI. Existing privacy, public records, civil rights, employment, procurement, cybersecurity, accessibility, and administrative law requirements continue to apply, while states are adding AI-specific rules and guidance unevenly. President Trump’s December 11, 2025 executive order seeks a minimally burdensome national framework and directs federal challenges to selected state laws, but it does not itself displace those laws. Local agencies should govern under the requirements presently applicable to them rather than wait for a national standard that Congress has not enacted. 

States have taken different approaches. The Texas Responsible Artificial Intelligence Governance Act (“TRAIGA”) applies directly to Texas governmental entities, including political subdivisions, although it excludes hospital districts and public institutions of higher education. TRAIGA requires disclosures for specified AI interactions and restricts governmental social scoring and certain biometric identification uses. Separately, Texas requires state agencies and local governments to adopt minimum risk management and governance standards for heightened scrutiny AI systems and an AI code of ethics, both established by the Department of Information Resources. Tex. Gov't Code §§ 2054.702-.703. Maryland, Connecticut, Kentucky, California, and Washington have adopted inventory, procurement, risk assessment, or governance requirements principally directed to state agencies. Those programs do not automatically govern local entities, but they do offer useful models for local policy and procurement.

Florida illustrates the records issue. Chapter 119 defines public records broadly, regardless of physical form or means of transmission. Florida courts apply the functional test articulated in Shevin v. Byron, Harless, Schaffer, Reid & Associates, Inc., asking whether material made or received in connection with official business was intended to perpetuate, communicate, or formalize knowledge. Depending on their content, purpose, and use, AI prompts, outputs, chat histories, and supporting logs may qualify as public records, although public record status, retention, and disclosure remain separate questions.

Enterprise agreements and platform selection

An enterprise or government agreement can give an agency access to controls such as single sign-on, role-based access, administrative logging, retention configuration, data location commitments, and negotiated restrictions on whether and how agency data, prompts, outputs, feedback, telemetry, and derived information may be used for training, product improvement, or other vendor purposes. The agency should verify which capabilities are included and how they are configured rather than merely infer them from the “enterprise” label. Selection should follow the agency’s existing cloud and records environment rather than brand preference. 

Diligence should typically include permitted data categories; training and product improvement restrictions; retention and deletion settings; administrator access; storage location and authorized subprocessors; searchable export and legal hold capability; incident notification; model and material feature changes; accessibility; audit or verification rights; offboarding; and post-termination return or deletion. Using an existing enterprise environment can reduce identity, records, security, and administrative fragmentation, but only if the incumbent tool and contract satisfy the agency’s requirements. Marketing material is not a control. The contract and incorporated terms define the vendor’s obligations; configuration, administration, monitoring, and evidence determine whether those protections operate in practice.

What a defensible policy covers

  • Purpose, scope, and ownership. State what the policy covers, including generative AI tools, AI features embedded in licensed software, AI used by contractors on agency work, and internally developed systems. Identify who owns the program, who approves new tools and uses, and who resolves conflicts among IT, records management, legal, HR, and operating departments. A policy without an owner tends to be revised only after an incident or other adverse development. Assign an owner, and give that person authority to approve, condition, or suspend a use.
     
  • Approved platforms and prohibited accounts. Name the approved enterprise tools with specificity. Permit only approved tools for official business unless a documented exception is granted. Prohibit personal or consumer accounts (and personal email or phone logins) for any work involving agency information. Personal accounts are likely to sit outside agency administration, retention settings, search tools, legal holds, and offboarding processes. That creates avoidable records management, preservation, security, and production problems under Florida’s Chapter 119 and comparable state public records laws.
     
  • Inventory and recurring discovery. Catalog approved tools and material AI features, including functionality added to software the agency already licenses. Do not delay governance of known consequential uses while seeking a complete inventory. Use procurement, renewals, technical discovery, internal development reviews, and department attestations to improve visibility over time.
     
  • Public records, retention, and legal holds. Whether an AI prompt, output, or log is a public record depends principally on its content, purpose, and use rather than the tool or account in which it resides. The policy should identify where qualifying records must be stored, map them to the existing retention schedule rather than a parallel one, and confirm that administrators can search, export, and preserve platform-held records and retrieve vendor- and contractor-held records when a request or hold arrives. Keep three questions separate: whether material is a public record, which retention schedule applies, and whether an exemption limits disclosure. An exemption from disclosure does not, by itself, eliminate otherwise applicable preservation or retention duties. Legal hold procedures should expressly reach AI platforms, vendor workspaces, and related prompts, outputs, and logs when they fall within a hold’s scope. The policy should also designate who routes records requests involving AI-generated material, so requests do not stall between the records custodian and IT. AI notetakers and summarization tools used in public meetings warrant particular attention, because their outputs may be public records and their use may implicate open meetings and recording consent requirements.
     
  • Data classification and AI acceptable use. Tie AI use to the agency’s existing data classification. For each approved tool, specify which categories of information may be entered: public, internal, confidential, privileged, personal, criminal justice, health, and security-sensitive. Restricted categories should be permitted only where the tool, configuration, contract, and use case have been expressly approved for that category. Acceptable use should also cover uses that are prohibited regardless of data type, such as generating unlabeled synthetic media for public release, or making final determinations in consequential matters without the required review.
     
  • Procurement, vendors, and contractors. AI risk does not stop at the agency firewall. Consultants, engineers, outside counsel, IT providers, and SaaS vendors may use AI on the agency’s data or produce work product the agency will adopt. Contracts should address approved tools; restrictions on training, product improvement, feedback, telemetry, and derived data; confidentiality requirements; flow-down to subcontractors; ownership of prompts and outputs; and the duty to preserve and produce records. A contractor’s use of AI may create agency records, security exposure, or discovery obligations depending on the contractor’s role, what the materials document, and the applicable law. The contract should provide the agency with access, preservation, export, and cooperation rights sufficient to satisfy those duties.
     
  • Employment and other consequential decisions. Using AI to screen applicants, score interviews, recommend discipline, or support termination carries different legal risk than drafting a press release. Depending on the jurisdiction, workforce, and decision, civil rights, veterans’ preference, collective bargaining, and public employment due process requirements may apply. Emerging state frameworks increasingly call for notice, human final authority, and a record of the relevant inputs, the resulting output or recommendation, and the human action that followed. The same concerns extend beyond HR: AI used in benefits eligibility, permitting, licensing, code enforcement, or service prioritization can affect rights and entitlements. Systems that materially influence these decisions should undergo legal, technical, and operational review before deployment, including HR and labor relations review where employment is involved. For each, define which outputs require human review, what information the reviewer must receive, what authority the reviewer has to reject or revise the output, and what evidence of review must be retained. Deploying these systems without appropriate review can create grievances, administrative challenges, litigation, and reputational harm.
     
  • Public-facing transparency and accessibility. Public-facing systems should be evaluated for disability access, language access, alternative service channels, and compatibility with the agency’s existing accessibility obligations. AI should not become the only practical route to a government service. Determine when applicable law requires disclosure that a person is interacting with AI or that AI materially influenced a service or decision. Even when not expressly required, agencies should consider plain language notice for public-facing chatbots, AI-triaged submissions, and materially AI-assisted communications, together with a route to human assistance where appropriate.
     
  • Cybersecurity and incident response. AI tools are another channel through which data can leave the network. Acceptable use rules should operate alongside DLP, identity, endpoint, SaaS discovery, and incident response controls. Agencies should restrict access to unapproved services where appropriate, monitor sensitive data movement, review AI features added to approved services, treat a breach at the model vendor like another third-party incident, and decide in advance who can obtain and preserve the relevant logs. Security-related exemptions, such as Florida’s exemption for specified agency cybersecurity information, Fla. Stat. § 119.0725, may limit disclosure but do not eliminate the preservation and retention duties discussed above.
     
  • Training, monitoring, and review. Access should follow training, not precede it. New users need a short, role-based briefing covering approved tools, restricted data, records handling, required review, and escalation. Refresher training should incorporate legal changes, new vendor functionality, and lessons from incidents. The policy should also require scheduled legal, IT, security, procurement, HR, accessibility, and records review, together with event-driven reassessment when a model, vendor, feature, integration, or consequential use materially changes. A policy the agency cannot show was distributed, taught, acknowledged, and revisited will be difficult to enforce.

AI use in local government will continue expanding. The legal framework surrounding that use will remain distributed across public records, privacy, civil rights, employment, procurement, cybersecurity, accessibility, and administrative law requirements. Using AI does not, by itself, displace those obligations.

The agencies best positioned are those that can identify which systems are in use, what information and decisions those systems affect, who is responsible for them, under what terms they operate, where their records reside, and who can restrict or stop them.

An enterprise license can support that work. It cannot perform it.

The Jones Walker Privacy, Data Strategy and Artificial Intelligence team advises public agencies and organizations on AI governance and acceptable use policies, tool inventories, enterprise and vendor contracting, public records and retention compliance, employment-related AI use, incident response, and the evolving state and federal regulatory landscape. Stay tuned and subscribe for continued insights from the AI Law and Policy Navigator.

Related Professionals
  • Christina Baptista
  • Jason M. Loring
  • Nick Primrose

Related Practices

  • Emerging Companies
  • Government Contracts
  • Government Relations & Legislative Advocacy
  • Privacy, Data Strategy, and Artificial Intelligence
  • State & Local
Sign Up For Alerts
© 2026 Jones Walker LLP. All Rights Reserved.
PrivacyDisclaimerAvident Advisors
A LexMundi Member