|
Issue No. 7 · Tuesday, September 15, 2026 · By Scott Olsen | |||||||
|
PULL UP A CHAIR I'll admit something. Documentation never got the time from me that it deserved. Not because I didn't believe in it. I believed in it the way most people believe in flossing, sincerely, and not often enough. Whatever was on fire that morning always won, and something was always on fire. The part that really got me was the backlog. It wasn't just documenting what we built. It was everything that existed before I ever walked in, systems somebody stood up years earlier, configured a certain way for a reason nobody wrote down, and then left. Every one of those was a small archaeology project, and there were a lot of them. Documentation's one of those running themes in the IT world. Most shops will tell you they need to get better at it, then kick that rock down the road another quarter. I want to be fair here though, because some shops genuinely are good at it, and I've got real respect for those people. It takes a discipline nobody hands out awards for. I'll say this much for my own team. We got better at it toward the end of my run at the clerk's office. The newer projects went in with documentation to match, and it made a real difference. We didn't suddenly find more hours in the week, we just stopped treating it as the optional part of finishing something. And don't be shy about pushing your vendors for their project notes either. You paid for the work, the documentation's part of the work. Just read what they hand you before you file it, because vendor notes have a way of describing the system they meant to build rather than the one that actually went in. Here's the standard I think is worth holding ourselves to. Your office should have documentation good enough that somebody could walk in, sit down, and pick it up. Not comfortably, but well enough to keep the lights on. And that should include the policies and procedures for running a responsible shop, not just where the servers are and what the passwords used to be. Which is the honest reason I keep pushing this policy template. It's not a magic fix, it's one less thing to worry about. If having a starting point is what finally gets one office to finish something they've been meaning to write for two years, that's a good week. What's the one document your office knows it should have written by now and still hasn't? Hit reply and tell me. THIS WEEK'S PICK Write your office's AI use policy in an afternoonI have put the same free AI Use Policy Template at the bottom of every issue for six weeks now. This week I want to actually walk you through filling it out, because a link in a box has never helped anybody adopt anything. Last week's issue explained why your prompts are public records. This is the part where you put that in writing. Then last week the UNC School of Government published fourteen recommendations for local government AI policies, and recommendation number one is "avoid copying templates." I am going to deal with that head on, because they are right, and it makes this walkthrough better rather than pointless.
THE TWO SECTIONS WORTH ARGUING ABOUT Approved uses and prohibited uses are opinions, not lawSections 4 and 5 are where the template takes a position, and where your office might reasonably take a different one. The draft allows AI for first drafts of letters, summaries, plain-language rewrites, and brainstorming. It prohibits entering confidential information, letting AI make a final decision about somebody's rights or benefits, publishing anything without human review, and doing office business on a personal AI account when an approved tool exists. Read those two lists out loud to whoever runs your departments before you adopt them. If a supervisor reads the prohibited list and says "well, we already do that," you have just found the actual conversation, and it is better to have it now than during a records request. WHERE MY TEMPLATE IS THIN Five things you should add yourselfI held the template up against those fourteen recommendations. It covers most of them already: IT approval, banning confidential data, human review and accountability, public records, transcription and retention, prohibited uses, annual review. Four gaps are worth closing before you adopt it, and fair warning, these four are writing rather than filling in a blank. They are the difference between an afternoon draft and a policy you are ready to adopt. Agentic AI. The template covers tools that answer you. It says nothing about tools that go take actions on their own, inside your systems, without a person clicking each step. That is showing up in products now. Decide whether you allow it at all before somebody turns it on. A tighter definition of "AI." My Section 3 defines the term broadly on purpose. The stronger approach is naming the categories separately, generative, predictive, automated decision-making, agentic, because the rules you want for each are genuinely different. Department-specific rules. One office-wide policy is the right starting point. It is not the right ending point if you have a law enforcement function, a benefits function, or anything else with its own legal exposure. A comprehension check. Hand the draft to three employees who were not in the room, ask them what it means, and watch where they hesitate. That is free, takes twenty minutes, and finds the sentence everybody will later claim was unclear. One more I am adding this week, and it did not come from that list. It came from the county in the Rulebook below, whose policy bans AI-enabled recording devices, smart glasses, wearable recorders, AI note-takers, in restricted work areas and during conversations with the public. My template does not cover that and it should. Those devices are shipping now, they are not a hypothetical, and a resident has no idea somebody's glasses are transcribing them. Their twelfth recommendation is one I would point you at rather than try to write for you: get legal counsel, IT, and your department heads in the room while you draft, and take an inventory of what AI is actually being used for across your office first. That second half is the quick win at the bottom of this issue, and it is worth doing before you write a word. One place I will note we differ: that guidance suggests being judicious about requiring staff to disclose when they used AI, partly because it is hard to enforce consistently and partly because of how the public reads AI use in the first place. My template takes the stricter position. Read both arguments and pick the one your office can actually live with, because a disclosure rule nobody follows is worse than an honest one you chose not to write. Read all fourteen recommendations: UNC School of Government, September 9, 2026 →
The honest catch: this template is a starting point, not legal advice, and the attorney review line is not throat-clearing. Public records exemptions, retention schedules, and AI disclosure rules vary a lot by state. The afternoon gets you a real draft instead of a blank page. It does not get you an adopted policy. THE RULEBOOK · TWO RULES WORTH A GLANCE What changed that affects how your office can use AI. Short, plain, and sourced. The part that keeps you out of the newspaper. Tagged Local for a city or county action, State for a change at the state level, Federal for a change at the federal level that reaches your desk.
GET THE TEMPLATE
ONE MORE QUICK WIN Ask your staff what they are already using, before you write a wordMost offices write an AI policy in a vacuum and then discover half the staff have been using ChatGPT on personal accounts for a year. Ask first, with no penalty attached, and you will write a far better policy. You will also find out which tools actually need to be on your approved list, instead of guessing. | |||||||
|
Know someone at another city or county who could use this? Forward it over.
Until next week, Scott Olsen, CGCIO Former CIO with eleven years in Florida local government Practical guidance for local government, not legal or procurement advice. |