Prompt LocalPrompt Local
 

Issue No. 7 · Tuesday, September 15, 2026 · By Scott Olsen

PULL UP A CHAIR

I'll admit something. Documentation never got the time from me that it deserved.

Not because I didn't believe in it. I believed in it the way most people believe in flossing, sincerely, and not often enough. Whatever was on fire that morning always won, and something was always on fire.

The part that really got me was the backlog. It wasn't just documenting what we built. It was everything that existed before I ever walked in, systems somebody stood up years earlier, configured a certain way for a reason nobody wrote down, and then left. Every one of those was a small archaeology project, and there were a lot of them.

Documentation's one of those running themes in the IT world. Most shops will tell you they need to get better at it, then kick that rock down the road another quarter. I want to be fair here though, because some shops genuinely are good at it, and I've got real respect for those people. It takes a discipline nobody hands out awards for.

I'll say this much for my own team. We got better at it toward the end of my run at the clerk's office. The newer projects went in with documentation to match, and it made a real difference. We didn't suddenly find more hours in the week, we just stopped treating it as the optional part of finishing something. And don't be shy about pushing your vendors for their project notes either. You paid for the work, the documentation's part of the work. Just read what they hand you before you file it, because vendor notes have a way of describing the system they meant to build rather than the one that actually went in.

Here's the standard I think is worth holding ourselves to. Your office should have documentation good enough that somebody could walk in, sit down, and pick it up. Not comfortably, but well enough to keep the lights on. And that should include the policies and procedures for running a responsible shop, not just where the servers are and what the passwords used to be.

Which is the honest reason I keep pushing this policy template. It's not a magic fix, it's one less thing to worry about. If having a starting point is what finally gets one office to finish something they've been meaning to write for two years, that's a good week.

What's the one document your office knows it should have written by now and still hasn't? Hit reply and tell me.

THIS WEEK'S PICK

Write your office's AI use policy in an afternoon

I have put the same free AI Use Policy Template at the bottom of every issue for six weeks now. This week I want to actually walk you through filling it out, because a link in a box has never helped anybody adopt anything. Last week's issue explained why your prompts are public records. This is the part where you put that in writing.

Then last week the UNC School of Government published fourteen recommendations for local government AI policies, and recommendation number one is "avoid copying templates." I am going to deal with that head on, because they are right, and it makes this walkthrough better rather than pointless.

FIRST, THE OBJECTION

"Avoid copying templates" is good advice, and it is not an argument against starting from one

The warning is about adopting somebody else's language wholesale without tailoring it to your own legal and technical situation. That is a real failure mode, and it is exactly how offices end up with a policy citing the wrong state statute and naming a department that does not exist there.

The template I have been handing you says the same thing in its own opening line: fill in the brackets, delete what does not fit, have your attorney and board review it. A blank page and an untailored copy are both bad outcomes. The work is in the middle, and the rest of this walkthrough is about doing that middle part on purpose instead of skipping it.

START HERE  THE FOUR BLANKS THAT ACTUALLY REQUIRE A DECISION

Everything else is read, keep, or delete

The template runs thirteen sections, which looks like a lot until you notice that most of it is already written. Only four bracketed fields need you to actually decide something, and those four are the whole job.

1. Your office name. Thirty seconds. Find and replace.

2. The designated contact. A real named person with a title, the one who answers "am I allowed to use AI for this?" This is the field offices leave blank, and leaving it blank is what turns a policy into a document nobody follows. If nobody owns the question, the answer defaults to whatever each employee guesses.

3. Your state's public records citation. Section 6 covers what staff must never type into an AI tool, and it points at your state law for the exempt categories. Your attorney or records officer can give you the chapter in about two minutes. Do not guess at this one.

4. Who approves new tools. Usually IT, sometimes the office administrator, occasionally nobody, which is the problem. Name the role, not just the department.

Cost: free, it is a Google Doc you copy     Time: an afternoon for the draft, longer for review and adoption

THE TWO SECTIONS WORTH ARGUING ABOUT

Approved uses and prohibited uses are opinions, not law

Sections 4 and 5 are where the template takes a position, and where your office might reasonably take a different one. The draft allows AI for first drafts of letters, summaries, plain-language rewrites, and brainstorming. It prohibits entering confidential information, letting AI make a final decision about somebody's rights or benefits, publishing anything without human review, and doing office business on a personal AI account when an approved tool exists.

Read those two lists out loud to whoever runs your departments before you adopt them. If a supervisor reads the prohibited list and says "well, we already do that," you have just found the actual conversation, and it is better to have it now than during a records request.

WHERE MY TEMPLATE IS THIN

Five things you should add yourself

I held the template up against those fourteen recommendations. It covers most of them already: IT approval, banning confidential data, human review and accountability, public records, transcription and retention, prohibited uses, annual review. Four gaps are worth closing before you adopt it, and fair warning, these four are writing rather than filling in a blank. They are the difference between an afternoon draft and a policy you are ready to adopt.

Agentic AI. The template covers tools that answer you. It says nothing about tools that go take actions on their own, inside your systems, without a person clicking each step. That is showing up in products now. Decide whether you allow it at all before somebody turns it on.

A tighter definition of "AI." My Section 3 defines the term broadly on purpose. The stronger approach is naming the categories separately, generative, predictive, automated decision-making, agentic, because the rules you want for each are genuinely different.

Department-specific rules. One office-wide policy is the right starting point. It is not the right ending point if you have a law enforcement function, a benefits function, or anything else with its own legal exposure.

A comprehension check. Hand the draft to three employees who were not in the room, ask them what it means, and watch where they hesitate. That is free, takes twenty minutes, and finds the sentence everybody will later claim was unclear.

One more I am adding this week, and it did not come from that list. It came from the county in the Rulebook below, whose policy bans AI-enabled recording devices, smart glasses, wearable recorders, AI note-takers, in restricted work areas and during conversations with the public. My template does not cover that and it should. Those devices are shipping now, they are not a hypothetical, and a resident has no idea somebody's glasses are transcribing them.

Their twelfth recommendation is one I would point you at rather than try to write for you: get legal counsel, IT, and your department heads in the room while you draft, and take an inventory of what AI is actually being used for across your office first. That second half is the quick win at the bottom of this issue, and it is worth doing before you write a word.

One place I will note we differ: that guidance suggests being judicious about requiring staff to disclose when they used AI, partly because it is hard to enforce consistently and partly because of how the public reads AI use in the first place. My template takes the stricter position. Read both arguments and pick the one your office can actually live with, because a disclosure rule nobody follows is worse than an honest one you chose not to write.

Read all fourteen recommendations: UNC School of Government, September 9, 2026 →

THE STEP MOST OFFICES SKIP

Decide whether this needs a board vote or not

An internal administrative policy and a policy adopted by your governing board are two different things with two different levels of weight. Some offices can issue this as an administrative directive on Monday. Others need it on an agenda. Which one you are depends on your charter, your state law, and whether your office is under an elected official or a board. Ask your attorney that question at the same time you ask for the records citation, because the answer changes your timeline from one afternoon to one meeting cycle.

The honest catch: this template is a starting point, not legal advice, and the attorney review line is not throat-clearing. Public records exemptions, retention schedules, and AI disclosure rules vary a lot by state. The afternoon gets you a real draft instead of a blank page. It does not get you an adopted policy.

THE RULEBOOK · TWO RULES WORTH A GLANCE

What changed that affects how your office can use AI. Short, plain, and sourced. The part that keeps you out of the newspaper. Tagged Local for a city or county action, State for a change at the state level, Federal for a change at the federal level that reaches your desk.

Local

A Wisconsin county adopted exactly this kind of policy last month

The Douglas County, Wisconsin board adopted its first generative AI use policy on August 20 as Resolution #38-26. I pulled the adopted text out of the board packet, and it is worth a read. It covers all employees plus appointed and elected officials, on or off county premises. Staff may only use tools already covered under county licensing and running inside the county's own environment, Microsoft Copilot being the named example. Training is expected before use. Sensitive and confidential data may not be entered "under any circumstances," and the policy spells out what counts in both categories rather than leaving it to interpretation. Employees are fully responsible for their work with or without AI, and have to disclose and cite AI assistance, with the exact citation format written into the policy.

Two provisions stood out to me. Video and image generation is treated as high risk and needs specific IT permission, while text tools are permitted with risk awareness. And AI-enabled recording devices, smart glasses, wearable recorders, AI note-takers, voice-activated tools, are strictly prohibited in restricted workspaces and during any conversation with the public where confidential information might come up. That is a genuinely forward-looking rule and most policies I have seen do not have it yet. Mine does not either.

What it means for you: worth noting how they got there. Reporting on the meeting says they built on neighboring Bayfield County's policy and worked with the city of Superior and UW-Madison Extension, and that not every supervisor was enthusiastic, one argued against adopting on the grounds that these tools are prone to mistakes and fabrication. They adopted it anyway as a starting point. So a county that just passed a policy did not begin from a blank page, and did not wait to feel certain about it. That is the honest version of the advice above.

Source: Douglas County Board packet, Resolution #38-26 and Exhibit G-8-26 (August 20, 2026) →

State

Texas offices, read this before you put a policy on an agenda

Texas HB 149, the Responsible AI Governance Act, has been in effect since January 1, and two pieces of it land on local offices right now. First, if your office runs a chatbot, an automated responder, or anything else that talks to residents, you have to tell them they are dealing with an AI system, clearly, in plain language. That duty reaches cities and counties, not just the state: the statute defines a governmental entity as any administrative unit "of this state or of any political subdivision of this state." As of September 1 the Attorney General's public complaint portal is live, and penalties run as high as $200,000 for a violation that cannot be cured.

Second, and this is the one that matters for this week. Section 552.003 says the chapter "supersedes and preempts any ordinance, resolution, rule, or other regulation adopted by a political subdivision regarding the use of artificial intelligence systems." Read that word resolution again, because a board resolution is exactly how most counties would adopt the policy I just spent this issue telling you to write.

What it means for you: I am not going to tell you an internal employee policy is safely outside that language, because I do not know, and neither does anyone else yet. The law is nine months old, no court has tested where the line falls, and at least one legal summary reads it as barring local AI policies outright. If you are a Texas office, that makes the attorney conversation the first step instead of the last one, and it specifically makes the form matter, an administrative directive to your own staff is a different instrument than a resolution adopted by your board. Ask before it reaches an agenda. Outside Texas, watch whether this model spreads, because a state that preempts local AI rules changes what your office gets to decide for itself.

Source: Texas Legislature, HB 149 enrolled text →

GET THE TEMPLATE

The AI Use Policy Template, one last time in this spot

Click it, make your own copy, and edit away. Nothing to buy, no email required, it is already yours. After this issue it moves off the weekly spot and lives permanently at promptlocal.net, so it will always be one click away even when this section moves on to something new.

Get the free template

ONE MORE QUICK WIN

Ask your staff what they are already using, before you write a word

Most offices write an AI policy in a vacuum and then discover half the staff have been using ChatGPT on personal accounts for a year. Ask first, with no penalty attached, and you will write a far better policy. You will also find out which tools actually need to be on your approved list, instead of guessing.

Know someone at another city or county who could use this? Forward it over.

Subscribe free

Until next week,

Scott Olsen, CGCIO

Former CIO with eleven years in Florida local government

Follow on X

Practical guidance for local government, not legal or procurement advice.