Civic Innovation

Cities Spent 2026 Writing AI Policies. The Lever Was Never the Policy

Read what a city AI policy actually does and it turns out to be a purchasing document. Harry Hayman on why the procurement file is the real instrument.

By Harry Hayman 6 min read
Cities Spent 2026 Writing AI Policies. The Lever Was Never the Policy

The most common artificial intelligence item on American city and county agendas this year is not a ban, a moratorium or a hearing. It is passing an AI use policy.

Every state. Every size of town. Civic IQ’s analysis of more than a thousand local government meeting signals puts policy adoption at the top of the list, and Arkansas went as far as requiring its municipalities to adopt one at all.

That looks, at a glance, like a wave of regulation.

Then you read what the policies actually contain, and the regulation framing falls apart in your hands.

What is in them

They name approved vendors. They mandate staff training. They create formal procurement pathways.

Mount Pleasant in Texas passed a generative AI policy that specifically names Microsoft Copilot as the approved tool. Lincolnton in North Carolina passed one mandating Google Gemini for all staff. Contra Costa County in California rolled Copilot out across the enterprise with training every two weeks.

Those are not statutes. They are purchasing decisions with a preamble.

And the sequence is visible in the data. Sixty two percent of the AI signals Civic IQ tracks now involve governance policies that directly precede vendor selection, and the average run from policy discussion to first contract is nine to eighteen months.

So the policy is not the ceiling on what a city does about AI. The policy is the starting gun on what a city buys.

Why that is good news

I want to make the optimistic case here, because the pessimistic one gets written every week and it is not very useful.

No city council in this country is going to write better law, faster, than a company with a research budget the size of a small nation can absorb. That fight is not close, it is not winnable, and pretending otherwise wastes the one year of attention a council will ever give this. I would rather we spent that year on the part where we can actually win.

But a city is not only a regulator. A city is a customer. And a customer gets to ask questions that a regulator would need a statute, a court and three years to compel.

What was this system trained on. Under what conditions was it tested. What are the actual values of the performance metrics, not the ones in the brochure. What have you done about fairness, about robustness, about being able to explain a decision to the person it was made about.

Those are not my questions. They are the questions on the GovAI Coalition’s vendor fact sheet, and cities have already been writing them into technology solicitations. Research presented at the 2025 ACM conference on fairness and accountability found city staff doing exactly that: pulling that language into their RFPs because the procurement document was the instrument they actually controlled.

A vendor can ignore a resolution. A vendor cannot ignore a question on the form they have to fill in to get paid. That is not a clever trick, it is just where the incentive lives, and the incentive has always been a more reliable instrument than the sentiment.

The version that actually scales

Here is the part I find genuinely exciting, and it is already happening rather than being somebody’s white paper.

Groups of local governments are running cooperative solicitations. One shared request for proposals across many cities, which sets collective standards, cuts the cost of running the process, and moves vendor behaviour in a way no single town could manage on its own. GovEx’s report from the GovAI Coalition Summit describes cities testing precisely this, and the GovAI Coalition maintains a shared contract hub for it.

Think about what that does to the asymmetry. A town of forty thousand people asking a large AI company to disclose its training data is a letter that gets filed. Two hundred towns asking the same question, on the same form, as a condition of a contract they collectively want to sign, is a market requirement.

That is not regulation. It is something better, because it is enforced by the one thing the vendor actually wants, which is the contract. And unlike a law, it can be updated in the next procurement cycle rather than the next legislative session.

Accountability, in its least glamorous form

The other piece that has to exist is the boring one, and Seattle is doing it.

During the autumn 2025 budget process, Seattle’s City Council asked its IT department for regular reports on the city’s AI investments and usage. The first 2026 quarterly report was published on the first of April, sitting alongside the city’s published 2025 to 2026 AI plan.

Not a task force. Not a summit. A standing reporting requirement attached to a budget, which is how councils have held departments accountable for everything else since councils existed.

Every city that has passed an AI policy this year should be asking why it did not attach one of those.

One honest caution

I want to end on the thing that worries me, and it is not the technology.

A pilot without defined success criteria is not a pilot. It is a subscription.

I have watched this pattern in every sector I have worked in. Somebody buys the thing, calls the first year a pilot, and nobody ever writes down what would count as it having worked. Twelve months later the renewal arrives, the only available comparison is with not having it at all, and the invoice gets paid because cancelling looks like admitting a mistake.

The whole reason procurement is the real instrument is that procurement is where you get to write down what success means, before you have spent anything. If a city puts one sentence in the contract that says what result it expects and when it will check, it has done more governance than most AI policies contain.

And the resources for doing that already exist. This is not a research problem.

Which brings me home

Philadelphia buys an enormous amount of software. So do our anchor institutions, whose purchasing I keep going on about for a different set of reasons. Every one of those contracts is a place where somebody can write down what the tool must disclose, what it must be tested against and what would count as it working.

I am not asking for a Philadelphia AI ordinance. There will probably be one, and it will probably be fine.

I am asking that the people who write our contracts understand that they are the ones holding the actual instrument, and that they are almost certainly not in the room where the policy is being discussed. The city already runs the purchasing side of this.

So my ask is small and it is aimed at a room most people never think about. Get the procurement officers into the AI policy conversation, early, while there is still something to decide. They are the ones who will write the sentence that ends up mattering.

Read the procurement file. That is where the power sits.

Sources and references