Executive Summary
More than half of government offices surveyed now use AI to help with their work. But fewer than half have written rules for how to use it safely. This gap is real, we can measure it, and it closes fastest when a government copies rules that already work somewhere else, instead of writing brand-new rules from scratch.
55.7%
of government offices say they use AI to help with some part of their work
42.9%
say they have written rules for how that AI use should work
12.8pp
is the gap between using AI and having rules for it — the gap grows to 27pp for public-facing work like answering questions
700+
local, county, and state governments now share AI policy templates through the GovAI Coalition network
What this comes down to
- In every area the Granicus survey looked at, governments started using AI faster than they wrote rules for it. This gap is biggest for everyday, informal AI use — like drafting text or summarising documents — rather than for one big AI system a government officially rolls out.
- The places that wrote AI rules fastest didn’t start from a blank page. They copied and adjusted an existing policy — from San José, Seattle, or a state government — instead of writing new rules from first principles.
- Looking at real dates instead of what people say in surveys, written policy shows up 18 months to just over 3 years after people started using AI informally.
The gap, explained in ten slides
Save it, share it, or send it to whoever writes your AI policy.










More than half of the government offices surveyed now use artificial intelligence (AI) to help with some part of their work. But fewer than half have written rules for how to use it. The Granicus 2026 State of Digital Government: Trends in Websites and Customer Service report found that 55.7% of government offices use AI, while only 42.9% have a written AI policy. That’s a 12.8 percentage-point gap between using the tool and having rules for it.
How big is the gap?
The Granicus numbers come from a survey done with ath Power Consulting, part of a bigger 2026 State of Digital Government research series. It combines survey answers with real usage data from about 30 billion digital interactions a year on the Granicus platform. The gap isn’t the same everywhere. A companion report in the same series, looking at broader public communication and engagement work, found 71% AI use against just 44% formal policy — a 27 percentage-point gap. These two numbers aren’t a perfect match, since they come from different groups within the same research programme, but they point the same way: governments are using AI faster than they are writing rules for it, and the gap is widest for informal, everyday AI use — like drafting text or summarising documents — rather than one big official AI system.
The reported benefits help explain why AI use keeps growing even without rules in place. Leaders surveyed say AI makes repeat tasks easier (85.7%), saves time (85.7%), and saves money (71.4%). None of these benefits need a written policy to happen — any staff member can get them just by using an AI tool directly, with no approval, security check, or IT sign-off needed. Call centres show how much room there is for this: 50% to 70% of incoming calls are simple information questions, each taking 1.3 to 10 minutes to handle, and 40% of call centres see seasonal spikes in demand. This is exactly the kind of task one employee can hand to an AI tool without anyone else finding out or reviewing it first.
Why use is running ahead of the rules
Older government software had to be bought and approved first, and that approval process worked like a built-in checkpoint: a system couldn’t be used until it had a budget, a security check, and a legal review — and a policy was usually written during that process. AI tools skip this step. Many are free or cheap, work right in a web browser, and any staff member can start using one without asking their department first. Buying approval no longer triggers policy-writing. Instead, formal rules are being written after the fact, once informal AI use is already common.
Real examples back this up. The city of Wentzville, Missouri (population 47,000) used AI for public communication before it had any AI-specific policy. It relied on the city’s general ethics rules instead, adding AI-specific rules later. The Center for Democracy and Technology reviewed city AI guidance documents and found that at least 15 of them state AI use must follow existing laws on cybersecurity, public records, and privacy. That kind of rule is only needed because AI use had already started under those older laws, with AI-specific rules bolted on afterward instead of set up in advance.
Places that are closing the gap
A number of cities, counties, and states have published official AI policies over the past 18 months. This list isn’t every one of them, but it shows the general pattern.
| Jurisdiction | Instrument | Date | Governance model |
|---|---|---|---|
| City of San José, CA | AI Policy 1.7.12 / Generative AI Guidelines | 24 April 2025 | Originating template; anchors the GovAI Coalition |
| City of Seattle, WA | Artificial Intelligence Policy (POL-211) | 6 May 2025 | Bespoke, cited by other jurisdictions |
| Maine Office of Information Technology | Generative AI Policy | 30 September 2025 | State-level, applied to agencies |
| Kentucky Commonwealth Office of Technology | AI Policy (CIO-126) | 6 October 2025 | State-level, applied to agencies |
| Benton County, WA | Generative AI Policy | 2025 | Adapted from Washington state guidance |
| Cowlitz County, WA | AI Policy | 2026 | Adapted from Washington state guidance |
| City of Bellevue, WA | AI Policy and Guidelines | Compiled in MRSC guidance, May 2026 | Procurement-focused, transparency principles |
| City of Baltimore, MD | Generative AI Executive Order | Undated in public listing | Bespoke, prohibits unverified output use |
| City of Birmingham, AL | Generative AI Guidelines | Undated in public listing | Explicitly adapted from Boston’s guidelines |
| Miami-Dade County, FL | AI Policy Report | Undated in public listing | Synthesised from Boston, San José, Seattle, Kansas, the White House, and NIST |
Sources: Municipal Research and Services Center (MRSC); Center for Democracy and Technology; Civic Marketplace policy register; ICMA.
What the fastest movers have in common
The places that wrote their AI rules earliest didn’t start from scratch. They copied and adjusted a policy that already existed. Birmingham says right in its guidelines that it copied Boston’s. Miami-Dade County’s policy pulls language from Boston, San José, Seattle, the state of Kansas, White House guidance, and the NIST AI Risk Management Framework. San José’s own guidelines now form the base of the GovAI Coalition — a network that ICMA reported in February 2026 has grown to more than 2,000 public workers from over 700 local, county, and state governments, all sharing free policy templates, vendor questions, and buying guidance. Washington state’s Municipal Research and Services Center does something similar for its region, collecting and updating AI policy examples from cities and counties across the state, most recently in late May 2026.
This points to one clear idea: the gap the Granicus data found is closing fastest when governments copy each other’s rules, not when each one writes its own from zero. If your agency is trying to close this same gap, the practical answer is to take a published policy from a similar place, then have your own lawyers review it. That’s faster, and better proven, than building a brand-new policy from the ground up.
Checking the timing with real dates
We can test whether rules really do lag behind AI use by looking at actual dates instead of what people say in surveys. Public AI tools became widely available after ChatGPT launched in November 2022, and the first big signal from the US federal government on AI use — President Biden’s executive order — came in October 2023. Measured from there, the city and state policies listed above cluster between April 2025 and 2026. That’s 18 months to just over 3 years after informal AI use began. This matches the gap Granicus found between AI use and AI policy, and anyone can check it against the publication dates in the table above.
What this means for planning ahead
Putting the Granicus numbers together with these real examples points to three clear steps for any government office that doesn’t yet have formal AI rules.
- Take an existing published policy — from San José, Seattle, or a state like Maine or Kentucky — and adjust it, rather than writing one from scratch. Have your own legal and records team review it before adopting it.
- Aim your first rules at the highest-volume, simplest tasks the data points to — mainly answering general questions and drafting text — since that’s where the proven time and money savings are.
- Attach a way to measure success, such as call-handling time, drafting speed, or hours saved, to each approved use of AI right when the policy is adopted. Don’t treat writing the rules and measuring results as two separate jobs.
This pattern — rules chasing AI use instead of leading it — is the same problem I’ve written about for private companies: rules and oversight should be a gate you pass through before rolling something out, not paperwork added after the fact. The risk governance framework I’ve laid out for companies works the same way the fastest-moving governments above do it: adjust an existing template instead of writing one from zero. The ISO 42001 AIMS checklist is a solid starting point for any organisation, public or private, still figuring this out from scratch.
Sources: Granicus, 2026 State of Digital Government: Trends in Websites and Customer Service, and Benchmarks for Building a Vital Digital Future: The 2026 State of Digital Government (April 2026); Center for Democracy and Technology, AI in Local Government: How Counties & Cities Are Advancing AI Governance (April 2025); Municipal Research and Services Center (MRSC), Artificial Intelligence (AI) Policies and Resources for Local Governments (updated May 2026); ICMA, AI in Your Municipality: Implementation and Governance (February 2026) and Generative AI Policies in Local Government (June 2024); Civic Marketplace, Model Policy for Artificial Intelligence in Local Government Agencies (November 2025); StateTech Magazine, New Guidance Offers a Blueprint for Local Government AI Governance (June 2026).
Free tool
ISO 42001 AIMS Readiness Checklist
Adapt this instead of writing your AI policy from scratch, 36 checks across the seven AIMS clauses, the same copy-and-adjust approach that’s closing the gap fastest for local governments.
