
AI governance for government covers the structures, principles and processes public bodies use to adopt artificial intelligence responsibly, from a city council approving a new chatbot to a federal agency setting rules for algorithmic decision-making. For elected officials and public-sector administrators, that oversight now sits alongside the transparency and accountability duties they already carry.
This guide covers what AI governance for government involves and how public bodies can put it into practice:
AI governance for government means setting clear ownership, policy and review processes for how a public body adopts, uses and oversees AI systems, then documenting that oversight in a way the public and regulators can inspect.
The gap between AI adoption and AI oversight shows up clearly in the data. A 2024 survey by the Public Technology Institute of 55 city and county government IT executives found that only 11% had assigned a single individual to coordinate AI development. 63% had assigned no one, and 26% said the responsibility was shared across more than one person. Oversight is lagging, and most public bodies know it.
Public bodies carry an added layer that corporate boards don't: every policy decision, procurement choice and use case sits under public-records law and community scrutiny. An AI governance structure for a municipal council or school board must answer two questions: Is this AI system safe and effective, and can the public see exactly how and why it's being used? AI adoption raises the stakes on how public bodies build public trust.
Federal guidance has moved from broad principle to specific requirement. Office of Management and Budget memoranda M-25-21 and M-25-22 direct federal agencies to name a chief AI officer, stand up an AI governance board, publish compliance plans and maintain annual inventories of AI use cases.
The General Services Administration has issued supporting guidance for agencies implementing those requirements, and the Government Accountability Office continues to publish government-wide AI oversight findings that shape how agencies structure their programs.
State and local governments are moving in parallel, often faster than federal agencies in specific areas. The National Conference of State Legislatures tracks a growing body of state AI legislation, and the National Association of State Chief Information Officers named AI its top priority in its State CIO Top Ten survey for the first time.
Local governments and school districts are drawing on guidance from organizations like the National League of Cities and the National Association of Counties as they build their own AI policies, often without dedicated legal or technical staff to interpret federal and state requirements. Guidance written specifically for publicly elected boards helps close that gap, since AI policy is becoming the next test of the transparency duties these bodies already carry.
A handful of frameworks anchor most public-sector AI governance work today.
The OECD's "Governing with AI" guidance and the NIST AI Risk Management Framework both give public bodies a structure for identifying AI risks and building oversight around them, and the two are increasingly used together rather than as alternatives. The UK's GOV.UK AI Playbook offers a parallel model built specifically for public-sector procurement and deployment decisions.
At the federal level, OMB M-25-21 sets the clearest concrete requirements currently in force: a named chief AI officer, an AI governance board with defined authority, a published compliance plan and an annual use-case inventory that gets updated as new systems come online.
"It's good to have an AI framework or council, a safe environment for people to say this is what's working, this is what isn't working, so that you have the guidelines in place for the organization," says Sophia Velastegui, AI Business Leader, Director and Committee Chair at BlackLine and former GM of AI Products and Chief AI Officer at Microsoft.
Public bodies below the federal level don't face identical requirements, but many are adopting the same structure, since a named owner, a governance body and a documented use-case list are core elements of any AI governance framework, regardless of jurisdiction size.
The core requirements above look different depending on the size and structure of the government body applying them.
Federal agencies work directly against OMB M-25-21 and M-25-22, with a chief AI officer, formal governance board and annual public reporting obligations.
State governments generally follow their own legislative and executive AI policies, often modeled on federal guidance but adapted to state agency structures and existing IT governance bodies.
County governments typically fold AI oversight into existing procurement and risk-management processes, since most counties lack a dedicated AI policy function and instead extend general IT governance practices already in place to cover AI-specific use cases.
Municipal councils increasingly rely on use-case inventories and procurement clauses that require vendors to disclose how their AI systems work, an approach central to AI governance in local government that cities including San Jose have documented publicly through coalition efforts among municipal AI officers.
School boards face a distinct mix of pressures: academic integrity concerns, student data privacy and a public expectation of transparency around any AI tool that touches instruction or student records. Policy templates from state school boards associations increasingly address AI directly, as part of broader school board AI policies, rather than folding it into general technology policy.
Elected officials weighing AI adoption or oversight can work through five questions before approving any new AI use case::
"Put AI in your risk register. No one's going to argue with that. Get an AI policy. Board should be asking management for a policy. Adding it to your risk register can get the ball rolling," says Richard Barber, CEO of MindTech Group, speaking on a panel about board AI governance.
Agentic AI, meaning systems that take multi-step actions on their own rather than simply generating a response, raises oversight questions public bodies haven't had to answer yet, many of the same questions already surfacing in agentic AI in the boardroom discussions at public companies, where director AI use is outpacing formal policy.
According to the APAC Governance Outlook 2026 by Diligent Institute, the Governance Institute of Australia and the Singapore Institute of Directors, 65% of more than 200 senior leaders across the Asia-Pacific region named the absence of governance processes to guide agentic AI decision-making among their top agentic AI risks, second only to concerns about data quality and privacy at 66%. Respondents were drawn largely from the private and not-for-profit sectors, so the finding describes a governance gap shared across sectors rather than one specific to public bodies. Governance processes for agentic systems are still forming, which gives public bodies room to set their own standards early rather than adapt someone else's later.
The obligations and frameworks documented above only matter if a public body can show, at any point, that it has a named owner, a documented use case and a review process behind every AI system in service. A connected governance platform is built to support that proof.
The transparency and accountability challenges documented throughout this guide — naming an owner, documenting a use case and showing the public how a decision got made — are the same challenges Diligent Community is built to address for public bodies more broadly.
Diligent Community centralizes agenda and meeting management, an ADA-compliant public transparency site, digital voting with an audit trail and AI-assisted minutes generation. Diligent Community's transparency features give councils, school boards and special districts one place to document policy decisions, including AI-related ones, for public review.
For the risk-oversight side of AI governance specifically, Diligent ERM extends the broader pattern of ERM in government with AI-powered risk identification and benchmarking for public-sector risk programs, backed by FedRAMP and DoD authorization that matters for government buyers evaluating security requirements.
The City of Lethbridge used Diligent ERM to complete a four-year risk maturity plan in under 12 months. "Diligent's Risk Manager tool helped move our ERM maturity level quickly. We had originally plotted out our program over a 4-year period. However, in less than a year of using Risk Manager, we can confidently say we got there within 12 months," says Bronwyn Jesse, Risk and Controls Manager at the City of Lethbridge. The Architect of the Capitol, a U.S. federal government office, has also used Diligent ERM in its enterprise risk program. Neither case involved AI-specific oversight directly, but both demonstrate the kind of structured, auditable risk process that AI governance depends on.
Request a demo to see how Diligent Community and Diligent ERM support secure, transparent AI oversight for public bodies.
AI governance for government is the set of structures, principles and processes public bodies use to adopt AI responsibly, including named ownership, documented use cases, privacy review and public transparency around each decision.
OMB M-25-21 directs federal agencies to name a chief AI officer, establish an AI governance board, publish a compliance plan and maintain an annual inventory of AI use cases.
Start with an inventory of any AI systems already in use, assign a named owner to each one as part of governing AI obligations that scales as the program grows, and build a simple public-facing description of what each system does before adding new use cases.
Agentic AI governance covers oversight of AI systems that take multi-step actions independently rather than only generating a response, a newer category where most public bodies and vendors alike are still building governance processes from scratch.
Many public bodies use the NIST AI Risk Management Framework as a starting structure for identifying and managing AI risk, often alongside guidance from the OECD or GOV.UK AI Playbook rather than as a standalone framework.
Ready to bring transparent, secure AI oversight to your public body? Request a demo to see Diligent Community in action