The Arcata City Council advanced a sweeping AI usage policy on July 15, 2026, setting firm limits on how city employees may use generative tools like Microsoft Copilot—and the draft rules contain hard-won lessons for any organization deploying AI in a Windows environment.
What Actually Changed
The proposed policy, which the council will vote on in two weeks, establishes a permission structure for AI use across all city departments. It requires department directors to approve the use of the city’s chosen platform, likely Microsoft Copilot because of Arcata’s existing Microsoft ecosystem. The policy applies to all employees, interns, and volunteers—whether on city-owned equipment or personal devices—closing a dangerous gap that often leads to “shadow AI.”
Three core safeguards define the draft:
- No sensitive data in prompts. Staff are explicitly barred from entering personal information—names, addresses, Social Security numbers, medical records—into any generative AI system. The rule acknowledges that a casual prompt can become a data-handling event with legal ramifications.
- Mandatory human review. Every AI-generated output must be checked for accuracy, tone, bias, and context before publication or official use. The policy treats the AI as a drafting assistant, never a source of truth.
- Public disclosure. AI-generated or significantly AI-altered content intended for the public must carry a label indicating its origin. The draft currently uses permissive “may” language, but council members Sarah Schaefer and Meredith Matthews pushed to swap it for “shall,” making disclosure a firm obligation.
City Manager Merritt Perry described the resolution as a “baseline” that will be updated regularly. The council also asked staff to address concerns about AI’s environmental impact and the use of artists’ work without consent—issues that surfaced during the discussion.
What It Means for You
Arcata’s policy may target municipal employees, but its implications ripple far beyond City Hall. Here’s how it lands for different audiences within the Windows ecosystem.
For Everyday Windows Users
If you use Copilot or other generative AI at home, Arcata’s rules are a cautionary tale. Entering a tax return, medical question, or legal document into a consumer AI service might seem harmless, but once that data hits an external server, you lose control. The city’s ban on sensitive information underscores a principle every individual should adopt: never type anything into an AI prompt that you wouldn’t want leaked or used for training.
For IT Administrators and Business Decision-Makers
This policy is a wake-up call for organizations that have rolled out Copilot without clear governance. Arcata’s draft gets the philosophy right—human accountability, no sensitive data, transparent disclosure—but it’s light on operational details. If you’re responsible for a Microsoft 365 tenant where Copilot is enabled, consider these immediate gaps:
- No approved-tools list. The policy mentions Copilot but doesn’t specify which versions or configurations. In practice, Copilot for Microsoft 365, Copilot in Windows, and consumer Copilot handle data differently. A formal list prevents confusion.
- No data classification scheme. A simple “don’t enter sensitive info” rule isn’t enough. Staff need a tiered model that distinguishes public data from confidential, legally protected, or high-risk material (personnel, health, law enforcement records).
- No audit or retention rules. If a staff member uses Copilot to draft a public report, is the prompt-and-response chain a public record? What happens if a resident requests it under FOIA? Organizations must define retention periods and ensure systems can reconstruct AI-assisted decisions.
- Training gaps. The policy requires human review, but without practical training on common AI hallucinations and bias, those reviews may be superficial.
For Developers
If you build applications that integrate with Copilot or other generative models, expect more customers to ask about labeling, data residency, and audit trails. Arcata’s policy signals that the public sector will demand verifiable compliance—and soon, similar requirements may leak into regulated industries. Start designing features that make it easy for users to disclose AI involvement and retain interaction logs.
How We Got Here
The road to Arcata’s AI policy began with a classic enterprise problem: employees adopted the tools before the organization did. Perry noted that some staff had already purchased personal AI subscriptions, creating a patchwork of unapproved, unsecured services. That scenario is common across companies and agencies worldwide, especially after Microsoft embedded Copilot into Windows 11 and Microsoft 365 in 2023–2025.
High-profile data exposures—from a Samsung engineer leaking source code via ChatGPT to healthcare workers accidentally sharing patient data with AI chatbots—have made privacy-first policies non-negotiable. Meanwhile, copyright lawsuits against AI companies over training data have raised fresh liability questions. Arcata’s council mirrored those broader tensions, with members voicing concerns about artists’ rights and the environmental footprint of large models.
The result is a policy that tries to balance productivity with caution. It’s not a ban—which would likely be ignored—but a framework that forces departments to own their use of AI. The decision to anchor on Microsoft Copilot is pragmatic: the city already pays for the suite, and having a single sanctioned tool simplifies oversight.
What to Do Now
Whether you’re an employee, an admin, or a policymaker, take these actionable steps today.
If You’re an Employee Using Copilot
- Stop entering sensitive data. Names, SSNs, financials, health details—pause before you type. If you need to summarize a confidential document, use a local, offline tool.
- Verify everything. Treat Copilot’s output like a junior intern’s first draft. Check facts, dates, regulations, and tone before hitting send.
- Ask about a policy. If your employer hasn’t set rules, request one. Point to Arcata as an example of a public entity taking this seriously.
If You’re an IT Administrator
- Create an approved AI tools list. Specify exactly which Copilot products are permitted (Copilot for Microsoft 365, Copilot in Edge, etc.) and under what circumstances.
- Implement data classification. Work with legal and compliance teams to define four tiers: public, internal non-public, confidential/restricted, and high-risk. Map each tier to allowed AI uses.
- Set up auditing. Use Microsoft Purview or third-party tools to log Copilot interactions, and establish a retention period that aligns with records-management laws.
- Enable privacy controls. Ensure that data-loss prevention (DLP) policies flag attempts to share sensitive information, and configure Copilot’s enterprise data protection features to prevent training on your tenant’s inputs.
- Train your users. Run scenario-based workshops showing real-world errors AI can make, and teach staff to label AI-assisted content.
If You’re Drafting a Policy
- Learn from Arcata’s strengths. Its insistence on human review, no-sensitive-data rules, and disclosure are solid pillars.
- Fortify the weak points. Add an approved-tools list, tiered data categories, retention rules, and consequences for misuse.
- Involve stakeholders. Get input from records managers, privacy officers, legal counsel, and frontline staff. The July 15 meeting showed that council members valued hearing from the city manager and each other—your process should be no different.
- Plan for regular updates. As Perry noted, the policy is a baseline. Schedule quarterly reviews to keep pace with new AI features and emerging risks.
Outlook
The Arcata City Council will likely vote on the finalized policy by the end of July 2026. Expect the “may” language to become “shall,” and possibly stronger wording on environmental and copyright concerns. Other municipalities in California and beyond are watching closely; a well-implemented policy here could become a model for small governments navigating AI.
For Microsoft, city-level adoption of Copilot with this level of scrutiny signals that public-sector customers need better built-in guardrails—simpler data classification, clearer audit trails, and maybe even a “government mode” that locks down training data exposure by default. The next 12 months will test whether the company’s responsible AI investments can keep up with the practical demands of real-world governance.
Arcata’s approach is not perfect, but it’s real. In a landscape where most organizations still lack any AI policy, it’s a starting line—and a reminder that the best time to write the rules is before something goes wrong.