A survey of Pennsylvania municipal employees has uncovered a troubling pattern: generative AI use has surged inside small local governments, but policies to govern that use are nearly nonexistent. Two-thirds of respondents said they use AI tools like ChatGPT or Microsoft Copilot for work at least monthly. More than half reported that their workplace had rolled out enterprise AI tools. Yet a staggering majority of those same employees said their organization had no generative AI policy at all—and more than a quarter admitted they were using personal, free AI accounts for official tasks.
These findings, drawn from a survey of 35 local-government employees in Pennsylvania published by Tech Policy Press on July 24, 2026, may seem like a niche concern. They are anything but. Small boroughs and townships, often with just a handful of staff, handle payroll, personnel records, permit applications, police reports, and resident complaints every day. When an employee pastes that information into a consumer chatbot, it can land on servers outside any government data-protection agreement, potentially exposing sensitive resident data.
The Survey That Exposed a Hidden Problem
The survey, conducted by the University of Pittsburgh’s Institute for Cyber Law, Policy, and Security (Pitt Cyber) and the Local Government Academy, targeted a notoriously hard-to-study population: small municipalities. Nearly 90 percent of Pennsylvania’s 2,555 municipalities have fewer than 10,000 residents. These are government offices where one person might juggle IT, human resources, public records, and council agendas.
Despite the sample’s small size, the numbers tell a clear story:
- 66% of respondents use generative AI for work at least monthly.
- Over 50% said their workplace had deployed enterprise AI tools such as Microsoft Copilot.
- More than 25% reported using personal, free AI accounts (like a standard ChatGPT login) for work-related tasks.
- Most respondents had no generative AI policy at their workplace.
- Of those without a policy, more than half said such guidance would be valuable.
- The biggest barrier to responsible adoption, cited by half the respondents, was a lack of staff expertise—ahead of budget constraints.
These figures paint a picture of technology adoption that has run ahead of institutional readiness. The tools are on desks, but the rulebook hasn’t been written.
Cracks in the Digital Foundation
For Windows users and IT administrators outside government, the scenario might sound familiar. Generative AI rarely enters an organization through a formal procurement process. It creeps in when an employee opens a browser, types a prompt, and discovers that a chatbot can draft a memo, summarize a 20-page report, or tidy up meeting minutes in seconds. In a small municipal office, those tasks involve real data—resident names, addresses, permit details, personnel matters, or preliminary budget figures.
“The problem is not that local governments are adopting AI,” write the survey authors. “The problem is that everyday use is outpacing institutional readiness.”
That mismatch is especially dangerous in the smallest governments. A borough manager using a free AI tool to polish a public notice might not realize that the tool’s terms of service allow the provider to store and analyze the input. A police clerk pasting an incident summary into a personal Copilot account could be placing law-enforcement information outside the chain of custody. These aren’t hypothetical risks; they are the logical consequence of giving employees powerful tools without clear boundaries.
The survey also found that many municipal leaders are sending mixed signals. About 40% of respondents described their leadership’s position on AI as “neutral or unclear.” Only two respondents said leadership actively discouraged use. In such a vacuum, individual employees are left to decide what is safe—a responsibility they rarely have the training to fulfill.
The Microsoft Copilot Factor
Many small local governments already operate inside the Microsoft ecosystem. Windows PCs, Microsoft 365, Teams, and SharePoint are the backbone of daily operations. That makes the roll-out of enterprise AI tools like Microsoft Copilot a double-edged sword.
When properly configured, Microsoft 365 Copilot can be a governance ally. It can respect existing identity controls, sensitivity labels, retention policies, and data-loss-prevention rules. A government that sets up Copilot correctly can ensure that an employee cannot accidentally surface data they don’t already have permission to see, and that all interactions are logged and auditable.
But that safety net doesn’t materialize on its own. Licensing, tenant configuration, and user training matter enormously. Without those pieces, a Copilot deployment can become a supercharged search box that exposes long-neglected permission problems. Overshared SharePoint sites, stale access rights, and missing sensitivity labels all become liabilities the moment an AI assistant starts indexing files.
More concerning is the survey’s finding that more than a quarter of respondents used personal AI accounts for work. A personal Copilot or ChatGPT login sits entirely outside the organization’s control. The municipality likely cannot enforce multifactor authentication, audit queries, or dictate data retention. If an employee leaves, the account—and all the prompts entered—goes with them. That is an unmanaged data exfiltration risk hiding in plain sight.
The Checklist Your Local Government Needs
Small governments don’t need a 100-page AI governance framework. They need a concise policy that answers four questions: what is allowed, what is prohibited, what needs approval, and what must be documented.
Here is a practical blueprint based on the survey’s findings and established risk-management principles:
1. Define clearly what’s off-limits. Employees should never enter the following into any unapproved AI tool: nonpublic resident data, personally identifiable information, personnel or payroll records, medical and benefits information, passwords, law-enforcement files, privileged legal advice, and sensitive procurement or bid details. This prohibition must be absolute and communicated in plain language.
2. Approve specific, low-risk tasks. Editing grammar in a public newsletter, creating outlines from already-public documents, generating plain-language summaries that a human will verify, and drafting internal checklists are all reasonable uses—provided a human reviews every output before it is shared or used in a decision.
3. Require review for anything beyond the basics. New AI subscriptions, meeting transcription services, tools that connect to municipal file repositories, public-facing chatbots, and any AI used for surveillance, identification, benefits decisions, or enforcement must go through a deliberate approval process involving legal, IT, and managerial review.
4. Maintain a simple AI inventory. A shared spreadsheet can track tool names, vendors, business purposes, data categories, account owners, and status of security reviews. This gives leadership something they often lack: visibility into what AI is actually running inside their organization.
5. Train staff with real local examples—not abstract frameworks. The survey respondents overwhelmingly asked for live peer-to-peer learning and hands-on training. A workshop showing how a neighboring township uses Copilot safely, what mistakes were made, and what a properly reviewed prompt looks like will be far more effective than a dusty PDF from a state agency.
What Residents Can Do
If you’re a resident of a small municipality, you have a stake in this story. The same borough that handles your permit application, your property tax records, or your noise complaint may be running those processes through an ungoverned AI pipeline. Here are a few reasonable steps you can take:
- Ask at a public meeting: Inquire whether the municipality has an AI usage policy and, if so, what it covers. If not, ask when one is expected.
- Check the website: Look for a posted policy or data-handling statement. Don’t be surprised if you find nothing—most municipalities are in the same boat.
- Support regional partnerships: The survey recommends activating state municipal associations, councils of governments, and universities to help translate best practices. Urge your local officials to participate in such networks.
- Demand transparency for high-risk uses: If your local government proposes using AI for surveillance, identity verification, or eligibility decisions, insist on a public hearing, legal review, and an independent evaluation of the technology’s accuracy and potential for bias.
The Bigger Picture
The Pennsylvania survey is a small window into a nationwide issue. Thousands of small governments across the U.S. are adopting generative AI in exactly the same ad hoc way—tool first, policy later. For IT professionals who support or consult for these municipalities, the message is clear: help them move beyond the “neutral” leadership stance that the survey uncovered. A hands-off approach does not prevent AI use; it merely guarantees that it will happen without controls.
The good news is that the building blocks for governed AI already exist in the Windows and Microsoft 365 environment many local governments use. Sensitivity labels, authenticated access, audit logs, and data-loss-prevention rules can all be extended to Copilot deployments. But those features must be turned on, configured, and reinforced with user training. The alternative—letting employees drift toward free, unmanaged tools—is a privacy incident waiting to happen.
Local government is the layer Americans encounter most directly. If AI becomes embedded in those interactions without clear rules, the consequences will not be theoretical. They will show up as incorrect permit decisions, leaked personal data, and a slow erosion of public trust. The tools are already on the desk. The time to govern them is now.