A practical governance checklist for municipal AI
Responsible municipal AI begins before procurement and continues after launch. The important questions are not limited to model accuracy. They include authority, privacy, records, accessibility, security, human review, public explanation, vendor obligations, and what happens when the system is wrong.
The following checklist draws on the Government of Canada's responsible AI guidance, the federal Directive on Automated Decision-Making, the City of Toronto's digital infrastructure principles, and the voluntary NIST AI Risk Management Framework. Those instruments do not all apply legally to every municipality. They are useful reference points, not a substitute for municipal legal advice or local policy.
Define the public-service objective
- What service outcome should improve?
- Which department and accountable official own that outcome?
- What baseline will show whether the change helped?
- Is AI necessary, or would a simpler process or software change solve the problem?
Beginning with a model or vendor rather than an objective makes it difficult to determine success.
Classify the decision and its impact
Document whether the system drafts, recommends, prioritizes, routes, predicts, or decides. Ask who is affected and what could happen if the output is late, biased, incomplete, or wrong.
The Government of Canada's Algorithmic Impact Assessment uses questions about system design, decision type, impact, and data to establish a proportionate level of safeguards. Federal requirements do not automatically govern municipalities, but the risk-based method is reusable.
Establish authority and human review
- Who is legally authorized to make the underlying decision?
- Which actions may AI prepare, and which require approval?
- When must the system stop or escalate?
- Can a resident reach a person, contest an outcome, and obtain an explanation?
Canada's Guiding principles for the use of AI in government call for explaining automated decisions to affected people and providing opportunities to contest them and seek remedies where applicable.
Control information
Identify every information source, its owner, the permitted purpose, retention requirements, and whether personal or sensitive information is involved. Do not paste municipal information into an unapproved public tool.
The City of Toronto's 2025 generative AI guidance directs staff to use approved tools for City work and ties that use to privacy, security, information governance, and records obligations.
Require useful evidence from suppliers
Procurement questions should cover:
- the specific system and model versions involved;
- where municipal information is processed and retained;
- subcontractors and external services;
- access control and audit records;
- evaluation data and known limitations;
- incident notification and corrective action;
- portability, deletion, and exit obligations;
- material changes that require municipal review.
A generic statement that a product is "responsible AI" is not control evidence.
Test ordinary failure
Evaluate incomplete requests, conflicting records, low-confidence output, unavailable systems, inappropriate content, language and accessibility failures, duplicate actions, and attempts to use information outside its permitted purpose.
NIST's voluntary AI Risk Management Framework organizes ongoing work into Govern, Map, Measure, and Manage. That sequence reinforces an important point: risk management is an operating practice, not a one-time approval form.
Monitor the public outcome
After launch, review service quality, correction rates, demographic or accessibility impacts where lawful and appropriate, complaints, escalations, privacy or security incidents, staff workload, cost, and the intended constituent outcome.
Pause or narrow the system when evidence no longer supports its use. Responsible operation includes the ability to stop.