Skip to main content

AI is becoming a normal part of the workplace, including local government.

Employees can access generative AI tools directly, while AI capabilities are increasingly being incorporated into the applications organisations already use. That creates opportunities to improve productivity, automate repetitive work, analyse information and potentially improve how services are delivered.

For council IT teams, however, there is another side to the conversation. How do you help the organisation take advantage of AI while maintaining appropriate visibility, security, governance and trust?

The challenge isn't simply deciding whether a particular AI tool works. IT teams increasingly need to consider where information is going, how AI-generated outputs are being used, what controls should apply and whether employees understand both the capabilities and limitations of the technology.

In other words, successful AI adoption isn't just about what AI can do. It's also about whether the organisation can trust how it is being used.

Why AI Matters for Local Councils

There are plenty of potential applications for AI within a council environment.

Depending on the organisation and the technology involved, AI could help employees summarise information, draft or refine documents, search large volumes of organisational knowledge, automate routine administrative work, analyse data or assist with interactions and enquiries.

But councils don't operate like technology start-ups. They manage community information, records, financial data and operational systems. They also have responsibilities around privacy, information governance, cybersecurity, transparency and service delivery.

That means the useful question isn't simply: “Where can we use AI?” It is: “Where can we use AI appropriately — and what needs to be in place before we do?” That distinction matters.

The AI Trust Challenge

The original article identified several issues that can affect confidence in AI adoption: data privacy and security, transparency, bias and fairness, and employee confidence in AI-generated results. Those considerations remain central to responsible adoption. For IT teams, some practical questions follow.

Where is council information going?

An employee pasting information into an AI tool may feel very different from uploading it to an unfamiliar cloud application. From an information-governance perspective, however, IT still needs visibility over questions such as:

  • What information is employees entering?
  • Where is that information processed?
  • Is it retained?
  • Can it be used to train or improve a model?
  • Who can access it?
  • What contractual and security controls apply?

This becomes particularly important when employees are experimenting with freely available AI services outside the organisation's approved technology environment.

AI governance therefore isn't only about choosing approved tools. It's also about helping employees understand why the distinction between approved and unapproved tools matters.

Can employees trust the output?

AI systems can produce convincing responses without guaranteeing that those responses are correct. That creates another challenge for councils: ensuring AI-generated information isn't automatically treated as authoritative simply because it sounds authoritative.

The level of human oversight required will depend on the use case. Using AI to brainstorm wording for an internal document is very different from relying on an AI-generated output to inform a decision affecting a member of the community.

The higher the potential impact, the more important appropriate review, accountability and human judgement become.

Does the organisation know where AI is being used?

AI adoption doesn't always begin with a formal technology project. An employee can create an account for a generative AI service in minutes. Another might discover an AI capability inside software they already use. A team may begin experimenting with AI to solve a particular business problem before IT is involved.

That creates a visibility problem. If IT doesn't know which AI tools are being used, it becomes much harder to understand where organisational information is going or to put appropriate controls around it. The objective doesn't have to be stopping employees from experimenting.

A better goal is creating an environment where employees know which tools they can use, what information they can use with them and when they should involve IT.

How IT Teams Can Build Trust in AI

Building trust doesn't require solving every AI governance question before anybody can begin experimenting. A more practical approach is to establish sensible foundations and build from there.

1. Start Small and Strategic

Not every AI use case carries the same level of risk. Starting with lower-risk applications can allow a council to develop experience with the technology while learning how employees actually use it.

That might include helping employees summarise non-sensitive information, develop first drafts, brainstorm ideas or automate relatively low-risk administrative tasks. From there, more sophisticated applications can be considered as governance, experience and organisational confidence mature.

The important point is to avoid adopting AI simply because the technology is available. Start with a problem worth solving. Then determine whether AI is actually an appropriate way to solve it.

2. Prioritise Data Governance

AI governance and data governance are closely connected.

Before approving an AI tool, IT teams should understand what information it can access, how that information is processed, what security controls apply and whether its use is consistent with the council's existing privacy and information-management requirements.

This is also where existing governance processes matter. AI shouldn't necessarily require an entirely separate universe of policies and controls. Existing approaches to information classification, access management, application approval, vendor assessment, privacy and cybersecurity can provide useful foundations.

The technology may be new. Many of the underlying governance questions aren't.

3. Keep Humans in the Loop

AI can assist people without replacing human judgement.

Clear review processes are particularly important where AI-generated outputs could influence decisions, public communications, operational activity or interactions with members of the community.

Employees should understand that AI output may need to be checked, challenged or validated before it is relied upon. That also means establishing accountability.

If an AI system assists with a piece of work, somebody should still understand who is responsible for the final decision or outcome. AI can support judgement. It shouldn't make accountability disappear.

4. Set Clear AI Guardrails

Employees are more likely to use AI appropriately when the rules are understandable. Rather than relying solely on broad statements such as “use AI responsibly,” councils can give employees practical guidance about:

  • which AI tools are approved;
  • what types of information can and can't be entered;
  • which activities require human review;
  • when IT, privacy, security or leadership should be consulted;
  • how AI-generated content should be checked before use; and
  • what employees should do if they're unsure.

This doesn't need to turn IT into the AI police. In fact, overly restrictive policies can create another problem: employees may simply use AI without telling IT.

The better outcome is one where employees see IT as somewhere they can go for guidance. Good governance should make responsible AI easier, not drive AI use underground.

5. Communicate How AI Is Being Used

Trust depends partly on transparency. Internally, employees should understand why particular AI tools have been approved, what controls apply and what responsible use looks like.

Where AI is being used in ways that materially affect community-facing services or decision-making, councils may also need to consider what level of transparency is appropriate for the people interacting with those services.

The answer will depend on the use case. But the underlying principle is useful: People are more likely to trust AI when they understand where it is being used, what role it plays and where human accountability remains.

IT Doesn't Have to Own AI Alone

There is another important point for council IT teams. AI governance shouldn't become yet another responsibility that lands entirely on IT.

IT has an important role in understanding security, applications, access, data and technical controls. But responsible AI adoption can also involve leadership, privacy, records management, governance, legal or risk functions, HR and the business teams actually using the technology.

Different organisations will divide those responsibilities differently. What matters is that responsibility is clear. This connects with a broader challenge we've explored in How Much of Your Council Depends on One IT Person?

As technology environments expand, internal IT teams can find themselves responsible for an increasingly broad range of disciplines. AI adds another layer — encompassing security, governance, vendor assessment, data, employee enablement and ongoing oversight.

The answer shouldn't automatically be: “IT will take care of AI.” A healthier question is: “Who needs to be involved for our organisation to use AI well?”

From AI Gatekeeper to AI Enabler

For IT Managers, perhaps the most useful shift is to stop thinking about AI governance purely as a mechanism for restricting technology.

There will certainly be AI tools and use cases that shouldn't be approved. But governance can also enable adoption. If employees understand which tools are approved, what information they can use, where the boundaries sit and who they can approach for help, they can experiment with much greater confidence.

IT can then move from reacting to unknown AI use toward helping the organisation make better technology decisions. That's a much stronger position. Instead of: “You can't use AI.” the conversation becomes: “Here's how we can use AI safely.”

Five Questions for Your IT Team

If your council is already exploring AI — formally or informally — these five questions can provide a useful starting point:

  1. Do we know which AI tools employees are currently using?
  2. Do employees understand what information can and can't be entered into those tools?
  3. Do we have a clear process for assessing and approving new AI applications or use cases?
  4. Do important AI-generated outputs receive appropriate human review?
  5. Do employees know who to approach when they want to use AI for something new?

If several answers are “No” or “We're not sure,” that doesn't mean AI adoption needs to stop. It simply identifies where stronger governance could make adoption safer and more sustainable.

Trust Isn't a Barrier to AI Adoption

AI will continue to create new opportunities for local government. Some will prove genuinely valuable. Others won't. And as the technology evolves, councils will continue learning which applications make sense for their organisation.

The objective doesn't need to be adopting AI as quickly as possible. Nor does it need to be eliminating every possible risk before employees are allowed to experiment.

A more practical goal is to create an environment where the council understands how AI is being used, where its information is going, what controls apply and where human accountability remains.

For IT teams, that means balancing enablement with appropriate governance. The goal isn't to slow AI down. It's to give the organisation enough confidence, visibility and governance to use it responsibly.

Ben Luks
Post by Ben Luks
8 October 2025, 15:15:46 GMT+10:30

Comments