The System of Record and Who Controls the Write Path
A city is not a private-sector buyer with an unusual logo. Four things make municipal agent integration structurally different, and none of them is about model capability. The write path into the system of record is almost always gated by the vendor rather than by the city, even though the city owns the data. Retention duties attach to what the agent produces, while disclosure duties are genuinely untested. Procurement is not a step before the project — it is the project's timeline. And accessibility is a federal regulation with a date on it, a date that moved on April 20, 2026.
Start with the one sentence this whole cluster hangs on: an agent can only be as autonomous as its write path allows. In a city, that sentence has an extra edge, because the write is frequently an official act. Creating a service request is administrative. Approving a permit is adjudication. The gap between those two things is where every serious design decision in municipal AI lives.
| Function | Who holds the system of record | What the documented integration posture actually is | The honest caveat |
|---|---|---|---|
| Permitting, licensing, code enforcement | Accela Civic Platform; Tyler Enterprise Permitting & Licensing (formerly EnerGov); OpenGov (ViewPoint Cloud lineage); BS&A; AMANDA | Accela publishes a REST Construct API with public developer docs and a documented three-step onboarding: register an app on the developer portal, get a test token and test-environment access, then call. The page states no approval, certification, marketplace listing or agency-consent gate. Tyler has no unified public developer portal; each product line has its own access path and docs behind customer login, with no public sandbox. | Accela is the most open of the major permitting vendors on the public record. But we could not verify Accela's write endpoints, OAuth scopes, partner fees, or whether production credentials require agency authorization — do not assume an agent can create a permit record. |
| 311 and service requests | CivicPlus SeeClickFix (volume leader); Catalis QAlert / Request 311; Cityworks; GoGov; Comcate; TextMyGov; Granicus; OpenGov; Salesforce Government Cloud; Citibot; Verint | CivicPlus's own documentation names exactly two SeeClickFix APIs: the Open311 API for pulling public data, and a private organizational API for internal dashboard and reporting purposes. Both are described as read or pull. | This is the single most consequential integration fact for a 311 agent. Read is documented; write is not. The docs also do not state rate limits, extra cost, licensing terms or an approval step — which means undocumented, not absent. |
| Utility billing (customer information systems) | Harris Computer brands under Constellation Software — Advanced Utility Systems, Cayenta, Cogsdale, inHance, MeterSense, NorthStar, Systems & Software; other names in the market — taken from a list published by one of the vendors on it, so we use the names and not its tiering — SpryPoint, Oracle Utilities Customer Cloud Service, NISC iVUE, Tyler Munis CIS, Bynry SMART360 | We could not verify a public API posture for the Harris CIS brands. Say not publicly documented, not no API. | Constellation does not sell the companies it acquires. That inverts the usual risk: with a PE-owned vendor you fear a flip and a repricing; here there is no exit event that will ever force modernization. |
| Clerk, agenda, records requests | Granicus (agenda and meeting management, civic engagement, and GovQA for records-request workflow, acquired 2021); CivicPlus NextRequest | Not publicly documented for either platform in what we could verify. | Ownership is in motion. Granicus is Vista- and Harvest-backed as of August 2026, with K1 Investment Management and AIMCo also on the cap table, and a sale process reported at roughly $4bn with Jefferies and William Blair engaged. No transaction had closed as of August 17, 2026 — and Granicus owns both AMANDA and GovQA. |
| Municipal code as a knowledge source | Municode; Encode Plus; ECode360 by GeneralCode; American Legal Publishing | Listed on the agent-native vendor's integration page under the label Municipal Code. | Our analysis, from the product category rather than any vendor statement: these are ingestion sources, not bidirectional systems. Your agent reads the code; nothing writes back. |
Read the second row again, because it is the most consequential fact on this page for anyone building a 311 agent. CivicPlus's own help documentation for SeeClickFix names two APIs: an Open311 API described as being for pulling public data, intended for external data-visualization tools, and a private organizational API described as being for internal dashboard and reporting purposes. Both are read or pull interfaces. The Open311 GeoReport v2 specificationdoes define a POST method for creating requests — but SeeClickFix's own Open311 documentation page returned an HTTP 403 to our fetch client, so we cannot confirm that SeeClickFix implements POST, or on what terms. We are reporting a gap, not asserting an absence.
At the other end of the spectrum sits Accela's Construct API, which is the most open posture among the major permitting vendors on the public record. The published getting-started flow is three steps: register an app on the developer portal, obtain a test token and test-environment access, then call. The page states no approval, no certification, no marketplace listing and no agency-consent gate. That is genuinely better than the market norm and worth saying plainly. It is also not the same as a green light: we could not verify whether Accela charges a partner or API fee, whether production credentials require agency authorization, or which specific write endpoints and OAuth scopes exist. Do not architect on the assumption that an agent can create a permit record.
Tyler Technologies is the incumbent across most of this estate — Enterprise Permitting & Licensing, Enterprise ERP, courts, public safety, appraisal, recording. Its integration posture is gated by design: no unified public developer portal, each product line with its own access path and credentialing, documentation behind customer login, no public sandbox or trial, and API access requiring an active licence plus an implementation or professional-services engagement. When we fetched Tyler's public API catalog page, it returned an HTTP 403 to our automated client. We report that as an observation about what a machine can retrieve, not as proof of policy — but it is consistent with the posture.
The cleanest evidence that API access in this market is a licensed, priced good does not come from us. It comes from a competitor-integrator: CivicPlus's own SeeClickFix documentation for its Tyler connector warns customers that the licence for the third-party software's API used for the integration may require additional cost from that vendor, and tells them to confirm their own API access and licence with Tyler directly. When one vendor tells your city to go check whether another vendor will charge it for access to its own data, the market has told you what rung you are on.
The tell, in one sentence from an agent-native vendor
Polimorphic — an AI platform built specifically for local-government 311, permitting and licensing, with a funding round led by General Catalyst and earlier investment from M13 — publishes an integrations page listing ArcGIS, BS&A ERP, Cityworks, Catalis Request 311, CivicPlus 311, Tyler ERP, Software Solutions ERP, Caselle, AMANDA by Granicus, four municipal code publishers and Stripe Payments. The page does not disclose the API-versus-sync method for most of them. Its FAQ says, verbatim: “We will do the legwork, including contacting the vendor, and come back with an easy plan you can approve.”
That sentence is the thesis of this article in one line. In municipal software, an integration is a negotiation with a third party who is not your customer — not a credential you fetch from a docs page. It is an honest sentence and a well-run vendor will say something like it. What it should tell a city manager is that the integration timeline contains a human on the other side of a phone, and that human works for someone else.
One structural note on utility billing, because it inverts the usual risk analysis. The consolidator in municipal customer information systems is Harris Computer, under Constellation Software, operating brands including Advanced Utility Systems, Cayenta, Cogsdale, inHance, MeterSense, NorthStar and Systems & Software. Unlike a private-equity roll-up, Constellation does not sell the companies it acquires — it buys from founders or investors and holds indefinitely. With a PE-owned vendor, the risk you plan for is a flip and a repricing. Here the risk runs the other way: there is no exit event that will ever force modernization. That is a structural observation, not a criticism, and it should change how long a horizon you assume when you plan around a CIS integration.
Finally, a conflict worth naming. The public-records request platform and the AI agent are frequently sold by the same vendor or its direct competitor. Granicus owns GovQA; CivicPlus owns NextRequest. An agent that generates records also generates the records-request workload that a second product then bills the city to process. Nobody is doing anything improper — but you should know that the cost of the agent and the cost of handling what it produces may land on two different line items, sold by the same account team.
Open311 in 2026: What the DNS and the Monitor Say
Every article about civic AI eventually says “cities have Open311, so agents can integrate.” We probed it directly on August 12, 2026, and that sentence is not supportable.
The standard's own front door is gone. open311.org does not resolve. DNS shows delegated nameservers but no A record. Only wiki.open311.org still resolves, and it resolves to a GitHub Pages site. The homepage of the open standard for municipal service requests is dark, and the community wiki survives on free hosting. That is not a rhetorical flourish; it is a DNS record you can check in fifteen seconds.
The official status monitor is still running and still watching 25 endpoints every ten minutes. At our fetch it showed 6 endpoints okay and 19 failing — a mix of 400, 404, 502 and 503 responses, connection failures, timeouts, and German endpoints returning HTML where XML was expected. It reported San Francisco at 0.54% uptime.
Then we curled the endpoints ourselves, and the monitor turned out to be wrong in both directions.
| Endpoint | HTTP status | What came back | Note |
|---|---|---|---|
| San Francisco — mobile311.sfgov.org/open311/v2/services.json | 200 | Valid Open311 JSON service list | The official monitor reported San Francisco at 0.54% uptime in the same window |
| Boston — 311.boston.gov/open311/v2/services.json | 200 | Valid Open311 JSON service list | Served from the same third-party vendor infrastructure as San Francisco |
| Bloomington — bloomington.in.gov/crm/open311/v2/services.json | 200 | Valid Open311 JSON | Also reported okay by the monitor |
| Columbus — 311.columbus.gov/open311/v2/services.json | 200 | An HTML page, not an API | A 200 status code is not evidence of a working endpoint |
| Chicago — 311api.cityofchicago.org | Connection failure | — | The monitor reported Chicago as okay; our probe disagreed |
| Baltimore — 311.baltimorecity.gov/open311/v2/… | 404 | — | Also reported okay by the monitor |
| Grand Rapids — grcity.us/api/open311/v2/… | 404 | — | Listed on the wiki server directory with no deprecation marker |
| Toronto — secure.toronto.ca/webwizard/ws/… | 403 | — | Blocked to an automated client |
| Washington, DC — 311.dc.gov/open311/v2/services.xml | 401 | — | Authentication required; no self-serve credential documented |
There is a further finding that matters more than the uptime. We pulled the discovery documents for the two most-cited US deployments. San Francisco's discovery.json carries a changeset of 2022-11-01, a noreply@spotmobile.io contact, a production endpoint on spotmobile.net, and a key_servicefield pointing at a web form to request an API key. Boston's is identical in shape: the same 2022-11-01 changeset, the same contact address, the same vendor domain, the same manual key-request form.
- The flagship deployments run one third-party vendor: The two Open311 implementations most often cited as proof the standard works are served from the same vendor's infrastructure, not from the cities' own systems. That is a single point of failure dressed as a distributed standard.
- The discovery documents are frozen at 2022-11-01: Nearly four years stale at the time of writing. A discovery document is how a client learns what the service supports; a stale one is a map of a city that has since been rebuilt.
- Access is not self-serve: Both cities gate the API key behind a manual request form. An agent developer does not just call the open API; they file a request and wait for a human to respond. Treat credential acquisition as a scheduled project task with a named owner.
The honest bottom line: Open311 GeoReport v2 exists, is genuinely implemented in a handful of cities, and is not a dependable 2026 integration substrate. It is read-oriented, key-gated, unevenly maintained, and its steward site no longer resolves. Use it where it works and you have confirmed it works this week. Do not put it on a critical path.
Which Rung of the Integration Ladder a City Is On
Across this cluster we use a five-rung ladder to describe how an agent reaches a system of record. Each rung down means less vendor cooperation, more fragility and more contractual exposure. You are on exactly one rung per system, whatever your architecture diagram says. Here is how the rungs land in a city.
| Rung | What it looks like in local government | What it costs you in practice | What breaks it |
|---|---|---|---|
| Rung 1 — Documented public API | Accela's Construct API is the clearest municipal example: public docs, a developer portal, a test token, a test environment. Stripe Payments appears on the agent-native vendor's list as an Open API. | Lowest cost, best versioning, the write surface is usually narrower than the read surface. Check the write surface before you architect — a documented API with no write path is a Rung 5 in disguise. | Version deprecation, rate limits, and unilateral repricing. The terms are the vendor's to set. |
| Rung 2 — Certified partner program or licensed API | Tyler: no self-serve access, an active license plus an implementation or professional-services engagement, no public sandbox. A competitor-integrator's own documentation warns customers that the license for the third-party software's API utilized for integration may require additional cost from that vendor. | This is where the money and the gatekeeping live, and where costs are least visible before you commit. Model the fee as recurring, forever, per interface. | Program terms are unilateral and renewable. Certification lapses. Fee models shift. The gate can simply close. |
| Rung 3 — Batch file, scheduled export, SFTP | Common between a CIS and a general ledger, and between a permitting system and a GIS. Boring, durable, still everywhere in local government. | For an agent this is often the safest write path precisely because it is batch: the file is a natural reconciliation checkpoint, and you get a review window before anything commits. | Schema drift on version upgrades, and latency — you reconcile against a stale world. |
| Rung 4 — Screen scraping or RPA | Frequently the only path into an on-premise system with no API. Legitimate, and the most fragile thing you will ever operate. | You are consuming a presentation layer the vendor is free to change without notice or versioning. Any UI change, MFA rollout or bot-detection deployment breaks it. And a contract renewal can add an anti-automation clause. | Both halves are true: sometimes it is the only rung available, and it is always the one that breaks first and exposes you contractually. |
| Rung 5 — No path at all | A real and common answer in this market. Several municipal platforms have no publicly documented third-party write path at any price. | The honest options: change vendors at the next renewal, wait for a forcing function, or put a human in the loop for the write step and let the agent do everything up to it. | The agent drafts and a human commits is a legitimate architecture, not a defeat. In a city it is frequently the correct one anyway, because the commit is an official act. |
Two things about this ladder are routinely misunderstood, and both are expensive.
First: a Model Context Protocol server does not change your rung. MCP standardises how a tool is described and called. It does not decide whether this agent may issue this write. If your permitting vendor requires a licence and a services engagement for API access, wrapping it in an MCP server does not create the licence. MCP is a wrapper around whatever rung you were already on — a genuinely useful one for portability and for keeping tool definitions honest, and not a substitute for a contract. The same applies to agent-to-agent protocols. They are transport and discovery, not permission.
Second: screen scraping and RPA deserve both halves of an honest treatment. In local government they are frequently the only path into an on-premise system that predates REST, and pretending otherwise helps nobody. They are also the most fragile thing you will operate, because you are consuming a presentation layer the vendor is free to change without notice or versioning. And the legal position is more nuanced than the confident version you will hear in a sales meeting.
The scraping law, stated precisely — because the confident version is wrong
The case everyone cites is hiQ Labs v. LinkedIn, and it did not make scraping legal. The Ninth Circuit was ruling on a preliminary injunction under its sliding-scale standard, and its own words were that hiQ “has raised a serious question as to this issue” and had “raised serious questions about whether LinkedIn may invoke the CFAA to preempt hiQ's possibly meritorious tortious interference claim.” A serious question is not a holding of legality. hiQ then lost on contract: a November 2022 summary judgment found it had breached LinkedIn's user agreement, and a December 2022 stipulated consent judgment imposed $500,000 plus a permanent injunction requiring it to cease scraping and destroy the derived data and code.
On the federal statute, Van Buren v. United Statesheld that an individual “exceeds authorized access” when he accesses a computer with authorization but then obtains information located in particular areas of the computer — such as files, folders, or databases — that are off limits to him. And it expressly reserved the question that matters most here: “For present purposes, we need not address whether this inquiry turns only on technological (or ‘code-based’) limitations on access, or instead also looks to limits contained in contracts or policies.” Anyone who tells you the Supreme Court settled whether terms of service can create liability is overstating it.
The practical translation for a city: terms-of-service breach and computer-fraud liability are different questions with different answers, and in the one case everybody cites it was the contract claim that bit. Before you automate against a vendor portal you log into, have the city attorney read the agreement you clicked through — and note that scraping behind a login you agreed to terms for is a materially worse position than reading a public page.
Rung 5 deserves its own paragraph because in municipal work it is often the right answer rather than a defeat. Some systems of record have no third-party write path at any price. The options are to change vendors at the next renewal, to wait for a forcing function, or to put a human in the loop for the write step and let the agent do everything up to it. The agent drafts and a human commits is a legitimate architecture. In a city it is frequently the correct architecture anyway, because the commit is an official act with due-process consequences, and you were never going to automate it.
One engineering note that belongs on this rung discussion. Whatever path you land on, the write needs idempotency, and there is no standard for it: the IETF draft for an idempotency key header reached revision -07 and expired without becoming an RFC. The de-facto convention is Stripe's, which saves the status code and body of the first request for a given key and returns the same result on retry — and prunes keys after at least 24 hours, so a retry a week later is a fresh write. Derive the key from business intent rather than from the attempt, persist it before the call, keep your own dedupe table alive longer than the downstream retention window, and never let the model generate the key. Non-determinism in key generation is indistinguishable from having no idempotency at all.
Public Records: Retention Is Answered, Disclosure Is Not
This is the constraint no vendor will raise in a demo, and it is the one that should shape your architecture. It has two halves, governed by two different statutes, with two very different levels of certainty. Getting them confused is the most common error in writing on this subject — including in our own earlier drafts.
Half one: retention. This has been answered, in writing, by people with authority to answer it. Washington State Archives issued a records-management advice sheet in June 2024 titled Are Generative AI Interactions Public Records? Its answer, verbatim:
Are generative AI interactions public records? YES – If a generative AI interaction (input and output) relates to public business, then it is a public record under RCW 40.14.010
— Washington State Archives, Records Management Advice, June 2024
Note the parenthetical: input and output. The prompt is a record, not just the answer. The same sheet addresses the obvious workaround directly, stating that if you use a personal AI account to conduct business for your agency you are creating public records, that it does not matter whether you use a personal account or an agency account, and that any public records created using generative AI must be retained accordingly.
The UNC School of Government reached the same conclusion for North Carolina in March 2026: prompts are records “made” in connection with public business, outputs are records “received,” and G.S. Chapter 132's definition covers electronic data-processing records regardless of physical form or characteristics. It adds the point that matters most for an agent deployment. Citing Gray Media Group, Inc. v. City of Charlotte (2023), the analysis holds that third-party server hosting does not remove records from the Act, because constructive possession is sufficient where officials can retrieve the records via contract or account access.
Half two: disclosure. Nobody has answered this, and you should stop reading anyone who says otherwise. The Washington advice sheet's own stated purpose is whether generative-AI interactions are public records “for the purposes of records retention (chapter 40.14 RCW).” That is the retention statute. The disclosurestatute — the one that makes a record releasable on request — is chapter 42.56 RCW, the Public Records Act, and the advice sheet does not address it. It refers the reader to agency counsel and the Attorney General's Open Government Program, which is exactly what a careful archivist does when a question is outside their remit.
We searched repeatedly for a resolution and found none. There is no state attorney general formal opinion holding that AI prompts, retrieval logs or model outputs are, or are not, subject to that state's open-records act. There is no reported court decision in any state resolving a public-records request for a municipality's AI logs. And there is no reported case on whether a vendor may withhold an agent's system prompt or retrieval index as a trade secret against a records request. In California, a defence firm writing in April 2026 argued that AI materials likely qualify under the CPRA as writings relating to the conduct of the public's business that are prepared, used or retained by a public agency — prompts prepared, outputs used, logs retained — and described an unnamed California city receiving a request for “generative AI records” with the outcome unknown. It is preventative guidance, not resolved law, and it cites no litigation.
The retrieval log is the sharpest open question.Whether the RAG trace, the embedding query and the chunk identifiers are themselves records is untested everywhere we looked. The Washington sheet's input-and-output framing plausibly captures them. Nobody has ruled. A city deploying an agent in 2026 is making a bet, and the defensible posture is to design as though the answer is yes: keep them, keep them somewhere you control, and know what you would produce if asked.
It has already happened once, and the mechanism worked in both directions
In August 2025, Cascade PBS and KNKX obtained two years of ChatGPT logs from nearly a dozen Washington cities through public-records requests, finding officials using the tool for mayoral letters, policy documents, talking points, speeches, press releases, responses to audit recommendations, grant applications and replies to constituent emails. Then, in January 2026, Cascade PBS reported a specific case: reporters FOIA'd a city's ChatGPT logs and surfaced prompts asking the tool to write a specification that would exclude a competing bidder. The city opened an independent fact-finding review.
The procurement in question was a five-year utility-billing software contract budgeted at $2.7 million, with thirteen applicants. The prompts dated from March 2025 and surfaced only because reporters filed records requests; the city was contacted about them in December 2025. The mayor, Kim Lund, said that use of AI tools or any other actions to circumvent the City's purchasing policies is not acceptable.
What we are not saying: the reporting establishes that the prompts existed. It does not establish that the procurement outcome was improperly influenced, and no finding of wrongdoing had been made. The review was expected to conclude in early 2026; as of August 17, 2026 we searched and found no published findings, no report and no announced result. We do not know whether it cleared anyone, faulted anyone, or is still running.
The point is the mechanism, not the blame. The prompt log was discoverable — which is the risk your city is taking on the day it deploys an agent. And it was discoverable — which is the accountability mechanism functioning exactly as designed. Both halves are true, and a city that internalises both will write better policy than one that only fears the first.
Adjacent evidence, and worth knowing even though it is not a records case: in January 2026 a federal district judge upheld a magistrate's order compelling OpenAI to produce a 20-million-conversation log sample in copyright litigation, rejecting an attempt to hand over only a curated subset. Commentators read the ruling as a rejection of a proposed “AI privilege.” That is civil discovery in a copyright case, not a public-records holding, and it should not be cited as one. What it does show is that no court has been willing to treat AI conversations as a special protected category. Assume yours are ordinary enterprise records until someone rules otherwise.
Now the delete side, which is the exposure vendors never raise. The failure mode is symmetric: an agent that fails to retain destroys evidence, and an agent that retains everything creates a discovery and records-request burden the city has to staff. Washington State Archives is unusually direct about the second half. Its companion advice sheet says the retention period depends on the content and function of the record, not its format — that having one retention period for all generative AI records would be like having a single retention period for all letter-sized documents — and then answers its own question about whether keeping everything is the answer:
Is retaining ALL generative AI Records the answer? NO – Storing every generative AI record is not the same as managing those records. Retaining everything is a strategy for chaos.
— Washington State Archives, How Long Do Generative AI Records Need to Be Kept?, June 2024
On the other side, California Government Code section 34090 sets a hard floor. It permits a department head to destroy a city record only with the approval of the legislative body by resolution and the written consent of the city attorney, and it expressly does not authorize destruction of records affecting title to real property or liens, court records, records required to be kept by statute, records less than two years old, or the minutes, ordinances or resolutions of the legislative body or a city board or commission. Texas takes a similar posture through the Texas State Library and Archives Commission's Local Schedule GR, which provides that no local government office may dispose of a record listed in the schedule before its retention period expires.
One last honest note on retention. We found no jurisdiction with a retention schedule item written specifically for generative-AI records. What Washington State Archives actually does is direct agencies to the existing content-and-function schedules and publish no AI-specific item; that is a description of Washington's approach, and the broader negative finding is ours, based on the jurisdictions we checked. The practical consequence is that your clerk will have to map agent artifacts onto series written for letters, drafts and correspondence. That mapping is a deliverable, and it belongs to the clerk and the attorney, not to your vendor.
Procurement Is the Delivery Timeline
A city cannot sign the way a startup can. That is not a complaint about bureaucracy; it is a description of the legal predicate for spending public money, and it is the single largest determinant of when your agent goes live. So we will start with what we will not tell you.
What is verifiable is the structure of the routes, and the structure is what you plan against.
- Competitive solicitation: The default. Longest, most defensible, and the one that produces the specification your agent will be measured against. If you write the specification, write it yourself — and log the drafting, because the drafting record is discoverable. The Bellingham reporting is what that risk looks like in practice.
- Cooperative purchasing, with a local statutory predicate: Sourcewell is authorized to run a cooperative purchasing program under Minnesota Statutes section 123A.21, subdivision 7(23), and makes contracts available through Minnesota's joint-exercise-of-powers law at section 471.59. Agencies elsewhere rely on their own jurisdiction's joint-powers, intergovernmental-cooperation or cooperative-purchasing statutes. The takeaway is sharp: being on Sourcewell is not by itself a legal basis for a given city to buy. Your own state law has to authorize the piggyback, and your attorney has to cite it.
- GSA Cooperative Purchasing — bounded by category: Under 40 U.S.C. section 502(c), state and local governments may buy from GSA schedules, but only within the Information Technology Category and the Security and Protection Category, or their successors. The definition of state or local government includes state, local, regional and tribal governments and instrumentalities, including local educational agencies and institutions of higher education, and entities clearly falling within that definition need not submit an eligibility request.
- Texas DIR cooperative contracts: DIR enables Texas state and local agencies, and eligible entities nationwide through interlocal cooperation agreements, to buy off competitively sourced contracts, and DIR's threshold and statement-of-work review and signature processes do not apply to local governments or out-of-state customers. DIR's own page cites $1.154 billion in purchases by Texas local governments. It does not publish the vendor administrative fee percentage, and we could not verify one — do not let a vendor quote you a DIR fee as though it were published.
- Sole source, with a written justification: Legitimate and narrow. The justification is a record, it will be read later, and 'this vendor already has our data' is a description of lock-in rather than a justification. Write it as though a reporter will read it, because in this market one might.
AI is already flowing through these vehicles rather than around them. Texas DIR awarded a contract to DataSnipper through Carahsoft on June 8, 2026, and Sembix is available through Carahsoft under both Texas DIR and NASPO ValuePoint. The cooperative route is not theoretical for this category; it is how a meaningful share of it is already being bought.
The security gate has a name and dates.StateRAMP announced its rebrand to GovRAMP on February 14, 2025, with the domain moving to govramp.org by March 2025 and existing memberships and certifications carrying over unaffected — the rebrand reflected that local, tribal and education members had outgrown a state-only name. State-level mandates with dates: Utah has been in effect since 2025; North Carolina requires executive-branch vendors to meet the GovRAMP cloud security standard beginning April 1, 2026 with full compliance by April 1, 2027; Nevada's requirement took effect July 1, 2026, with risk-assessment requirements aligned to GovRAMP and NIST SP 800-53 Rev. 5 and products required to reach at minimum GovRAMP “Core” status. Texas handles this through TX-RAMP, where FedRAMP-authorized products go through a reciprocity review submitted via ARCHER. States named as using GovRAMP include Arizona, Indiana, Massachusetts, Minnesota, Nevada, New Hampshire, North Carolina, North Dakota, Oregon, Texas and Utah.
The most actionable procurement fact for anyone on either side of this transaction: the contract language a city hands you is increasingly likely to come from the GovAI Coalition, and it is public. Founded by the City of San José in November 2023 with roughly fifty agencies, it now reports more than 3,000 members across more than 900 government agencies, and the San José City Council unanimously approved its transition to an independent non-profit in 2026. It publishes free templates for AI policy, AI incident response plans and vendor agreements, intentionally aligned to the NIST AI Risk Management Framework, and it launched an AI Contract Hub with Pavilion offering contract templates, cooperative agreements and procurement guidance. You can read the terms before the RFP drops. Do that.
One practical consequence for scheduling. Because procurement is the timeline, the correct project sequence puts the procurement determination in the first month, in writing, alongside the write-path investigation — not after a pilot has already produced enthusiasm. A pilot that succeeds against a vehicle nobody approved creates political pressure to shortcut a legal step, and that is the pattern that generates the records nobody wants read back to them later.
ADA Title II: The Deadline Moved and It Is Provisional
This is the highest error-risk item in municipal AI writing right now. The 2024 rule's dates are obsolete; anyone writing from memory or from a pre-May-2026 article will publish the wrong ones. Anyone writing the new dates as settled may also be wrong, for a different reason.
On April 20, 2026, the Department of Justice published an interim final rule in the Federal Register, Extension of Compliance Dates for Nondiscrimination on the Basis of Disability; Accessibility of Web Information and Services of State and Local Government Entities, amending 28 CFR Part 35.
| Covered entity | Date under the 2024 final rule | Current date under the interim final rule |
|---|---|---|
| Public entities with a population of 50,000 or more | April 24, 2026 | April 26, 2027 |
| Public entities under 50,000, and any special district government | April 26, 2027 | April 26, 2028 |
The interim final rule took effect on April 20, 2026, with a comment deadline of June 22, 2026. The technical standard did not change: WCAG 2.1 Level AA. DOJ stated that the rule does not alter any other provisions of the 2024 final rule and does not impose new substantive requirements.
DOJ's own stated reasons are worth reading closely, because they say something about generative AI in government that cuts in two directions at once. Quoting the Department:
Advanced technology, such as generative AI, does not yet reliably automate the remediation of inaccessible content at scale, and staff resources and availability continue to pose significant challenges.
— DOJ, interim final rule, Federal Register, April 20, 2026
The Department finds the compliance concerns raised in the foregoing correspondence to be compelling and upon its own review determines that it overestimated the capabilities (whether staffing or technology) of covered entities to comply with the rule in the time frames provided.
— DOJ, interim final rule, Federal Register, April 20, 2026
And the sentence most coverage left out, which is the interesting one:
Third, covered entities have been generating substantial amounts of content that would be covered by the 2024 final rule using generative AI that is potentially inaccessible.
— DOJ, interim final rule, Federal Register, April 20, 2026
Put those together and the Department's own account is that generative AI is simultaneously producing inaccessible content faster than entities can remediate it and failing to automate the remediation — while staffing constraints bind independently. That is a more precise story than “AI did not deliver,” and it is a direct warning to any city about to point an agent at its own document estate. If your agent generates public-facing content, it is generating content the rule covers.
The extension does not lower the litigation floor.The interim final rule does not suspend Title II's underlying nondiscrimination and effective-communication obligations, which have supported web-accessibility claims for years without a specific technical standard. The duty lives at 28 CFR section 35.160 — communications with applicants, participants and members of the public with disabilities must be as effective as communications with others, with the required auxiliary aid varying with the method, nature, length, complexity and context of the communication. Private enforcement runs through 42 U.S.C. section 12133, which supports injunctive relief, in some cases compensatory damages, and attorney's fees. Multiple defence firms reached the same conclusion independently in their April 2026 client alerts. Counsel have also reported that HHS has a separate May 2026 deadline under its own web-accessibility rule for recipients of HHS financial assistance, which the DOJ extension does not move; we did not independently verify that date, so treat it as reported rather than established.
Two exceptions that decide how you build the agent
28 CFR section 35.201 excepts archived web content; conventional electronic documents available before the entity's compliance date, unless currently used to apply for, gain access to, or participate in the entity's services, programs or activities; content posted by a third party, unless the posting is due to contractual, licensing or other arrangements with the entity; conventional electronic documents that are both about a specific individual, their property or their account and password-protected or otherwise secured; and social media posts made before the compliance date.
Two conclusions follow, and we label them as our analysis rather than as the regulation's text. First, an agent that surfaces an old PDF in order to let a resident apply for a permit pulls that PDF out of the exception — the exception dies the moment the document becomes part of the transaction path. An agent is very good at making old documents part of the transaction path. Second, a vendor-supplied conversational widget is not third-party content, because it is there under a contract with the city. The agent is the city's content, and it is covered.
The design consequence is concrete: the agent's interface needs a WCAG 2.1 Level AA conformance review as a phase gate, not as a post-launch remediation project, and the review has to cover the dynamic states — streaming responses, focus management when a new answer arrives, error and timeout states, and any interactive component the model can render. Those are exactly the parts a static accessibility audit of a marketing site never has to think about.
Language Access: The Obligation Outlived the Guidance
Language access is where a resident-facing agent can do the most obvious good and create the least obvious liability. The federal scaffolding around it changed substantially between 2025 and 2026; the underlying obligations did not.
- March 2025 — Executive Order 14224: Designating English as the Official Language of the United States, published in the Federal Register in March 2025. It revokes EO 13166, the 2000 order on improving access to services for persons with limited English proficiency. It is an executive action directed at federal agencies, not a statute, and its own text does not require any agency to change services or to stop producing non-English materials.
- April 2025 — DOJ rescinds its 2002 LEP Guidance: LEP.gov was suspended. The playbook agencies had used for two decades came down.
- July 2025 — DOJ guidance scaling back multilingual services: It stated the Department will no longer rely on the Title VI disparate impact regulations and directed other agencies likewise, asserting that language proficiency is not an immutable characteristic and not interchangeable with national origin or race.
- Replacement guidance promised, not delivered: Replacement DOJ guidance was promised by January 10, 2026 and, as of our research, had not been published, with no announced timeline. The ground is still moving.
- July 2026 — DHS publishes a Notice of Rescission of its own Title VI LEP guidance: Crucially, the notice restates that all recipients of DHS financial assistance have a continuing obligation to comply with Title VI, all applicable Title VI regulations, and all applicable federal civil-rights laws and nondiscrimination provisions. Parallel Title VI regulatory rescissions were published by State, Labor, Education and HHS across July 2026.
- The statute did not move: Title VI of the Civil Rights Act of 1964 still prohibits national-origin discrimination, including on the basis of English ability, in programs receiving federal financial assistance. Executive orders cannot repeal statutes or regulations.
And the operative obligations for a city are frequently local rather than federal. New York City's Local Law 30 of 2017 requires covered agencies to appoint a language access coordinator, adopt an implementation plan, provide telephonic interpretation in at least 100 languages, translate the most commonly distributed documents into ten designated citywide languages — Spanish, Chinese, Russian, Bengali, Haitian Creole and Korean, plus Arabic, Urdu, French and Polish — and post signage about free interpretation. The Mayor's Office of Immigrant Affairs reports annually to the Council by June 30, including the number of language-access complaints received through 311. That last detail is worth pausing on: in New York, the 311 system is itself the language-access complaint channel.
Practically, that means your evaluation set has to be built per language, not translated from English and assumed equivalent. Test the languages your city actually serves, on the questions your residents actually ask, with reviewers who speak them. Measure refusal rates, citation accuracy and reading level per language. If the agent's Spanish is excellent and its Haitian Creole is a machine translation of an English answer that was already wrong, you have built a two-tier service and documented it in your own logs.
One drafting note. We were not able to verify the current text, thresholds or municipal applicability of California's Dymally-Alatorre Bilingual Services Act for this article, so we are not citing specifics from it. If you are a California city, that statute belongs in your attorney's review and we would rather say so than paraphrase it from memory.
The AI Rules Actually Binding a City in 2026
Most of what circulates as “AI regulation” does not reach a municipal service agent. One state statute clearly does, and it is not the one most articles name.
Texas is the outlier that binds. The Texas Responsible Artificial Intelligence Governance Act — HB 149 of the 89th Legislature, signed June 22, 2025, effective January 1, 2026, codified at Business & Commerce Code chapter 552 — reaches cities. Section 552.001(3) defines “governmental entity” to include any department, commission, board, office, authority, or other administrative unit of the state or of any political subdivision of this state, that exercises governmental functions, with hospital districts and institutions of higher education excluded. Cities, counties and local governments are in scope.
A governmental agency that makes available an artificial intelligence system intended to interact with consumers shall disclose to each consumer, before or at the time of interaction, that the consumer is interacting with an artificial intelligence system.
— Texas HB 149, enrolled text, Business & Commerce Code § 552.051(b)
Sections 552.051(d) through (f) govern the form of that disclosure: it must be clear and conspicuous, written in plain language, and must avoid dark patterns. Section 552.053 bars governmental entities from deploying AI that assigns social scores resulting in detrimental treatment based on social behaviour or personal characteristics. Section 552.054(b) limits government development of AI for uniquely identifying individuals using biometric data, and the gathering of images from public sources without consent, where doing so infringes constitutional or statutory rights.
The provision that should be on the city attorney's desk, though, is the preemption clause:
This chapter supersedes and preempts any ordinance, resolution, rule, or other regulation adopted by a political subdivision regarding the use of artificial intelligence systems.
— Texas HB 149, enrolled text, Business & Commerce Code § 552.003
A Texas city cannot pass its own AI ordinance. A city that wrote an AI-use policy into local law is preempted, and state law is the ceiling as well as the floor. That does not stop a city adopting an internal administrative policy — but it does mean the enforceable rules come from Austin.
Colorado is the one everybody gets wrong — including most of the articles correcting it. SB 24-205, the Colorado AI Act, was signed in May 2024 with an original effective date of February 1, 2026, and a special-session bill pushed that to June 30, 2026. It did take effect on that date and it is on the books right now. What it is not is enforced: on April 27, 2026, in xAI LLC v. Weiser, No. 1:26-cv-01515 in the District of Colorado, a federal magistrate judge granted a joint motion — filed by xAI, the United States as intervenor, and Attorney General Weiser together — staying enforcement of the act, and of any legislation replacing or amending it, until fourteen days after the court rules on xAI's forthcoming preliminary-injunction motion. That is a pause the parties agreed to, not a judicial defeat: no court has ruled on the merits and nothing has been struck down. Meanwhile SB 26-189, the Automated Decision-Making Technology Act, was signed by Governor Polis on May 14, 2026 and repeals and reenacts the framework effective January 1, 2027, shifting terminology from “high-risk artificial intelligence system” to “automated decision-making technology” that “materially influences” a “consequential decision,” with narrower obligations, new carve-outs, and enforcement by the attorney general alone as a deceptive trade practice with a 60-day cure period except for knowing or repeated violations. The accurate sentence for August 2026 is therefore that Colorado's 2024 act is live law nobody is enforcing, and its replacement takes over on January 1, 2027 — not that it died, and not that it applies. Whether either version reaches a municipal service agent is a separate question we could not resolve from primary sources, and it belongs to your city attorney.
Federally, the interesting fact is a carve-out. Executive Order 14365, signed December 11, 2025, directs the Attorney General within 30 days to establish an AI Litigation Task Force whose sole responsibility shall be to challenge State AI laws inconsistent with the policy set forth in the order, alongside 90-day deadlines for a Commerce evaluation of state AI laws, an FCC proceeding on federal reporting standards, and an FTC policy statement on deceptive AI practices. But section 8(b) provides that the legislative recommendation shall not preempt state AI laws relating to child safety protections; AI compute and data-center infrastructure other than generally applicable permitting reforms; State government procurement and use of AI; and other topics as determined.
Read that carve-out carefully. Even the most aggressive federal preemption push explicitly leaves government procurement and use of AI to the states. The rules a city has to follow when it buys and runs an agent are the one category nobody is trying to preempt. The Task Force is reported to have begun operating around January 10, 2026, and as of July 2026 no federal preemption statute had been enacted, with states having enacted 109 AI laws and 28 data-center laws by July 1. Note the asymmetry with Texas: federal preemption efforts protect the state layer, while Texas has preempted its own cities. The protected layer is the state, not the municipality.
Finally, what is not a municipal obligation, because it gets conflated constantly. California SB 243 on companion chatbots, effective January 1, 2026; New York's AI companion models law, effective November 2025; and Illinois' AI video-interview employment provisions, effective February 2026, are consumer-companion and employment statutes. They are not general requirements that a city disclose an AI service agent to residents. California's Executive Order N-5-26 of March 30, 2026 directs state agencies to draft AI safety recommendations for companies serving state agencies — state agencies, not cities. We found no general state statute in force in 2026, outside Texas, requiring a local government to disclose to residents that they are interacting with AI. If someone tells you most states require disclosure, they are wrong.
The closest thing to a de-facto municipal AI standard in the United States is the NIST AI Risk Management Framework, which is the alignment target for the GovAI Coalition's public templates — and it is voluntary. That is worth stating plainly rather than dressing up: in most of the country, the rules governing your city's agent are the ones your council and your attorney choose to write.
The Human-in-the-Loop Boundary
The write-path analysis tells you what the agent can do. This table is about what it should do, and the two answers are different. In a city, the distinguishing question is whether the action is an official act with due-process consequences. Administrative steps can be automated; adjudication cannot, and the fact that a vendor will sell you the credential does not change that.
| Action | Autonomy boundary | Why the line sits here | The control that enforces it |
|---|---|---|---|
| Answering a factual question from published city sources — trash days, office hours, fee schedules | Agent alone | No legal consequence, fully reversible, and the answer is a citation rather than a judgment. | Retrieval restricted to city-published sources; every answer carries a link to the codified source; AI disclosure banner on the interface. |
| Creating a 311 service request from a resident report | Agent alone, with nightly reconciliation | A case created in error is an annoyance, not a liability. A duplicate is the realistic failure and it is cheap. | Idempotency key derived from business intent — jurisdiction, normalized address, service code, time window — persisted before the call, never generated by the model. Read back against the CRM nightly. |
| Classifying and routing a case to a department | Agent alone, with a mandatory escalation list | Misroutes delay service, and a buried life-safety report is the failure nobody recovers from. | A keyword and intent list — gas, flood, downed line, structural, weapon, child, elder — that forces immediate human review regardless of model confidence. |
| Telling a resident which permit they need, or what a code section requires | Agent drafts, human commits — or agent answers only with a verbatim citation | This is precisely the NYC MyCity failure mode: a city chatbot giving residents and businesses incorrect information about their legal obligations. | The answer must quote the codified section it retrieved. If the retrieval returns nothing on point, the agent hands off to staff rather than synthesizing. |
| Issuing, approving, denying or conditioning a permit or licence | Never the agent | Adjudication. Due process, findings and appeal rights attach. | No write credential is provisioned to the approval endpoint at all. Not a policy setting — an absent scope. |
| Code enforcement: opening a case versus issuing a notice of violation | Open, yes. Issue, never. | A notice of violation is a legal instrument carrying penalties and appeal rights. | The agent assembles the inspector's packet — history, photos, code sections, prior cases at the address — and stops there. |
| Utility billing: answering balance and usage questions versus adjusting a bill or arranging shutoff | Read-only. Never for adjustments or shutoff. | A shutoff is a due-process event with statutory notice requirements in most states. | A read-only CIS credential with no write scope provisioned. Scope minimization is the control, not a confirmation dialog. |
| Records-request intake: logging, acknowledging, deduplicating, routing | Agent alone | Clerical, and the statutory response clock starts on receipt regardless of who logs it. | The agent timestamps at receipt and cannot alter a timestamp. Acknowledgement templates are approved in advance by the clerk. |
| Determining responsiveness, applying an exemption, redacting | Never the agent | These are legal determinations belonging to the records custodian and the city attorney. | The agent may propose a candidate document set and flag likely exemption categories. The release decision, the redaction and the exemption log stay human and are themselves records. |
| Destroying a record whose retention period has expired | Never the agent | In California, destruction requires a legislative-body resolution and the written consent of the city attorney, and nothing under two years old may be destroyed at all. | The agent holds no delete permission anywhere in the estate. Retention actions are proposed into a queue a human clears. |
| Drafting a staff report, RFP scope of work, or council memo | Agent drafts, human commits — and the draft is itself a record | The Bellingham reporting is the cautionary case: prompts asking a chatbot to write a specification that would exclude a competing bidder were recovered months later through a records request. | The prompt, the output and the retrieval trace are written to the records system at creation, not at publication. Assume everything is recoverable, because in at least one documented case it was. |
| Reading untrusted inbound content — resident email, uploaded PDF, faxed complaint — while holding a write credential | Never in the same session | Private data plus untrusted content plus the ability to communicate outward is the combination that makes prompt injection consequential. | Split the architecture: a read-only agent processes untrusted input against a replica; a separate, narrowly-scoped component performs writes on structured output only. |
The last row deserves expansion, because it is the security posture that everything else rests on and it is routinely sold as solved.
Prompt injection: unsolved, and the discipline is blast-radius reduction
The useful framing is the lethal trifecta: access to your private data, exposure to untrusted content, and the ability to externally communicate in a way that could be used to steal data. On whether it is fixable, the author is direct: “we still don't know how to 100% reliably prevent this from happening.” On the vendor defences you will be pitched, he is equally direct — they “almost always carry confident claims that they capture ‘95% of attacks’ or similar… but in web application security 95% is very much a failing grade.”
The municipal version of the trifecta is an agent that holds a write credential into a city system of record, reads untrusted content — a resident email, an uploaded PDF, a scanned complaint, a web page — and can act without a human seeing it first. Remove any one leg and the blast radius collapses. That is an architecture decision, not a filter you buy.
The MCP specification's security document is instructive precisely because of what it contains. Its normative requirements are about token audience validation, confused-deputy protection, consent, state-handle binding and scope minimization — it names expanded blast radius, privilege chaining and audit noise as the risks of broad scopes, and names wildcard or omnibus scopes as anti-patterns. Every one of those is a blast-radius control. None of them prevents prompt injection.A published specification's security chapter being one hundred percent blast-radius controls and zero percent injection prevention is the clearest available signal about the state of the field.
For a checklist that a security-literate reviewer will recognise, the OWASP GenAI LLM Top 10 for 2026, published on August 4, 2026, lists LLM01:2026 Prompt Injection, LLM03:2026 Excessive Agency and LLM10:2026 Improper Output Handling. For an agent with tool access to production systems, LLM03 and LLM10 are the priority pair, and the mitigations cited for excessive agency are exactly the boring ones: least privilege, confirmation for high-impact actions, and tool-usage logging. Note that the 2025 numbering was different and is still widely reproduced; cite the 2026 numbers if you are citing numbers at all.
On identity, the practical controls are unglamorous and real: a separate identity per agent rather than a shared service account, least-privilege scoping, credential rotation, per-action audit logging, and step-up authorization for privileged operations. Microsoft's own documentation for agent identities makes the case for why a service principal is the wrong primitive — application identities carry the expectation of long-term stability, known ownership and a managed lifecycle, whereas an agent might exist for minutes during a specific task, or be created and destroyed thousands of times per day. It also distinguishes autonomous access, where the agent uses rights given directly to its own identity, from delegated access, where it acts on behalf of a user with rights the user controls. In a city, most resident-facing work should be autonomous-but-read-only, and anything touching a resident's own account should be delegated, so that the audit trail says who authorised what.
A caution on that last point: pairing an agent with a shim “agent user” account so that a legacy system which only understands human users will accept it is a real compatibility technique, and it is where audit trails get muddy. If your permitting system logs the agent's writes as a named employee, your records are wrong in a way that will matter the first time someone asks who made a change. Ask the question before you deploy, not during the investigation.
What Breaks First
These are the failure modes specific to municipal deployments, in rough order of how often we see them, each with the signal that tells you it is happening and the rollback that contains it.
| Failure mode | What it looks like in a city | Detection signal | Rollback |
|---|---|---|---|
| The vendor ships it natively | Accela acquired OpenCounter in July 2024 (guided permit discovery and fee estimation) and ePermitHub in April 2025 (digital plan room and AI-driven plan-review automation). Tyler added AI-assisted application review, partnered with Avolve for embedded plan review, launched an early-adopter agentic-AI pilot inside its own applications in Q1 2026, and has a Resident AI Assistant live in six states. | The renewal quote arrives with the capability bundled, and your account rep starts describing it as included. | Keep the retrieval corpus, the evaluation set and the conversation logs portable and city-owned. Treat the conversational surface as replaceable and the knowledge layer as the asset. |
| The read-only ceiling, discovered after design | The 311 platform documents pull APIs only. The agent triages beautifully and cannot close anything. | Discovered in week two if you ask for the write path in writing; week twelve if you assume it. | Phase 0 write-path proof, before any build. If there is no write path, redesign as draft-and-commit rather than negotiating mid-build. |
| Manual key gating on a standards-based endpoint | The two most-cited Open311 cities both gate the API key behind a human request form. An agent developer does not just call the open API; they file a request and wait. | Onboarding stalls with no error to debug — the ticket is with a person, not a system. | Treat credential acquisition as a project task with an owner and a date, not an implementation detail. |
| Screen-scraping and RPA fragility | A UI change, an MFA rollout, an A/B test or a bot-detection deployment silently changes what the automation sees. A scripted bot fails loudly and identically; an agent may improvise around a changed screen and write something wrong. | A synthetic transaction run hourly against a known record, plus an alert on any write whose read-back does not match. | A kill switch that reverts the workflow to a human queue within one shift, and a written contractual review of the anti-automation terms before you start. |
| Retries becoming duplicates | There is no IETF standard for idempotency keys — the relevant draft expired without becoming an RFC — so every vendor's semantics differ. Stripe's widely-copied convention prunes keys after at least 24 hours, which means a retry a week later is a fresh write. | A rise in duplicate cases or duplicate charges at the same address, and reconciliation counts that drift from the system of record. | Key on business intent, persist the key before the call, keep your own dedupe table alive longer than the downstream retention window, and never let the model generate the key. |
| Ownership churn and contract renewal | A ~$4bn sale process was reported for Granicus with no transaction closed as of August 17, 2026; a recapitalization was reported to be with Accela's advisers, and we did not verify its status. OpenGov passed to majority ownership by Cox Enterprises in February 2024 at a reported ~$1.8B valuation. | The account team changes, the roadmap slips, and the integration terms come up at the next renewal. | Contract for data and log portability at signature, not at renewal. Re-verify ownership and API terms quarterly; ownership facts in this market go stale in months. |
| Standards rot | open311.org does not resolve. The wiki server directory carries no deprecation markers at all, so the published directory overstates reality. Discovery changesets at the flagship deployments are frozen at 2022-11-01. | An endpoint that has been listed as live for years starts returning 404 or HTML, and nobody notices because nobody owns the monitor. | Probe your own dependencies on a schedule and alert on content, not just status codes — a 200 returning an HTML page is a failure. |
| A regulatory date moves | The ADA Title II compliance dates slid a full year on April 20, 2026, by an interim final rule that had not been finalized as of August 17, 2026. Colorado's 2024 AI Act took effect on June 30, 2026 under a court-ordered enforcement stay the parties agreed to, and a replacement statute repeals and reenacts it on January 1, 2027. | Your compliance-driven business case evaporates, or a date you planned around shifts again. | Never build a project justification whose only load-bearing element is a regulatory deadline. Re-check the Federal Register before each phase gate. |
| Retention rotation quietly destroys records | A vendor default rotates conversation logs at 30 or 90 days. In California nothing under two years old may lawfully be destroyed, and permitted destruction requires a council resolution and written city-attorney consent. | You will not detect this from the application. You detect it by attempting to produce a nine-month-old interaction and failing. | Set retention explicitly at deployment, export to a city-controlled store on a schedule, and test a retrieval of an old record quarterly as a fire drill. |
| The election | New York City's MyCity chatbot survived two years of documented failure and came down in early February 2026, weeks after a new mayor took office and called it functionally unusable. | A change of administration, a new department head, or a council that never approved the thing in the first place. | In municipal government the contract's real termination clause is the ballot. Build so the knowledge layer, the records and the evaluations survive a change of surface — and get the council on the record early rather than late. |
The first row is the one cities underweight. If you are building permit-intake triage on a platform whose vendor has spent the last two years acquiring guided-permitting and AI plan-review companies, you are building inside the acquisition path. That is not a reason to stop — the capability is worth having and waiting has a cost too — but it is a reason to make the knowledge layer, not the chat surface, the thing you own. Your municipal code corpus, your evaluation set, your logged interactions and your retention wiring should all survive a decision to swap the conversational front end. If a vendor's architecture makes that hard, that is a finding about the vendor.
And the last row is the one nobody puts in a project plan. New York City's MyCity chatbot is the best-documented municipal AI failure available, and it now has an ending. It launched in the autumn of 2023, built on Microsoft's cloud platform as part of the MyCity project. Reporting by The Markup and THE CITY in March and April 2024 documented it telling landlords they could discriminate against Section 8 voucher holders, giving inaccurate minimum-wage information, saying that refusing cash payment was acceptable despite a 2020 city law, and advising employers they could take cuts of employee tips. The administration initially defended it — the mayor said the city was going to fix them and have the best chatbot system on the globe — then added disclaimers and limited functionality, requiring users to accept limitations before use. It remained live and continued giving illegal advice after the reporting. Reported figures: building the bot's foundations reportedly cost nearly $600,000; on the running cost, Mayor Mamdani put it at around half a million dollars, and the same article states plainly that it was not clear how much it cost to maintain. A new mayor took office on January 1, 2026, called it functionally unusable, and it came down in early February 2026, replaced with a notice that the beta test had ended and a redirect to NYC.gov. No usage statistics were ever published.
There is a second lesson in that story, and it is uncomfortable. Consider what happens when a city agent tells a resident something wrong. Courts are restrictive about equitable estoppel against government: the Illinois Supreme Court has held that a municipality cannot be estopped based on the apparent authority of its employees; California courts apply the doctrine against government rarely, if ever; Florida requires an affirmative act; and at the federal level erroneous advice from a government employee cannot estop the government from denying benefits not otherwise permitted by law. Those are general doctrinal statements, not holdings about chatbots, and we present them as such.
The synthesis, which is our analysis rather than anyone's ruling: when a city agent gets it wrong, the resident probably cannot hold the city to the answer — the doctrine cuts against them. The city's exposure runs a different way entirely: records discoverability, ADA effective-communication claims, Title VI, and in Texas an attorney-general notice. The resident eats the error; the city eats the record. That asymmetry is the strongest argument for citation-grounded answers, conservative refusals and a visible handoff to staff — not because a lawsuit is likely, but because the harm lands on the person with the least recourse.
A Sequenced Implementation Path
This is a sequence, not a menu, and the ordering is deliberate. Every phase has an owner who is a named person in the city rather than a vendor, an entry criterion, an exit criterion, and an explicit answer to what happens when it fails. The most common way a municipal agent project goes wrong is that Phase 3 happens first, produces enthusiasm, and then Phases 0 through 2 have to be done under political pressure.
| Phase and duration | Owner | Entry and exit criteria | What to do when it fails |
|---|---|---|---|
| Phase 0 — Write-path proof (weeks 0–2) | IT director, with the vendor account representative | Entry: one named workflow and one named system of record. Exit: a written vendor answer to five questions — which endpoints exist, which of them write, what the API license costs, whether production credentials need agency authorization, and what happens to the terms at renewal — plus one successful sandbox write, or a written statement that no write path exists. | If it fails: you are on Rung 5. Redesign as draft-and-commit before writing a line of integration code. Do not proceed on a promise. |
| Phase 1 — Records and retention determination (weeks 2–5) | City clerk, with the city attorney | Entry: Phase 0 exit. Exit: a written determination mapping each artifact — prompt, output, retrieval trace, tool-call log, conversation transcript — to an existing retention series by content and function; a legal-hold procedure; and a runbook for responding to a records request that seeks agent logs. | If it fails: stop. An agent deployed without a retention determination is an unlogged records generator, and the exposure is on the delete side as much as the disclosure side. |
| Phase 2 — Procurement route and security review (weeks 4–8, overlapping) | Purchasing officer, with the city attorney | Entry: a scoped requirement. Exit: a written determination of the route — competitive solicitation, cooperative piggyback citing the specific local statute that authorizes it, or sole source with a documented justification — plus the applicable security review path and the contract template you will start from. | If it fails: default to the longest route and re-baseline the schedule publicly. Never start a build against a vehicle that has not been approved; that is how a finished system sits unpaid for a quarter. |
| Phase 3 — Read-only pilot in one department (weeks 6–12) | The department director whose queue it is | Entry: signed contract or approved pilot authority, plus the retention determination. Exit: the agent answers a fixed question set from retrieved city sources with citations; the AI disclosure is live and plain-language; a WCAG 2.1 Level AA conformance review of the interface is complete; and language coverage is evaluated per language, not asserted in aggregate. | If it fails: fix the retrieval corpus and the evaluation set before adding any write capability. Almost every disappointing municipal pilot is a corpus problem wearing a model costume. |
| Phase 4 — One reversible write (weeks 10–18) | IT, jointly with the department | Entry: Phase 3 exit plus a write path proven in Phase 0. Exit: exactly one write type in production — create a 311 case, or create a draft permit application — with business-intent idempotency, nightly reconciliation against the system of record, per-action audit logging tied to a distinct agent identity, and a documented kill switch that a duty officer can operate. | If it fails: revert to draft-and-commit within one shift. The human keeps the write, and the agent keeps everything up to it. That is a working system, not a failed one. |
| Phase 5 — Expand by workflow, never by permission (weeks 16–24) | A standing steering group: IT, clerk, city attorney, department | Entry: 30 consecutive days of clean reconciliation with no unexplained writes. Exit: a second workflow live under the same controls, with its own narrowly-scoped credential. Scopes stay per-workflow; no omnibus credential is ever created. | If it fails: stop expanding and diagnose. In our experience the cause is a scope or reconciliation problem rather than a model problem, and adding capability on top of it compounds the error. |
| Phase 6 — Quarterly re-verification (ongoing) | Contract administrator | Entry: production. Exit each quarter: a one-page memo confirming vendor ownership and API terms, the status of any pending rulemaking your compliance posture depends on, retention-schedule changes, and a successful test retrieval of a record older than six months. | If it fails: treat a failed test retrieval as an incident, not a chore. It is the only way you find out that a rotation setting has been quietly destroying records. |
Two notes on running this in a real city.
The five questions in Phase 0 are the whole engagement in miniature. Ask your vendor representative, in writing: which endpoints exist for this workflow; which of them write; what the API licence costs, as a separate line item; whether production credentials require agency authorization beyond the sandbox; and what happens to these terms at renewal. Get the answers in email. A vendor that answers all five in writing is a vendor you can plan around, whatever the answers are. A vendor that will not put the write path in writing has told you something important, and it is better to learn it in week one than in month four.
Phase 1 is the phase cities skip, and it is the one that creates liability.A retention determination is not a policy document; it is a mapping from artifacts your system produces to series in a schedule your state already publishes, made by the clerk and the attorney, in writing, before deployment. Both the retention and the disclosure runbook should be written when nobody is under time pressure. The first time you think hard about whether an agent's retrieval trace is producible should not be the day a request lands with a statutory clock attached.
On sequencing between workflows: start with records-request intake or 311 triage if your queue backlog is the visible problem, because those are read-heavy and the write is either clerical or absent. Start with permit pre-screening if your counter volume is the problem, but accept that the agent's output is a draft and a citation, not a determination. Do not start with anything in utility billing that touches a balance, an adjustment or a shutoff. That is not a capability question; it is a due-process question, and the answer does not change with model quality.
Red Flags When Selecting a Vendor
Most of these are answerable in a single meeting, and a good vendor will not mind being asked. The ones that produce discomfort are the ones worth pursuing.
- 1.They will not put the write path in writing: The single highest-value question in the process. If the answer to 'which endpoints write, and what does the licence cost' is a demo rather than a sentence, you are being sold a screen, not an integration.
- 2.Deflection, containment or resolution-rate claims with no methodology: Every 311 deflection rate we encountered originates with a vendor selling the tool. Ask for the study, the sample, the baseline and the date. If those do not exist, the number is marketing and should not appear in your council packet.
- 3.'We're on Sourcewell' offered as the whole procurement answer: Being on a cooperative is not a legal basis for your city to buy. The correct answer names your own state's authorizing statute, and your attorney should be the one who names it.
- 4.Prompts and logs treated as the vendor's trade secret: Ask directly: on our written request, will you produce our prompts, outputs, retrieval traces and tool-call logs, in a machine-readable format, within a stated number of days? Get it in the contract. Under the constructive-possession analysis, your ability to retrieve is what makes them your records — and it is also what makes them producible.
- 5.A default log-retention setting presented as data hygiene: A 30-day rotation is a records-destruction schedule wearing a different name. Ask what the default is, whether you can change it, and where the data goes when it leaves.
- 6.No AI disclosure surface at all: In Texas this is a statutory failure. Everywhere else it is a trust failure, and the state guidance in at least one state indicates AI-generated government documents should be labelled as such — while none of the records reviewed in the Washington reporting carried any AI disclosure.
- 7.Accessibility answered with an undated VPAT: Ask for a WCAG 2.1 Level AA conformance review of the conversational interface including its dynamic states, dated within the last twelve months, and ask who performed it. The agent is the city's content, not third-party content.
- 8.'100+ languages' with no per-language evaluation: Ask for accuracy and refusal rates broken out by the specific languages your city serves. An aggregate claim conceals exactly the disparity that creates exposure.
- 9.A demo on the vendor's data rather than your municipal code: Insist the pilot runs against your own code, your own fee schedules and your own forms. Retrieval quality against a curated demo corpus tells you nothing about retrieval quality against forty years of amendments.
- 10.'Our filter catches 95% of prompt injection': In web application security, 95% is a failing grade. A serious answer describes architecture — what the agent can reach, what credential it holds while reading untrusted input, and what a successful injection could actually do.
- 11.No named path to export the retrieval corpus and evaluation set: If you cannot leave with your corpus and your evals, you did not buy a system; you rented a dependency. Given the acquisition activity in this market, portability is a risk control, not a nicety.
- 12.Any statement of the ADA deadline without the words 'interim final rule': A vendor confidently citing April 2026, or citing April 2027 as settled, has not read the current rule. It is a cheap, precise test of whether their compliance claims are researched or recited.
- 13.A quote with no line item for third-party API licensing: One vendor's own documentation warns that another vendor's API licence may cost extra. If your quote does not name that cost, it is incomplete, and the gap will surface after signature.
The numbers we refuse to print, and why
The house rule across this cluster is that we refuse statistics nobody can source, and we say so in the text. Naming a number as untraceable is more useful to a city manager than repeating it in a council presentation that a reporter will later check.
| The claim | What it actually is | What we do with it |
|---|---|---|
| 311 deflection, containment or resolution rates | Every instance we encountered originates with a vendor selling the tool. No published methodology, no independent replication. | Refused. Measure your own baseline before deployment or you will never know. |
| Procurement cycle-time ranges — RFPs take 3–6 months, cooperative compresses to 30–60 days, sole-source thresholds of $5,000–$150,000 | All trace to sales-enablement blogs aimed at vendors selling into government. We found no neutral primary source for any of them. | Refused as neutral fact. If you need a range, get it from your own purchasing office's last ten awards. |
| 311 CRM pricing of $2,500 to $950,000 per year | A vendor-facing content site, no methodology published. | Refused. Ask for a written quote with the third-party API license as a separate line item. |
| Tyler's market share and installation counts | The same vendor-facing content site. Tyler's revenue is corroborated by its SEC filings — FY2025 total revenue of $2.33 billion, up 9.1%, with recurring revenue of $2.03 billion, or 87.1% of total. The share and install counts are not sourced anywhere we could find. | We print the SEC-filed revenue and refuse the share and install counts. |
| AI could save government 1.2 billion hours and $41.1 billion annually | A real report, applied wrongly. It is Deloitte University Press, AI-augmented Government, from 2017, and the figure is the high-investment modeled scenario for the US federal government alone. The same report's low end is 96.7 million hours and $3.3 billion. | Refused for cities. It is a 2017 model of federal agencies, not an observation about local government. |
| Blended local-government AI adoption rates of 46%, 48% or 52% | Different surveys of different populations being averaged together. | Refused. We use the ICMA survey with its methodology and its date stated plainly. |
The one adoption figure we willuse comes with its methodology attached. ICMA — a professional association, not a vendor — surveyed local-government practitioners in April and May of 2024, drawing 635 responses, the vast majority from the chief administrative officer or assistant CAO of their local government, with 41% of respondents representing communities of 5,000 to 24,999 residents and 10% representing communities under 2,500. Among the results: 69.0% of respondents had taken none of the listed AI actions — no organization-wide policy, no governing-body resolution, no training, no committee, no staff, no budget line; 48.3% placed a low priority on developing or using AI and a further 19.1% none at all; 51.1% reported no current AI use in any listed area; 55% identified resident engagement as the area with the most potential; and 77% named lack of AI awareness and understanding as the biggest barrier. ICMA's own framing was that the use of AI as a core practice of local government in the United States is clearly in its infancy.
ICMA also published a comment from a small West Coast city administrator that is worth reading twice, because it is a practitioner describing the trade correctly:
There is an irrational exuberance that is building up in the profession from championing AI use in local government. I see it trumpeted as a miracle answer to manage workload, with lip service towards accountability for AI outputs. It can alleviate workload, but only in exchange for more rigorous oversight and a greater need for personal accountability for automated output, i.e., a different kind of work, but work nonetheless…
— ICMA, Artificial Intelligence in Local Government: Summary of 2024 Survey Results
What This Costs and How Long It Takes
These are Frenchy Digital's bands for this category of work. They are the same bands we publish across this cluster; what changes for a city is where the effort concentrates. In municipal engagements a disproportionate share of the discovery phase is spent on the write-path investigation and the records determination, and a disproportionate share of the calendar is spent waiting on a procurement route that nobody can compress.
| Engagement | Range | Timeline | Typical scope in a city |
|---|---|---|---|
| Discovery + workflow audit | $9,000 – $22,000 | 2–4 weeks | Write-path investigation with each vendor, records and retention determination with the clerk and attorney, procurement route analysis, and a scored shortlist of candidate workflows. |
| Single-workflow agent | $28,000 – $70,000 | 4–9 weeks | 311 intake and triage, permit pre-screening, records-request intake, or a utility-billing question agent — with disclosure, accessibility conformance, retention wiring and audit logging built in from the start. |
| Multi-workflow platform with system-of-record integration | $70,000 – $180,000 | 9–16 weeks | Two or more workflows against your permitting or CRM system of record, with idempotent writes, reconciliation, per-workflow scoped credentials and a departmental review console. |
| Enterprise / multi-department / regulated build | $180,000 – $420,000+ | 14–24 weeks | Multi-department deployment with full per-action audit logging, human-in-the-loop gates, records export to a city-controlled store, language-access evaluation per language, and a documented security posture for review. |
Frenchy Digital cost bands for municipal AI agent engagements, 2026.
Senior-led delivery runs $150 to $225 per hour, and ongoing retainers run $2,500 to $9,500 per month covering model and dependency upgrades, evaluation expansion, incident response and a quarterly technical review — which in a city should include the re-verification memo described in Phase 6. Every engagement carries a 30-day post-launch warranty, and you receive a written scope with a fixed-price phased proposal within 5 business days of the discovery call.
On budgeting honestly for the council: the two costs cities systematically underestimate are the records-handling burden the agent creates and the ongoing evaluation work. The first is structural — an agent that generates records generates records-request workload, and in many cities the platform that processes those requests is a separate paid product from a related vendor. The second is that evaluation is not a launch activity; municipal code changes, fee schedules change, and an agent whose corpus is a year stale is confidently wrong in exactly the way the NYC deployment was. Budget the retainer or budget the staff time, but do not budget zero.
Limitations: What We Could Not Verify
Everything above is sourced. A good deal of what surrounds it is not, and it is worth being precise about which is which — particularly because several of these gaps are the exact questions a vendor will answer confidently in a sales meeting.
- Accela's write surface: We confirmed the published three-step onboarding and the absence of any stated approval or certification gate on the getting-started page. We could not verify whether Accela charges a partner or API fee, whether production credentials require agency authorization, or which specific write endpoints and OAuth scopes exist. Do not read this article as saying an agent can create a permit record on Accela.
- Tyler's API posture: Our characterisation is assembled from third-party writeups and the observable fact that the public API catalog page returned an HTTP 403 to an automated client. That is an observation about what a machine can retrieve, not proof of policy. Confirm your own access terms with your Tyler account team.
- OpenGov, Cityworks, AMANDA and the Harris CIS brands: We could not verify a public API posture for any of them. The correct phrasing is 'not publicly documented,' not 'no API.' If your system of record is one of these, the Phase 0 investigation is the only way to know.
- Whether SeeClickFix implements Open311 POST: The GeoReport v2 specification defines a POST method for creating requests, but SeeClickFix's own Open311 documentation page returned a 403 to our fetch client. We cannot confirm whether it implements POST or on what terms, and we have deliberately not asserted either.
- The Bellingham review's outcome: The city opened an independent fact-finding review and the mayor said in December 2025 that it was expected to conclude in early 2026. As of August 17, 2026 we found no published findings, no report and no announced result. We do not know whether it cleared anyone, faulted anyone, or is ongoing, and we are not implying any of the three.
- Whether AI prompts and logs are disclosable: No state attorney general opinion, no reported court decision in any state, and no reported case on whether a vendor may withhold a system prompt or retrieval index as a trade secret against a records request. Retention is answered; disclosure is not.
- Whether a retrieval log is a record: Untested everywhere we looked. The RAG trace, the embedding query and the chunk identifiers are plausibly captured by Washington's input-and-output framing, and nobody has ruled.
- AI-specific retention schedules: Washington State Archives directs agencies to the existing content-and-function schedules and publishes no AI-specific schedule item. We found none in any jurisdiction we checked — that broader negative is our finding, not the archivist's.
- Whether any GovRAMP mandate binds a city or county: The mandates we reviewed are written for state agencies and executive-branch procurement. We did not verify that any binds a municipality directly. Treat them as standards cities increasingly mirror.
- The Texas DIR administrative fee: DIR's cooperative contracts page confirms local-government eligibility and cites $1.154 billion in local-government purchases, but does not publish the vendor administrative fee percentage, dollar thresholds or statement-of-work rules for local buyers. We could not verify a percentage and will not print one.
- Litigation over the ADA interim final rule: Disability-advocacy organizations published objections to it, and an interim final rule issued without notice and comment is a standard APA target. We did not verify that any lawsuit has been filed. We are not saying one has.
- The HHS web-accessibility deadline: Counsel have reported a separate May 2026 deadline under HHS's own rule for recipients of HHS financial assistance, unaffected by the DOJ extension. We did not independently verify that date.
- California's Dymally-Alatorre Bilingual Services Act: We did not verify its current text, thresholds or applicability to cities, so we cited no specifics from it. It belongs in a California city attorney's review.
- Whether Colorado's act reaches a city at all: The status itself is verified: SB 24-205 took effect June 30, 2026 and enforcement is stayed by a joint motion granted April 27, 2026 in xAI LLC v. Weiser, No. 1:26-cv-01515 (D. Colo.), until fourteen days after the court rules on the preliminary-injunction motion, with the replacement act taking over January 1, 2027. What we could not resolve from primary sources is whether either version reaches a municipal service agent. That is a city-attorney question, and we have not answered it here.
- Vendor ownership, which is the fastest-moving fact here: A sale process was reported for Granicus at roughly $4bn with no transaction closed as of August 17, 2026, and a recapitalization was reported to be with Accela's advisers with a status we did not verify. Because Granicus is associated with both AMANDA and GovQA, a single transaction would date several passages above. Re-check ownership before you rely on it.
- The adoption data's vintage: The ICMA figures are April–May 2024. We found no 2025 or 2026 replication with published methodology. A separate survey of public employees reporting AI use and barrier percentages was not reached to its primary report, so we have not printed its numbers as established.
- Everything a vendor would call a benchmark: There is no independent measurement of 311 deflection, containment or resolution improvement from an AI agent that we could find, and no neutral primary source for any procurement cycle-time figure. Measure your own baseline before deployment; you will not be able to reconstruct it afterwards.
Two closing observations, offered as judgement rather than fact. The first is that the binding constraint in municipal AI is almost never the model. It is a write path a vendor controls, a records question nobody has finished answering, and a procurement calendar with its own legal predicate. A city that treats those three as the project — and the agent as the thing that gets built once they are resolved — will ship. A city that treats them as paperwork will produce a pilot, some enthusiasm, and a records request it cannot answer.
The second is that the accountability mechanism here is genuinely working, and cities should take some comfort from that. The reason we can write this article with citations rather than anecdotes is that public-records law made a city's AI use visible, and journalism did the rest. That same transparency is the risk a city assumes when it deploys an agent. Both things are true. The city that designs for disclosure — citation-grounded answers, logged prompts, retention mapped in advance, a visible handoff to a human — is the one that will be comfortable when someone eventually asks to see it. And in this sector, someone eventually asks.
Find Out What Your Vendors Will Actually Let an Agent Do
Book a free 60-minute discovery call with Frenchy Digital — a senior-led Black-owned LA agency. Bring your permitting, 311 and CIS contracts; you leave with a write-path assessment, a records-exposure summary and a fixed-price phased proposal within 5 business days. Call +1 (424) 272-5601.
Not Sure Whether Your Vendor Will Let an Agent Write?
Book a free 60-minute discovery call. Bring your permitting and 311 contracts; you leave with a write-path assessment, a records-exposure summary and a fixed-price phased proposal within 5 business days.
1517 S Bentley Ave Unit 204, Los Angeles CA 90025
Frequently Asked Questions
Sources & References
- 1DOJ interim final rule, Extension of Compliance Dates, 28 CFR Part 35 (FR Doc. 2026-07663, April 20, 2026)↗
- 228 CFR § 35.201 — Exceptions to the web and mobile app accessibility requirements↗
- 3Texas HB 149 (89R) — enrolled text, Responsible Artificial Intelligence Governance Act↗
- 4Washington State Archives — Are Generative AI Interactions Public Records? (June 2024)↗
- 5Washington State Archives — How Long Do Generative AI Records Need to Be Kept? (June 2024)↗
- 6UNC School of Government, Coates' Canons — The Intersection of Artificial Intelligence and the Public Records Act (March 11, 2026)↗
- 7Liebert Cassidy Whitmore — Public Records Act Meets AI (April 28, 2026)↗
- 8Cascade PBS — Bellingham staffer asked ChatGPT about a city contract specification (January 5, 2026)↗
- 9The Markup — NYC to end the MyCity chatbot (January 30, 2026)↗
- 10The Markup / THE CITY — Malfunctioning NYC AI chatbot still active (April 2, 2024)↗
- 11California Government Code § 34090 — destruction of city records↗
- 12Texas State Library and Archives Commission — Local Schedule GR↗
- 13ICMA — Artificial Intelligence in Local Government: Summary of 2024 Survey Results↗
- 14Accela — Construct API getting started (developer portal)↗
- 15CivicPlus — Available SeeClickFix APIs↗
- 16Polimorphic — published integrations list↗
- 17Open311 — GeoReport v2 status monitor↗
- 18Open311 wiki — GeoReport v2 server directory↗
- 19Texas Department of Information Resources — Cooperative Contracts↗
- 20Sourcewell — compliance and legal (statutory authority)↗
- 21GSA — Cooperative Purchasing programs for state and local governments↗
- 22GovRAMP (formerly StateRAMP)↗
- 23City of San José — GovAI Coalition templates and resources↗
- 24Executive Order 14365 — Ensuring a National Policy Framework for Artificial Intelligence (December 11, 2025)↗
- 25Tyler Technologies — investor relations and SEC filings↗
- 26Simon Willison — The lethal trifecta for AI agents↗
- 27Model Context Protocol — security best practices, specification 2026-07-28↗
- 28OWASP GenAI Security Project — LLM Top 10, 2026 edition (numbering per the project's own repository; the public landing page still serves the 2025 list)↗
- 29Stripe — idempotent requests↗
- 30IETF — draft-ietf-httpapi-idempotency-key-header (expired, not an RFC)↗
- 31Microsoft Learn — What are agent identities (Microsoft Entra Agent ID)↗
- 32NIST — AI Risk Management Framework↗

