Skip to Main Content

Automated Decision-Making and Municipal Chatbots: Preparing for Colorado’s New AI Laws

Printable Version

Published 07/30/2026


Municipal operations depend heavily on administrative work, much of it repetitive, time-sensitive, and difficult to scale as workloads increase. Against that backdrop, automation offers a compelling promise of helping staff process more information, respond faster, and devote more attention to work that requires human judgment. Why spend hours sorting applications, routing requests, checking forms, or answering the same questions from scratch when technology can do it faster?

Indeed, municipal employees are increasingly using generative AI to draft correspondence, summarize documents, prepare public information, and assist with administrative tasks. Municipalities are also using automation tools that can screen employment applications, identify potentially eligible benefit recipients, prioritize service requests, evaluate permit materials, and communicate with residents through public-facing chatbots.

While it can be tempting to automate as many tedious, repetitive tasks as possible, overreliance on automated tools may increase risks when efficiency begins to replace judgment. This can be particularly problematic when automated tools are tasked with making or influencing decisions that have a real impact on stakeholders, or when AI-powered communication
tools give the user the impression they’re speaking to a human.

The Colorado General Assembly responded to those perceived risks by adopting two significant AI laws during the 2026 legislative session: Senate Bill 26-189 (“SB 26-189”)(1) and House Bill 26-1263 (“HB 26-1263”). Beginning January 1, 2027,(2) the Acts will impose new transparency, notice, review, and accountability requirements on “developers” and “deployers” of automated decision-making technologies, and on “operators” of public-facing conversational AI services, extending to both public and private entities meeting those definitions.(3)

SB 26-189 regulates automated decision-making technology used to materially influence decisions involving employment, housing, financial services, insurance, health care, education, and essential government services and public benefits. The Act does not prohibit municipalities from using AI in consequential decision-making; instead, it emphasizes transparency, accuracy in data, meaningful human review, and accountability for technology-assisted decisions. HB 26-1263 is separately intended to address distinct consumer-safety risks created by publicly available conversational AI systems that simulate human interaction, with particular emphasis on protecting minor users.

When these Acts take effect, the central challenge for municipalities will be to capture the benefits of automation without losing the human oversight and accountability that public decision-making requires. To prepare, municipalities must understand where these Acts’ requirements may apply.

SB 26-189: AUTOMATED DECISION-MAKING TECHNOLOGY IN CONSEQUENTIAL DECISIONS

SB 26-189 regulates “automated decision-making technology,” or “ADMT,” that is used to “materially influence” a “consequential decision.” Understanding those terms is critical. An ADMT is a technology that processes personal data(4) and uses computation to generate an output, including predictions, recommendations, classifications, rankings, scores, or other information that is used to make, guide, or assist a decision, judgment, or determinations about an individual.(5)

The Act excludes many routine technologies and uses. Examples include basic calculators and databases, qualifying spreadsheets, administrative routing, scheduling, translation, summarization, and tools that merely organize or present information for human review. The Act also excludes certain natural-language tools that provide information, answer questions, make referrals, or generate content when they are not intended, marketed, or configured for making consequential decisions and are subject to an acceptable use policy prohibiting that use.(6)

A “consequential decision” is a decision, determination, or action concerning an individual related to the provision of, or the individual’s access to, eligibility for, selection for, or compensation relating to a “covered domain.” “Covered domains” include educational opportunities, employment opportunities, the lease or purchase of residential housing, financial and lending services, insurance, health-care services, and essential government services and public benefits, including eligibility and renewal determinations.

A decision concerning differentiated pricing, cost sharing, compensation, or other material terms may also qualify as a consequential decision when the differentiation is reasonably likely to materially limit, delay, effectively deny, or otherwise fundamentally alter the individual’s access or opportunity to a covered domain.

For example, suppose a municipal housing authority operates a housing program that owns dwelling units that it offers to qualifying applicants at below-market rental rates. The housing authority uses a technology that assigns applicants a “needs and risk assessment score” based on financial information included in the application. The technology then uses the score to recommend approval or denial of the application. If the authority approves the application for placement in a unit but the authority’s housing stock is limited, the technology recommends the applicant’s “place in line” on a waitlist based on the applicant’s needs and risk assessment score.

While a decision to place an already-approved applicant on a waitlist does not formally deny assistance, the decision may result in a material delay or effective denial of access to residential housing—particularly if the score assigned to the applicant places them far down on the waitlist—and thus may rise to the level of a consequential decision.

Suppose, instead, that the housing authority offers rent payment assistance to qualifying applicants, and uses the technology to recommend how much assistance to provide to individual applicants based on their needs and risk assessment score. That recommendation, too, could rise to the level of a consequential decision because it involves a decision concerning
differentiated compensation that could materially limit the individual’s access to the program funding.

On the other hand, the definition of “consequential decision” expressly does not include low-stakes or routine decisions, actions, and business processes that do not materially influence eligibility for, selection for, denial of, compensation for, pricing of, or access to an opportunity or service for a covered domain, including routine scheduling, administrative routing, or workflow management.

A technology “materially influences” a consequential decision when its output is a “non-de minimis factor” affecting the decision-making process or its outcome. This includes functions such as filtering, ranking, scoring, recommending, or classifying individuals as part of the decision-making process for a consequential decision. This means the presence of a human decision-maker does not automatically remove the system from the Act’s application, even if the human will make the final decision related to the covered domain.

Employment-Related Decisions. Importantly, while employment and employment opportunities are a covered domain, municipalities will want to review closely with their own counsel whether SB 26-189’s notice, disclosure, correction, and human-review requirements apply to municipal use of ADMT in decisions impacting this domain. The Act incorporates the Colorado Wage Act’s definition of “employer,” which excludes municipal corporations and certain other public entities. Accordingly, a municipality’s use of automated technology in hiring or other employment decisions could potentially fall outside SB 26-189’s employment-related coverage. However, Attorney General rulemaking or future judicial interpretation may clarify the issue.

Nevertheless, use of automated employment screening tools poses risks. Suppose, for example, that a municipality uses an applicant-tracking platform that parses résumés, processes applicants’ personal information, assigns applicants a score, ranks them against the position’s qualifications and other candidates, and recommends which candidates should receive interviews. Even if SB 26-189’s requirements do not apply to a municipality’s use of this type of employment screening tool, SB 26-189 expressly preserves existing rights and remedies available under state or federal law, including the Colorado Anti-Discrimination Act (CADA). A municipality could, therefore, face liability if its selection, configuration, or reliance on an automated screening tool causes unlawful discrimination in employment, including where the system screens out qualified applicants based on criteria that disproportionately affect a protected group.

Obligations for Deployers of ADMT. SB 26-189 regulates “developers” that create or commercially provide covered ADMT and “deployers” that use it. The Act defines a “deployer” as a person doing business in Colorado that deploys covered ADMT. Depending on the context, a municipality could meet either definition.(7) Though, in most use cases, a municipality is more likely to be considered a deployer of ADMT.

The principal obligations of a deployer of ADMT concern notice, adverse outcomes, data access and correction, human review, and record retention. Before using covered ADMT to materially influence a consequential decision, the deployer must provide clear and conspicuous notice that covered technology will be used in a consequential decision affecting the individual and provide instructions about how the affected individual may obtain additional information.(8) The notice requirement is met if a prominent notice is maintained at accessible points of the individual’s interaction. For example, if ADMT will be used in the hiring process, it may suffice to include the notice within the employment portal or on the application form.

If the technology materially influences a consequential decision resulting in an “adverse outcome,” the deployer must make certain “post-adverse outcome disclosures” to the affected individual within 30 days of making the decision. An “adverse outcome” includes denying, terminating, revoking, or materially restricting an individual’s access, eligibility, selection, compensation, opportunity, or service. It also includes decisions resulting in materially less favorable pricing, compensation, cost-sharing, or other terms that are reasonably likely to limit, delay, deny, or fundamentally alter an individual’s access to an opportunity or service compared with similarly situated individuals.

The post-adverse outcome disclosure must include a plain-language explanation of the decision and the role the covered ADMT played. It must also explain how the individual may request available information regarding the system, its developer, its version, and the types and sources of personal data used, to the extent the deployer receives the necessary information from the developer as required of the developer under the Act.(9)

The disclosure must also include notice about the individual’s applicable rights and instructions about how to exercise them, including how the individual may access the personal data used and request correction of factually incorrect or materially inaccurate personal data, and of the individual’s right to request meaningful human review of the decision.(10) While a deployer is not required to “correct” opinions, predictions, scores, or protected evaluations made by the technology, the deployer may need to correct an inaccurate employment date, income amount, address, credential, or other factual input that affected the decision, when requested by the affected individual.

Upon the affected individual’s request, the deployer must provide the affected person with an opportunity for meaningful human review and reconsideration following an adverse outcome, to the extent commercially reasonable.(11) Meaningful review requires more than confirming that the technology generated a particular score. The reviewer must have appropriate training, understand the system’s intended use and material limitations, and have the authority to consider relevant primary evidence and approve, modify, or override the decision.

Deployers must retain records reasonably necessary to demonstrate compliance for three years after the consequential decision upon which ADMT had a material influence, or for a longer period if required by applicable state or federal law.

Enforcement of SB 26-189. The Act’s developer and deployer requirements are enforced exclusively by the Colorado Attorney General. A violation constitutes a deceptive trade practice under the Colorado Consumer Protection Act, allowing the Attorney General to pursue the remedies available under that law, including injunctive relief and civil penalties. Until January 1, 2030, the Attorney General generally must provide a developer or deployer with written notice and 60 days to cure an alleged violation before filing an enforcement action, if the Attorney General determines that a cure is possible. But that cure opportunity is not required for knowing or repeated violations. The Act does not create a new private right of action, meaning an individual cannot directly sue for civil liability for a violation of the Act.

However, the absence of a new private action does not insulate a municipality from liability under other laws. SB 26-189 expressly preserves existing rights and remedies available under state or federal law, including claims alleging unlawful discrimination arising from a consequential decision materially influenced by covered ADMT. For municipalities acting as deployers, potential liability may arise from their own selection, configuration, oversight, or use of the technology under laws such as the Colorado Anti-Discrimination Act, Title VII of the Civil Rights Act of 1964, the Americans with Disabilities Act, the Age Discrimination in Employment Act, and other federal, state, or local civil-rights, employment, housing, disabilityaccess, and program-specific laws.

HB 26-1263: CONVERSATIONAL ARTIFICIAL INTELLIGENCE SERVICE OPERATOR REQUIREMENTS

HB 26-1263 applies to those who develop, make publicly available, or offer to a consumer (i.e., an “operator”) a “conversational artificial intelligence service.” That term is defined as an AI system that is accessible to the general public and that primarily simulates human conversation through adaptive text, visual, or audio communications.

The Act excludes several categories of tools from the definition of a “conversational artificial intelligence service,” which clarify the Act’s primary focus on open-ended generative systems designed to sustain adaptive, human-like conversations. Most relevant to municipalities, the Act excludes tools used solely for internal business purposes; systems designed primarily or business operations, productivity, information analysis, internal research, training, or technical assistance; narrow-topic tools that cannot generate sexually explicit content or sustain dialogue concerning suicide or self-harm; and commercerelated or transactional assistants used for functions such as payments, ordering, delivery, returns, customer support, or customer service. For example, a scripted tool that retrieves fixed information, routes a resident to a webpage, or performs a narrow transaction may not fall within the Act’s coverage.

Accordingly, not every municipal chatbot will qualify, and it may be that most will not—at least not those that are commonly deployed.(12) It seems unlikely that a municipality would operate the type of open-ended “AI companion” that appears to be the Act’s principal focus. However, municipalities should assess the chatbot’s actual functions rather than relying on the vendor’s label or the municipality’s informational intent, as it’s possible municipal chatbots may fall within the Act’s coverage, particularly as tools become more adaptive and conversational.

For covered systems, operators generally must clearly disclose that the user is interacting with AI at the beginning of the user’s first interaction each day, at least once every three hours during a continuing interaction unless the disclosure remains persistently visible, and whenever the user asks whether the service is human or artificially generated. HB 26-1263 imposes additional requirements intended to protect the safety of minors and further mental health and suicide prevention objectives, including protocols for suicidal ideation and self-harm, restrictions on misleading professional-service claims, and age-estimation and other safeguards for known minor users.

When a Chatbot May Trigger Both Acts. While it may be that most municipal chatbots will not fall within HB 26-1263’s coverage, it’s possible a chatbot could implicate SB 26-189’s coverage. On the one hand, a chatbot used only to retrieve general information should not ordinarily be covered ADMT under SB 26-189. This is because natural-language technologies used to provide information, answer questions, or make referrals are expressly exempt from SB 26-189’s coverage when the chatbot is not intended or configured for consequential decisions and is subject to an acceptable-use policy prohibiting such use.

The result may change if the chatbot collects personal data and begins determining probable eligibility, calculating benefit amounts, ranking programs, recommending approval or denial, prioritizing service requests, or generating individualized recommendations on which municipal employees rely. At that point, it’s possible the chatbot could implicate both Acts:
HB 26-1263 because it may simulate public-facing conversation, and SB 26-189 because it may materially influence consequential decisions.

Municipalities can reduce this risk by maintaining clear informational boundaries. Public-facing chatbots should not access personal accounts or protected databases, make eligibility determinations, or provide individualized legal or professional advice unless the municipality has intentionally designed the process to satisfy applicable legal requirements. Chatbots should prominently identify themselves as AI, direct users to authoritative sources, provide access to human assistance, support accessibility and language access, and operate under clear retention and acceptable-use rules. Finally, a disclaimer is helpful but not decisive. A municipality cannot characterize an AI system as “informational only” if, in practice, employees or residents rely on the AI system to determine access to municipal services or benefits.

CONCLUSION

Colorado’s new AI laws do not prevent, nor should they discourage, municipalities from pursuing tools that can improve efficiency, expand access, and reduce the burden of repetitive administrative work. But the Acts reinforce that when technology begins to influence decisions with real consequences for real people, efficiency cannot come at the expense of transparency, accuracy, human judgment, or accountability.

For municipalities, the key is to understand what their automated and artificial intelligence tools actually do. In all cases, the applicability of Colorado’s new AI laws depends less on how a product is labeled and more on how it functions, how employees use its output, and what effect it has on individuals.

Importantly, the most significant municipal risk may not arise from deliberately purchasing a product advertised as an “AI decision-maker” or “adaptive AI companion.” It may arise, instead, from a feature already embedded in familiar, exiting software program. Indeed, an existing system may appear to be merely administrative, informational, or supportive, yet may
quietly rank applicants, prioritize residents, recommend outcomes, or otherwise shape consequential decisions. Likewise, while a chatbot may seem like a routine customer-service feature, it may evolve into an open-ended “AI companion” as it grows more adaptive, conversational, and personalized.

Ultimately, however, the practical response to Colorado’s new AI laws is not to avoid AI tools altogether, but to govern their use deliberately. In preparation for the Acts’ implementation date, municipal officials should implement or update existing policies to preserve meaningful human authority, demand sufficient information from vendors, avoid unexplained automated rejection, and maintain clear limits on public-facing chatbots. Municipal officials should also inventory existing systems, identify where automated outputs affect consequential decisions, establish meaningful human-review procedures, and require sufficient vendor transparency.

Click here for a practical checklist municipalities can use to begin evaluating current systems and otherwise prepare for SB 26-189’s January 1, 2027, effective date. Because application of the Act is fact-specific—and Attorney General rulemaking may provide further guidance—municipalities should consult with their attorneys before implementing automated technology
that may deny, delay, rank, or materially affect an individual opportunity, service, or benefit.

This article is intended for general informational purposes only and is not intended or to be construed as legal or professional advice on any specific issue. Municipal officials should consult with their entity’s own counsel concerning application of the Acts to particular technologies and municipal processes.


  1. SB 26-189 repeals and replaces the framework originally enacted through Senate Bill 24-205. The new Act is narrower in some respects and more operationally focused. Rather than broadly regulating “high-risk artificial intelligence systems,” it applies to “automated decision-making technology,” or “ADMT,” that is used to “materially influence” a “consequential decision” in a “covered domain.”
  2. SB 26-189’s developer and deployer requirements apply beginning January 1, 2027. HB 26-1263’s principal operator obligations likewise become effective January 1, 2027.
  3. While there may be some question about the applicability of SB 26-189 to municipal organizations (e.g., due to the Act’s placement in the Colorado Consumer Protection Act of Title 6 of the Colorado Revised Statutes, and the Title 6 definition of “person”), the Act does not contain an express, general exemption for municipalities or other government entities. Moreover, the Act expressly applies to domains within which municipalities have significant authority (e.g., essential government services and public benefits). Accordingly, unless and until a court weighs in on the applicability issue, municipal officials should seek to determine whether and how the Act applies to its technologies instead of assuming that public-entity status exempts them from the Act.
  4. “Personal data” means information that is linked or reasonably linkable to an identified or identifiable individual; it does not include de-identified data or publicly available information. “Publicly available information” means information that is lawfully made available from federal, state, or local government records and information that a controller has a reasonable basis to believe the consumer has lawfully made available to the general public. C.R.S. §§ 6-1-1701(16) & 6-1-1303(17).
  5. A product need not be marketed as “artificial intelligence” or an “ADMT” to satisfy this definition. Applicant-tracking software, eligibility-scoring systems, automated recommendation tools, and other familiar platforms may qualify based on their actual functions.
  6. These exclusions are function specific. A tool initially used only for summarization or administrative processing may become covered if the municipality later configures or uses it to generate an inference that materially influences a consequential decision.
  7. See supra endnote 3.
  8. Required notices and disclosures must also be reasonably accessible to individuals with disabilities and individuals with limited English proficiency. Municipalities should also consider the applicability and requirements of Colorado’s technology accessibility laws and regulations to notices and disclosures when hosted or transmitted digitally.
  9. Developers must provide deployers with documentation addressing intended uses, known limitations and inappropriate uses, categories of training data, appropriate-use instructions, monitoring, and meaningful human review. Developers must also notify deployers of material updates and intentional and substantial modifications to their technologies.
  10. Because appropriate post-adverse outcome disclosures may differ by subject area, the Act directs the Attorney General, by January 1, 2027, to clarify the required content and format of the post-adverse outcome disclosure through sector-specific rulemaking while ensuring that consumers receive meaningful and understandable information.
  11. The Act does not define or otherwise provide guidance as to what “commercially reasonable” may mean in this context, but it’s possible the issue will be addressed by the Attorney General in the Act’s implementing rules and regulations.
  12. Denver’s “Sunny” chatbot provides a useful Colorado example. Denver describes Sunny as an AI-powered virtual assistant that answers questions regarding city services, assists users in reporting municipal issues, communicates in numerous languages, and provides informational, but not official, responses. Denver also states that Sunny cannot access personal accounts or information.

Embracing the Future: Responsible Use of Generative Artificial Intelligence in Local Government Operations

Printable Version

By Nick Cotton-Baez, CIRSA Associate General Counsel

INTRODUCTION

The rapid advancement of artificial intelligence (AI)—a broad field aimed at creating intelligent machines capable for performing tasks typically requiring human intelligence—has transformed various sectors of the economy, and local government is no exception. From automated customer service chatbots to predictive maintenance of infrastructure, AI has the potential to transform the way local governments operate and serve their constituents. As local governments navigate the implementation and use of AI in government operations, it’s crucial for municipal officials to understand both the opportunities and risks.

This article focuses on “Generative AI”, which is a subset of AI that refers to systems utilizing algorithms and statistical models to process, categorize, analyze, and draw inferences from patterns in the dataset on which the program has been trained (e.g., large language models) to generate statistically probable outputs, such as text, images, and videos, when prompted by users. Popular Generative AI tools and platforms include ChatGPT, Dall-E2, Lensa AI, and Perplexity AI, among many others.

Generative AI platforms and tools offer local governments unprecedented opportunities to enhance public services, optimize job performance, streamline processes, and improve citizen engagement. However, their use gives rise to a variety of risks, and thus their implementation must be approached with caution and foresight.

This article is intended to help CIRSA members identify key risk considerations associated with the use of Generative AI tools in local government—including data privacy, copyright infringement, ethical considerations, and the potential for inaccuracy and bias—in view of local governments’ role of remaining at the forefront of innovation while upholding the trust and welfare of the communities they serve.

RISKS

By now, you’ve likely come across ominous warnings about AI’s potential to surpass human intelligence, giving AI systems the ability to undertake actions beyond human control, potentially in malicious ways that may pose existential threats. Maybe you fear AI’s potential to increase government surveillance and social manipulation, leading to the erosion of citizen privacy and enabling authoritarian control. While these and other potential outcomes shouldn’t be ignored, they’re largely out of local governments’ control.

That said, there are several known risks surrounding the use of Generative AI that local governments can control and minimize by implementing sound policies and training programs for the appropriate and responsible use of Generative AI. Local governments must familiarize themselves with these risks to inform good policies and practices surrounding the use of Generative AI in local government services and functions.

Risks associated with Generative AI use generally fall into two broad categories: (A) risks associated with user prompts; and (B) risks associated with using AI-generated content.

A. User Prompts

User prompts and AI-generated responses generally are not private, as Generative AI models recycle and learn from previous interactions (i.e., prompts and responses) with users. If used in prompts, security breaches involving Generative AI systems may contain personal information or personally identifying information and other sensitive and confidential information, which could give rise to liability under data protection or other laws.(i) The practice of copying and pasting information from local government records into prompts may increase this risk. Additionally, use of Generative AI may result in the creation of a public record subject to disclosure under the Colorado Open Records Act (CORA). When using Generative AI, local government officials and employees should keep this in mind, particularly if it’s in the local government’s interest or required by CORA that certain prompts and AI-generated content are kept confidential.

B. Using AI-Generated Content

Many risks associated with using AI-generated content arise from characteristics of the source materials from which the Generative AI system draws to generate its responses to user prompts. Indeed, Generative AI systems are most-often trained on data sourced from the internet, which may produce inaccurate or fictitious responses to prompts, content reflecting the biases of such data, or content containing copyrighted material.

Generative AI is designed to make up information when it does not have an answer, which may lead to inaccurate responses because the data it’s using is incomplete or inaccurate. In some cases, Generative AI has even been observed to “hallucinate” website URLs, court cases, and other purported source materials. This is exactly what happened when a Colorado attorney used ChatGPT to generate case citations and case-specific details to support his motion to set aside an unfavorable district court decision entered against his client. The lawyer filed the motion without verifying whether the cases existed, and when the judge noticed the cited cases did not exist, the lawyer lied about his use of ChatGPT blaming the fictitious case citations on a legal intern. The events led to the suspension of the attorney’s law license. Lawyers in Texas and New York have also been sanctioned for citing fictitious cases generated by AI chatbots. It easy to see from just these examples in the legal field how use of unverified AI-generated content in any context can significantly damage careers and reputations and, for local governments, public trust. Thus, as discussed more below, your organization’s AI policies should require any AI generated content be verified!

Moreover, content produced by Generative AI systems may include copyrighted material, which has formed the basis for many lawsuits brought against Generative AI developers by artists, authors, and other content creators. Generative AI systems are trained using data that has been sourced from the internet, often without regard to copyright or licensing terms. It’s often difficult to determine the content used to train a Generative AI system, and the extent to which AI-generated content regurgitates copyrighted material. Some Generative AI systems do not include citations or links to the websites or other sources used to generate responses to user prompts, which may hamper the user from verifying the accuracy and completeness of the generated response and the right to use it.

Additionally, Generative AI systems can reflect the biases (e.g., cultural, political, social, etc.) of the source materials on which the system has been trained, as Generative AI systems cannot compensate for preexisting prejudices, stereotypes, or underrepresented data sets. For example, a Generative AI might pair the term “municipal clerk” with a female pronoun, and the term “mayor” with a male pronoun. The algorithms and statistical models used by Generative AI to parse and process content derived from source materials can also be a source of bias, resulting in decisions that could be discriminatory. Indeed, the use of AI in employment matters, including but not limited to hiring, pay determinations, and performance monitoring, may run the risk of violating Title VII of the federal Civil Rights Act of 1964 or other employment laws.(ii)

While some Generative AI systems implement guard rails to warn against or block offensive, harmful, or unsafe content, others may not. Due to the rapid advancement of Generative AI, even systems with guard rails might allow unwanted content to slip through.

MINIMIZING RISK

With knowledge of the risks associated with Generative AI, and that risks may evolve, local governments should develop and implement policies and training programs to minimize such risks while preserving the benefits of Generative AI to local government services and functions. Policies should contain (1) requirements for responsible user prompts, (2) mechanisms for reviewing AI-generated content for accuracy and bias and ensuring no copyrighted material is used without proper attribution or without obtaining proper rights, (3) provisions for the security of login information and data, (4) procedures for monitoring Generative AI use and policy enforcement, (5) supervisory expectations for employee use of Generative AI, and (6) provisions concerning the policy’s interaction with other local government employment policies. Local governments can foster a culture of accountability and transparency by establishing clear expectations for employee use of Generative AI.

A. User Prompts

Because information used in prompts and AI-generated responses are generally not private, local government policies should prohibit employees from submitting sensitive, confidential, or regulated data, or any personal information or personal identifying information (PII) to a Generative AI system. Policies should also warn that use of Generative AI may result in the creation of a public record under the Colorado Open Records Act (CORA). Accordingly, policymakers should consider adopting policies respecting prompts that may result in AI-generated information that the local government desires to keep confidential.

B. Accuracy & Bias

Policies should require users of Generative AI to carefully review AI-generated content for accuracy and bias before using the content in any work product. To that end, when crafting your entity’s policies, consider requiring employees to use Generative AI systems that provide links to source materials so that employees may readily evaluate AI-generated information. When available, employees may verify accuracy and identify bias by following links within the Generative AI system to source materials. When source materials are not cited, it is suggested your policies require employees to verify the accuracy and identify bias by independent research.

C. Copyrighted Material

Policies should require careful review of AI-generated content and available source materials to ensure no copyrighted material is published or distributed to citizens or third parties without proper attribution or without obtaining proper rights. As with reviews for accuracy and bias, policymakers should consider requiring employees to use Generative AI systems that provide links to source materials so that employees may readily identify copyrighted material. As to systems that do not provide links, policies should require employees to track down source materials to evaluate AI-generated information for plagiarism concerns and potential copyright infringement. Local governments may wish to take advantage of one of the many internet or software programs that reviews texts for plagiarism to further discourage publication and distribution of work product containing copyrighted material. Some “plagiarism checkers” are available for free. However, be wary of using plagiarism checkers powered by AI, as using these tools carries many of the same risks as the Generative AI systems discussed in this article.

D. Security

Policies should require compliance with all applicable federal and state data protection laws, including those pertaining to data security and acceptable computing. Policies pertaining to data privacy and security should be reviewed by your municipal attorney or an attorney specializing in cyber security law, as associated laws and regulations are complex and filled with legal and industry jargon.

Moreover, Generative AI users should be made responsible for safeguarding their own system login information and should require adherence to specific security requirements such as the use of strong passwords, frequent password changes, multifactor authentication (if available), prohibiting credential sharing, and reporting of unauthorized access events and security incidents. Policymakers should carefully consider which email addresses and servers employees should be required to use to create Generative AI accounts, as hackers gaining access to Generative AI accounts created using work credentials may be able to use the same credentials to access to local government systems.

E. Supervisory Expectations

Policymakers should also consider whether employees must obtain permission from, or at least inform, supervisors when employees use Generative AI in connection with the formation of opinions, conclusions, or other information integrated into employee work product. Policies might also benefit from listing prohibited and acceptable employee uses of Generative AI. Moreover, policies should ensure citation to the sources underlying the AI-generated information used in work product rather than to the Generative AI system used to generate it, thus enabling supervisors to independently verify the information used in the work product.

F. Interaction with Other Employment Policies

Policymakers should also consider the interaction between policies related to the use of Generative AI and other existing employment policies, and potential conflicts that may arise due to overlap. If a specific use of Generative AI could implicate other employment or information technology policies of the local government, then the Generative AI policy should contain a statement as to which policy governs in the event of a conflict.

G. Monitoring & Enforcement

Policymakers should also consider reserving the right to monitor and audit employee use of Generative AI to ensure compliance with its Generative AI policy and to protect the entity’s data, reputation, and legal and government interests. Moreover, policymakers should consider consequences for violations of the local government’s Generative AI policy. Some policymakers may prefer to confine consequences to the loss of the privilege of using Generative AI for work-related purposes, or computer privileges in general. Others may wish to subject violators to disciplinary action authorized under the local government’s general personnel policies, even up to termination.

CONCLUSION

The integration of Generative AI into local government operations presents both significant opportunities and considerable challenges. As discussed in this article, the potential for enhanced public services, improved efficiency, and increased citizen engagement is tempered by critical risks, including risks related to data privacy, the propagation of biases, and copyright infringement.

While this article outlines known risks associated with Generative AI use and offers tips for mitigating them, Generative AI is a new and rapidly evolving field, and thus the potential policy impacts and risks to local government organizations are not fully known. Accordingly, local governments must keep a pulse on the changing landscape of opportunities and risks associated with Generative AI.

Ultimately, the successful adoption of Generative AI will depend on a balanced approach that prioritizes innovation without compromising faith and trust in government systems and information, or public welfare. By striking the right balance, CIRSA members can position themselves at the forefront of innovation while safeguarding the interests of their organizations and the communities they serve.

If you have questions about this article or would like samples of AI use policies for employees, contact CIRSA’s Associate General Counsel Nick Cotton-Baez at nickc@cirsa.org.

Note: This article is intended for general information purposes only and is not intended or to be construed as legal advice on any specific issue. Readers should consult with their entity’s own counsel for legal advice on specific issues.


(i) For example, Colorado local governments are subject to the data privacy requirements of House Bill 18-1128, codified at C.R.S. Section 24-73-101, et seq. Among other provisions, these statutes require a government entity that maintains, owns, or licenses personal identifying information (PII) to implement and maintain reasonable security procedures for the protection of PII. You can read this CIRSA article to learn more about these data privacy requirements.

(ii) The EEOC has published guidance on how the use of AI in employee assessment and selection can potentially violate Title VII and the ADA. The two sets of guidance can be viewed here and here. In addition, effective February 2026, Colorado employers will face new requirements and potential liabilities related to the use of AI in employment decisions under Senate Bill 24-205. The application of this legislation to public entities is not clear and a discussion of this Bill is beyond the scope this article.

 

Published 12/31/2024