{"resourceId":"nyc-ai-governance-follow-up","versions":[{"version":"legacy/2026-08-31/nyc-ai-governance-follow-up","resource":{"id":"nyc-ai-governance-follow-up","title":"Follow-up audit finds visible governance progress but no complete inventory or mandatory risk process","organization":"New York State Office of the State Comptroller; New York City Office of Technology and Innovation","sector":"Municipal government governance and oversight","geography":"New York City, New York, United States","publishedAt":"August 27, 2026","sourceName":"Artificial Intelligence Governance (Follow-Up), Report 2025-F-17","sourceLabel":"New York State Comptroller follow-up audit","sourceUrl":"https://www.osc.ny.gov/state-agencies/audits/2026/08/27/artificial-intelligence-governance-follow","evidenceClass":"government-audit","outcomeClass":"cautionary","topics":["knowledge-work","developers-agents","data-security","governance-procurement","accessibility-workforce","operating-model"],"finding":"A state follow-up audit assessed New York City's implementation of three 2023 AI-governance recommendations as of April 13, 2026. The City had issued principles, definitions, generative-AI guidance, public-engagement guidance, a cybersecurity policy, and a risk-assessment template; established steering and advisory bodies; and completed seven risk assessments. Auditors nevertheless rated all three recommendations only partially implemented.","sledRelevance":"This is rare longitudinal evidence showing what happens after a large local government publishes an AI action plan. It distinguishes visible program activity from the harder controls needed to govern AI consistently across agencies, including schools, police, child services, and buildings.","evidence":"The audit found no complete citywide inventory, no mechanism to verify the completeness and accuracy of agency self-reporting, no mandatory citywide AI risk-assessment process, and no follow-up process requiring agencies to implement assessment recommendations. Five template-based assessments identified risks and mitigations, while two earlier assessments lacked important structure and details. A cybersecurity policy required approval, inventory, training-data approval, and continuous monitoring, but broader accuracy, bias, data-quality, and appropriate-use controls remained incomplete.","architectureImplications":"Build discovery beyond procurement records and voluntary declarations, including embedded AI, proofs of concept, vendor updates, and systems whose outputs influence inspections or other field activity. Connect inventory entries to model and data sources, owners, integrations, affected services, monitoring, and lifecycle state.","governanceImplications":"Convert guidance into risk-tiered requirements, define when assessment and approval are mandatory, track recommendations to closure, audit agency compliance, and provide a citywide mechanism for questions, complaints, investigation, and remedy when AI causes suspected harm.","securityPrivacyImplications":"Cybersecurity approval is necessary but insufficient. Require data-quality, privacy, bias, accuracy, explainability, acceptable-use, and ongoing outcome monitoring alongside security review; preserve public reporting and complaint channels for consequential systems.","caveats":"This was a follow-up of three prior recommendations rather than a full new audit of every city AI system. Testing included OTI and a judgmentally selected Department of Buildings review, and the report evaluates governance implementation rather than the effectiveness or fairness of individual AI tools."}},{"version":"enrichment/2026-09-05T02:42:45.193Z/nyc-ai-governance-follow-up","resource":{"id":"nyc-ai-governance-follow-up","title":"Follow-up audit finds visible governance progress but no complete inventory or mandatory risk process","organization":"New York State Office of the State Comptroller; New York City Office of Technology and Innovation","sector":"Municipal government governance and oversight","geography":"New York City, New York, United States","publishedAt":"August 27, 2026","publicationDate":"2026-08-27","eventDate":null,"sourceName":"Artificial Intelligence Governance (Follow-Up), Report 2025-F-17","sourceLabel":"New York State Comptroller follow-up audit","sourceUrl":"https://www.osc.ny.gov/state-agencies/audits/2026/08/27/artificial-intelligence-governance-follow","evidenceClass":"government-audit","outcomeClass":"cautionary","topics":["knowledge-work","developers-agents","data-security","governance-procurement","accessibility-workforce","operating-model"],"finding":"A state follow-up audit assessed New York City's implementation of three 2023 AI-governance recommendations as of April 13, 2026. The City had issued principles, definitions, generative-AI guidance, public-engagement guidance, a cybersecurity policy, and a risk-assessment template; established steering and advisory bodies; and completed seven risk assessments. Auditors nevertheless rated all three recommendations only partially implemented.","sledRelevance":"This is rare longitudinal evidence showing what happens after a large local government publishes an AI action plan. It distinguishes visible program activity from the harder controls needed to govern AI consistently across agencies, including schools, police, child services, and buildings.","evidence":"The audit found no complete citywide inventory, no mechanism to verify the completeness and accuracy of agency self-reporting, no mandatory citywide AI risk-assessment process, and no follow-up process requiring agencies to implement assessment recommendations. Five template-based assessments identified risks and mitigations, while two earlier assessments lacked important structure and details. A cybersecurity policy required approval, inventory, training-data approval, and continuous monitoring, but broader accuracy, bias, data-quality, and appropriate-use controls remained incomplete.","architectureImplications":"Build discovery beyond procurement records and voluntary declarations, including embedded AI, proofs of concept, vendor updates, and systems whose outputs influence inspections or other field activity. Connect inventory entries to model and data sources, owners, integrations, affected services, monitoring, and lifecycle state.","governanceImplications":"Convert guidance into risk-tiered requirements, define when assessment and approval are mandatory, track recommendations to closure, audit agency compliance, and provide a citywide mechanism for questions, complaints, investigation, and remedy when AI causes suspected harm.","securityPrivacyImplications":"Cybersecurity approval is necessary but insufficient. Require data-quality, privacy, bias, accuracy, explainability, acceptable-use, and ongoing outcome monitoring alongside security review; preserve public reporting and complaint channels for consequential systems.","caveats":"This was a follow-up of three prior recommendations rather than a full new audit of every city AI system. Testing included OTI and a judgmentally selected Department of Buildings review, and the report evaluates governance implementation rather than the effectiveness or fairness of individual AI tools.","streamIds":["local-government","public-safety","k12"],"roles":{"sales":"Interpretation — Problem and stakeholders: City technology, agency leaders, auditors, school officials, and public-safety leaders may have AI principles without verified inventory or enforced assessment follow-up. Discovery: How are embedded vendor features and pilots found, which uses require review, and who verifies mitigation closure? Value hypothesis: Reconciling inventory and recommendations could make oversight accountable and reduce unknown exposure. Potential engagement: A cross-agency inventory reconciliation and assessment-closure review using existing governance tools. Evidence boundary: The follow-up rated three recommendations partially implemented and examined selected evidence. It does not show every city system is ungoverned, that a particular tool is inaccurate or unfair, or that publishing an inventory alone prevents harm.","engineering":"Interpretation — Fit: Focus on controls around deployments, including embedded features and outputs influencing field activity. Architecture: Link procurement, applications, model and data records, agency owners, integrations, monitoring, assessments, and mitigation tickets. Prerequisites: Agreed definitions, agency access, discovery beyond self-reporting, and mandatory review triggers. Constraints: Incomplete supplier disclosure and decentralized pilots may prevent first-pass completeness; label uncertainty. Security: Restrict sensitive system details while covering privacy, accuracy, bias, and data quality alongside cybersecurity. Proposed validation: Reconcile independent discovery sources, sample deployed services back to their records, and trace recommendations to tested closure. Confirm that newly discovered or changed systems enter review rather than relying on static declarations or committee membership as evidence of control.","delivery":"Interpretation — Work and dependencies: Establish citywide inventory ownership and agency attestations, reconcile records, define risk tiers, and verify assessment closure. Ownership: Agencies remain accountable for service behavior; central governance maintains requirements; audit checks implementation independently. Skills and adoption: Train departmental staff to recognize embedded AI and report changes, and provide practical complaint and question channels. Governance checkpoints: Require assessment at defined deployment and change events and review overdue mitigations. Proposed acceptance: Sampled systems reconcile across discovery sources, required assessments exist, material findings have evidence-backed disposition, and complaint or remedy routes function. Risks: Voluntary reporting can omit systems, cybersecurity approval can crowd out broader risks, and committees or templates can create visible activity without operational control."},"retrievedAt":null,"enrichedAt":"2026-09-05T02:42:45.193Z","enrichmentBasis":"archived evidence"}}]}