Lighthouse Advisory · Research librarySLED AI Adoption Intelligence
Daily · 10:00 PM Central

Issue 04 · Evidence briefing

SLED AI Adoption Intelligence

Audited municipal governance, multi-state assurance, shared AI infrastructure, and the community legitimacy of AI compute.

A decision-oriented read of what public institutions tried, what the evidence supports, and what leaders should design for next. Vendor claims are treated as claims, not outcomes.

4evidence records
4cross-source patterns
7topic lenses

Synthesis

Patterns across the evidence

01

Governance progress must become enforceable operating controls

New York City's follow-up audit found meaningful progress in principles, committees, guidance, cybersecurity policy, and seven risk assessments, yet all three original recommendations remained only partially implemented. NAIC's evolving supplement shows the complementary pattern: governance becomes more usable when it produces explicit inventories, materiality thresholds, model and data details, third-party oversight, and evidence references.

Which AI requirements are mandatory, who verifies implementation, and what evidence proves that identified risks and remediation recommendations were actually addressed?

02

Inventory is the bridge between policy and operations

Both the New York audit and NAIC's regulator tool converge on inventory as a prerequisite for risk-tiered oversight. A procurement list or voluntary self-report is not enough: usable inventory records need purpose, model, data, developer, affected population, inherent risk, limitations, third parties, status, and evidence of ongoing monitoring.

Can the organization identify every material AI system—including embedded, vendor-managed, experimental, and agentic capabilities—and connect each one to an owner, data, risk, controls, and lifecycle state?

03

Shared platforms trade local capacity gaps for concentrated platform risk

Japan's QommonsAI illustrates how standardized knowledge, common model access, administrative telemetry, and shared development can extend AI to many municipalities that could not build equivalent capabilities independently. The same design concentrates vendor, model, data-standardization, access-control, and future agent-marketplace risk in a common layer.

Which capabilities should be shared across jurisdictions, and which identity, tenant-isolation, portability, model-choice, audit, and exit controls must be enforced centrally because local adopters cannot provide them alone?

04

AI infrastructure now requires a community legitimacy strategy

New polling indicates data-center opposition is materially higher than opposition to new housing and has worsened over six months, with electricity, transmission, water, land use, transparency, and local input driving concern. Technical feasibility and tax incentives therefore do not establish social license for AI infrastructure.

Before approving or subsidizing AI compute, can leaders show who pays for electricity and transmission, how water and land impacts are bounded, what benefits remain local, and how residents influence enforceable commitments?

Full record

Evidence ledger

Showing 4 of 4 records · All

Updated August 31, 2026

New York State Office of the State Comptroller; New York City Office of Technology and InnovationNew York City, New York, United States

Follow-up audit finds visible governance progress but no complete inventory or mandatory risk process

A state follow-up audit assessed New York City's implementation of three 2023 AI-governance recommendations as of April 13, 2026. The City had issued principles, definitions, generative-AI guidance, public-engagement guidance, a cybersecurity policy, and a risk-assessment template; established steering and advisory bodies; and completed seven risk assessments. Auditors nevertheless rated all three recommendations only partially implemented.

Government auditCautionaryMunicipal government governance and oversight
Read full analysis

What happened

A state follow-up audit assessed New York City's implementation of three 2023 AI-governance recommendations as of April 13, 2026. The City had issued principles, definitions, generative-AI guidance, public-engagement guidance, a cybersecurity policy, and a risk-assessment template; established steering and advisory bodies; and completed seven risk assessments. Auditors nevertheless rated all three recommendations only partially implemented.

Evidence read

The audit found no complete citywide inventory, no mechanism to verify the completeness and accuracy of agency self-reporting, no mandatory citywide AI risk-assessment process, and no follow-up process requiring agencies to implement assessment recommendations. Five template-based assessments identified risks and mitigations, while two earlier assessments lacked important structure and details. A cybersecurity policy required approval, inventory, training-data approval, and continuous monitoring, but broader accuracy, bias, data-quality, and appropriate-use controls remained incomplete.

Why it matters for SLED

This is rare longitudinal evidence showing what happens after a large local government publishes an AI action plan. It distinguishes visible program activity from the harder controls needed to govern AI consistently across agencies, including schools, police, child services, and buildings.

Architecture implications

Build discovery beyond procurement records and voluntary declarations, including embedded AI, proofs of concept, vendor updates, and systems whose outputs influence inspections or other field activity. Connect inventory entries to model and data sources, owners, integrations, affected services, monitoring, and lifecycle state.

Governance implications

Convert guidance into risk-tiered requirements, define when assessment and approval are mandatory, track recommendations to closure, audit agency compliance, and provide a citywide mechanism for questions, complaints, investigation, and remedy when AI causes suspected harm.

Security and privacy implications

Cybersecurity approval is necessary but insufficient. Require data-quality, privacy, bias, accuracy, explainability, acceptable-use, and ongoing outcome monitoring alongside security review; preserve public reporting and complaint channels for consequential systems.

Limits of the evidence

This was a follow-up of three prior recommendations rather than a full new audit of every city AI system. Testing included OTI and a judgmentally selected Department of Buildings review, and the report evaluates governance implementation rather than the effectiveness or fairness of individual AI tools.

New York State Comptroller follow-up audit (opens in a new tab)
National Association of Insurance CommissionersUnited States; 12 participating states

Twelve-state pilot converts AI oversight into a risk-tiered regulatory evidence request

After field testing with California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia, and Wisconsin, NAIC exposed version 5.0 of its AI Risk Evaluation Supplement for public comment. The March–September pilot applies the tool in market-conduct reviews, financial analysis, and financial examinations while allowing jurisdiction-specific tailoring.

Standards or public-body guidanceEmergingState insurance regulation
Read full analysis

What happened

After field testing with California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia, and Wisconsin, NAIC exposed version 5.0 of its AI Risk Evaluation Supplement for public comment. The March–September pilot applies the tool in market-conduct reviews, financial analysis, and financial examinations while allowing jurisdiction-specific tailoring.

Evidence read

NAIC's change summary says pilot feedback led version 5.0 to make the model inventory explicit; distinguish AI systems from AI models; add materiality thresholds, inherent-risk language, direct-consumer and material-financial-impact fields, explainability and transparency questions, document-and-page evidence references, third-party model oversight, model-risk and limitation fields, data-to-model mapping, and an agentic-AI definition. The pilot is designed to assess usability and training needs; final effectiveness results are not yet available.

Why it matters for SLED

Although focused on regulated insurers, this is an operational model for state oversight of third-party AI: begin with a materiality-scoped inventory, escalate inquiry for direct consumer or financial impact, and request governance, model, data, limitation, explainability, and third-party evidence proportionate to risk.

Architecture implications

Maintain separate but linked inventories for systems, models, use cases, data sets, and third parties. Use the initial inventory to decide which systems warrant deeper technical and governance evidence, and support different thresholds for back-office, consumer-facing, and financially material workloads.

Governance implications

Adopt a proportional assurance process that can reuse existing audit and examination mechanisms, identify inherent risk before controls, require traceable evidence rather than unsupported questionnaire answers, coordinate requests across oversight bodies, and refine the instrument from operator and regulated-entity feedback.

Security and privacy implications

Ask how sensitive and protected attributes enter models, how data sets map to model uses, how third-party models are governed, what limitations and failure modes are known, and how confidentiality is preserved when detailed model and control evidence is collected.

Limits of the evidence

Version 5.0 remains an exposure draft and the 12-state pilot is still underway. Participating jurisdictions may adapt the questions, results have not yet established inter-rater consistency or regulatory effectiveness, and insurance-specific materiality concepts will require translation for other SLED services.

NAIC Big Data and Artificial Intelligence Working Group (opens in a new tab)
Polimill and OpenAIJapan

Vendor case reports a shared municipal AI platform reaching roughly 1,050 jurisdictions

OpenAI and Polimill report that QommonsAI supports about 1,050 Japanese municipalities and 550,000 public employees across assembly responses, public services, social welfare, and legal search. The platform standardizes distributed assembly minutes and administrative information, adds metadata, exposes common search and model access, and provides administrators with usage-history and model-availability controls.

Vendor claimEmergingLocal government shared services and software development
Read full analysis

What happened

OpenAI and Polimill report that QommonsAI supports about 1,050 Japanese municipalities and 550,000 public employees across assembly responses, public services, social welfare, and legal search. The platform standardizes distributed assembly minutes and administrative information, adds metadata, exposes common search and model access, and provides administrators with usage-history and model-availability controls.

Evidence read

The customer story reports adoption counts, a three-to-five-times increase in Polimill's development speed using Codex, and internal validation in which less-experienced staff drafted policy proposals rated close to those from veteran officials. Experienced officials still received the highest ratings, which the company attributed to tacit knowledge. No independent methodology, baseline detail, usage distribution, cost analysis, or service-outcome measure is published.

Why it matters for SLED

The case illustrates a shared-service route for small and medium municipalities that lack data-engineering, model-platform, security, and AI-development capacity. It also connects knowledge-worker augmentation, cross-jurisdiction knowledge management, developer copilots, and a planned multi-application agent marketplace in one architecture.

Architecture implications

A shared municipal AI layer can combine standardized administrative knowledge, tenant-aware search, approved model brokerage, usage telemetry, and common applications. The planned super-agent and third-party application store will require workload identity, per-tenant authorization, tool allowlists, transaction boundaries, application review, provenance, and reversible execution.

Governance implications

Treat the common platform operator as a shared accountable service with published onboarding, acceptable-use, evaluation, model-change, application-review, records, accessibility, and exit processes. Preserve local policy authority while avoiding inconsistent minimum controls across municipalities.

Security and privacy implications

Validate tenant isolation, administrator access, logging scope, retention, model-training restrictions, sensitive welfare and legal-data handling, incident response, supplier dependencies, and portability. Concentration in one platform increases the blast radius of access-control, data-quality, and supplier failures.

Limits of the evidence

All effectiveness and adoption figures are supplier and customer claims published by the model vendor, not an independent evaluation. The source does not define active use, measure municipal service outcomes, disclose security architecture in depth, or evaluate the planned agent marketplace, which had not yet launched.

OpenAI customer story (opens in a new tab)
Public First and Information Technology and Innovation FoundationUnited States with international comparison

New polling finds AI data centers face unusually high and worsening community opposition

A new Public First survey briefing reports substantially stronger U.S. opposition to local data-center construction than to new housing, declining support between January and July 2026, and greater resistance in rural areas. Resource costs and public input were central concerns.

Independent researchCautionaryAI infrastructure, land use, and public policy
Read full analysis

What happened

A new Public First survey briefing reports substantially stronger U.S. opposition to local data-center construction than to new housing, declining support between January and July 2026, and greater resistance in rural areas. Resource costs and public input were central concerns.

Evidence read

The briefing reports that 46% of respondents opposed a new data center in their community versus 15% opposing new housing. Respondents often preferred leaving otherwise unused land undeveloped, and the most popular conditions centered on developers paying the full cost of electricity and new power lines, limiting water impacts, and increasing resident input. Public attitudes toward AI itself strongly correlated with data-center opposition.

Why it matters for SLED

State and local governments are simultaneously AI adopters, economic-development sponsors, utility planners, land-use authorities, and community representatives. AI strategy can therefore fail politically or financially even when the technology plan is sound if infrastructure costs and benefits are perceived as opaque or unfair.

Architecture implications

Include electricity, transmission, water, cooling, backup generation, network, land, and decommissioning assumptions in AI infrastructure planning. Compare centralized hyperscale, regional shared, cloud, on-premises, and edge options using total public cost and resilience—not compute price alone.

Governance implications

Require transparent cost-allocation rules, enforceable community-benefit and resource commitments, public reporting, meaningful local participation, and review of tax incentives and stranded-capacity risk before approving projects or utility upgrades.

Security and privacy implications

Physical concentration also creates resilience and critical-infrastructure dependencies. Planning should address grid and water-system effects, emergency coordination, facility and network security, continuity, supplier concentration, and disclosure that does not expose exploitable details.

Limits of the evidence

The 17-page briefing provides limited methodological detail in the public document, is produced by organizations active in technology policy, and measures attitudes rather than realized environmental or economic impacts. The 46% figure should not be generalized to every locality or treated as proof that a specific project lacks support.

Public First survey briefing (opens in a new tab)

How to read this briefing

Methodology and definitions

Selection and freshness

This edition prioritizes primary government material, public audits, independent research, and relevant public-sector association guidance available for theAugust 31, 2026 run. Every surfaced item remains in the All view and keeps its original source.

Evidence classes

Government evaluation
A public body’s measured evaluation or documented pilot.
Government audit
An oversight review of performance, controls, or operations.
Academic research
Research produced through an academic institution or peer-reviewed venue.
Independent research
Research conducted outside the implementing organization.
Public-sector association guidance
Practitioner guidance or an association-supplied case; not independent outcome evidence.
Independent reporting
Independent reporting with attributable sources but without a formal evaluation design.
Standards or public-body guidance
Normative or advisory guidance from a standards body or public institution.
Vendor claim
A supplier-provided assertion that has not been upgraded to independent evidence.

Outcome labels

Effective
Evidence supports a useful result within the tested scope.
Mixed
Benefits and material limitations appear together.
Cautionary
The record surfaces failure, risk, or a control gap.
Emerging
A developing practice or claim without measured outcomes.

Claims discipline

Vendor, operator, and association claims are attributed and are not upgraded to independent evidence. Caveats identify self-reporting, bounded pilots, contested findings, and missing outcome measures.