Lighthouse AdvisorySLED AI Adoption Intelligence
← Back to results

From the SLED-wide archive edition of August 31, 2026

Government auditCautionaryNew this fortnight

Follow-up audit finds visible governance progress but no complete inventory or mandatory risk process

New York State Office of the State Comptroller; New York City Office of Technology and Innovation · Municipal government governance and oversight · New York City, New York, United States

Publisher
Artificial Intelligence Governance (Follow-Up), Report 2025-F-17
Original publication
August 27, 2026
Source retrieved
Not recorded in the historical archive
Read original source

What happened

A state follow-up audit assessed New York City's implementation of three 2023 AI-governance recommendations as of April 13, 2026. The City had issued principles, definitions, generative-AI guidance, public-engagement guidance, a cybersecurity policy, and a risk-assessment template; established steering and advisory bodies; and completed seven risk assessments. Auditors nevertheless rated all three recommendations only partially implemented.

Why it matters

This is rare longitudinal evidence showing what happens after a large local government publishes an AI action plan. It distinguishes visible program activity from the harder controls needed to govern AI consistently across agencies, including schools, police, child services, and buildings.

Evidence and measured results

The audit found no complete citywide inventory, no mechanism to verify the completeness and accuracy of agency self-reporting, no mandatory citywide AI risk-assessment process, and no follow-up process requiring agencies to implement assessment recommendations. Five template-based assessments identified risks and mitigations, while two earlier assessments lacked important structure and details. A cybersecurity policy required approval, inventory, training-data approval, and continuous monitoring, but broader accuracy, bias, data-quality, and appropriate-use controls remained incomplete.

Limitations and uncertainty

This was a follow-up of three prior recommendations rather than a full new audit of every city AI system. Testing included OTI and a judgmentally selected Department of Buildings review, and the report evaluates governance implementation rather than the effectiveness or fairness of individual AI tools.

Put this evidence to work

Lighthouse Advisory interpretation, grounded in this source as summarized in the preserved archive. Enriched 2026-09-05; this does not change the original publication date. Labels below come from the analysis itself.

Sales

Role takeaway

Problem and stakeholders: City technology, agency leaders, auditors, school officials, and public-safety leaders may have AI principles without verified inventory or enforced assessment follow-up.

Discovery
How are embedded vendor features and pilots found, which uses require review, and who verifies mitigation closure?
Value hypothesis
Reconciling inventory and recommendations could make oversight accountable and reduce unknown exposure.
Potential engagement
A cross-agency inventory reconciliation and assessment-closure review using existing governance tools.
Evidence boundary
The follow-up rated three recommendations partially implemented and examined selected evidence. It does not show every city system is ungoverned, that a particular tool is inaccurate or unfair, or that publishing an inventory alone prevents harm.

Pre-sales engineering

Role takeaway
Fit
Focus on controls around deployments, including embedded features and outputs influencing field activity.
Architecture
Link procurement, applications, model and data records, agency owners, integrations, monitoring, assessments, and mitigation tickets.
Prerequisites
Agreed definitions, agency access, discovery beyond self-reporting, and mandatory review triggers.
Constraints
Incomplete supplier disclosure and decentralized pilots may prevent first-pass completeness; label uncertainty.
Security
Restrict sensitive system details while covering privacy, accuracy, bias, and data quality alongside cybersecurity.
Proposed validation
Reconcile independent discovery sources, sample deployed services back to their records, and trace recommendations to tested closure. Confirm that newly discovered or changed systems enter review rather than relying on static declarations or committee membership as evidence of control.

Delivery

Role takeaway

Work and dependencies: Establish citywide inventory ownership and agency attestations, reconcile records, define risk tiers, and verify assessment closure.

Ownership
Agencies remain accountable for service behavior; central governance maintains requirements; audit checks implementation independently.
Skills and adoption
Train departmental staff to recognize embedded AI and report changes, and provide practical complaint and question channels.
Governance checkpoints
Require assessment at defined deployment and change events and review overdue mitigations.
Proposed acceptance
Sampled systems reconcile across discovery sources, required assessments exist, material findings have evidence-backed disposition, and complaint or remedy routes function.
Risks
Voluntary reporting can omit systems, cybersecurity approval can crowd out broader risks, and committees or templates can create visible activity without operational control.

Implementation considerations

Lighthouse Advisory interpretation across the operating dimensions a public-sector buyer must settle before this evidence becomes a design. Each note answers the question under its heading for this specific source.

Architecture and integration

What must connect, and where does the AI sit in the workflow?

Build discovery beyond procurement records and voluntary declarations, including embedded AI, proofs of concept, vendor updates, and systems whose outputs influence inspections or other field activity. Connect inventory entries to model and data sources, owners, integrations, affected services, monitoring, and lifecycle state.

Governance

Who approves, reviews and stays accountable for outcomes?

Convert guidance into risk-tiered requirements, define when assessment and approval are mandatory, track recommendations to closure, audit agency compliance, and provide a citywide mechanism for questions, complaints, investigation, and remedy when AI causes suspected harm.

Security and privacy

What data, permissions and controls need testing?

Cybersecurity approval is necessary but insufficient. Require data-quality, privacy, bias, accuracy, explainability, acceptable-use, and ongoing outcome monitoring alongside security review; preserve public reporting and complaint channels for consequential systems.

The preserved archive analysis covered architecture, governance and security. Not assessed for this record: accessibility and workforce, procurement, operating model.

Publication history

  1. 2026-08-31SLED-wide archive · Issue 044 resources
Read preserved resource versions (JSON)

Stable resource ID: nyc-ai-governance-follow-up