From the SLED-wide archive edition of August 31, 2026
Follow-up audit finds visible governance progress but no complete inventory or mandatory risk process
New York State Office of the State Comptroller; New York City Office of Technology and Innovation · Municipal government governance and oversight · New York City, New York, United States
- Publisher
- Artificial Intelligence Governance (Follow-Up), Report 2025-F-17
- Original publication
- August 27, 2026
- Source retrieved
- Not recorded in the historical archive
What happened
A state follow-up audit assessed New York City's implementation of three 2023 AI-governance recommendations as of April 13, 2026. The City had issued principles, definitions, generative-AI guidance, public-engagement guidance, a cybersecurity policy, and a risk-assessment template; established steering and advisory bodies; and completed seven risk assessments. Auditors nevertheless rated all three recommendations only partially implemented.
Why it matters
This is rare longitudinal evidence showing what happens after a large local government publishes an AI action plan. It distinguishes visible program activity from the harder controls needed to govern AI consistently across agencies, including schools, police, child services, and buildings.
Evidence and measured results
The audit found no complete citywide inventory, no mechanism to verify the completeness and accuracy of agency self-reporting, no mandatory citywide AI risk-assessment process, and no follow-up process requiring agencies to implement assessment recommendations. Five template-based assessments identified risks and mitigations, while two earlier assessments lacked important structure and details. A cybersecurity policy required approval, inventory, training-data approval, and continuous monitoring, but broader accuracy, bias, data-quality, and appropriate-use controls remained incomplete.
Limitations and uncertainty
This was a follow-up of three prior recommendations rather than a full new audit of every city AI system. Testing included OTI and a judgmentally selected Department of Buildings review, and the report evaluates governance implementation rather than the effectiveness or fairness of individual AI tools.
Put this evidence to work
Lighthouse Advisory interpretation, grounded in this source as summarized in the preserved archive. Enriched 2026-09-05; this does not change the original publication date. Labels below come from the analysis itself.
Sales
Role takeaway
Problem and stakeholders: City technology, agency leaders, auditors, school officials, and public-safety leaders may have AI principles without verified inventory or enforced assessment follow-up.
- Discovery
- How are embedded vendor features and pilots found, which uses require review, and who verifies mitigation closure?
- Value hypothesis
- Reconciling inventory and recommendations could make oversight accountable and reduce unknown exposure.
- Potential engagement
- A cross-agency inventory reconciliation and assessment-closure review using existing governance tools.
- Evidence boundary
- The follow-up rated three recommendations partially implemented and examined selected evidence. It does not show every city system is ungoverned, that a particular tool is inaccurate or unfair, or that publishing an inventory alone prevents harm.
Pre-sales engineering
Role takeaway
- Fit
- Focus on controls around deployments, including embedded features and outputs influencing field activity.
- Architecture
- Link procurement, applications, model and data records, agency owners, integrations, monitoring, assessments, and mitigation tickets.
- Prerequisites
- Agreed definitions, agency access, discovery beyond self-reporting, and mandatory review triggers.
- Constraints
- Incomplete supplier disclosure and decentralized pilots may prevent first-pass completeness; label uncertainty.
- Security
- Restrict sensitive system details while covering privacy, accuracy, bias, and data quality alongside cybersecurity.
- Proposed validation
- Reconcile independent discovery sources, sample deployed services back to their records, and trace recommendations to tested closure. Confirm that newly discovered or changed systems enter review rather than relying on static declarations or committee membership as evidence of control.
Delivery
Role takeaway
Work and dependencies: Establish citywide inventory ownership and agency attestations, reconcile records, define risk tiers, and verify assessment closure.
- Ownership
- Agencies remain accountable for service behavior; central governance maintains requirements; audit checks implementation independently.
- Skills and adoption
- Train departmental staff to recognize embedded AI and report changes, and provide practical complaint and question channels.
- Governance checkpoints
- Require assessment at defined deployment and change events and review overdue mitigations.
- Proposed acceptance
- Sampled systems reconcile across discovery sources, required assessments exist, material findings have evidence-backed disposition, and complaint or remedy routes function.
- Risks
- Voluntary reporting can omit systems, cybersecurity approval can crowd out broader risks, and committees or templates can create visible activity without operational control.
Implementation considerations
Lighthouse Advisory interpretation across the operating dimensions a public-sector buyer must settle before this evidence becomes a design. Each note answers the question under its heading for this specific source.
Architecture and integration
What must connect, and where does the AI sit in the workflow?
Build discovery beyond procurement records and voluntary declarations, including embedded AI, proofs of concept, vendor updates, and systems whose outputs influence inspections or other field activity. Connect inventory entries to model and data sources, owners, integrations, affected services, monitoring, and lifecycle state.
Governance
Who approves, reviews and stays accountable for outcomes?
Convert guidance into risk-tiered requirements, define when assessment and approval are mandatory, track recommendations to closure, audit agency compliance, and provide a citywide mechanism for questions, complaints, investigation, and remedy when AI causes suspected harm.
Security and privacy
What data, permissions and controls need testing?
Cybersecurity approval is necessary but insufficient. Require data-quality, privacy, bias, accuracy, explainability, acceptable-use, and ongoing outcome monitoring alongside security review; preserve public reporting and complaint channels for consequential systems.
The preserved archive analysis covered architecture, governance and security. Not assessed for this record: accessibility and workforce, procurement, operating model.
Publication history
- 2026-08-31SLED-wide archive · Issue 044 resources
Stable resource ID: nyc-ai-governance-follow-up