Philadelphia officially has a new AI policy for municipal workers that restricts the use of consumer tools and mandates strict risk assessments for new software. 

However, the infrastructure needed to actually enforce these rules appears to be missing, according to public records obtained by Technical.ly via a right-to-know request.

The new policies follow a contentious City Council hearing last fall, where council members grilled OIT and the mayor’s office representatives over their handling of AI. 

At the end of March, the city’s Office of Innovation and Technology (OIT) published an AI use policy for city departments. The guidelines outline approval standards for AI tools, rules for employee use of generative AI and plans to manage the technology’s impact on city services.

The policy repeatedly mentions an “AI governance committee” that’s responsible for approving tools and ensuring compliance, but it’s not clear if it exists. In response to Technical.ly’s public records request, the city explicitly stated there are no records regarding the committee.

Councilmember Rue Landau, chair of City Council’s Technology and the Information Services Committee, hosted a hearing last fall on how the city is using AI and its plans for future policy. She acknowledged the lingering uncertainty surrounding the governance committee’s structure moving forward.

“There are some important questions to sort through,” Landau told Technical.ly in June, “like how this policy will be put into practice, how it will be implemented by law-enforcement agencies and what the makeup of the governance committee will be.”

OIT officials did not respond to repeated requests for clarification on this issue.

What the new compliance policy actually requires

The city’s AI policy focuses heavily on vendor vetting and risk mitigation.

OIT, in partnership with the Law Department, requires “all departments, agencies, employees and contractors” to track, log and justify every tool they plan to use.

That includes an inventory of active AI systems kept by the governance committee and regular evaluation of tools to ensure they meet the city’s standards. OIT plans to update these procedures as technology evolves and will publish them “wherever feasible.”

The framework also mandates equity impact tests to measure how AI systems affect residents and employees. 

OIT, the Law Department and the AI governance committee are meant to subject all new software to risk and security assessments to align with city data standards, while reviewing third-party contracts to guarantee data security and transparency.

The new guidelines restrict employees to only use licensed “enterprise” versions of tools and ban unapproved “consumer” generative AI. The text does not specify which apps belong in which category. 

Employees using approved generative tools must review all outputs for mistakes and bias.

To ensure compliance, the city mandated AI training starting April 1, according to CIO Melissa Scott at a budget hearing in March. OIT and the Law Department hold the power to halt the use of any non-compliant tool.

At the hearing, Scott also explained the core principles behind the policy’s specifics.

“The AI policy … is anchored in three core principles,” Scott said. “Ethical utilization, robust governance frameworks [and] data security emphasizing bias reductions, human oversight and stringent data protection measures.” 

Addressing public pushback and ethical questions

The new policies follow a contentious City Council hearing last fall, where council members grilled OIT and the mayor’s office representatives over their handling of AI. 

At the time, CIO Scott and Kristin Bray, chief legal counsel to the mayor, promised an AI policy, employee training, and a governance committee by spring.

During that hearing, officials could not answer public concerns regarding data privacy or potential civil rights violations. While the new policy touches on these ethical questions, it still lacks specific timelines or actionable steps to safeguard privacy.

“Residents need clear information on when and how AI is being used with the city,” Councilmember Landau said. “I would like to see regular reports and public engagement opportunities added to this process.”