In most agencies, the AI question isn't whether to start. It's how to govern what has already started. Staff use general-purpose AI tools to draft emails, rewrite policies and summarize packets, usually without an approved-use policy, often with data that shouldn't leave the building.
Meanwhile, procurement is drafting a solicitation for an AI chatbot.
Governance is a deliverable
An approved-use policy isn't a memo that says "be careful." It's a short set of decisions your CIO and counsel can stand behind:
- Data classification: which information can go into which tools, and which never leaves the agency tenant.
- Risk tiers: drafting a newsletter isn't the same as summarizing a personnel file.
- Employee-review rules: consequential outputs, such as an award, a payment, a permit decision or a letter to a resident, get a named person's approval.
- Vendor criteria: what any AI tool must show before it's bought: where data goes, what's logged, what you own at exit.
- A roadmap: the sanctioned pilots that replace the shadow use, in order.
Governance is how IT blesses the next step without pretending the last one didn't happen.
Why it comes before the RFP
A solicitation written before these decisions tends to buy the wrong thing: a broad chatbot with vague data terms, priced per seat, evaluated on a demo. A solicitation written after them asks for specific workflows, deployment in your tenant, audit logging, an evaluation set and portability at exit. The vendors who can't meet those terms disqualify themselves.
Munivera's governance engagement takes three to four weeks and is often the first purchase. It's sized to fit common small-purchase thresholds, and it leaves you with a policy, a risk model and a roadmap whether or not you ever hire us for the next step.