As a local government leader, procuring the right AI model is a challenge. Government agencies face a unique set of considerations, including compliance, public accountability, and data security, all of which must be addressed.
But make no mistake about it: staff are using AI, whether or not you’ve vetted the tools.
Thomson Reuters Institute’s 2026 Future of Professionals report found that 34% of professionals use AI tools their organization has not sanctioned. IBM’s 2026 Cost of a Data Breach Report found that 43% of security incidents in 2026 involved this kind of unsanctioned AI use, more than double the 20% recorded a year earlier. Those incidents cost more than the average breach—$5.39 million versus $4.99 million—and 21% of them resulted in regulatory fines.
As agencies explore AI, local leaders are encountering a wide range of tools that promise faster workflows and enhance efficiency. On the surface, many of these tools may appear similar, but in practice, they are built on very different assumptions about security, governance, and how government work gets done.
Ultimately, not every AI solution is designed to meet the needs of local government.
These are the general-purpose tools anyone can open in a browser. Think ChatGPT, Claude, or Gemini. These are powerful tools for drafting, summarizing, and creating, and they’re also the tools staff reach for first, often without asking.
The issue here is not that these tools aren’t capable, but that that they lack the required compliance context that government workflows operate in: Generic AIs have no connection to the system of record and no audit trail, creating real security issues for local agencies. The National Cybersecurity Alliance found that 43% of AI users have shared sensitive workplace information with AI tools without their employer’s knowledge, and half of those shared internal documents.
In an attempt to curb these risks, some local agencies are blocking AI all together. MissionSquare found that 35% of state and local government employees say their department prohibits or limits at least some AI tools.
Rather than restrict AI, local government should prioritize investment in AI that meets their specific needs.
Another category of AI is enterprise software built for commercial use and later adapted for government. These retrofitted tools are more capable and more governable than the general-purpose ones, and they work well for many back-office functions. But there are gaps when it comes to explainability, clear ownership, consistent outcomes, and strong public accountability.
Additionally, retrofitted tools tend to optimize a step rather than a process, but when AI is bolted on, it can create more work and handoffs, not fewer. Salesforce’s Connectivity Benchmark found that organizations run an average of 897 applications and only 29% of them are connected to one another.
When it comes to plan review, agencies need purpose-built AI, designed specifically around the Community Infrastructure Delivery workflow—where the output of each stage becomes the input of the next.
The third category is software designed around the workflow from the start, integrated with the system of record, and built to meet the security and auditability standards public agencies are held to.
Purpose-built AI models are built by trusted technology vendors with long-standing domain experience. Because they’re designed around government workflows, these solutions perform better while ensuring the required compliance needs are met.
Recent analyst research supports this. Gartner’s 2026 work on domain-specific language models (DSLMs)—AI that’s been optimized to specific verticals, industries, or functions—indicates that these models outperform general purpose LLMs on tasks within their domain. Gartner reports that DSMs “offer up to 50% lower development costs, faster deployment and consistently higher reliability in business-critical workflows.”
This is why Avolve has partnered with Microsoft. For many agencies, Microsoft is already the central nerve of daily operations. From cloud infrastructure to productivity tools, it’s among the best-known and most-trusted technological environments to meet strict public-sector compliance standards.
Government buyers are already converging on the right questions. Appian’s June 2026 survey of 2,000 public sector workers found the top responsible-AI priorities are to be data privacy and security (46%), compliance with laws and standards (45%), human oversight and accountability (44%) and transparency and auditability (42%).
Procurement is catching up, too: NASCIO found that 41% of state CIO organizations now require vendors to disclose their use of AI.
Four questions worth asking any vendor:
Learn more about Avolve AI, built for plan review rather than adapted to it.
Generic AI refers to general-purpose tools adopted informally for government work. They lack integration with the system of record, an audit trail and awareness of compliance requirements. Purpose-built AI is designed around a specific government workflow, integrated with the system of record, and built to meet public sector security and explainability standards.
Because plan review is a sequence rather than a single step. If AI output lands outside the review record, it creates an undocumented decision input and additional handoffs. Integration keeps results auditable, traceable and available to the next stage of the workflow.
Where data is processed and stored, whether output is written into the existing system of record, whether reviewers can see the reason for a flag and override it, and whether the tool reduces or adds handoffs across the full workflow.
Intentional AI is Avolve’s term for AI purpose-built for government plan review and designed to augment professional expertise rather than replace it, keeping accountability with the jurisdiction.