The least glamorous AI risk in government is not the rogue chatbot. It is the shared inbox where a pilot waits for privacy, security, procurement, legal, records, accessibility, and the committee that meets after the budget window closes. Oversight matters, but serial uncertainty is not oversight. It is latency wearing a policy badge. The useful question is not whether public agencies should govern AI. They should, and residents are entitled to more than procurement optimism. The question is whether the approval path tells a team what evidence to produce, who decides, and what happens after launch. If the answer is no, the agency has not made AI safer. It has made the queue more official. ## The queue is now part of the control WaTech and UC Berkeley frame responsible public sector AI as an implementation problem with staged goals, not a values poster. Their report sets short term goals at 6 months, medium term goals at 1 to 2 years, and a long term vision at 2 years or more. That sequencing is useful because it treats governance as something agencies build, test, and maintain. A policy that cannot be routed, staffed, or audited is not a control. It is a PDF with aspirations. The World Bank makes the service delivery reason plain. Its summary note says AI can support personalized services, back end efficiency, policy compliance, and fraud identification when used with human management and decision making. Translation for agencies: review has to protect residents, but it also has to reach the part of government where forms are processed, benefits are checked, and fraud flags are reviewed by people with job titles. If every low risk internal assistant faces the same path as an eligibility system, risk triage has quietly failed. ## Simplification is an obligation map, not a shortcut The World Bank also links public sector AI use to fiscal stress and limits on mobility for citizens and civil servants during COVID 19. That is a reminder that government AI adoption is usually justified in the language of service continuity and cost pressure, not abstract experimentation. Simplifying approval does not mean deleting privacy review or security review. It means asking once, in one intake, what the system does, what data it uses, whose services or rights it may affect, who can override it, and how performance will be monitored. The European Commission describes AI adoption in the EU public sector as an opportunity to better serve citizens and support startups. That opportunity collapses quickly if a small vendor must answer the same data, audit, and human oversight questions in four different formats for one agency. Article numbers are not the problem here. The problem is making each office rediscover the same facts because nobody owns the shared evidence file. ## The legal floor still has teeth The Center for Security and Emerging Technology summarized the European Commission proposal as imposing strict controls on certain high risk commercial AI applications and banning others entirely. Its examples of prohibited AI included social scoring, subliminal manipulation, and real time biometric surveillance by law enforcement, with certain exceptions. For systems deemed high risk, CSET described extensive inspections before deployment, clear and transparent information for users, human oversight, and attention to well organized and unbiased data. It also noted proposed fines of up to 6 percent of global sales. That is the part LinkedIn usually rounds into either panic or compliance theater. The proposal CSET described does not mean every chatbot needs a twelve stop pilgrimage. It means consequence matters. If an AI system affects access to benefits, public services, or enforcement, the agency should expect stronger evidence, named accountability, and a monitoring plan. If it summarizes meeting notes for staff, the review should still cover data handling and records obligations, but it should not pretend the risk profile is identical. ## What agencies and builders should change next WaTech and UC Berkeley give agencies the more useful posture: treat responsible AI as a roadmap with near term and longer term work. In practice, that means a single AI intake form, a risk tiering rule, a common evidence pack, and one coordinated decision record. The privacy office should not learn about a tool after procurement. Security should not ask for architecture details after the pilot has already handled sensitive data. For builders, the lesson is equally plain. Bring a deployment memo, not a slogan. Explain data sources, retention, human review, failure modes, user notice, logging, and escalation before the agency asks for them in three separate portals. Public sector AI will not move faster because governance got softer. It will move faster when the same evidence can satisfy the right reviewers in the right order. The next thing to watch is whether agencies turn AI principles into operating procedure. A good sign is one visible intake path with risk based routing and postlaunch monitoring. A bad sign is a new AI committee that leaves procurement, data access, and security review exactly where they were. Builders can work with strict rules. They have a harder time with rules that exist only after the meeting starts. ## Sources - Artificial Intelligence in the Public Sector

Sources