Toolkit · Instrument 1
AI Use Inventory
You cannot govern what you have not mapped. An AI use inventory is the foundation for risk classification, procurement review, transparency, human oversight, and incident response. It helps a city understand which AI-enabled tools are already being used, where they came from, and whether they affect residents or sensitive government functions.
How to run the inventory
- 1
Survey departments
Send a short inventory request, authorized by city leadership, to every department head. Ask about standalone AI tools and AI features embedded in existing software. Expect the first response to be incomplete.
- 2
Review procurement and technology records
Review active contracts, software inventories, renewals, purchase records, and technology portfolios for references to AI, machine learning, automated decision-making, analytics, prediction, biometrics, or 'smart' features. AI capabilities may also appear through product updates, optional modules, or changes to existing vendor platforms during the contract term.
- 3
Interview higher-exposure departments
Prioritize departments whose systems may directly affect residents, rights, public safety, employment, or access to services. These may include police, fire and dispatch, human resources, permitting, housing, social services, code enforcement, and public-facing communications. Interview these departments directly rather than relying only on surveys.
- 4
Record, classify, and review
Enter each system into the inventory and assign a preliminary risk tier. Circulate an internal summary, identify systems requiring immediate review, and establish a regular refresh schedule. Consider creating a separate public-facing register after appropriate legal, privacy, security, procurement, and records review.
What to record for each system
| Field | What it captures |
|---|---|
| System name and vendor | What the tool is and who provides it, including AI features embedded in other software. |
| Department and internal owner | Which department uses it and the named staff member responsible. |
| Deployment status | Whether the system is proposed, in pilot, active, suspended, or retired. |
| Function | Whether it drafts, predicts, ranks, detects, transcribes, recommends, or supports decisions. |
| Data inputs | What information it receives, especially personal, biometric, confidential, protected, or surveillance-derived data. |
| Personal or sensitive data involved | Whether the system processes personal, protected, or otherwise sensitive information. |
| Biometric or surveillance data involved | Whether the system uses biometric identifiers or surveillance-derived data. |
| Affected population | Which residents, employees, applicants, businesses, or groups may be affected. |
| Public-facing or internal use | Whether residents interact with the system directly, or use is limited to internal staff. |
| Decision impact | Whether outputs influence benefits, enforcement, permits, employment, public safety, housing, or other consequential decisions. |
| Human review | Whether a person reviews the output before action is taken and who retains final authority. |
| Contract status | Procurement vehicle, renewal date, relevant contract terms, and termination provisions. |
| Audit or testing rights | Whether the city has rights to test, audit, or inspect the system and its outputs. |
| Data-reuse terms | Whether the vendor may use city or resident data to train or improve models. |
| Risk tier | Preliminary classification using the Risk Tier Classifier. |
| Appeal or complaint process | Whether affected people can seek review or correction of an outcome. |
| Last reviewed | When the system was last reviewed and by whom. |
| Responsible reviewer | The named official or team accountable for the most recent review. |