Toolkit · Instrument 1

AI Use Inventory

You cannot govern what you have not mapped. An AI use inventory is the foundation for risk classification, procurement review, transparency, human oversight, and incident response. It helps a city understand which AI-enabled tools are already being used, where they came from, and whether they affect residents or sensitive government functions.

Definition. For this inventory, an "AI-enabled tool" includes generative AI, machine learning, automated prediction or ranking, computer vision, biometric identification, speech recognition, and AI features embedded in existing software.

How to run the inventory

  1. 1

    Survey departments

    Send a short inventory request, authorized by city leadership, to every department head. Ask about standalone AI tools and AI features embedded in existing software. Expect the first response to be incomplete.

  2. 2

    Review procurement and technology records

    Review active contracts, software inventories, renewals, purchase records, and technology portfolios for references to AI, machine learning, automated decision-making, analytics, prediction, biometrics, or 'smart' features. AI capabilities may also appear through product updates, optional modules, or changes to existing vendor platforms during the contract term.

  3. 3

    Interview higher-exposure departments

    Prioritize departments whose systems may directly affect residents, rights, public safety, employment, or access to services. These may include police, fire and dispatch, human resources, permitting, housing, social services, code enforcement, and public-facing communications. Interview these departments directly rather than relying only on surveys.

  4. 4

    Record, classify, and review

    Enter each system into the inventory and assign a preliminary risk tier. Circulate an internal summary, identify systems requiring immediate review, and establish a regular refresh schedule. Consider creating a separate public-facing register after appropriate legal, privacy, security, procurement, and records review.

What to record for each system

FieldWhat it captures
System name and vendorWhat the tool is and who provides it, including AI features embedded in other software.
Department and internal ownerWhich department uses it and the named staff member responsible.
Deployment statusWhether the system is proposed, in pilot, active, suspended, or retired.
FunctionWhether it drafts, predicts, ranks, detects, transcribes, recommends, or supports decisions.
Data inputsWhat information it receives, especially personal, biometric, confidential, protected, or surveillance-derived data.
Personal or sensitive data involvedWhether the system processes personal, protected, or otherwise sensitive information.
Biometric or surveillance data involvedWhether the system uses biometric identifiers or surveillance-derived data.
Affected populationWhich residents, employees, applicants, businesses, or groups may be affected.
Public-facing or internal useWhether residents interact with the system directly, or use is limited to internal staff.
Decision impactWhether outputs influence benefits, enforcement, permits, employment, public safety, housing, or other consequential decisions.
Human reviewWhether a person reviews the output before action is taken and who retains final authority.
Contract statusProcurement vehicle, renewal date, relevant contract terms, and termination provisions.
Audit or testing rightsWhether the city has rights to test, audit, or inspect the system and its outputs.
Data-reuse termsWhether the vendor may use city or resident data to train or improve models.
Risk tierPreliminary classification using the Risk Tier Classifier.
Appeal or complaint processWhether affected people can seek review or correction of an outcome.
Last reviewedWhen the system was last reviewed and by whom.
Responsible reviewerThe named official or team accountable for the most recent review.