Most Local Governments Are Letting Employees Use AI Without Realizing What It Can Already Access

By Jeff Reiter

Most conversations around AI in local government are focused on productivity.

Faster meeting notes. Easier email drafting. Quicker document creation. Better search capabilities.

People see that part immediately.

The larger issue is what these tools can already access inside Microsoft 365 environments that municipalities have allowed to evolve for years without consistent oversight.

Many municipalities are preparing employees to use AI tools before fully reviewing accumulated permissions, outdated Teams structures, inherited file access, shared departmental folders, and years of collaboration decisions that quietly expanded visibility across the environment.

AI does not create most of these problems. AI governance matters because these tools can surface information that existing permissions already allow employees to reach.

It exposes them faster.

The distinction matters because many agencies did not intentionally build weak governance structures. Most environments simply evolved over time as departments adopted cloud collaboration, remote work, shared systems, and faster operational workflows.

The convenience expanded quickly.

Oversight often did not.

How Municipal Environments Quietly Became More Complicated

Over the last several years, local governments rapidly adopted Microsoft Teams, SharePoint, OneDrive, cloud storage, mobile access, and collaborative workflows. Municipalities made most of those decisions for good operational reasons. Departments needed flexibility. Employees needed remote access. Information had to move faster between offices, vendors, elected officials, and outside partners.

The problem is that collaboration tends to expand faster than structure.

A Teams site created for a temporary project remains active years later. A shared folder originally intended for a small group slowly expands to additional departments. Microsoft 365 often inherits file permissions automatically, and no one always revisits whether that access still makes sense.

Over time, environments begin accumulating:

    • outdated Teams channels
    • broad file-sharing permissions
    • duplicate document storage
    • stale user access
    • inconsistent ownership
    • unmanaged guest accounts
    • disconnected departmental structures

None of this feels urgent during normal operations. Employees continue working. Departments adapt. The environment appears functional from the surface.

That is why many leadership teams assume their Microsoft 365 environment is probably under control.

Then AI enters the conversation.

What AI Can Access Depends on What Users Can Already Reach

AI tools do not magically know which documents are sensitive, outdated, confidential, or intended for a small group of people.

They work from the access structure already in place.

In a Microsoft 365 environment, that matters because access often spreads over time. A user may still have access to a SharePoint site because of a project from three years ago. A Teams channel may include employees who no longer need the information inside it. A OneDrive folder may have been shared broadly to solve a short-term problem. A department file may live in a location that made sense to one person but was never reviewed as part of a larger governance process.

When AI enters that environment, it does not fix those decisions.

It can make them easier to find.

Municipal leaders need to understand this part clearly. The issue is not only whether employees are allowed to use AI. The issue is whether the municipality knows what AI may be able to surface based on permissions that were never cleaned up.

What AI Tools Actually Surface Inside Poorly Governed Microsoft 365 Environments

That is why poorly governed Microsoft 365 environments become more concerning once AI tools are introduced.

The concern is not that AI tools are secretly bypassing security controls or accessing information nobody had permission to see.

The concern is that they are extremely effective at surfacing information users already have access to, even when nobody fully understood how broad that access had become.

Historically, weak governance sometimes stayed hidden because information was difficult to locate. Employees had to manually search through folders, Teams sites, emails, and SharePoint libraries to find documents.

AI removes much of that friction.

An employee may not know a document exists today. An AI assistant may surface it almost instantly tomorrow.

That changes the operational importance of:

    • permission reviews
    • document ownership
    • Teams governance
    • SharePoint structure
    • access management
    • information lifecycle oversight

Inside local government environments, this matters more than many agencies initially realize.

Municipal Microsoft 365 environments often contain years of:

    • payroll information
    • employee disciplinary records
    • personnel files
    • legal correspondence
    • closed-session materials
    • contract negotiations
    • resident complaint tracking
    • procurement discussions
    • board packet drafts
    • financial planning documents
    • public safety administrative records
    • internal policy revisions
    • vendor agreements
    • shared reports that were never meant for broad access

Most agencies assume these areas are already properly segmented.

Many have never formally verified that assumption.

Why Many AI Policies Miss the Larger Issue

A large number of AI discussions still focus almost entirely on employee behavior.

Do not upload sensitive information into public AI systems.
Do not paste confidential documents into ChatGPT.
Do not share resident information externally.

Those are important guidelines.

But they only address part of the issue.

The larger challenge is internal visibility.

An agency can prohibit employees from uploading sensitive information into external AI tools and still maintain years of excessive Microsoft 365 permissions, unmanaged sharing, inconsistent ownership, and stale access.

That is where administrative access becomes part of the AI conversation. If too many people can change permissions, manage users, alter security settings, or retain elevated rights from old projects, AI governance starts from an unstable foundation.

The result is a dangerous sense of confidence.

Many leadership teams still approach AI governance primarily as a software restriction or employee conduct issue. In reality, it is increasingly becoming a discussion about operational maturity.

Who has access to what?
Who reviews it?
How often is it validated?
Which departments still rely on inherited permissions nobody revisited?

Those questions matter now in ways they did not a few years ago.

Many municipalities spent years expanding collaboration faster than they expanded oversight.

AI is simply making those gaps easier to see.

What Strong AI Governance Looks Like in Local Government

Strong AI governance is not built around fear or overreaction. Most of the time, it starts with visibility and structure.

That aligns with the NIST AI Risk Management Framework, which encourages organizations to govern, map, measure, and manage AI risk.

In practical terms, AI should not be treated as a standalone software decision.

Before expanding AI usage, local governments should review five areas:

1. Microsoft 365 permissions

Who can access Teams, SharePoint sites, OneDrive folders, shared mailboxes, and sensitive document libraries? Broad access that felt harmless before AI may become much more visible once search, summarization, and content discovery improve.

2. Sensitive data locations

Where do personnel files, payroll records, legal correspondence, resident information, public safety administrative records, board documents, and finance materials actually live? If leadership does not know where sensitive data sits, it cannot make informed decisions about what AI should or should not touch.

3. Guest, vendor, and inactive access

Which outside users, vendors, former employees, or inactive accounts still have access to files, Teams, portals, or shared folders? AI governance depends on cleaning up the access model before visibility expands.

4. Administrative rights

Who can change permissions, create users, modify security settings, approve external sharing, or alter access across the environment? Administrative control should be limited, documented, and reviewed before AI tools are allowed to rely on the existing permission structure.

5. AI acceptable use expectations

Do employees know what information should not be entered into public AI tools, summarized by AI, or used in AI-assisted drafting? A useful AI policy should give practical direction, not just a general warning to “be careful.”

This is where many agencies realize the real issue is not AI itself.

The larger issue is that governance standards often never evolved at the same pace as collaboration tools, cloud adoption, and departmental data sharing.

That is a fixable problem.

But it requires leadership visibility into how information actually moves across the environment today, not how people assume it works.

Microsoft 365 environments are no longer just technical systems sitting quietly in the background. They now directly affect:

    • operational accountability
    • legal exposure
    • public trust
    • records management
    • continuity planning
    • insurance defensibility

Governance becomes a leadership issue, not simply an IT discussion.

Questions Municipal Leaders Should Be Able to Answer Before Expanding AI

Before AI becomes part of daily municipal work, leadership should be able to answer these questions:

    • Do we know what employees can already access in Microsoft 365?
    • Have Teams, SharePoint, OneDrive, and shared mailbox permissions been reviewed recently?
    • Do we know which outside users, vendors, former employees, or inactive accounts still have access?
    • Have we identified sensitive data that should not be broadly surfaced?
    • Do employees know what information should not be entered into public AI tools?
    • Do we have an AI Acceptable Use Policy?
    • Who owns the ongoing review of AI risk, permissions, and approved tools?

If those questions are hard to answer, the municipality may not have an AI problem first.

It may have a Microsoft 365 governance problem that AI is about to make visible.

The Agencies That Handle AI Well Will Approach It Differently

The local governments that manage AI successfully over the next several years will probably not be the ones rushing to deploy the most tools first.

They will be the ones that took the time to understand their environments before expanding visibility further.

Strong AI governance starts by reviewing what employees, guests, vendors, and departments can already access.

That review should happen before AI usage expands across the organization.

That means reviewing how information is shared, cleaning up outdated permissions, establishing ownership standards, and treating governance as an operational discipline instead of an afterthought.

Because AI is accelerating conversations many agencies were eventually going to need to have anyway.

About accountability.
About oversight.
About information ownership.
About how much visibility quietly accumulated over time.

In many municipal environments, collaboration expanded much faster than the structure surrounding it.

AI did not create those problems.

It simply made them easier to see.

Questions Leaders Are Asking

What can AI tools actually access inside a municipal Microsoft 365 environment?

AI tools do not magically know which documents are sensitive, outdated, confidential, or intended for a small group of people. They work from the access structure already in place. The concern is that they are extremely effective at surfacing information users already have access to, even when nobody fully understood how broad that access had become.

Why do local governments have weak Microsoft 365 governance even when they didn't intend to?

Many agencies did not intentionally build weak governance structures. Most environments simply evolved over time as departments adopted cloud collaboration, remote work, shared systems, and faster operational workflows. The convenience expanded quickly. Oversight often did not.

Why isn't an AI acceptable use policy enough to protect a municipality?

An agency can prohibit employees from uploading sensitive information into external AI tools and still maintain years of excessive Microsoft 365 permissions, unmanaged sharing, inconsistent ownership, and stale access. Many leadership teams still approach AI governance primarily as a software restriction or employee conduct issue. In reality, it is increasingly becoming a discussion about operational maturity.

What should local governments review before expanding AI tool usage?

Before expanding AI usage, local governments should review five areas: Microsoft 365 permissions, sensitive data locations, guest and vendor and inactive access, administrative rights, and ongoing governance ownership. Strong AI governance starts by reviewing what employees, guests, vendors, and departments can already access, and that review should happen before AI usage expands across the organization.

What types of sensitive information are commonly exposed by poor Microsoft 365 governance in local government?

Municipal Microsoft 365 environments often contain years of payroll information, employee disciplinary records, personnel files, legal correspondence, closed-session materials, contract negotiations, resident complaint tracking, procurement discussions, board packet drafts, financial planning documents, public safety administrative records, internal policy revisions, vendor agreements, and shared reports that were never meant for broad access. Most agencies assume these areas are already properly segmented. Many have never formally verified that assumption.