Iowa Counties Draft AI Policies to Protect Sensitive Data
Municipal employees face new documentation requirements as generative AI tools become embedded in everyday software.
Iowa Counties Draft AI Policies to Protect Sensitive Data
Multiple Iowa counties are establishing formal policies governing how public employees use artificial intelligence tools, with a focus on preventing sensitive government data from being absorbed into commercial AI systems.
Johnson County is among the municipalities developing guidelines that may require employees to report when and how they use AI applications. Bill Horning, the county's IT director, explained that once information enters an AI system, it becomes part of that system's training data permanently.
"AI tools are a great assistance in doing things, but we can't just put data out there," Horning said. "AI learns from being fed information. So you put county data in there, it has that county data going forward. You can't just say, 'Oh, erase everything I told you.' It doesn't work that way. Once it's there, it's there."
The Documentation Requirement
Under the emerging policies, employees who use AI tools will need to create detailed records of their interactions. This includes documenting what task the AI was used for, what parameters were set, and what information was shared with the system.
The documentation serves a dual purpose: creating an audit trail for potential security incidents and establishing accountability for how public data flows through third-party systems. If a data breach or privacy concern arises later, IT administrators can trace exactly what information was shared and when.
The concern extends to routine tasks. When a county employee uses ChatGPT to refine an email draft, for example, any details in that message—names, addresses, case information—become part of OpenAI's dataset.
Statewide Adoption
Johnson County is not alone in addressing these risks. Black Hawk, Pottawattamie, Sioux, and Woodbury counties have all created their own AI usage guidelines. Iowa state employees are also subject to an AI policy, though specific details of that policy were not disclosed.
Horning emphasized that these policies are becoming more urgent as AI capabilities are integrated directly into widely used software platforms. Microsoft's Copilot and Google's Gemini now offer AI assistance within productivity tools that government workers use daily, making it easier to inadvertently share protected information.
Why it matters
Public sector organizations handle vast amounts of personal data—tax records, health information, legal documents—that are protected by privacy laws. As generative AI becomes embedded in standard office software, the risk of accidental data exposure grows. These policies represent an early attempt to balance the productivity benefits of AI with the legal and ethical obligations government agencies have to protect citizen information. The documentation requirements also create precedent for AI accountability that could influence private sector practices.
These details were first reported by Eliza Billingham for Iowa Public Radio.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
