---
title: "What County Technology Leaders Just Told Us About AI Governance"
id: "3400"
type: "insight"
slug: "public-sector-ai-governance-policy-gap"
published_at: "2026-08-07T15:54:44+00:00"
modified_at: "2026-08-07T15:54:45+00:00"
url: "https://jetstream.security/insights/public-sector-ai-governance-policy-gap/"
markdown_url: "https://jetstream.security/insights/public-sector-ai-governance-policy-gap.md"
excerpt: "County governments report 68% AI-policy adoption, but a written policy is not the same as governing what AI does once it is running."
taxonomy_insight_category:
  - "AI Advisory"
taxonomy_insight_type:
  - "Editorial"
taxonomy_insight_tags:
  - "AI Advisory"
  - "AI Governance in government"
  - "AI Visibility"
  - "Shadow AI"
---

AI Advisory

# What County Technology Leaders Just Told Us About AI Governance

County governments report 68% AI-policy adoption, but a written policy is not the same as governing what AI does once it is running.

[AI Advisory](https://jetstream.security/insights/insight_tags/ai-advisory/)
[AI Governance in government](https://jetstream.security/insights/insight_tags/ai-governance-in-government/)
[AI Visibility](https://jetstream.security/insights/insight_tags/ai-visibility/)
[Shadow AI](https://jetstream.security/insights/insight_tags/shadow-ai/)

JetStream Security

Editorial

Each year, the Center for Digital Government surveys county governments across the United States on their technology work. Its Digital Counties 2026 results are written for public-sector leaders, but the findings describe the problem every security team is now working. The counties surveyed named cybersecurity their top priority and artificial intelligence their third. Those two priorities are converging, and the survey shows exactly where. You can see the full survey results at the infographic below. JetStream Security sponsored this survey.

Most counties have set the rules: 68% have implemented a countywide policy on artificial intelligence, and 59% have one on data governance, according to the survey results. That is real progress, and it also marks where the harder work begins. A written policy says what a system is supposed to do. It cannot show what that system actually does once it is running, calling tools, and handling a resident’s data. The distance between the two is [where risk collects](https://jetstream.security/insights/audit-the-evidence-ai-policy/)
.

Corporate boards are in the same position. When [JetStream polled members of the National Association of Corporate Directors](https://jetstream.security/insights/what-boards-are-asking-about-ai-risk/)
 in May 2026, 70% had an AI policy, but 67% were not performing AI discovery and 74% had no manifest of the AI running across their organization. County policy adoption sits two points below that board figure, which suggests the same gap likely sits behind it. Policy without visibility is not governance. It is paperwork.

That gap is not theoretical, because AI is already in production across county operations. Counties report AI in threat detection and prevention (68.2%), personal productivity (52.3%), and AI-augmented application development (27.3%), per the Center for Digital Government. Read together, those numbers show AI woven through daily work, from the security operations center to staff desktops to the teams that build the county’s own software. In many organizations that building now moves faster than any approval process, led by [staff who reach for an AI tool when they hit a problem](https://jetstream.security/insights/citizen-developer-employees-risk/)
. These are live systems shaping real services and decisions. The governance question is who owns each system and what keeps it inside the lines while it runs.

##### Will agentic AI come to county governments next?

The identity data hints at a question counties may face next. They have invested in identity controls for people and machines. Multifactor authentication is in place at 83.3% of them, identity and access management at 77.3%, and privileged access management at 68.2% (Center for Digital Government). That is a mature foundation. As county AI use grows, some may begin to explore AI agents. If they do, a further question follows: would any of that identity control reach the non-human identities such systems run under? An AI agent that mints a key, reads county data, and calls an external service would be a new kind of account. It would need an identity, an owner, and a revocable boundary, the same way a privileged human account does.

This is the difference between governing AI on paper and governing it at runtime. A policy sets the intended behavior. A runtime control plane checks live behavior against that intent, continuously, and revokes access in seconds when the two diverge. JetStream AI Blueprints™ exist for this. A Blueprint is the approved description of what an AI system may do, and the runtime enforces it, so the policy a county has already written becomes something it can prove. The AI system that was granted access last quarter is still doing only what it was approved to do this quarter, or it is stopped.

For public-sector teams, that proof is turning into a procurement requirement rather than a nice-to-have. FedRAMP authorization already signals that a vendor meets a recognized federal security bar. The next question follows naturally: do the AI systems inside that authorized environment stay within their approved boundaries after they go live, and can the agency account for each one the way [it accounts for every other asset](https://jetstream.security/insights/make-the-ai-agent-a-reportable-asset/)
? That is the step ahead for counties: turning the policy they have already written into evidence the runtime produces on demand.

County governments are keeping pace with corporate boards on policy adoption, and they face the same unfinished work: turning a written rule into something the runtime enforces. The lesson travels well beyond local government.

[CDG26 Counties Infographic v Jetstream](https://www.scribd.com/document/1070650307/CDG26-Counties-Infographic-v-Jetstream#from_embed)
 by [JetStream AI Advisory](https://www.scribd.com/user/985601713/JetStream-AI-Advisory#from_embed)

The full Digital Counties 2026 results, including the winning counties in each population category, are available from the Center for Digital Government at [govtech.com/digitalcounties2026.](http://govtech.com/digitalcounties2026)

## Stay ahead with our newsletter

Stay informed on industry trends, expert analysis, and product updates.

#### Explore more insights

[See all Insights](/insights)

[https://jetstream.security/insights/mcp-vs-skills/](https://jetstream.security/insights/mcp-vs-skills/)
Aug 18, 2026

###### MCP vs. Skills: A False Debate

MCP gives an agent its tools and Skills give it the instructions. The teams winning with Claude run both, and governance is what keeps the pairing safe.

[https://jetstream.security/insights/mcp-vs-skills/](https://jetstream.security/insights/mcp-vs-skills/)

[https://jetstream.security/insights/a-policy-is-not-a-control/](https://jetstream.security/insights/a-policy-is-not-a-control/)
Aug 14, 2026

###### A Policy Is Not a Control

Approval happens in a moment, but the system keeps moving. Design control is the artifact that makes every AI change visible and every deviation provable, which…

[https://jetstream.security/insights/a-policy-is-not-a-control/](https://jetstream.security/insights/a-policy-is-not-a-control/)

[https://jetstream.security/insights/leaked-api-key-what-to-do/](https://jetstream.security/insights/leaked-api-key-what-to-do/)
Aug 11, 2026

###### Burt has a key problem. Make sure that you don't.

One leaked API key shouldn't be able to stop your business. With a virtual key, it can't.

[https://jetstream.security/insights/leaked-api-key-what-to-do/](https://jetstream.security/insights/leaked-api-key-what-to-do/)

## Top Articles

01

Press Release

### [JetStream Security Achieves FedRAMP Class D (High) Certification Through Second Front](https://jetstream.security/insights/jetstream-security-fedramp-high-certification/)

July 22, 2026

02

Press Release

### [JetStream Releases ‘AI Kill Switch’ to Shut Down Individual Agents](https://jetstream.security/insights/jetstream-ai-kill-switch-agents/)

July 27, 2026

03

Press Release

### [JetStream Announces Verified MCP Governance Layer for Enterprise AI Agents](https://jetstream.security/insights/jetstream-verified-mcp-governance-layer-for-enterprise-ai-agents/)

July 13, 2026

## Featured Experts

[https://jetstream.security/author-bio/patrick-zeller/](https://jetstream.security/author-bio/patrick-zeller/)

### [Patrick E. Zeller](https://jetstream.security/author-bio/patrick-zeller/)

General Counsel, Legal and Compliance

Patrick has spent over twenty years advising Fortune 100 companies on privacy, cybersecurity, and data protection — including...

[https://jetstream.security/author-bio/keith-weisman/](https://jetstream.security/author-bio/keith-weisman/)

### [Keith Weisman](https://jetstream.security/author-bio/keith-weisman/)

Head of Forward Deployed Engineering

Keith brings thirty years of hands-on cybersecurity and services leadership, beginning with enterprise security consulting at Accenture and...

[https://jetstream.security/author-bio/tommy-hui/](https://jetstream.security/author-bio/tommy-hui/)

### [Tommy Hui](https://jetstream.security/author-bio/tommy-hui/)

Head of Sales Engineering

Tommy Hui has spent more than a decade leading sales engineering at security companies, including six years at...
