What Detroit decided
BridgeDetroit's Jasmine Snow reviewed the policy and interviewed Art Thompson, the chief information officer of the city's Department of Innovation and Technology (DoIT). Thompson said the rules took effect over the summer. They cover every city department and also bind third-party vendors, interns, consultants and volunteers. They extend to AI systems that don't exist yet.
The main points:
- One approved LLM. BridgeDetroit cites an internal memo from September 2026. It says Microsoft Copilot Chat is the only approved text-based model. ChatGPT, Claude, Gemini, Alexa and Siri have not been approved.
- No synthetic media of real events. Staff can't use AI to create images or media depicting real events.
- No AI judging of people or programs. Employee reviews are the example given.
- Human review for sensitive data. The policy generally prohibits AI systems that handle sensitive or personally identifying information without human review.
- Nothing non-public goes in. Employees, consultants and volunteers shouldn't give AI data that isn't safe for public disclosure.
- Disclosure and fact-checking. Users must say when they use AI. They must check the output before relying on it.
Thompson put the data stance this way: "Detroit's data is Detroit's data." He added that the city doesn't farm it out, share it or give it out.
Why Copilot Chat is a logical pick
The city hasn't published its reasoning for choosing Copilot Chat, so what follows is my analysis, not Detroit's stated rationale. For a Microsoft 365 shop, the appeal is easy to see.
Microsoft documents that prompts and responses aren't used to train the underlying foundation models. For users signed in with a Microsoft Entra account, Copilot Chat offers enterprise data protection (EDP). Microsoft says EDP is available in Copilot Chat at no extra cost. A city already running Microsoft 365 can therefore add a governed chat tool without a separate procurement.
Copilot Chat also respects existing permissions. Microsoft's overview says it continues to respect existing Microsoft 365 permissions and doesn't expose content that users can't already access. For the license distinction, Microsoft's documentation says the baseline Copilot Chat primarily uses web data and has limited use of organizational content. Its FAQ says that without a Microsoft 365 Copilot license, Copilot Chat can't access the user's shared enterprise data, though users can choose to upload files directly.
That has a practical consequence. The policy's data-handling rules still matter even with a protected tool. An employee who uploads a file or pastes in a resident's record has made a choice the technology can't make for them.
A tool allow-list isn't a data policy
Copilot Chat's protections apply when staff sign in with their work account. Microsoft says it uses your work or school account for authentication and automatically provides enterprise data protection in that case. If staff open a consumer chatbot in another tab, the city's contracts and controls don't apply. That is presumably why Detroit's policy pairs a named tool with rules about what may be entered.
The BridgeDetroit account doesn't describe technical blocking of other AI services. It says enforcement runs through the city employee handbook. Violations can bring discipline up to and including discharge, and illegal activity can bring legal action.
Admins drafting something similar should consider:
- Name the sanctioned tools and the sign-in method. "Copilot Chat" is clearer than "approved AI."
- Define data tiers. Detroit's test is whether information is safe for public release.
- Require disclosure. Disclosure is how reviewers know which work needs extra scrutiny.
- Create an intake path. Detroit lets employees request review of new AI tools or AI-inclusive upgrades. Several DoIT staff, Thompson among them, review those requests.
- Check permissions hygiene. Oversharing in SharePoint and similar repositories becomes more visible once an AI assistant can surface what users can already reach. This is general industry guidance, not something Detroit has reported doing.
Governance context
The policy lists nine values: human-centered design, security and safety, privacy, transparency, equity, accountability, effectiveness, workforce empowerment, and compliance with applicable laws. The compliance value specifically names the city's Community Input Over Government Surveillance ordinance. A dedicated "AI Risks" section covers data breach risk and adverse outcomes tied to biased or false output.
The drafting began in April 2023. Thompson said it drew in the Law Department, DoIT, Human Resources, the City Council's Legislative Policy Division, Procurement, and the police and fire departments. He said a draft was in effect near the end of former mayor Mike Duggan's term. Duggan withheld final approval so the incoming administration could take the lead. Detroit also joined the GovAI Coalition, which helped inform the policy.
BridgeDetroit also notes an earlier experiment. "Emily" was a Duggan-era AI pilot that answered resident calls and took messages for the Department of Neighborhoods. It has since ended. Thompson and Department of Neighborhoods director Bryan Peckinpaugh both said it performed well.
Public input
Residents can comment on the policy through several channels:
- City Council public comment, in person or virtually
- Their council members' offices
- District meetings hosted by council members
- Department of Neighborhoods district managers, whom Thompson said have a direct line to his office
The reporting doesn't identify a dedicated public-comment portal or a deadline.
Limits of what's known
Both reports rely on the policy text and Thompson's account. Neither describes how compliance is audited or logged. Neither says which Copilot Chat licensing or admin settings the city uses. A single approved tool also makes the city dependent on one vendor's roadmap and terms. Microsoft's documentation has already shifted: Copilot Chat was renamed and Microsoft says there are no changes to data protection. The city's review process for upgrades is the sensible hedge.
Bottom line
Detroit's approach is conservative and easy to explain. It has one approved chat model, strict data limits, mandatory disclosure and human verification. It also has a path to change as AI tools change. For Windows and Microsoft 365 administrators, the lesson is that choosing Copilot Chat doesn't replace governance. Permissions, labeling, user training and clear rules about what may be typed into a prompt still decide how safe the tool is.
References
- Detroit Sets AI Policy for City Workers and Invites Public Input - 94.7 WCSX 94.7 WCSX · 2026-10-07T17:48:28+00:00
- How is Detroit using AI? We dug into the city’s policy - BridgeDetroit bridgedetroit.com
- Data protection when using Microsoft Copilot Chat for work or school support.microsoft.com