Nelsonville City Council has sent a proposed artificial-intelligence policy back to committee rather than fast-tracking it as an emergency ordinance, and the delay exposes a more consequential issue than the council’s debate over Claude, ChatGPT, Microsoft Copilot, Grok, Gemini, or Meta AI: Ohio’s cybersecurity law requires the city to maintain a cybersecurity program, but it does not require Ohio municipalities to adopt a standalone AI policy.

The Athens County Independent reported that Ordinance 69-26 would approve Claude, ChatGPT and Microsoft Copilot for city business while forbidding xAI’s Grok, Google Gemini and Meta AI. The proposed policy also reportedly says substantive AI-generated work must be retained while chat sessions used only as a drafting aid can be treated as informal notes. Council referred the measure to its Utilities Committee after its first reading, despite language that would have declared an emergency and allowed quicker adoption.

For municipal IT staff, the committee referral is the right moment to separate a useful AI governance policy from the legal compliance work Ohio has already required. Nelsonville’s immediate statutory obligation is a documented cybersecurity program under Ohio Revised Code 9.64, enacted through House Bill 96. The city may decide that an AI policy is part of that program, but the state law does not turn an AI vendor allowlist into a cybersecurity control by itself.

Officials review an AI ordinance and municipal cybersecurity policies during a technology committee meeting.HB 96 imposes a cyber program requirement, not a city AI mandate​

Ohio House Bill 96 took effect in stages in 2025. Its cybersecurity provisions generally became effective September 30, 2025, and the Ohio Auditor of State says cities and counties had to adopt cybersecurity programs by January 1, 2026. The requirement covers every political subdivision, including municipal corporations such as Nelsonville.

The statute’s focus is specific: protecting the availability, confidentiality and integrity of local-government systems and data. The state’s guidance directs public entities toward recognized practices such as the NIST Cybersecurity Framework and CIS Controls. It also requires a local government to identify risks and critical functions, prepare detection and response procedures, and report cybersecurity or ransomware incidents to the Ohio Department of Public Safety within seven days and to the Auditor of State within 30 days.

That is a broader operational burden than simply deciding which chatbot employees may open in a browser. A sound AI policy can support the state requirement by controlling data exposure, credential use, procurement and records handling. But it cannot substitute for asset inventory, access controls, incident response, backups, phishing defenses, vendor management and recovery planning.

Nelsonville City Manager Danette Miller told council that the Public Entities Pool of Ohio had identified 16 areas for improvement and that the city had completed 12, according to the Athens County Independent. The four outstanding items were not detailed in the report. That omission matters more than the brand names in Ordinance 69-26, because the city has already passed the deadline for a compliant cybersecurity program. Without the assessment or a published policy, residents and outside IT administrators cannot tell whether the missing work involves documentation, training, incident reporting, multifactor authentication, records procedures or a more serious control gap.


An allowlist needs product tiers, contracts and identity controls​

The reported version of Ordinance 69-26 names products, but “Claude,” “ChatGPT” and “Microsoft Copilot” are not single, uniform services. They are product families with materially different data handling, administrative logging, identity integration and contractual terms.

ChatGPT’s consumer service and a managed business deployment are different choices. Microsoft Copilot can refer to the public web-connected Copilot experience, Microsoft 365 Copilot operating in a tenant with organizational controls, or separate Copilot products with different permissions and data paths. Anthropic likewise offers consumer-facing Claude services and business offerings. An ordinance that approves names without defining the authorized edition, licensing model, tenant, account type and administrator is open to being interpreted as approval for employees to use personal accounts.

That is where a policy designed to reduce risk can accidentally authorize shadow AI. An employee who believes “ChatGPT is approved” may paste a draft contract, a resident complaint, a personnel issue or a utility-account detail into a free service. A city can prohibit that conduct in later guidance, but the policy should say it clearly before deployment begins.

The Athens County Independent also reported that Nelsonville would select among approved vendors only after adopting the policy. That sequencing is understandable if the council wants general rules first. It leaves a central question unanswered, however: whether staff would be authorized to use any AI tool before the city has selected a managed vendor and executed procurement, privacy, security and records terms.

A municipal AI policy should distinguish between approval in principle and permission to process city information. In practical terms, Nelsonville should not treat an approved product name as a green light until the city can identify the exact service and its controls.

At minimum, a usable implementation policy would specify that:

  • City work may occur only through city-managed accounts, rather than personal, free or anonymously created accounts.
  • No employee may submit nonpublic, confidential, personally identifiable, financial, personnel, law-enforcement or security-related information unless the city has approved that exact data flow.
  • AI-generated material that informs an official decision, public communication, report, notice, code change or resident-facing service must receive human review by an accountable employee.
  • Administrators must be able to disable accounts, review usage where appropriate, preserve required records and respond to public-records requests or litigation holds.
  • Procurement must establish what data is retained, whether prompts or outputs may be used to train models, where information is processed, and what happens to city data when the contract ends.

The records clause cannot decide disclosure by label alone​

The proposed ordinance’s reported distinction between substantive content and chats used only for drafting is a reasonable policy goal, but the legal test under Ohio public-records law is more demanding than whether a conversation is called a “chat session” or an “informal note.”

Ohio law defines a record broadly as an item, including an electronic record, created or received by a public office that documents the office’s organization, functions, policies, decisions, procedures, operations or other activities. The law excludes personal notes maintained and accessed solely by the individual who created them. The Ohio Attorney General’s public-records guidance similarly draws the line based on whether the material documents office activity, rather than merely serving as an individual reminder.

Applied to generative AI, the practical test is the function of the prompt and output. A staffer asking an AI system for alternative headlines for a draft newsletter may be creating a transient drafting aid. A staffer using an AI chat to analyze code-enforcement cases, prepare recommendations on a zoning decision, summarize a resident’s complaint, draft a policy rationale or calculate a budget scenario may be creating material that documents public business.

The proposed rule, as described by the Athens County Independent, is therefore incomplete if it depends on an employee’s own characterization of the chat. A better rule would require staff to preserve the relevant prompt, output and human edits when AI material materially informs official work. The city also needs a retention schedule that tells employees how long to keep the materials and a legal-hold process that overrides routine deletion.

There is a second complication. Ohio’s new cybersecurity law makes certain records involving cybersecurity programs and the software, hardware, goods and services used or considered for security purposes exempt from mandatory public disclosure as security records. That exemption can protect operational security, but it is not a blanket secrecy rule for ordinary AI use. Nelsonville should define which records are security-sensitive and which remain subject to normal public-records handling rather than leaving the determination to an improvised response after a request arrives.


Banning brands does not explain the risk decision​

Council’s reported decision to bar Grok, Gemini and Meta AI while approving Claude, ChatGPT and Microsoft Copilot is a policy choice, but the public account so far does not identify the evaluation criteria. The Athens County Independent has reported the list, but no other outlet has published Nelsonville’s ordinance text or a documented vendor comparison.

That makes it impossible to assess whether the city evaluated encryption, data retention, administrative controls, audit logs, model-training terms, government contracting options, data residency, accessibility, security certifications, price, integration with .gov email, or the ability to restrict sensitive prompts. It also means the public cannot know whether a listed prohibition applies to every version of a vendor’s service or only to consumer editions.

A brand-based rule can also age badly. Vendors change product names, merge features and alter privacy settings. A policy that says “approved tools” without a recurring review process can leave staff using a service under conditions that have changed since council last considered it.

The Utilities Committee should demand a documented risk assessment before returning Ordinance 69-26 to the full council. That review does not need to become a years-long procurement exercise. It should, however, establish a repeatable approval process tied to the actual service, its configuration and the categories of city data it may handle.

Nelsonville has time to fix the policy, but not to ignore the cyber deadline​

Council President Cameron Peck’s argument that a local data-center moratorium and office use of AI address different questions is fair. Local opposition to data-center construction concerns land, water, power and environmental impacts; city staff using hosted AI services concerns information governance and operational efficiency.

But the policy debate should not become a symbolic vote for or against AI. The immediate technology question is whether Nelsonville can show auditors that its systems and information are governed under Ohio’s cybersecurity requirements, and whether AI use strengthens or weakens that posture.

The city’s next regular meeting is scheduled for September 14. Before Ordinance 69-26 returns, Nelsonville should publish the revised text, identify the four remaining cybersecurity improvements, and make clear that no city employee may use an AI service for official work outside a managed, contracted and documented deployment. That is the difference between an AI policy that looks decisive on paper and one that can withstand a public-records request, a security incident or an audit.