San Diego’s AI program is being built around a control point that many large Microsoft 365 deployments still lack: departments cannot simply acquire an AI tool or launch a use case on their own. The City of San Diego is routing AI procurement and proposed deployments through central IT governance, a cross-functional review structure, employee training, and an internal launchpad for approved tools. For a municipal workforce of roughly 13,000 people, that is the practical foundation—not the chatbot itself.

Cities Today reports that San Diego now supports Microsoft 365 Copilot, Google Gemini and Copilot Chat, has created an AI center of excellence, and has received 33 proposed use cases through its intake process. The city’s CIO, Jonathan Behnke, described the aim plainly: meet growing departmental demand while preventing rogue AI—staff-led adoption outside approved security, legal, procurement and data controls.

The city’s own records support the broad direction of travel, but they also correct part of the timeline in the Cities Today account. San Diego’s 2025 Annual Report on Internal Financial Control says the Department of IT issued initial employee guidance in 2023 and finalized its AI and generative-AI policy and adoption framework in January 2025, following work by a multi-departmental steering committee. Cities Today places completion of that framework in 2024. The most likely reading is that the framework was assembled during 2024 but formally finalized in January 2025; the city has not publicly explained that distinction.

That is more than a date quibble. It shows San Diego did not go from policy to full-scale deployment in one clean, finished sequence. The city was preparing its Microsoft 365 Copilot initiative while its governance framework was still being formalized, then used the rollout process to deepen security, training and organizational controls.

Business team reviewing a digital government security dashboard in a modern conference room.The policy came with a Microsoft 365 readiness project​

Public records reviewed by Axios show that San Diego signed a contract with Planet Technologies on November 18, 2024, for a Microsoft 365 Copilot proof of value and end-to-end enablement project. The agreement authorizes up to $300,000 in services and explicitly calls for a Microsoft 365 data-security assessment, a Copilot readiness and remediation effort, governance planning, change-management work, pilot evaluation and rollout support.

The scope is revealing. Rather than treating Copilot as a feature switch in Microsoft 365, the contract treats it as a data-governance exercise. Planet was tasked with reviewing Microsoft 365 repositories and user behavior for vulnerabilities and compliance gaps, then mapping identified risks to Microsoft Purview controls. It was also expected to produce a data-security governance plan covering AI security, data handling and integration with existing policies.

That approach addresses Copilot’s central operational reality: it works from data that a user is already authorized to access. Copilot does not need to “break into” a SharePoint site to expose a long-standing sharing mistake; broad permissions, poorly classified files and overshared collaboration spaces can become much easier for legitimate users to discover and summarize. Microsoft itself advises customers to assess oversharing and access governance before broadly enabling Copilot.

San Diego’s official internal-control report says AI technology procurement or use is subject to IT governance review and approval under the city’s technology-procurement rules. That is the enforceable mechanism behind the center of excellence rhetoric. A centralized AI team that merely publishes guidance can be bypassed; one that is tied to procurement approval has a meaningful chance of seeing the software, data and contract terms before a department puts information into a model.

The city has also updated managed-service-provider contracts to fit the new structure, according to Cities Today. That is an important, if underexplained, step. Many public agencies rely on outside administrators and integrators to run identity, cloud, endpoint and collaboration platforms. If those vendors are not bound to the same AI approval process, security obligations and escalation paths as city departments, the governance model stops at the organizational boundary where much of the technology work occurs.

Mandatory acknowledgement is not the same as mandatory AI training​

Cities Today says all city employees completed mandatory training on the AI policy before deployment began. San Diego’s annual report describes something narrower: employees were required to acknowledge the policy, while the Department of IT provided a recommended Introduction to Artificial Intelligence course covering productivity, risks and responsible adoption.

The public record therefore confirms a required policy acknowledgement, but it does not confirm that every employee completed substantive AI training. Nor has the city published a training-completion rate, assessment results, number of Copilot licensees, the departments initially enrolled, or the exact safeguards configured in its Microsoft 365 tenant.

Those omissions matter when a city cites adoption outcomes. Behnke told Cities Today that a post-deployment survey estimated annual savings of 47,500 employee hours, valued at $3.8 million. That works out to roughly $80 per hour, suggesting the estimate uses a fully loaded labor-cost assumption rather than salary alone. It is a useful directional measure of reported productivity, but it is not an audited cash saving: saved time only becomes budget relief if the city actually eliminates work, avoids hiring, reduces contractor spending, or redeploys staff from lower-value tasks to work that otherwise would not be completed.

The city also has not disclosed the recurring licensing spend needed to evaluate that claim. The $300,000 Planet contract covers enablement services and is capped as such; it is not a published total-cost figure for citywide Copilot use. A financial case that compares estimated time savings with only consulting costs would be incomplete. It needs the license tier, active-seat count, implementation and support labor, data-governance remediation costs, and any usage-based charges for tools outside Microsoft’s per-user licensing model.

Behnke’s warning to Cities Today about vendors shifting toward consumption pricing is therefore well founded. A city can forecast named-user licenses. Forecasting agent calls, model tokens, document processing, AI search queries or workflow transactions is much harder, particularly when a successful pilot encourages departments to automate more work. The center of excellence will need authority over budgets as well as security reviews if it is to prevent decentralized AI experiments from producing decentralized bills.

San Diego’s first serious workflow is a compliance problem​

San Diego’s work with Google on an AI-assisted procurement workflow is a more consequential test than drafting emails or generating slide decks. The system is being designed around California Assembly Bill 339, which took effect on January 1, 2026, and added Government Code Section 3504.1.

The law requires local public agencies to give recognized employee organizations at least 45 days’ written notice before issuing a request for proposals or request for quotes—or renewing or extending a contract—for services within the scope of represented job classifications. The notice must state the expected contract duration, scope of work, anticipated cost, draft solicitation or equivalent information, and why the agency considers the contract necessary. There are limited exceptions, including emergencies and certain construction-related work.

Cities Today reports that San Diego Human Resources expects more than 12,000 submissions this year, and that the proposed workflow would help departments prepare statements of work, identify compliance problems and determine which job classifications may be affected. A conversational AI agent would analyze submissions, while human staff would make the final review and send notices.

The key legal constraint is timing. AB 339 requires notice before the city issues the solicitation or extends the contract. An AI workflow cannot be allowed to operate as a post-submission checker that discovers represented work after a procurement has already advanced. The useful design is one that flags potentially affected classifications at intake, forces a human reviewer to resolve uncertain matches, preserves an auditable record of the decision, and blocks the procurement clock from moving until the notice requirement is satisfied.

That workflow could produce far more value than generic copilots because it attacks a high-volume, deadline-driven process with explicit statutory fields and human accountability. It is also safer to measure. The city can track how many submissions were correctly routed, how much rework was avoided, whether deadlines were met, whether notices contained the required information, and how often staff overruled the model. Those are operational metrics, not self-reported impressions of time saved.

The public-facing line remains deliberately narrow​

Axios reported in April that city staff were using Copilot and Gemini for routine internal work such as summarizing email threads, preparing council-presentation slides and assigning follow-up tasks from meetings. It also reported that San Diego was considering AI for meeting transcription and analysis, public-records processing and police non-emergency calls.

Those should still be treated as prospective applications rather than deployed city services. Axios found that the city’s only public-facing AI at that point was My eCISO, a cybersecurity assessment chatbot for small businesses. The City of San Diego describes My eCISO as a conversational tool based on Anthropic’s Claude 3 Haiku model that generates a cybersecurity report card aligned with the NIST framework.

Keeping that boundary matters. Internal productivity tools generally create risks around employee data, access permissions and work quality. Public-facing systems add resident privacy, accessibility, due process, disclosure, records retention and the danger that a resident will mistake generated output for an official determination. San Diego’s insistence on human review is a necessary baseline, but the city has not publicly laid out model-specific audit standards, incident reporting, public disclosure rules or retention practices for each type of deployment.

San Diego will host the City Innovation Network’s North America leadership forum on September 9–10, where governance, internal efficiency and public-facing AI are expected to be central topics. The city’s real evidence will not be the 33 use cases in its queue or a survey-derived dollar figure. It will be whether the procurement workflow can handle 12,000 submissions without missed labor notices, whether the city can publish its AI costs and controls, and whether staff can show that centralized review catches the data, security and legal problems that departmental experimentation would have missed.