St. Petersburg has already authorized city employees to use Microsoft Copilot, ChatGPT and Gemini under a new administrative policy that took effect August 3, while City Council begins considering a broader AI strategy and the Welch administration asks residents how the technology should be adopted. The sequence matters: the public consultation is beginning after a baseline permission structure is already in force, but the city’s public-facing AI page does not link to that policy, identify approved product editions, disclose spending, or explain how AI conversations will be retained for public-records requests. The St. Pete Catalyst, which obtained the internal policy document, reported that Administrative Policy 071200 permits approved generative-AI tools for routine drafting, summaries of public information, research and brainstorming. It bars employees from placing confidential data, personally identifiable information, criminal-justice records and other protected information into AI systems without written approval, and prohibits AI from making legal, disciplinary, procurement or public-safety decisions.
On Thursday, August 7, the council unanimously referred a proposed citywide AI strategy to its Public Services and Infrastructure Committee at Council Member Mike Harting’s request. The referral is an inquiry, not a vote to buy a platform or deploy automated decision-making. But it puts the council in the position of reviewing guardrails and cost after the administration has given employees a defined set of permitted uses.

A government hearing combines courthouse proceedings with AI-powered document and cybersecurity displays.A public rollout that begins after employee authorization​

The city’s official AI public-input page says the administration is launching a 30-day comment period to guide AI adoption in municipal operations. It also schedules an open house for August 25, from 5:30 p.m. to 7:30 p.m., at the President Barack Obama Main Library. Residents are invited to discuss appropriate and responsible use with city staff.
That invitation is genuine public engagement, but the public documentation is materially thinner than the employee policy described by the Catalyst. The official city page does not mention Administrative Policy 071200, offer a copy of it, name Microsoft Copilot, ChatGPT or Gemini, or say whether the city has bought enterprise licenses for any of them. It also gives no implementation timetable, departmental pilot list, contract information or cost estimate.
That omission turns an otherwise routine policy discussion into the important governance question. Residents are being asked to help shape the city’s future use of AI, but cannot readily assess the operating rules that reportedly took effect four days before the council’s referral and more than two weeks before the open house.
The city may yet publish those details or provide them through its committee process. As of Friday, however, the public consultation is framed around broad principles rather than the concrete technical decisions that determine whether an AI policy can actually be enforced: account type, identity controls, logging, retention, access to city data, vendor terms and funding.

“Copilot,” “ChatGPT” and “Gemini” are not sufficient technical specifications​

The policy’s reported naming of Microsoft Copilot, ChatGPT and Gemini is useful as a starting point, but it is not enough for a municipal security or records-management program. Each name covers consumer, business and enterprise products with substantially different privacy, identity, audit and retention behavior.
Microsoft says Microsoft 365 Copilot Chat used under an Entra work account can provide enterprise data protection, with prompts and responses logged for audit and eDiscovery under Microsoft 365 controls. Microsoft also says the precise controls vary with the underlying subscription and configuration. That distinction is central in a city environment: a staff member using a managed Microsoft 365 tenant is working inside a different control plane from a person using a personal account in a browser.
OpenAI similarly says ChatGPT Business, Enterprise, Education and API customers are not opted into model training by default, while individual ChatGPT workspaces have different default data-sharing settings. Google provides administrative controls over whether Gemini can access Workspace content, including Drive and Gmail data. In practical terms, approving a product name is not the same as approving a specific managed service, tenant configuration and identity boundary.
The Catalyst reports that St. Petersburg’s policy requires use of city-approved platforms, which could mean the administration has already made those distinctions internally. The public record available so far does not show which editions are approved, whether employees must use city single sign-on, whether personal accounts are prohibited, or whether web-grounding and third-party connectors are enabled.
For Windows administrators, this is the difference between a policy that can be administered through Entra ID, Microsoft Purview, conditional access and audit logs, and a policy that rests mostly on employees remembering what not to paste into a chat window. The latter may work for low-risk drafting guidance; it is a poor fit for a municipal government handling records, permits, constituent communications and protected information.

The public-records problem is more specific than “save the output”​

Florida’s public-records law is deliberately broad: records made or received in connection with official business can be public records regardless of their format or transmission method. The Florida Department of State’s records-management guidance likewise bases retention on a record’s content, nature and purpose—not simply whether it started as an email, document or chat.
According to the Catalyst, St. Petersburg’s new policy tells employees to preserve qualifying AI-generated records. That is a sensible principle, but the operative details determine whether it works. A city employee could use a prompt to summarize a public-records request, draft a permit explanation, organize inspection notes or research a policy question. The output may be copied into an email or Word document, but the prompt, source material, chat history and generated draft can each be relevant to reconstructing how an official decision or communication was made.
Microsoft’s own documentation shows the possible upside of an enterprise deployment: Copilot Chat prompts and responses can be logged and made available for audit, eDiscovery and retention processes. But that only helps if the city deploys the managed product, configures the controls, establishes retention rules and trains employees to use it consistently.
The city has not publicly explained how it will handle that workflow. It has not said whether AI prompts count as records by default, when an employee must retain a complete chat rather than only the final document, whether supervisors can audit usage, or how the city will search vendor-hosted AI material when it receives a public-records request. Those are not abstract compliance issues. They are the mechanisms that decide whether a city can substantiate its own work after AI enters the drafting process.
The policy’s reported ban on uploading confidential information, personally identifiable information and criminal-justice data reduces the most obvious disclosure risks. Its prohibition on AI making procurement, legal, disciplinary or public-safety decisions also draws a needed line around high-consequence uses. Yet an AI tool does not need to make the final decision to influence one. A flawed summary, invented citation, incomplete technical explanation or misleading records search can shape the human review that follows.

Human review is necessary, but it is not an implementation plan​

Council Member Richie Floyd raised the sharpest objection at Thursday’s meeting. The Catalyst reported that Floyd called the policy “far too permissive,” questioned whether the city is already paying for enterprise licenses and argued that requiring employee review may not be enough when technical errors are difficult to spot.
His cost point deserves more attention than it has received. The council has authorized study of a citywide strategy without a stated budget, vendor inventory or license count. A city can begin with AI features already included in existing Microsoft 365 or Google Workspace agreements, but meaningful governance—retention, audit, data-loss prevention, role-based access, legal hold support, training and help-desk capacity—can require additional licensing and staff work. The city has not publicly said which of those it has, which it needs, or what it will cost.
Floyd’s point about review is also operationally sound. “Human in the loop” often becomes a slogan unless the organization defines what the reviewer must check, when outside sources must be verified, which tasks need a second reviewer and how the review is documented. The policy reportedly requires employees to check AI material for accuracy and intellectual-property concerns, and to have city employees review public-facing content before release. Those are appropriate minimums. They do not establish a standard for validating a technical permit explanation, a public-records summary or a document produced from incomplete source material.
Council Member Copley Gerdes sees a potential use in permitting and public-records work and told the council he has been working with city staff and an outside consultant. He expects to present to the committee this fall. Those are exactly the areas where a controlled, auditable pilot could produce value—but they are also the areas where records retention, source verification and permissions must be settled before scaling.

The committee now has a defined job​

St. Petersburg’s immediate AI policy appears designed to let employees use generative tools for low-risk productivity work while preventing direct automation of consequential decisions. That is a defensible first boundary. The council’s committee review should now determine whether the administrative controls behind that boundary are real.
The committee should insist on a public accounting of approved AI versions and license tiers, managed-account requirements, vendor agreements, data-use terms, prompt and output retention, audit capabilities, staff training, incident reporting and the cost of any new enterprise tooling. It should also require a clear rule for when an AI interaction becomes a city record and how that record can be produced without relying on an employee’s memory or a vendor’s default chat history.
The August 25 open house can inform the city’s values and priorities. The more immediate test is whether St. Petersburg publishes the policy it has reportedly put into effect and turns its broad restrictions into controls that IT, records managers and department heads can verify.

References​

  1. Primary source: St Pete Catalyst
    Published: August 7, 2026 at 4:41 PM UTC
  2. Related coverage: learn.microsoft.com
  3. Related coverage: learn.microsoft.com