From a hundred-person agency to a one-person consultancy, the answer is yes. The difference is what “policy" means.
This article is part of an ongoing column on AI and planning by urban planning professor and AI expert, Tom Sanchez. Learn more about Tom and read more installments of his column.
A few months ago, as I started thinking about setting up my own consulting practice, I came across a challenging question. I use AI tools every day in my work, and I spend a good deal of my time thinking about how planning agencies can get ready to use them. So, for a one-person endeavor, did I need my own AI policy?
It felt like overkill to write a governance document for a company of one. And yet the longer I thought about it, the more I realized I had already made a dozen or so quiet decisions about how I use these tools. I just hadn’t documented any of them. That gap, between the rules we follow and the rules we have actually thought through, is the focus of this month's column.
The question I want to work through is easy to ask and harder to answer: does everyone need an AI policy? Most planning organizations I encounter are dealing with this question, whether they know it or not. Some have “finished” governance documents. Many have nothing at all. And a growing number are one- or two-person teams doing serious professional work with tools that did not exist even two or three years ago.
Everyone already has a policy (they may just not know it)
Here is the challenging part. If people in your organization are using AI, and they almost certainly are, then you already have an AI policy. It is just an implicit one. It exists in whatever each person decided on their own about what to paste into a chatbot, what to trust, and whether to tell anyone they used it.
Some recent evidence makes this more tangible. In early 2026, market signals showed that AI governance and policy development had become a very active type of local government AI work, ahead of chatbots and productivity tools. The reason is fairly easy to understand. Standalone tools like ChatGPT and Claude now account for a large share of AI use inside public agencies, and many organizations are buying enterprise licenses first and building the rules around them second.

When Boston surveyed its employees in spring 2025 about how they were using generative AI, more than a fifth responded, and those responses helped inform the Gen AI policy that followed.
So the real question is not whether you have a policy. It is whether the one you have is the one you would choose on purpose.
What a "policy" actually is
Part of what makes this question feel weighty is the word itself. "Policy" implies a long document, legal review, a committee, etc. For a large agency, that may be true, but not for a one- or two-person firm.
It helps to separate the document from the function. A policy, at its core, is a set of decisions made ahead of time so that you are not improvising in the moment. Who can use these tools? For what kinds of work? What has to be checked, and by whom? What gets disclosed, and to whom? Who is responsible when something goes wrong? Those questions do not change based on the size of your organization. What changes is how formally you need to answer them.
This is really the main point of the column. The question is not "does everyone need the same policy?" It is "has everyone actually made a decision?" Big organizations often make decisions through documents. Small ones can decide through workplace habits. The trap is the same either way: gradually moving into some default position nobody ever really thought about.
The big organization version
For a large planning department or a city, the case for a written policy is straightforward. When dozens or hundreds of people use these tools, informal norms do not scale or provide adequate direction, and the public accountability element is much larger. Residents are subject to the decisions agencies make, and it is reasonable for them to know how those decisions were reached.
Boston is a very good example here, mostly because they started early and kept improving over time. Their 2023 interim guidelines were designed to encourage people to experiment responsibly rather than lock everything down, and they leaned on an idea worth noting: the technology enables your work, but it doesn't take accountability off your hands. Since then, the city has moved from interim guidelines to an actual policy. Staff have to complete training before they can use the approved tools. The city keeps track of which ones are sanctioned, and if you've got a new use case, there's a clear place to bring it for review. This is effective governance that doesn't ban the technology; it provides guidance.
Here's another very good example. Back in 2023, San Jose started the GovAI Coalition, basically a bunch of public agencies sharing what they'd worked out about responsible AI so nobody had to start from scratch. It took off. What began with about fifty agencies at that first meeting has grown to more than 3,000 members across roughly 900 agencies. They now put out free, editable templates you can just pick up and use: an AI policy, an incident response plan, vendor agreement language, and use case worksheets, all built to line up with NIST's national framework. San Jose's CIO, Khaled Tawfik, explained: "AI is moving fast, so it's really hard for San Jose to tackle this challenge alone." That's the central point of the coalition. A small city with a skeleton crew shouldn't have to invent an AI policy on its own.
If you're running a large or even a midsize agency, a lot of the policy writing is already done. You'll be adapting, and not authoring.
The small organization version
Not every organization needs Boston's depth and scale. A small-town planning office of four people does not need a governance committee. It may need a page of essential guidelines.
Some of the most useful AI policies I have read are also some of the shortest. Several smaller cities have adopted brief generative AI use policies that fit on a few pages and cover the essentials: protect sensitive and personal data, respect public records obligations, do not discriminate, and check outputs for accuracy before relying on them. Kirkland and Puyallup, Washington, are clear examples, and Fort Worth, Texas, takes a similar short, operational approach. Other cities go broader, with Lebanon, New Hampshire, and Tempe, Arizona, writing principles-based frameworks built around values and governance rather than a short checklist. Both models are good approaches. The point is that a small agency does not need a hundred pages to get started. It needs a clear policy that answers the core questions, and it can grow that policy as the work grows.
Function matters more than size
Here is one aspect that often gets missed. The right amount of governance depends less on how big you are than on what you are doing with AI.
A planner using a chatbot to clean up the writing of an internal memo carries very little risk. The same planner using AI to summarize a thousand public comments, or to help triage code enforcement, or to shape a recommendation about who gets what, is very different territory. The consequences, not the headcount, should determine the level of care. A three-person firm building a resident-facing tool needs more discipline around verification and disclosure than a large department that uses AI only for back-office drafting.
So when you’re thinking about the need for a policy, ask about it in terms of the work, not just the organization. What is the most consequential thing anyone here does with these tools?
The sole proprietor, and the heart of the question
Which brings me back to where I started. What about the consultant of one? The independent planner working from a home office, with no committee, no IT department, and no one to write a policy for?
This is where the "does everyone need a policy" question comes into play, and where I think the answer is still yes, just in a different shape. If you are an AICP-certified planner, your professional obligations do not shrink because your firm is small. The Code of Ethics applies to you, not to your letterhead. Its commitments to honesty, to serving the public interest, to competence, and to disclosure apply whether you are one of a thousand or entirely on your own. A one-person shop does not get a lighter ethical load. If anything, you carry the whole thing yourself, because there is no second set of eyes unless you build one in.
In practice, that means a solo practitioner's "policy" is a set of personal guidelines. What client data will you never paste into a public tool? When will you tell a client that AI was part of how you produced their work? What is your own verification step before something goes out under your name? These are not small questions. Disclosure norms are already forming around us. Some states have begun requiring that people be told when they are interacting with generative AI rather than a human. Utah was the first to require disclosure of generative AI in commercial interactions as far back as 2024, and professional expectations are drifting in the same direction even where the law is still emerging. Getting ahead of that is not only prudent but also part of the honesty we already owe our stakeholders.
For me, writing my own rules down helps clarify. It turned a set of half-formed practices into something I could refer to and describe to someone else easily. That is the value of a policy at any scale.
So, does everyone need a policy?
Yes. But not the same one, and not the same size.
A city needs governance with clear roles, training, and public disclosure. A small agency may need a page per person. A consultant of one needs a set of personal rules grounded in the professional obligations they already carry. What unites them is not the format. It is the willingness to answer a few questions on purpose rather than by accident: who uses these tools, for what, with what verification, with what disclosure, and with whom the responsibility rests.
Some AI policies to explore:
City of Fort Worth. 2023. "Generative Artificial Intelligence (AI) Policy." Human Resources Department. Effective December 18, 2023.
City of Kirkland. 2024. "Generative Artificial Intelligence Use Policy." Administrative Policy Manual, Policy 7-13. Effective July 16, 2024.
City of Lebanon. 2023. "ADM-143 Use of Artificial Intelligence." Adopted December 19, 2023. Updated July 16, 2025.
City of Puyallup. 2024. "General Artificial Intelligence Use Policy."
City of Tempe. 2023. "Ethical Artificial Intelligence (AI) Policy."
A call to action
If you have not written anything down yet, start small— just one page, or even one paragraph. Name what you will not do, what you will always check, and what you will disclose. You can borrow from sources such as the GovAI Coalition, since their templates are public, and many cities have posted their own policies for others to adapt. You don’t have to be first, and you don’t necessarily have to be comprehensive. The main point is to get started.
As always, I would love to hear how you are handling this in your own practice, including the plans your agency has adopted and any errors you have caught. You can comment in the section below and, if you have a question you would like answered, please email [email protected] with "AI question for Tom Sanchez" in the subject line. Let's learn together how to put AI to work in ways that truly serve our communities. You can also check out my new 6-week Planetizen class, "Preparing Your Planning Agency for AI." The next cohort begins October 15.
Planetizen Federal Action Tracker
A weekly monitor of how Trump’s orders and actions are impacting planners and planning in America.
‘Going backwards:’ Baltimore mayor, students rally against state's transit funding plan
Maryland's proposed six-year plan provides no funding for Baltimore’s BMORE bus program and reduces its road maintenance funding.
Detroit to transform waterfront with $2.2 billion investment
Developers will convert about 18 acres of unused parking lot space into civic spaces.
Less housing, wasted money: study reveals impact of city parking mandates
The study found that 71% of carless households in the United States pay for a parking space they don’t use.
Minnesota seeks to replace fraud-ridden Housing Stabilization Services with new program
Federal prosecutors have charged over a dozen people in fraud cases involving at least $26 million.
A multi-billion dollar problem is brewing under Oakland’s streets
Oakland’s stormwater drainage systems are in desperate need of upgrades and repairs. The El Niño will only further strain the city’s infrastructure.
FREE Course: Walkable City 1: Why Walkability?
After describing his path towards focusing on walkability as the essence of good planning, Jeff Speck marches through his five principal reasons for making more walkable places.
Reinventing Malls: Planning Alchemy—Turning Gray Fields Into Gold
The course focuses on the opportunities and imperatives that shape reinvention of mall sites.
One Hundred Miles
County of Mendocino
planning NEXT
The Architects Foundation
University of Cincinnati Online
Montrose County
Northern Illinois Transit Authority (NITA)
The Pocatello Development Authority