Right-Sized Public Tech flagship guide

AI procurement scoping guide for state and local government

A source-linked guide and printable workbook for deciding whether AI belongs in the solution, then defining a responsible, testable procurement.

Use operational facts, not protected or procurement-sensitive records.

Do not enter confidential procurement, resident, student, personnel, vendor, security, incident, or controlled information. Workbook entries stay in this browser unless you print or save them on this device.

Version: 1.0, published August 26, 2026

Source review: Complete as of August 26, 2026

External review: Not claimed

Start before the solicitation

Scope the public decision, not the AI product.

AI procurement scoping starts with an operational outcome, affected people, available evidence, and a named decision owner. It should not start with a model, chatbot, vendor, or feature list.

Gate 1

Problem fit

Confirm that AI is more suitable than process repair, configuration, rules-based automation, or conventional software.

Gate 2

Responsible boundary

Name the people, data, authority, review, appeal, security, and accessibility conditions.

Gate 3

Testable acquisition

Define representative tests, acceptance measures, cost visibility, and a reversible pilot.

Gate 4

Operational control

Preserve monitoring, data and intellectual-property rights, portability, shutdown, and lessons learned.

How to use this pack

Bring the people who own the outcome and the consequences.

At minimum, include the operational owner, procurement, IT, security, privacy, legal, finance, data, accessibility, and evaluation perspectives that apply. A smaller organization may assign several roles to one person, but it should still address each responsibility.

This guide does not:

  • Determine purchasing authority or legal compliance.
  • Replace local policy, counsel, security review, or public participation.
  • Recommend a vendor or guarantee that AI is appropriate.

Working procurement brief

Build the minimum defensible record.

Complete what is known. Mark assumptions, disagreements, and unresolved questions instead of manufacturing certainty.

Workbook started. Nothing has been submitted.

Context

Working record

1. Problem fit

Describe the job before choosing the technology.

Alternatives examined

2. Impact and authority

Name who is affected and where human authority remains.

3. Data and rights

Use only data the organization may use for this purpose.

4. Cross-functional team

Assign each decision to a responsible role.

Cover operational ownership, procurement, IT architecture, cybersecurity, privacy, legal, finance, data, accessibility, records, evaluation, communications, and workforce effects as applicable.

5. Market research and competition

Ask questions that preserve choice and expose the whole cost.

Capability

What can be demonstrated with representative conditions, failure cases, and current limitations?

Pricing

What drives implementation, usage, model, integration, monitoring, support, and exit costs?

Control

What data, prompts, models, outputs, logs, and artifacts can the organization access, export, or delete?

Change

How are model, feature, subcontractor, hosting, policy, and price changes disclosed and tested?

6. Bounded test

Design a reversible test that resolves a material uncertainty.

7. Evaluation and acceptance

Test performance where failure matters.

Use representative tasks and affected groups. Include incorrect outputs, missed cases, inconsistent behavior, unsupported claims, security and privacy failures, accessibility barriers, human-review burden, response time, and cost.

8. Contract and exit

Keep the operating terms aligned with the test.

Ask the responsible procurement and legal officials to address requirements, testing, acceptance, security, privacy, accessibility, records, pricing, intellectual property, government data, training use, subcontractors, changes, monitoring, incidents, audit evidence, portability, termination, transition, and deletion.

9. Decision and learning record

Record why the organization will proceed, pause, change course, or stop.

Primary sources

What this guide relies on.

Factual resources last verified August 26, 2026. Federal requirements do not automatically apply to state or local organizations. NIST materials are voluntary unless adopted or otherwise made applicable.

Artificial Intelligence Risk Management Framework

National Institute of Standards and Technology. AI RMF 1.0 with current NIST resource updates. Last verified August 26, 2026.

Voluntary risk management across Govern, Map, Measure, and Manage, including trustworthiness considerations throughout the AI life cycle.

AI Guide for Government

U.S. General Services Administration. Living public guide. Last verified August 26, 2026.

Problem selection, organizational readiness, integrated teams, buy-versus-build decisions, testing, data rights, sustainable capability, and lessons learned.

Digital Services Playbook

U.S. DOGE Service. Current public edition. Last verified August 26, 2026.

User needs, iterative delivery, accountable ownership, security and privacy, and decision-linked measurement.

Commercial disclosure

No related JSTK product is presented in this guide.

JS Technology Solutions, Inc. publishes Right-Sized Public Tech and provides technology services. This guide does not recommend a product, vendor, purchasing route, or specific contract language.