A public-sector AI policy can be thoughtful and still fail in practice. The test is not whether the policy names fairness, transparency and accountability. The test is whether the workflow can enforce them when a real case arrives.
The policy is not the control
AWS's public-sector agentic AI governance framework focuses on identity, data protection, audit logging, model controls, agency boundaries and orchestration. That list is technical, but the underlying idea is institutional: governance has to be enforceable.
A public body cannot rely on users remembering policy during a busy service queue. The system must know who is acting, what they are allowed to do, what data they can see, what needs approval and what evidence must be logged.
This is especially important when AI moves from advice to action.
Workflow controls answer the questions auditors ask
Who accessed the record? Which source did the AI use? Was sensitive data exposed? Who approved the output? Was the citizen-facing response reviewed? What changed after correction?
Those questions cannot be answered by model documentation alone. They require workflow-level traces.
SBL's civic technology work uses this pattern across legislative, municipal and public-record systems. The workflow has to preserve institutional accountability.
Human oversight should be specific
Public-sector AI guidance often says "keep a human in the loop". That phrase is too broad to be useful unless the loop is defined.
Which human? At what point? With what evidence? Can they override? Is override logged? Does the system learn from the correction? Are some cases blocked from automation entirely?
A useful governance design answers those questions before rollout.
Build governance into the service path
Public-sector AI should be designed around the service path: intake, identity, data access, analysis, review, decision, communication, appeal and record retention.
Every step has different governance needs. A summary for internal staff is not the same as a public notice. A draft response is not the same as an official decision.
The cost of the wrong public record is higher than the cost of the system that prevents it. That is the standard civic AI should meet.
Questions teams ask before they start
What is public-sector AI governance?
It is the set of policies, workflow controls and evidence requirements that make AI use accountable in public institutions.
Why are workflow controls important?
They enforce who can access data, what the AI can do, when approval is needed and what evidence is stored.
What does human oversight mean in practice?
It means named roles, defined review points, evidence access, override rights and logged decisions.
