Situation report active Rev. 2026.4 119 reports 237 source records updated
Real Life After AGI The human survival briefing

Institutional AI-preparedness playbooks

What NIST, federal agencies, and cities like Seattle have actually published to help schools, hospitals, governments, and small businesses prepare for AI.

Written by
Dwight Ringdahl
Status
Reviewed
Revised
Sources
20 cited
Reading
7 min

A shared floor: NIST’s Generative AI Profile

Most sector-specific AI guidance did not start from a blank page. It started from the same federal document: NIST AI 600-1, the Generative AI Profile companion to the base AI Risk Management Framework, published July 26, 2024. AI 600-1 doesn’t replace the base framework’s four functions — Govern, Map, Measure, Manage — it layers twelve generative-AI-specific risk categories onto them: confabulation, data privacy, information integrity, harmful bias and homogenization, value-chain and component integration, and others, each mapped to more than 200 suggested actions across Section 3 of the document.

The framework is voluntary. NIST has no enforcement authority, and a school district’s or hospital’s claim that it “follows NIST” is not evidence that any particular control actually works — the same caution this manual raises about corporate boards citing the base framework in shareholder and corporate governance advocacy. What NIST supplies instead is common vocabulary. When a state education agency, a health regulator, and a city IT department each publish their own AI guidance independently, the fact that most organize around something resembling Govern/Map/Measure/Manage is not coincidence — it is the closest thing to a shared national reference architecture that currently exists, credited or not. For where binding law rather than voluntary framework is doing the work, see legal and regulatory leverage and the 2026 AI law and enforcement landscape.

Schools: guidance is real, mandates are catching up

Federal guidance for K-12 arrived through the U.S. Department of Education’s Office of Educational Technology, which released Empowering Education Leaders: A Toolkit for Safe, Ethical, and Equitable AI Integration on October 24, 2024 — a 74-page document built from listening sessions with 90 educators across 12 roundtables held between December 2023 and March 2024, issued under the Biden administration’s October 2023 AI executive order. A companion resource from ED’s Office for Civil Rights, “Avoiding the Discriminatory Use of Artificial Intelligence,” addresses the civil-rights side. The toolkit followed an earlier, less operational May 2023 ED report whose first recommendation was simply to keep humans in the loop. After the 2025 change in administration, President Trump signed a separate executive order, “Advancing Artificial Intelligence Education for American Youth,” on April 23, 2025, creating a White House Task Force on AI Education and a Presidential AI Challenge.

States moved faster and more unevenly than Washington. By mid-2026, 37 states plus Puerto Rico had issued their own K-12 AI guidance, according to trackers maintained by Ballotpedia and K-12 Dive. Most of that guidance is advisory. Louisiana is representative: its education department published Artificial Intelligence in Louisiana Schools: Guidance for K-12 Schools on August 28, 2024, built by a dedicated LDOE AI Task Force, covering implementation strategy, safeguards, and technical considerations — but adoption by any given district remains optional.

Tennessee took the opposite approach. Public Chapter 550, which took effect March 11, 2024, is a legal mandate: every local board of education and public charter school governing body must adopt its own AI-use policy, not merely consult voluntary guidance. The Tennessee School Boards Association responded with Model Policy 4.214, dated June 26, 2024, covering acceptable use, academic integrity, data privacy, and discipline; most districts adopted it close to verbatim rather than drafting from scratch. California is still mid-process: SB 1288 (2024) created a state AI working group housed at the California Department of Education, with statutory deadlines of January 1, 2026 for LEA guidance and July 1, 2026 for a model policy. Both deadlines have now passed as of this writing; this manual has not independently confirmed whether CDE published on schedule, so check that page directly rather than assume.

Healthcare: transparency rules layered on top of device law

Healthcare AI governance runs on two separate tracks that are easy to conflate. The first is device clearance, handled by the FDA. The second — newer, and distinct from device approval — is transparency reporting for AI tools embedded in the electronic health records that most U.S. clinicians already use. HHS’s Office of the National Coordinator for Health IT finalized the HTI-1 rule on December 13, 2023, effective March 11, 2024: the first federal rule requiring developers of predictive decision-support tools built into certified EHR systems to disclose the data that trained the model, its intended use, and its bias or health-disparity risk. HTI-1 replaced the older “Clinical Decision Support” certification criterion with a new “Decision Support Intervention” criterion; multiple law-firm trackers report enforcement deadlines pushed from January 2025 to January 2026, so implementation is still very much in progress rather than settled practice.

On the device-clearance side, the FDA, Health Canada, and the UK’s MHRA jointly issued ten Good Machine Learning Practice guiding principles on October 27, 2021 — covering multidisciplinary expertise across the product lifecycle, independence of training and test datasets, performance testing under clinically relevant conditions, and post-deployment monitoring. That framework has since been extended for AI systems that keep changing after clearance: the FDA’s January 2025 draft guidance on AI-enabled device lifecycle management, followed by final guidance on Predetermined Change Control Plans in August 2025, lets manufacturers update a deployed clinical model without a new marketing submission, provided the update path was pre-specified and disclosed at clearance. That is the specific mechanism that governs whether a hospital’s AI diagnostic tool can change behavior next quarter without anyone outside the manufacturer being told in advance.

Local government: cities wrote the first playbooks

Before most states or federal agencies acted, city IT departments were already writing rules, mostly restricting what employees could do with generative AI tools rather than governing AI used on residents. Seattle adopted its Generative Artificial Intelligence Policy on November 3, 2023, after a six-month process run by a Generative AI Advisory Team; it requires employees to attribute AI-generated work, have a human review all AI output before publication, and keep personal or sensitive information out of GenAI tools. Boston’s interim guidelines, first issued March 18, 2023, apply to city agencies other than Boston Public Schools and explicitly treat themselves as a placeholder pending formal policy — an unusually honest admission that the guidance was written faster than anyone could fully think through.

San José’s Generative AI Guidelines go further operationally: all information entered into city GenAI tools is treated as subject to a public-records request, staff must fact-check outputs against multiple sources, staff must log GenAI use through a dedicated internal form, and staff must use city accounts rather than personal ones. Puyallup and Spokane, Washington adopted their own generative-AI policies in 2024, tracked alongside dozens of others by the Municipal Research and Services Center. Smaller municipalities without in-house AI counsel have leaned on the Michigan Municipal League’s AI Handbook for Local Government and the International Municipal Lawyers Association’s compilation of state and local AI use policies, which reproduces real city and county policy text side by side rather than offering generic advice.

Small business: a resource hub, not yet a rulebook

Small business is the least developed of these four sectors, and the gap is worth naming rather than papering over. The Small Business Administration’s “AI for Small Businesses” resource hub launched around its inaugural Artificial Intelligence Small Business Summit at Georgia Tech, held December 11, 2024. The SBA’s Office of Advocacy has since published its own research — Research Spotlight: AI in Business — Small Firms Closing In, released September 24, 2025 — tracking small-firm AI adoption rates. What the SBA has not published, as of this writing, is an operational checklist comparable to what schools, hospitals, or cities now have. A number of advisory and consulting blogs circulate specific-sounding “SBA checklist” language on topics like vendor review and human-in-the-loop requirements; none of that traces back to sba.gov itself, and this manual declines to attribute it to the agency. The real institutional signal to watch is legislative: the U.S. House passed bills in 2026 requiring the SBA to help small businesses adopt AI, which reads less as settled guidance than as evidence that guidance is still being built.

The pattern across sectors

Read together, these four sectors show the same shape: a voluntary federal framework, a handful of binding rules layered on top of it in the highest-stakes domains (Tennessee’s school mandate, the HTI-1 rule), and a much larger body of advisory guidance that individual institutions can adopt, ignore, or half-implement. None of it substitutes for the harder question this manual keeps returning to elsewhere — who has the authority to act when evidence conflicts with a deployment schedule — but each of these documents is a concrete, dated, checkable answer to “what has an actual institution published,” which is more than most AI-governance conversations can offer.

References

Summarized position

NIST published the AI 600-1 Generative AI Profile in July 2024, adding twelve generative-AI-specific risk categories and more than 200 suggested actions onto the Govern-Map-Measure-Manage structure of the base AI Risk Management Framework.

NIST, U.S. National Institute of Standards and Technology
AI 600-1: Artificial Intelligence Risk Management Framework — Generative Artificial Intelligence Profile, Report
Summarized position

U.S. Department of Education released a 74-page toolkit for K-12 leaders on safe, ethical, and equitable AI integration, built from listening sessions with 90 educators across 12 roundtables held between December 2023 and March 2024.

U.S. Department of Education, Office of Educational Technology
Empowering Education Leaders: A Toolkit for Safe, Ethical, and Equitable AI Integration, Report
Summarized position

State of Tennessee is, as of its March 2024 effective date, a legal mandate rather than voluntary guidance, requiring every Tennessee local board of education and public charter school to adopt its own AI-use policy.

State of Tennessee, Tennessee General Assembly
Public Chapter 550 (2024), codified at Tenn. Code Ann. §§ 49-7-185 and 49-13-118, Primary
Summarized position

Louisiana Department of Education published K-12 AI guidance in August 2024, developed through a dedicated LDOE AI Task Force, covering implementation strategy, safeguards, and technical considerations for districts.

Louisiana Department of Education, State education agency
Artificial Intelligence in Louisiana Schools: Guidance for K-12 Schools, Report
Summarized position

HHS Office of the National Coordinator for Health IT finalized in December 2023 the first federal rule requiring developers of AI-driven clinical decision support tools embedded in certified electronic health record systems to disclose the data, intended use, and bias or health-disparity risks behind each tool.

HHS Office of the National Coordinator for Health IT, Federal health-IT regulator
HTI-1 Final Rule (Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing), Primary
Summarized position

FDA, Health Canada, and UK MHRA jointly issued ten guiding principles in October 2021 covering multidisciplinary expertise, representative training data, and post-deployment monitoring for AI-enabled medical devices.

FDA, Health Canada, and UK MHRA, Joint medical-device regulators
Good Machine Learning Practice for Medical Device Development: Guiding Principles, Report
Summarized position

City of Seattle adopted a generative-AI policy in November 2023, after a six-month advisory process, requiring employees to attribute AI-generated work, have a human review all AI output before publication, and keep personal or sensitive information out of GenAI tools.

City of Seattle, Seattle Information Technology Department
Generative Artificial Intelligence Policy, Report
Summarized position

U.S. Small Business Administration launched an "AI for Small Businesses" resource hub around its December 2024 inaugural Artificial Intelligence Small Business Summit at Georgia Tech.

U.S. Small Business Administration, Federal agency
"AI for Small Businesses" resource hub, Report
  1. May 2023 ED report ed.gov
  2. executive order, "Advancing Artificial Intelligence Education for American Youth," whitehouse.gov
  3. Ballotpedia ballotpedia.org
  4. K-12 Dive k12dive.com
  5. SB 1288 cde.ca.gov
  6. interim guidelines boston.gov
  7. Generative AI Guidelines sanjoseca.gov
  8. Municipal Research and Services Center mrsc.org
  9. Michigan Municipal League's AI Handbook for Local Government stpp.fordschool.umich.edu
  10. International Municipal Lawyers Association's compilation of state and local AI use policies imla.org
  11. Research Spotlight: AI in Business — Small Firms Closing In advocacy.sba.gov
  12. passed bills in 2026 requiring the SBA to help small businesses adopt AI pymnts.com

The source index also tracks the manual's recurring core sources and expert positions.

Type to search the manual.

navigate open esc close