The EU AI Act Is Fully Live — What U.S. City Governments Should Steal From Their Playbook
Last week, a neighboring city employee called her city attorney in a mild panic. Her council had just asked whether the new AI tool the police department wanted to buy would "comply with that European law everyone's talking about." She didn't have an answer. Honestly, most city attorneys don't yet.
Here's the thing — the EU AI Act's enforcement teeth are now in the water. Fines, classification rules, and obligations for general-purpose AI systems are live as of this month. And state legislatures from Texas to Connecticut are openly borrowing the EU's risk-tier playbook for their own bills.
You don't need to comply with a European law. But you do need to understand it, because something that looks a lot like it is coming to your state. In this post, I'll show you exactly which pieces of the EU playbook your city can steal — and put into a procurement checklist this quarter.
What does the EU AI Act actually require, in plain English?
Quick Answer: The EU AI Act sorts AI systems into four risk tiers — unacceptable, high, limited, and minimal — and assigns rules to each. High-risk systems (like AI used in hiring, benefits decisions, or law enforcement) must meet strict requirements: human oversight, documentation, bias testing, and transparency to the public. Fines for violations can reach 7% of global revenue.
The law went into partial effect in 2024, but the general-purpose AI obligations and full enforcement penalties just kicked in this month. That's the headline.
In my experience working with government teams, the tier system is the part that translates best to U.S. local government. Most cities don't need 400 pages of regulation — they need a way to sort the AI tools landing on their desks into "buy carefully," "buy with guardrails," or "don't buy at all."
Why should a U.S. city care about a European law?
Quick Answer: Three reasons: state laws are copying the EU framework, federal grant guidance is starting to reference similar risk tiers, and your vendors already comply with the EU rules — meaning you can demand the same documentation at no extra cost. Cities that adopt the framework now will be ahead when state mandates arrive.
Colorado already passed an AI law modeled on the EU's high-risk categories. California, Connecticut, Texas, and New York have active bills doing the same thing. The pattern is clear.
What I've seen consistently with my city clients: the vendors selling you AI tools — Microsoft, Google, Workday, Tyler Technologies — already produce EU compliance documentation. You can simply ask for it. They'll hand it over because they already made it.
That's free leverage.
What should city CIOs and attorneys steal for procurement?
Quick Answer: Steal four things — a risk classification step, a vendor documentation requirement, a human oversight clause, and a public transparency commitment. Add these to your existing IT procurement template. You don't need a new policy; you need four new questions in the contract review process.
Here's the practical checklist I give my clients. Add these to every AI-related purchase over a set dollar threshold:
- Risk tier classification. Before signing, classify the system as high, limited, or minimal risk. High-risk includes anything touching hiring, benefits eligibility, code enforcement, policing, or utility shutoffs.
- Vendor documentation request. Ask for the vendor's EU AI Act technical documentation or model card. If they sell in Europe, they have it.
- Human-in-the-loop clause. Require contract language stating no automated decision affecting a resident is final without staff review.
- Public-facing notice. Commit to telling residents when AI is used in a decision that affects them. A line on your website is enough to start.
- Bias testing evidence. For high-risk tools, require the vendor to share testing results for disparate impact across protected groups.
A common question I get from city attorneys: "Is this enforceable in our contracts?" Yes. It's standard procurement language dressed in new clothes.
Which AI uses should U.S. cities treat as "high-risk" right now?
Quick Answer: Treat these as high-risk: hiring and promotion tools, public benefits eligibility, predictive policing, facial recognition, automated code enforcement, utility disconnection decisions, and any tool scoring or ranking residents. These categories are flagged across the EU Act, Colorado's law, and most pending state bills — so the bar is converging.
If a tool in this list lands on your desk, slow down. That doesn't mean reject it. It means run the full checklist above and document your decision.
In my experience, the cities that get into trouble aren't the ones using AI — they're the ones using it without a paper trail showing they thought carefully about it.
How do you roll this out without slowing down operations?
Quick Answer: Pilot the checklist on your next three AI purchases, not all current systems. Train your procurement officer and city attorney together in a single two-hour session. Add the four questions to your existing IT review form. Most cities can have a working framework in 30 days without hiring anyone new.
Don't try to audit every tool you already own. That's how good initiatives die.
Start forward-facing. Apply the checklist to new purchases for one quarter. Then, in the second quarter, review your existing high-risk systems against it. By month six, you have a real program — without disrupting daily work.
What's the bottom line?
The EU AI Act is now the global template, and U.S. state laws are following it fast. Cities that quietly adopt its risk-tier thinking into procurement this quarter will be ready when state mandates land — without scrambling.
Ready to train your team? I run plain-language workshops for city procurement, legal, and IT staff on exactly this framework — reach out here to talk through your city's next steps.
LaTonya Koonce is the founder of GovAI Education Group and a City of Lilburn Merit Award recipient for implementing AI in government operations. She has trained government teams for 20+ years and specializes in plain-language AI education for public-sector professionals. Learn more about our training programs →
LaTonya Koonce
Founder, GovAI Education Group · City of Lilburn Merit Award Recipient
LaTonya has trained government teams for 20+ years and specializes in plain-language AI education for public-sector professionals. Learn more →

