Use-case guide
AI in Smart Cities & Urban Tech
Smart-city AI is where public-procurement-procedure meets the strictest AI rules. The EU AI Act treats public-space biometric ID, law-enforcement AI, and access-to-public-services AI as high-risk or prohibited. New York Local Law 35, San Francisco's Stop-Secret-Surveillance, and Portland's Surveillance-AI Ordinance build city-level controls. The US AI Executive Order 14110 (rescinded 2025, replaced by EO 14179 + OMB M-25-21) and OMB Memo M-25-21 establish federal-procurement-driven baselines. Cross-cutting: NIST AI RMF, the IEEE Standard for Algorithmic Bias Considerations, and growing state procurement rules.
For: City CTOs, urban-tech vendors, transit authorities, public-procurement officers, civic-tech compliance leads, municipal-data privacy officers
What's at stake
Real-time biometric ID in public spaces largely banned in EU
EU AI Act Article 5(1)(h) prohibits real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes — with narrow exceptions. Cities that deployed face-rec cameras face wind-down obligations.
Public-services AI is high-risk under Annex III §5(a)
AI to evaluate eligibility for public services (housing, benefits, utility programmes) is high-risk in the EU. Annual impact assessment + algorithmic-decision register publication.
US city + state surveillance-ordinance patchwork
Local laws (San Francisco, Oakland, Portland, NYC POST Act/LL 65, Seattle Surveillance Ordinance) require pre-deployment review + community engagement + impact assessment for AI surveillance tools. Procurement bypass is an audit finding.
Federal procurement AI rules apply to vendors
OMB M-25-21 (replacing M-24-10 + M-24-18) establishes federal-agency AI use principles. Vendors selling to federal/state agencies face flow-down requirements + the new Section 5301-compliant Responsible AI certifications.
Regulations that apply
EU AI Act
LawPublic-space biometric ID largely banned (Article 5(1)(h)); public-services AI high-risk (Annex III §5(a)); law-enforcement AI high-risk (Annex III §6).
Where in the text: Article 5(1)(h); Annex III §§5(a), 6.
US OMB M-25-21 + state procurement AI rules
LawFederal-agency AI use principles; flow-down to vendors. State equivalents (California Generative AI procurement order, Texas, Connecticut) expanding.
Where in the text: OMB M-25-21 (2025); California Exec. Order N-12-23.
City surveillance ordinances
LawPre-deployment review + community engagement + impact assessment for surveillance AI. San Francisco, NYC, Seattle, Oakland, Portland, Boston — patchwork with similar core.
Where in the text: S.F. Admin. Code Ch. 19B; NYC LL 65 (2020); Seattle SMC 14.18.
California Generative AI Procurement Order
LawProcurement-side rules requiring impact assessment + transparency for generative AI bought by California state agencies. Template for other state procurement rules.
Where in the text: Cal. Exec. Order N-12-23 (2023); GenAI Procurement Order (2024).
Do
- ✓Run pre-deployment impact assessments for any AI-driven public-services tool — the EU AI Act Article 27 FRIA, US OMB M-25-21, and most state procurement rules all converge on the same workflow.
- ✓Publish an algorithmic-decision register — multiple cities (NYC, Amsterdam, Helsinki) have led; the practice is becoming legally expected.
- ✓Build community-engagement into procurement BEFORE selection — surveillance-ordinance compliance demands it, not just disclosure.
- ✓Maintain a vendor-RAI-certification trail. Federal + state procurement increasingly require it; private city contracts pulling in the same direction.
- ✓Plan AI-tool sunset/wind-down processes — public-sector tech accumulates without governance; surveillance-ordinances increasingly require sunset reviews.
Don't
- ✗Don't deploy real-time face-rec in EU public spaces for law-enforcement purposes — Article 5(1)(h) bans it with very narrow exceptions.
- ✗Don't bypass surveillance-ordinance review with 'pilot programme' framing — the ordinances now have explicit anti-pilot provisions.
- ✗Don't procure AI for public services without an algorithmic-impact assessment — Canada's Directive on ADM template is the gold standard reference.
- ✗Don't share city-aggregated AI-decisioning data with commercial vendors without procurement-contract limits — this has been the visible failure in surveillance-ordinance complaints.
- ✗Don't deploy generative-AI customer-service for public services without Article 50 (EU) + state procurement disclosure rules. Public-sector chatbot disclosure standards are tighter than commercial.
Also worth knowing
For transit authorities: AI in fare-enforcement + accessibility face dual EU AI Act + Equality Act / ADA pressure. For utility operators (water, electric, gas): AI in demand-response + outage-prediction interacts with NIS2 essential-entity duties + state PUC oversight. For pavement/infrastructure AI: federal Highway Safety Administration AI guidance + state DOT procurement rules apply.
Want a tailored answer?
The wizard takes your jurisdiction, AI use case, and data types and gives you the top-3 regulations to focus on — in 60 seconds.
Start the wizard →Educational guide. Not legal advice. For specific compliance decisions, consult qualified counsel in the relevant jurisdiction.
Note: this guide was drafted with AI assistance — Anthropic Claude.