Yes, with limits. A public sector communications team can use AI for message testing, fact checking, tightening and blind spot hunting. It cannot put deliberative or pre decisional material into a public tool, and it should disclose precisely what the AI did rather than issuing a vague blanket notice that makes readers distrust everything.
In a two-day session with a federal agency in Washington DC in July the AI question arrived before we had finished the first cup of coffee. Not the abstract version. The practical one. A senior communicator put it plainly: we are being told to use these tools, and we are also being told we cannot put anything into them. Which is it?
That contradiction is the real state of AI in government communications. It is not a technology problem. It is a permissions problem, a records problem and a procurement problem, in that order. In 20 years of training communicators, including teams at the Social Security Administration, Bureau of Labor Statistics, Department of Labor, The National Park Service and others, this is the first issue where the constraint is almost never skill.
Can a government agency use AI to draft public messaging?
Yes, on material that is already public or already cleared. Testing whether your approved language is actually understandable. Hunting for the objection you have not thought of. Checking a fact you will then verify yourself. Cutting three hundred words to a hundred and fifty without losing the meaning. (If you are reading this and from a government agency, always get approval and open lines of communication on this topic.)
What it cannot receive is the unreleased draft. That is where the first of three walls goes up, because during an incident the unreleased draft is nearly everything on your desk. None of the three is the wall people expect.
Why does the approved tool keep giving you out of date answers?
Agencies that solved the security question usually did it by sandboxing: an internal tool, walled off, no live connection to the open web. That creates a specific, predictable failure.
The tool's knowledge is frozen at a snapshot. Ask it who currently leads a given office and it will hand you the predecessor, confidently, in a complete sentence, with no hedge and no timestamp. It is not lying. It genuinely does not know that anything has changed, and it has no mechanism for suspecting so.
Anything that changes over time is the sandboxed tool's weakest point. Who holds a role. What the current figure is. What the latest guidance says. What the deadline now is. Treat every name, title, number and date it produces as unverified until you have checked it against something live.
What can you not put into a public tool?
Deliberative and pre decisional material. Your draft holding statement. The internal question and answer document. The options memo. The list of questions you are worried a reporter will ask on Thursday.
That list is the entire working set of an incident response. The material you would most like a second pair of eyes on is the material with the least room to move.
There is a second layer underneath it. What you type may itself become a record. Once it is sitting in a third party system, you no longer control where it lives or who can retrieve it. That is a records question, not an IT question, and the two offices do not always talk to each other.
Here is where I will be straight with you rather than tidy: the room did not resolve whether a prompt typed into an approved internal tool is a record in its own right. Several people had opinions. Nobody could point to a settled answer. I am not going to invent one. Ask your own records officer, in writing, well before the day you need the answer.
Why does procurement block AI tools when the budget is fine?
A product can be blocked from purchase purely because it contains an AI feature. Not because you intend to use that feature. Not because the data goes anywhere. The feature can be switched off, can be irrelevant to why you want the software, and the purchase still will not move, because the rule attaches to the product rather than to the use.
The consequence is that the tool you can get is rarely the tool you would choose, and the gap is not a budget conversation. If you have money and the purchase is stuck, stop rewriting the justification and go and read the acquisition rule. Ask for the capability you need rather than the brand you saw demonstrated. Brands trip the rule. Capabilities sometimes do not.
How should you disclose that you used AI?
If your policy requires disclosure and you satisfy it with a blanket line, something like "this message was produced with the assistance of AI," you have told the reader nothing except that they should be suspicious of every sentence above it. You have not built trust. You have installed a small alarm at the bottom of your own release.
The fix is precision. There is an enormous difference between "AI wrote this" and "AI tools were used for message testing, fact checking and grammar." The first invites the reader to discount the content. The second describes a professional process that a reader can evaluate, and most readers will conclude, correctly, that a message which was stress tested is better than one that was not.
- Weak: "Produced with AI assistance."
- Better: "AI tools were used for grammar and length editing. All facts were verified by staff."
- Better still: "AI tools were used to test this message for clarity and to check it for missing questions. Content, sourcing and approval are ours."
The room did not agree on where that line belongs, in the release itself or on a standing policy page that the release points to. Both arguments are reasonable and the answer probably depends on your public. What everyone did agree on was that vagueness costs more trust than it saves.
Which prompts are actually worth using?
These four survive contact with a place where you cannot paste whatever you like.
1. "What are the blind spots on this that I need to know about?" The single most valuable prompt I can give a communicator, and also the safest, because you are asking for a stress test rather than for copy. Describe the situation generically, with no unreleased text at all, and you still get back the three questions you had not braced for. It is the same instinct as building the tough question list before a reporter builds it for you.
2. "Critique your own response." Four words, one extra line, and it routinely catches the weakness you would otherwise have found on your own third read. Models will happily point out that their own answer was generic, unsupported or repetitive if you simply ask them to.
3. Constrain the sources before you ask for a quote. Never ask an open question like "find me a good quote about resilience." Paste the cleared text and say: use only the material below. If it is not in there, say so. This one habit prevents the failure in the next section.
4. "Tighten this." Two words, and the best length instruction I have found. It cuts without flattening, which is more than "make it shorter" reliably does. If you have not settled what the message is yet, that is a different problem, covered in key messages for media interviews.
What happens when nobody checks the quote?
A communicator wanted a line with a bit of ceremony to it. They asked a tool for an official sounding presidential quote. The tool produced one. It was a good line. It attributed the line to a president, by name, in a complete sentence with no hedging whatsoever.
On checking, the line was from an unrelated person at an unrelated agency.
Two things are worth noticing, and neither is the obvious one. The tool was confident, and it was specific. Confidence and specificity are precisely what a fabricated attribution looks like from the outside. There is no wobble in the text to warn you, which is why the check has to be a step in your process rather than an instinct.
I spent 13 years producing at ABC, NBC and Fox. A correction never travels as far as the thing it corrects, and a fabricated quote in a public release is a story about your agency, not about your software vendor.
What can you do today with zero approvals?
Open two windows side by side. On the left, a raw notes document: everything you know, in whatever order it fell out of your head. On the right, a structured one with your headline, one key message, three supporting points and the action you want. Copy and paste from left to right, deciding as you go what earns a place.
That is it. It takes minutes, needs nobody's permission, and no data leaves the building. It captures most of the benefit, because the benefit was never the writing. It was being forced to separate what you know from what you are going to say. A team that does this by hand beats a team with better tools and no structure, which is the argument I make in crisis communication for agencies.
Three walls, four prompts and one workaround that starts this afternoon. If your communicators have to be right the first time with fewer people, that is a training conversation. Tell us what is coming up.
Observations in this article come from a two-day media and presentation training run for a federal agency in Washington DC on 13 and 14 August 2026, with all identifying detail removed. Nothing here reflects the policy of any specific agency. Confirm your own records and acquisition rules with your agency counsel before changing how you work.