Oklahoma Counties Are Already Using AI — Whether You Planned for It or Not
At the recent ACCO Spring Conference, Josh Cochran spoke about Artificial Intelligence.
Not the futuristic version.
Not the “maybe one day” version.
The version your employees are already using…
without policy, without guardrails, and without visibility.
Why Most Oklahoma Counties Underestimate AI Risk
Take a normal day at a county office.
The clerk’s office is busy. Phones are ringing. Emails are stacking up. Someone needs help summarizing a report quickly before a meeting.
So an employee opens an AI tool.
Not because of policy.
Not because it was approved.
Just because it’s fast.
They paste in:
- Notes from an internal case
- Names tied to a report
- A few identifying details to give the AI “context”
And within seconds—they get exactly what they needed.
Clean. Organized. Efficient.
Problem solved… right?
What Happens Next (That No One Sees)
What that employee doesn’t see is everything happening behind the interface.
Depending on the platform and settings:
- That data may be processed through external servers
- It may be logged or retained temporarily
- It may contribute to system learning or optimization
- It now exists outside of the county’s controlled environment
No alert is triggered.
No system flags it.
No one in IT is notified.
To the employee, it was just another task completed.
Where This Becomes a County-Level Risk
Now fast forward.
A records request comes in.
An audit is performed.
A compliance question is raised.
And suddenly the county has to answer:
- Where has this data been stored?
- Who has had access to it?
- Was it shared outside approved systems?
- Can you prove how it was handled?
If that data touched a system outside your control—and there’s no documentation or policy governing its use—
That’s where exposure begins.
The Part Most Counties Miss
This didn’t happen because someone was careless.
It happened because:
- There was no clear AI usage policy
- No training on what should never be entered
- No visibility into what tools employees are using
The employee was trying to be efficient.
The system allowed it.
The risk was invisible.
Now Multiply That Across Every Department
Clerk’s office
Sheriff’s department
Treasurer
HR
Court staff
If even a handful of employees are using AI tools without guidance…
You don’t have one instance of risk.
You have dozens of uncontrolled data touchpoints happening every day.
What Your Information Security Policy Already Requires (And Where AI Is Testing It)
If you attended the ACCO Spring Conference and Josh’s session on AI risks, you were provided with an Information Security Policy template to help your county define expectations around data protection, access, and usage.
(If you missed it, we’ve included it here for you as well.)
That policy establishes something important:
Your data is a valuable asset, and it must be protected.
It also outlines expectations around:
- How data is accessed
- How it is stored
- How it is transmitted
- And who is responsible for protecting it
But here’s where things start to break down.
Having a policy is one thing.
Making sure it applies to how employees are using AI tools today is another.
Because whether it’s ChatGPT, Copilot, or other AI platforms, employees are already interacting with systems that can store, process, and potentially expose sensitive information.
If your county hasn’t formalized a policy yet, this template gives you a strong starting point.
If you already have one in place, now is the time to revisit it—because AI is pushing those policies into territory they weren’t originally built to handle.
The Takeaway
This is what modern risk looks like.
Not a hacker breaking in…
But sensitive information being quietly handed out—
one helpful prompt at a time.
Know Where You Stand
As always, we offer a complimentary cybersecurity and network assessment for Oklahoma counties.
Know where you stand.
Understand how AI is being used inside your environment.
And make sure your policies match today’s reality, not yesterday’s assumptions.
If your current IT provider can clearly show you your security policies, controls, and protections—you’re in a good place.
If not…
You know where to find us.
Thank You for Attending ACCO
We truly appreciate everyone who attended the session. We hope you walked away with valuable insights—and a practical starting point with the policy template.
If you need help implementing it, refining it, or aligning it with how your county actually operates today…
We’re just a click away.