AI consulting for government agencies
Agencies are under pressure to adopt AI fast and under obligation to do it responsibly. We advise on which uses pay off, and on what the governance, security review and staff training have to look like before you switch anything on.
AI in government is moving faster than its governance
Staff are already drafting with generative AI, usually without telling anyone. A purchasing agent signs an AI-enabled software contract without reading the data terms, and a director is asked to approve the project without a clear picture of what approval covers.
The concrete risks are a resident's file pasted into a commercial chatbot, and model output used in a benefits decision that nobody checks behind. Often the staff are further along with these tools than IT is.
The gains are worth having. These tools can cut administrative work and let a short-staffed office get more done. Our position is that agencies should adopt AI, and should do it in a way that survives a public records request and an audit.
We advise government organizations on AI adoption, governance and risk. In practice that is drafting the policy, reviewing what procurement is about to sign and training the staff who will use the tools. A year later we come back and check whether any of it held.
"Government agencies don't need to avoid AI: they need to adopt it the right way. That means governance first, not governance as an afterthought."
Spencer Wood, Founder, CEO and Principal Consultant
What is included
Some agencies want one AI risk assessment. Some want the whole governance program built.
-
AI governance framework development
We build the policy and the governance structure around AI use: acceptable use, data handling, what procurement has to ask for, who reviews what and who answers for it. Written against NIST AI RMF and current state and federal requirements.
-
AI security assessments
We review the AI tools you already run and the ones you are considering: where your data goes, how the vendor secures it, how the model behaves and what breaks when it plugs into the systems you have.
-
AI enablement strategy
A practical order of operations for AI adoption: which use cases pay off first, what to sequence behind them and which policies and infrastructure have to exist before you scale.
-
Workforce AI training
AI literacy training for staff at every level: how generative AI works, how to use it without creating a records problem, what never goes into it and how to spot a deepfake or an AI-written phishing email.
-
Emerging technology risk
You keep a standing line to us for when something changes. Usually that is a leadership briefing on AI-enabled attacks, on deepfakes aimed at your organization and on state and federal rules arriving faster than anyone can read them.
-
AI policy development
We draft or mark up AI policies, executive orders, procurement language and the AI clauses in a vendor contract, including what you have to disclose, how to handle bias and fairness questions and what the public is entitled to see.
Disinformation, deepfakes and public trust
Election officials are already dealing with AI-generated disinformation and synthetic media aimed at their offices and their staff.
The same offices are using these tools on the operational side, from voter outreach to results processing. An election office should be able to explain, in one page, what the tool did and who checked it, and if it cannot, that tool does not belong in public-facing work yet.
We work on both sides of this. Spencer Wood co-wrote Inside Ohio's Practical Use of AI for Election Administration with TJ Pyche and Trevor Timmons, published in the AI & Elections Clinic in March 2026, and he is one of the co-authors of the clinic's July 2026 guest post on what election offices put in an AI use policy.
Who this is for
- State and local agencies writing their first AI policy
- Election offices weighing an AI tool for operational use
- Agencies where AI arrived informally and now needs oversight
- Critical infrastructure operators looking at AI supply chain and vendor risk
- Government contractors facing federal AI requirements
Every consultant who works with Foundation Consultant Group served as a Cybersecurity Advisor with CISA, the federal field role for reducing cyber risk in state and local government and critical infrastructure.
- Six states CISA Region 5: Illinois, Indiana, Michigan, Minnesota, Ohio and Wisconsin, where Spencer Wood served.
- More than 20 years His record in enterprise, government and critical infrastructure.
- Nationwide Where we take engagements now.
Leadership
Our AI advisory work comes from the government side of the table. Spencer Wood was interim State Chief Information Officer of Ohio and later a Cybersecurity Advisor with CISA, and he has written for the AI & Elections Clinic, most recently on what election offices put in an AI use policy. We start from security and risk, so what you get from us is advice on how these tools behave in a working government office.
Next step
Tell us which gap you have: no policy yet, or tools nobody has reviewed. We can start from either.
Get in Touch