Direct Answer: Human Agencies Must Remain Legally Accountable
The defensible answer is that an AI system may help evaluate applications, identify missing documents, estimate review time, and recommend applicable rules, but a qualified public official must make and sign the permit decision. Human oversight is not satisfied merely because an employee clicks “approve” after seeing an algorithmic recommendation. The reviewer must have authority, access to the underlying evidence, time to investigate disagreements, and a documented reason for accepting or rejecting the system’s output. Agencies should also be able to explain how a decision was reached without disclosing sensitive model information or personal data. This allocation of responsibility is consistent with the direction of modern public-sector AI governance, including the U.S. Office of Management and Budget’s M-24-10 and the NIST AI Risk Management Framework.
Also worth reading: How Should Permit AI Accountability Rules Govern High-Risk Planning Decisions? · How Are AI Zoning Review Tools Reshaping Permit Decisions in 2026? · How Should Cities Use Responsible AI to Speed Up Building Permits Without Weakening Public Oversight?
A useful test is whether the official could defend the decision in an administrative appeal, court hearing, or public-records request without relying on “the computer said so.” If the answer is no, the process is not meaningfully human-led. Conversely, pretending that a human merely rubber-stamps a model recommendation also fails the test. Permit decisions affect public health, safety, zoning rights, property values, and neighborhood equity, so agencies need more than a general promise of supervision. They need traceable rules, trained reviewers, performance monitoring, appeal routes, and consequences when the technology contributes an error. The goal is not to ban AI in permitting; it is to prevent opaque automation from acquiring government authority it was never designed to possess.
How Human Oversight Should Work in Permit Administration
A sound permit workflow divides work into three layers: administrative support, analytical recommendation, and legal decision-making. Software can classify an application, compare it against a checklist, detect missing material, flag possible conflicts, and draft questions for the applicant. More advanced systems may suggest a likely code interpretation or predict the duration of review, but those suggestions should remain distinguishable from the agency’s formal findings. The authorized official must examine the application record, consider relevant law and policy, consult specialists where needed, and issue a reasoned decision. Routine low-risk cases may receive lighter review, while contested, unusual, or safety-sensitive matters should trigger stronger controls.
The system should not silently combine unverified data with binding requirements. Planners need to know which inputs came from the applicant, which came from an external database, and which came from a predictive model. A recommendation should include confidence or uncertainty information, applicable provisions, and links to source evidence. If data is stale, incomplete, or contradictory, the tool should route the matter to a person rather than generate false certainty. For example, an AI system may notice that a proposed building height conflicts with a mapped zoning district, but it should not declare the conflict dispositive if the map may be outdated or an amendment may still be pending. Human oversight means managing uncertainty rather than transferring it to an applicant or reviewer.
For oversight to be effective, responsibility must extend beyond the individual deciding officer. A permit director should supervise the operating process, a compliance office should test whether outcomes remain consistent with law, and an elected or appointed body should receive aggregate information about errors, delays, appeals, and demographic effects. Agencies should publish a plain-language AI policy stating whether the technology makes recommendations, drafts documents, or performs any independent assessment. They should also identify prohibited uses, such as inferring protected traits, ranking neighborhoods by desirability, or using social-media content as a substitute for a lawful application. The official signature demonstrates formal authority, but institutional controls determine whether that authority is being exercised responsibly.
Why Fully Automated Permit Decisions Are Risky
Permit decisions are unusually open to legal challenge because they are government actions affecting private property and public space. Errors can involve zoning interpretation, environmental requirements, fire safety, accessibility, flood risk, historic preservation, or procedural rights. A text model can omit a condition, misread an exception, or rely on an outdated code edition. Predictive tools can also reproduce historical enforcement patterns: applications from under-resourced neighborhoods may receive more requests for documentation, while well-connected applicants receive faster approvals. That is not merely a software defect; it may become a civil-rights and policy problem if officials fail to identify and correct it.
The scale of automation also matters. A system used to precheck six routine fields poses less risk than one evaluating a $100 million mixed-use development across hundreds of regulations. The latter may appear objective because it processes thousands of criteria, yet its outputs depend on data quality, code interpretation, training choices, and assumptions about acceptable development. Complex cases often require balancing public objectives that cannot be reduced to a fixed score, including neighborhood traffic, affordable housing, climate effects, displacement risk, and the credibility of commitments made by an applicant. Humans may not always reach the correct result, but they can exercise judgment, explain exceptions, and respond to new evidence in ways a static model cannot.
Automation can create an accountability gap even when the tool is accurate most of the time. Developers may say they only supplied software, vendors may say the agency configured it, and staff may say they were instructed to follow its output. Public law generally cannot end with that circular denial. The public authority must select the system, define permissible uses, test it, monitor it, and retain responsibility for the resulting action. It should also maintain a non-automated route for applicants and reviewers who need to dispute an output. A system’s high average accuracy is not enough if failures are rare but severe, difficult to detect, or concentrated among applicants least able to appeal.
Practical Standards Before a City Deploys Permit AI
The first practical step is a written purpose statement defining exactly what the tool will and will not do. A city could begin with document completeness checks or routing suggestions while reserving interpretation and approval for staff. Procurement documents should require data provenance, security protections, accessibility, audit logs, version records, incident reporting, and cooperation during investigations. Vendors should identify whether the product uses customer data to train general models and whether subcontractors can access permit records. Contracts should preserve public records, provide needed data in usable formats, and prevent a vendor from locking the city into a system it cannot independently inspect.
Before production use, the agency should test the tool against a representative sample of prior cases. Testing should include routine applications, complex approvals, denials, appeals, withdrawals, and cases with conflicting information. Officials should measure incorrect recommendations separately from the time staff spend correcting them, because an apparently time-saving system can create hidden review work. Suggested thresholds might include at least 95% accuracy for low-risk routing tasks, immediate human review of uncertain cases, and a documented escalation process whenever confidence is low. Those percentages are management targets rather than universal legal standards; risk-based agencies may demand more conservative performance for safety-related findings.
After deployment, the agency should monitor at least four categories of performance: timeliness, accuracy, consistency, and equity. Timeliness measures the time between submission and a reliable decision, rather than simply the time until software recommends approval. Accuracy measures whether staff corrections expose factual or legal defects. Consistency examines whether similar applications receive materially different treatment. Equity testing should examine approval rates, request-for-correction rates, processing times, and appeal outcomes across relevant lawful categories, while recognizing that raw disparity is not automatically proof of discrimination. Material findings should lead to retraining, configuration changes, suspension, or retirement of the system. Public reporting should be understandable and should not reveal applicant information or reveal security weaknesses.
| Feature | AI-assisted permit review | Fully automated approval | Conventional manual review only |
|---|---|---|---|
| Accountability | Named public official approves and explains the decision | Vendor or platform may obscure responsible authority | Named public official retains responsibility |
| Typical role | Checks documents, routes files, identifies possible conflicts | Selects and issues decisions with minimal intervention | Staff manually read, route, and evaluate every item |
| Speed potential | High after setup because routine work is automated | Potentially highest per transaction | Often slower for simple and complex applications |
| Error control | Human investigation, audit trail, testing, and appeal | Model controls and post-hoc monitoring are harder to apply | Human review is direct but may be inconsistent or slow |
| Legal defensibility | Strongest when evidence, discretion, and review are documented | Weakest where discretion and explanation are required | Strong when reviewers have adequate time and expertise |
| Equity risk | Reduced through monitoring; can increase through biased data | High because errors may affect many applicants at once | Human bias remains possible, especially under heavy workloads |
| Best use | Drafting, completeness checks, search, and prioritization | Rarely appropriate for discretionary permit decisions | Small agencies, early-stage digitization, and exceptional cases |
One common mistake is treating human presence as a box to be checked. Staff may be shown hundreds of recommendations per day without enough time to inspect each one, creating rubber-stamping rather than informed review. Oversight works only when workload is controlled, reviewers understand the tool’s limitations, and the system makes disagreement easy. Managers should not reward staff for accepting AI recommendations or penalize them excessively for seeking clarification, because both incentives can distort judgment. The agency should measure corrections, escalations, and suspected safety problems as signs that review is functioning rather than treating them automatically as employee failure.
Another mistake is failing to distinguish a planning prediction from a legal rule. A model may predict that a project will cause traffic, infer local support from incomplete information, or estimate the likelihood of approval; none of those outputs is a binding code requirement. Staff must know when they are using a probabilistic tool and when they are applying law. The interface should label generated text, show retrieval dates, and prevent obsolete code from appearing current. Agencies should also avoid having applicants submit unnecessary data merely because the software is capable of collecting it. Data minimization reduces privacy risk and limits the possibility that a neutral-looking input becomes a proxy for race, income, disability, or political affiliation.
A third mistake is treating historical decisions as a flawless training set. Past approvals may reflect lawful discretion, uneven enforcement, outdated policy, or discrimination. Data should be reviewed for missing variables, underrepresentation, and differences caused by historically limited access to professional services. Removing a protected characteristic does not remove bias if address, language, wealth, neighborhood, or prior enforcement is serving as a proxy. Testing should include counterexamples: comparable applications with names, addresses, and applicant types varied where lawful and appropriate. If the agency cannot explain a disparity, it should not claim that the system is neutral simply because it was designed without an explicit protected field.
Alternatives and Different Operating Models
Not every jurisdiction needs to purchase an AI platform. Many permit offices can obtain faster service through electronic applications, standardized intake forms, public code search, automatic timestamp validation, and integrated plan-review systems. These “rules-first” tools are often more predictable because they execute approved logic instead of generating open-ended recommendations. A city could initially automate completeness checks and schedule coordination, measure results for six to twelve months, and only then consider AI for searching complex records or drafting staff questions. This staged approach limits cost and provides a baseline against which any later tool must be judged.
Some agencies may use a four-eyes model in which one person evaluates the technical proposal and another reviews the legal or policy basis. That approach increases staffing time but can improve accountability for high-risk decisions. Another option is to use AI only outside government decision-making, helping applicants understand documents or locating public standards while agency staff retain the entire decision process. This can improve access without allowing unreviewed model text to become an “entitlement.” For example, an assistant could translate instructions into several languages, but the official application, code edition, and agency response should remain controlled and authoritative.
Judicial review, public hearings, and appeal rights remain necessary even under the best technical model. A permit applicant should be able to identify whether AI influenced the record, submit contrary evidence, and request human reconsideration. Agencies should not conceal the involvement of a system when it materially shaped a decision, although they can protect trade secrets, security details, and personal information. A private contractor’s contractual interest does not override public transparency. A sound alternative therefore keeps commercial tools where they add measurable value, places official authority in public hands, and preserves a route for correction when the model, data, or human reviewer is wrong.
Timing, Costs, and Procurement Decisions
A city should act when a clearly defined delay or administrative burden can be measured, not merely because a vendor demonstrates an impressive planning demo. Before procurement, the permit office should record current median and 90th-percentile processing times, resubmission rates, staff hours per application, appeal frequency, and error rates. Those figures establish whether automation addresses a real problem. A reasonable pilot may run for three to six months; a fuller evaluation often requires at least a year if it is intended to cover different application types and seasons. The public authority should be prepared to stop the pilot if staff time rises, material errors increase, or affected communities lose meaningful access to human service.
Pricing varies widely because some products are enterprise platforms priced per user, seat, agency, transaction volume, or custom implementation, while simpler document tools may cost far less. Public procurement should require a total-cost disclosure covering licenses, data integration, cybersecurity review, model usage, training, validation, maintenance, upgrades, records retention, and exit costs. Avoid claims that a tool will always save 50% or double throughput unless the vendor provides a verifiable baseline and the city defines how savings will be measured. The largest expense may be process redesign and staff training rather than the software license. A contract with no reliable output or data-access provisions can also create replacement risk that is difficult to calculate in advance.
Cities should prefer staged, cancellable agreements and require a pilot exit plan. Before signing, they should ask where the tool runs, what data is retained, whether generated outputs can be audited, how often models change, and what happens after contract termination. Agencies should reject any arrangement that prevents inspection of consequential decision logic or makes permit records inaccessible to the city. They should also budget for accessibility testing, multilingual support, independent evaluation, and public communication. As of 29 September 2026, many AI vendor products and regulatory details will change, but these procurement principles are more durable than any current product name or headline price.
A Decision Rule Cities Can Apply Now
The safest operating rule is: AI may accelerate preparation, but the public agency must decide. This rule fits common constitutional and administrative expectations that government exercises its authority through accountable institutions rather than delegated private systems. It also recognizes that regulations such as the EU AI Act treat several categories of public-authority activity as high risk when they may substantially affect fundamental rights. A permit decision can affect access to property and shape local development, so an EU jurisdiction subject to that framework would need role assignment, human oversight, data governance, monitoring, and transparency in addition to any other applicable duties.
The rule should become more demanding as stakes increase. A tool that identifies a missing signature can usually operate with ordinary staff verification. A system recommending approval of a high-rise tower, industrial facility, or major rezoning should trigger independent technical review, conflict screening, and a written explanation of material assumptions. Any case involving protected characteristics, vulnerable populations, contested facts, or potential safety effects should receive individualized human consideration. Agencies should not use automation to make routine cases more equal while silently allowing exceptional cases to bypass scrutiny. Higher risk calls for stronger documentation and possibly more—not less—human attention.
This approach also gives the public a workable answer to the question of responsibility. The agency is responsible because it selected the objective, supplied lawful authority, configured the workflow, trained staff, monitored results, and issued the decision. The vendor remains responsible for contractual performance, security, accuracy claims, and lawful handling of data. The professional applicant remains responsible for the truth of submitted information. These duties can coexist, but they cannot be merged into the fiction that a neutral algorithm decided the case. A permit becomes defensible when every party performs its assigned function and the final public decision remains connected to evidence, law, and accountable human judgment.
Ultimately, human oversight is valuable not because people are always superior to machines, but because law requires legitimate authority and because public decisions demand reasons, exceptions, and remedies. AI can reduce search time, improve consistency, and help staff manage volume; those benefits are real but conditional. If speed comes from skipping evidence, limiting review, or hiding responsibility, it is not good government. Cities that preserve a qualified official’s meaningful control, publish clear operating rules, test for unequal effects, and maintain genuine appeal rights can adopt AI without surrendering public trust.