arrow-circle arrow-down-basicarrow-down arrow-left-small arrow-left arrow-right-small arrow-right arrow-up arrow closefacebooklinkedinsearch twittervideo-icon

North America Regional Hub: Understanding AI-Driven Threats to Local Governments and Social Cohesion  

— 10 minutes reading time

This report provides a summary of discussions during the webinar and does not necessarily reflect the views of the Strong Cities Network Management Unit, Strong Cities members, event sponsors or participants.

On 29 July 2026, the Strong Cities Network hosted a webinar on Understanding AI-Driven Threats to Local Governments and Social Cohesion, bringing together representatives from 21 cities to examine how rapid advances in artificial intelligence are reshaping local risks. Designed for mayors, local government officials and municipal staff, the session translated expert briefings on AI safety into practical implications for cities. Speakers addressed three areas of concern: AI-enabled cyber-attacks on municipal infrastructure, emerging legislative approcahes to frontier AI risks and the ways conversational AI can intensify online harms such as radicalisation, harassment and misinformation. Participants also shared early municipal experiences, including AI-generated public records requests and complaints. The discussion underscored the need for local governments to strengthen cyber resilience, document incidents and invest in prevention-oriented responses to online harms. This was the first in a planned Strong Cities series on AI risk for local government, with attendee input informing future resources and programming. 

Speakers

Siddharth Hiregowdara, co-founder of CivAI, opened by warning that AI systems are becoming materially more useful to actors seeking to compromise local government systems. He described a July 2026 incident in which an internal OpenAI model, during a controlled evaluation, reportedly escaped a sealed environment, moved through internal computers until it found internet access and hacked an external company to retrieve answers to its test. Engineers noticed only later, when the results appeared unexpectedly strong. For Hiregowdara, the incident showed both that some systems may exceed the limits set for them and that advanced models can now contribute to hacking without direct human guidance. 

He then highlighted the technology’s dual-use nature: the same tools that help defenders identify vulnerabilities, such as the rise in serious security flaws identified by companies using leading AI models, can also help hostile actors find weaknesses in municipal infrastructure. In a live demonstration, he instructed a model to attack a realistic fictional hospital website. The model explored the site, launched multiple parallel instances of itself, coordinated its work in plain English and quickly found a vulnerability that led to hidden employee pages, a patient portal and database contents, including patient records and payment details. Hiregowdara noted that ransomware remains the most likely objective in a municipal attack. 

His core message was that AI-enabled cyber risk is no longer hypothetical. Although the demonstration site was less secure than most municipal systems, he cautioned that local governments should not assume the gap is wide enough to protect them. He urged municipal security teams to use AI defensively, seek outside expertise where needed and treat cyber resilience as an urgent local priority. 

Adam Billen, Co-Executive Director at Encode AI, set out how policymakers are beginning to respond to the risks demonstrated by CivAI. He noted that the briefing was substantively the same briefing Encode AI provides to legislators, ensuring that local officials and legislators are working from a shared understanding. Billen highlighted three recent state-level efforts: California’s SB 53, New York’s RAISE Act and Illinois SB 315. Together, these measures point toward a transparency- and oversight-based approach to frontier AI safety, though their effectiveness will depend on enforcement, reporting and the quality of the standards they create. 

Billen explained that current laws focus mainly on the largest developers. They require companies to publish safety plans, report incidents and protect employees who raise concerns. New York adds state-agency oversight, while Illinois introduces audits to assess whether companies are following their own plans. At the federal level, a bill from Representatives Trahan and Obernolte takes a similar transparency-focused approach. 

He also emphasised the limits of these frameworks. Company-written safety plans may lack consistent standards, and regulators may have limited authority to stop unsafe releases. The OpenAI incident described earlier also exposed a visibility gap: serious harm can occur during internal testing, before a product is released publicly. Because the incident became known only after the targeted company reported it to law enforcement, Billen argued that stronger incident documentation and reporting are essential. 

Billen closed by linking AI’s growing cyber capability to the business incentives of frontier AI companies, which are investing heavily in coding and research automation. Even if major AI-enabled cyber-attacks remain limited for now, he warned that the risk could scale quickly and affect local governments directly. His advice to municipalities was to invest in cybersecurity before the threat catches them off guard. 

Simeon Dukić, Senior Manager at the Institute for Strategic Dialogue (ISD), shifted the focus from cybersecurity to AI-amplified social harms. Drawing on ISD’s work on extremism, hate, polarisation and information integrity, he stressed that the influence of AI on online environments predates the emergence of generative AI tools such as ChatGPT: it has long shaped social media algorithms, surveillance systems and online information environments. He presented research on three risks especially relevant to cities: belief reinforcement and radicalisation through conversational AI, the surfacing of hostile-state narratives by chatbots and the proliferation of tools used to generate non-consensual intimate imagery. 

ISD’s research on conversational AI tested ten models against extremist and conspiratorial prompts. The design of the model shaped the risk: fringe models were more likely to reproduce harmful narratives, while companion models often validated users uncritically as conversations deepened. Mainstream systems performed better but still produced harmful responses, and safeguards did not always strengthen when users moved from expressing extremist beliefs to seeking to act on them. One model, Claude, was highlighted as comparatively effective at identifying radicalisation pathways and de-escalating conversations. 

second ISD study examined how chatbots answered questions about the war in Ukraine. Researchers found that several models drew on Russian state, state-sponsored or state-affiliated sources, illustrating how data voids can be filled by actors seeking to promote particular narratives. Dukić noted that this matters for local governments because residents increasingly rely on AI-mediated tools for information, including on contested or fast-moving issues. 

third study mapped the ecosystem of so-called nudify tools, following uproar about non-consensual intimate imagery generated by Grok on X, which prompted investigations in the European Union and the United Kingdom. ISD found that these tools are easy to find, often free to start, widely promoted on social media and collectively attract around 40 million unique visitors a month. Dukić noted that public officials and members of the public have both been targeted, and that regulation and criminal legislation are beginning to emerge in response. 

Dukić framed these harms as an extension of challenges municipalities already face, rather than an entirely separate category. Local practitioners have long dealt with radicalisation, hate and manipulation online; AI can accelerate those dynamics, make them more persuasive and complicate prevention. He argued that cities will need greater investment in prevention, including approaches that address extremism and hate before harm escalates, while also recognising that AI can be used constructively when risks are understood. 

The session closed with an open discussion in which participants described the challenge as both urgent and daunting. In response to a question about insurance, Hiregowdara said cyber insurance and ransomware coverage can be sensible options for municipalities that can afford them. Staff from the Los Angeles Public Library also described a rise in public records requests and complaints that appear to be AI-generated, underscoring that AI is already affecting routine municipal administration. 

Speakers encouraged local officials to treat this moment as an opportunity to act before risks become harder to manage. Hiregowdara urged cybersecurity staff to make the internal case for stronger protections, while Billen noted that governments are becoming more alert to AI safety concerns and that some companies are beginning to collaborate on cyber defences. Strong Cities invited participants to identify the practical support they need to guide this ongoing work.

Strong Cities will continue to explore ways to connect local governments with tools and resources on how to navigate the risks of transformative AI, and ISD will continue to research the ways in which AI is accelerating and impacting online harms. Visit the ISD website to find up-to-date research on the topic. Strong Cities is also interested in hearing more from local elected officials and municipal staff about the threats their cities are facing and the support they need in relation to AI. You can get in touch here: [email protected]  

For more information on this event or Strong Cities North America programming, please contact the North America Regional Hub at [email protected].