From Shadow to Institutional AI

Notes from NCSL and IPU meetings, and what parliaments should already be discussing before their next meeting

BY BEATRIZ REY

In my last piece, I reported and reflected on how legislatures across the globe are starting to decide how, when, and how much AI can be used in legislative processes. That shift was already visible in April at the Inter-Parliamentary Union (IPU)’s 152nd Assembly in Turkey: after adopting somewhat independent AI tools and initiatives to improve legislative processes, parliaments are now turning to how to govern these.

The same pattern held a month later at the in-person meeting of the IPU’s in-person meeting of its Centre for Innovation in Parliament’s (CIP) Parliamentary Data Science Hub, which occurred at the Chamber of Deputies of Italy in Rome. The meeting gathered senior officials from 23 parliaments from Africa, the Americas, Europe, and the Middle East.

Following preliminary data from the IPU’s World e-Parliament Report 2026, according to which 88% of parliaments report using AI, the discussion revealed that AI adoption is outpacing AI governance. A report from the CIP meeting goes as far as to discuss the existence of a “shadow AI,” whereby staff and MPs use their own, unsanctioned tools. Shadow AI, they write, is not so much a problem as a signal that official supported tools are not meeting users’ needs.

To learn how this tension between adoption and governance is playing out in the United States, I chatted with POPVOX Foundation’s Program Associate Caitlin McNally, who writes the excellent State of the Art newsletter and attended the National Conference of State Legislatures (NCSL) Legislative Summit in Chicago in late July.

My first question was whether she observed a similar development in state legislatures as the one I reported on. Although she didn’t observe anything happening in states per se, she joined a presentation that is aligned with the movement that I described in my last piece.

At NCSL, Mark Egge, who calls himself an “AI evangelist,” argued that blanket human-in-the-loop requirements are becoming outdated, and that the review burden should scale with the stakes of the decision instead of applying uniformly. I’ve reached out to him to understand exactly what he means, but this is how I read it: as AI systems earn a track record, the threshold for what counts as high-stakes keeps rising, so fewer decisions require mandatory human review each year, until the human-in-the-loop stops functioning as a rule and becomes one input among several used to route a decision.

Chile has taken a harder line: its Chamber of Deputies requires every institutional document to carry a color-coded declaration of AI involvement, and anything in the fully-automated category loses institutional value outright, unable to be cited as an official source no matter how sound the output is.

Egge’s take and Chile’s policy are each trying to answer the same underlying question. How much human review does AI output deserve? Human-in-the-loop is only a question when the boundary between human and AI authority isn’t built into the system itself – when each part of the institution has to settle it on its own. What is missing is a framework that unites existing AI tools and initiatives inside a legislature and gives them a shared architecture, with the potential to replace the siloed mix of tools and policies each office has picked up independently.

Human-in-the-loop is only a question when the boundary between human and AI authority isn’t built into the system itself…

This is close to what POPVOX Foundation has been developing under the name “Institutional AI” – a framework that treats AI for parliaments as its own category, distinct from the consumer chatbots staff might otherwise reach for and the enterprise tools vendors sell to executive agencies. The distinction speaks directly to the shadow AI problem: a consumer tool has no access to a committee’s own record, so a staffer using one to draft a memo is, by definition, working outside the institution.

Institutional AI is built to operate on the parliament’s own structured record instead: ask it where a bill stands and it answers from the chamber’s own record of who has it and what happened to it, not from an external chatbot’s best guess at what “in committee” means.

The framework also complicates Egge’s read on human-in-the-loop. Rather than treating human review as a blanket rule that recedes as trust in AI grows, Institutional AI fixes it structurally: some functions, such as voting, signing, and authenticating the official record, stay exclusively human, permanently by design, while others, like drafting or oversight monitoring, become more AI-assisted depending on the stakes. That is a version of “review scales with the decision,” but built to last rather than to bridge to something else.

Mauritius has already built something close to Institutional AI, on its own. Its National Assembly put a governance framework in place before deploying anything, then produced a generative AI portal running on its own structured parliamentary data. It’s almost like POPVOX Foundation designed the theory and Mauritius built the first application. Neither knew about the other when they got there – a sign, maybe, that there aren’t many other shapes this architecture could take.


Modern Parliament (“ModParl”) is a newsletter from POPVOX Foundation that provides insights into the evolution of legislative institutions worldwide. Learn more and subscribe at modparl.substack.com.

Previous
Previous

Digital Parliaments Project Launches in Africa with Workshop in Accra

Next
Next

AI and Legislative Modernization Workshop with Balkan and Moldovan Parliaments