Oxford Insights, the British research firm that has spent years ranking national governments on how prepared they are for artificial intelligence, is now building the same kind of measure for cities. The firm published the proposal on 6 October, arguing that the level of government people actually deal with has no agreed way of judging whether it can run AI safely.
"Cities are where most people deal with government, yet there has been no shared way to judge how ready they are for AI," said Richard Stirling, the firm's chief executive. The six cities that went into the study were Abu Dhabi, Seoul, London, Montreal, Helsinki and Tallinn. All six turned out to care about the same four things, governance, funding, talent and infrastructure, and all took different routes through them.
Out of that comparison came four categories. Platform cities lead with infrastructure, cognitive cities with research, and delivery cities organise around services. Strategic cities put AI at the centre of how the government and the economy are planned, and Abu Dhabi and Seoul sit in that last group.
London's entry is the one that shows what the framework is for. The city has deep research and business strength, set up digital leadership early, and runs solid data infrastructure through the London Datastore and the London Office of Technology and Innovation. It still has no dedicated AI strategy, and its AI work is scattered across broader programmes rather than coordinated in one place.
The firm now plans to test the six-pillar framework across 15 to 20 cities. It built the work with the Mohamed bin Zayed University of Artificial Intelligence and Khalifa University, and Abu Dhabi was the city it examined in most depth.
Cities Are Already Buying
The gap the report describes is not ahead of the market. It is behind it. Around two thirds of local government leaders were already putting AI into municipal operations by the time Ernst & Young surveyed them in 2025. The procurement tracker Civic IQ counted more than 1,000 buying signals from American cities and counties inside a 180-day window.
The money involved is modest by enterprise standards and real by municipal ones. Chatbot projects run from $30,000 to $250,000, licences for tools such as Microsoft Copilot or Google Gemini cost $50,000 to $500,000 a year, predictive analytics for traffic and public safety runs from $100,000 to $800,000, and multi-year asset management work passes $1M.
What cities buy first says something. The strongest single signal in that data is spending on AI governance policy, between $25,000 and $150,000 a time. Councils are paying consultants to write the rules before they buy the systems those rules will cover.
The applications themselves are unglamorous and useful, and they sit alongside the physical systems a city buys at scale. Chatbots answer permit questions and staff the 311 non-emergency lines American residents call about potholes and rubbish collection, and Los Angeles, Austin and Honolulu have all put AI into planning and permitting.
The Exposure Is Already Inside
The more uncomfortable finding is what municipal staff are doing without being asked. Research cited by the National League of Cities found that 68% of employees use free-tier AI tools through personal accounts rather than anything their employer approved, and that 57% put sensitive data into those tools.
The cost when that goes wrong is measurable. Security incidents involving AI ran about $670,000 above the average breach. In 97% of them, the AI system had no proper limit on what it could reach.
That reframes what a readiness index would be measuring. A city is not deciding whether to start using AI, but whether to acknowledge the use already happening. The question is where an agent's authority ends, rather than what the strategy document says.
It also explains why governance consulting leads the spending. Councils are discovering the exposure before they have decided what they want to build.
Who Paid, And What An Index Sells
One detail in the announcement is worth stating plainly, because readers can weigh it themselves. Abu Dhabi is the city Oxford Insights examined in most depth, and it is one of two cities the framework places in its strategic category, the group where AI sits at the centre of government and economic planning. The two academic partners on the work, the Mohamed bin Zayed University of Artificial Intelligence and Khalifa University, are both Abu Dhabi institutions.
Nothing in that makes the analysis wrong, and the firm has not published what the arrangement was worth. It does mean the deep-dive city, the research partners and one of the top classifications all point to the same place, which is the kind of thing a reader comparing city rankings would want to know.
The firm's national index has drawn its own methodological scrutiny over the years, largely because ranking governments against each other requires judgements that are not purely technical. A city index inherits every one of those difficulties and adds the problem that cities differ enormously in what powers they actually hold.
The four-category structure is the part that reveals most about how this is built to work. A ranking that simply orders cities first to last produces one winner and a long tail of losers, and the losers stop participating. Sorting cities into platform, cognitive, delivery and strategic types means a city that scores poorly overall can still be told it is a different kind of city rather than a worse one.
That is genuinely more useful than a single league table, because a port city with devolved transport powers and a capital with none are not attempting the same thing. It also makes the index far more durable as a business, since every city has a category to belong to and a reason to keep taking part. Oxford Insights sells advisory work alongside the research, which is the ordinary model for this kind of firm and the reason the measure and the remedy tend to arrive together.
What Would Make It Matter
An index becomes consequential when somebody spends money because of it. The national version is cited widely in policy documents, which is influence of a sort, though citation is cheaper than adoption. The test for the city version is narrower: whether a council uses it to decide what to procure, or a national government uses it to allocate funding between cities.
Neither can be observed yet. The framework has been applied to six cities, with 15 to 20 more planned. Whether a shared readiness measure changes what cities actually buy will take considerably longer to answer than building the measure did.