News
Ostrołęka City Hall Uses ChatGPT but Skips Cybersecurity Oversight of Local Units

Ostrołęka City Hall admitted it doesn't verify where the AI models used by its staff come from and doesn't monitor ransomware defenses at the units it oversees. The case fits a nationwide pattern recently exposed by Poland's Supreme Audit Office (NIK).
Ostrołęka City Hall uses ChatGPT and a voicebot to handle resident inquiries, but as it admitted in response to questions, it carries out no verification of where the artificial intelligence models used by its staff come from, and does not oversee ransomware protections at the units under its authority.
What the city hall disclosed
The information comes from Ostrołęka City Hall's response to questions from the eOstroleka.pl news portal. The city hall described how it uses AI-based tools: a voicebot handles part of the traffic on the office's helpline, while access to ChatGPT is limited to selected employees who have previously completed training on the safe use of such tools.
The problem arises when it comes to the question of where those models come from. The city hall admitted outright that it does not carry out any separate verification of whether the AI models it uses were developed outside the European Union. That matters, because the EU's AI Act and national cybersecurity regulations are placing growing emphasis on the origin and supply chain of AI systems used in public administration.
A gap in ransomware oversight
The second, more serious issue is the city hall's response to a question about oversight of ransomware protection at units under the city's authority, including schools and other municipal facilities. The city hall stated outright that it exercises no such oversight. It also has no knowledge of how much these units spend on security safeguards and protective mechanisms.
That means the city's central administration does not know how well, or how poorly, the IT systems of schools and other entities it formally oversees are protected. In practice, each of these units handles cybersecurity on its own, without uniform standards imposed and monitored centrally.
Not just Ostrołęka
Ostrołęka is not an isolated case. A few days earlier, NIK, Poland's Supreme Audit Office, published the results of an audit of the Cyberbezpieczny Samorząd program, which provides funding to gminas (Poland's basic local government units) and counties to improve resilience against cyberattacks. NIK audited 19 entities: 12 gmina offices, 5 county administration offices, and the Centrum Projektów Polska Cyfrowa (Digital Poland Projects Centre) and NASK, Poland's national research institute.
The results are not encouraging. In 8 of the 19 audited offices, or 47 percent, the mandatory information security audit had not been carried out. More than half of the audited units had never implemented the required Information Security Management System. Among the 17 offices with the highest grant values, totaling 13 million zlotys, irregularities were found at 6, or 36 percent, including unauthorized equipment purchases and false declarations about security measures that had supposedly been implemented.
Why it matters
According to NIK data, the Cyberbezpieczny Samorząd program itself covered 2,490 projects worth a total of 1.47 billion zlotys as of the end of August 2025, of which 62.4 percent of the budget had been used. That illustrates the scale of public money flowing to local governments for cybersecurity improvements, alongside a lack of certainty over whether those funds are actually translating into better protection.
For public administration, this is a two-fold problem: on one hand, offices are increasingly turning to AI tools like ChatGPT and voicebots to improve services for residents, while on the other, those same offices often lack basic oversight mechanisms for the security of systems they manage directly or indirectly. Rolling out new tools without strengthening oversight expands the potential attack surface rather than shrinking it.
Since April 3, 2026, wójts, mayors, and city presidents (the heads of Poland's local governments) have borne personal financial liability for the state of cybersecurity in their units, under an amendment to the National Cybersecurity System Act that brings Polish law in line with the EU's NIS2 directive. The Ostrołęka case shows that despite this change, gaps in basic oversight still exist, including in places where local governments are simultaneously rolling out new AI tools.

