ANALYSIS Wisconsin Assembly Bill 487 / Senate Bill 633 Closed Sessions for Information Technology Security Issues Prepared January 13, 2026
EXECUTIVE SUMMARY Assembly Bill 487 creates a new exemption to Wisconsin's Open Meetings Law (Wis. Stat. § 19.85(1)(i)) and Public Records Law (Wis. Stat. § 19.36(17)) for "information technology security issues." This analysis identifies significant legal and policy concerns with the bill as drafted. Issue
Summary Concern
Constitutional Tension
May conflict with Wisconsin Constitution Art. IV, § 10 requiring legislative doors remain open "except when the public welfare requires secrecy." Unclear if IT security meets this high constitutional threshold.
Vagueness
"Information technology security issues" is undefined and could encompass virtually any discussion involving computers, networks, or electronic systems.
Overbreadth
Amendment AA1-AB487 extends to ALL governmental bodies, creating a statewide blanket exemption far broader than existing closed-session exceptions.
No Balancing Test
Unlike existing exemptions requiring specific showings (e.g., "substantial adverse effect"), this exemption has no requirement to demonstrate public disclosure would actually cause harm.
Election Transparency
Specifically shields Elections Commission discussions of voting system security from public scrutiny, potentially undermining citizen oversight of election integrity.
1. CONFLICT WITH STATE LAW AND POLICY 1.1 Wisconsin's Strong Presumption of Openness Wisconsin Statute § 19.31 declares: "[A]ll persons are entitled to the greatest possible information regarding the affairs of government and the official acts of those officers and employees who represent them." The statute further mandates that public records law 1
"shall be construed in every instance with a presumption of complete public access, consistent with the conduct of governmental business. The denial of public access generally is contrary to the public interest, and only in an exceptional case may access be denied." Similarly, the Open Meetings Law under Wis. Stat. § 19.81(1) provides that the public is entitled to "the fullest and most complete information regarding the affairs of government as is compatible with the conduct of governmental business."
1.2 Exemptions Must Be Strictly Construed Wisconsin courts and the Attorney General consistently hold that exemptions to open government laws must be "strictly construed" and "invoked sparingly and only where necessary to protect the public interest." State ex rel. Hodge v. Turtle Lake, 180 Wis. 2d 62, 71 (1993). The Wisconsin DOJ Open Meetings Law Compliance Guide states: "If there is any doubt as to whether closure is permitted under a given exemption, the governmental body should hold the meeting in open session."
1.3 AB487 Departs from Existing Exemption Standards Existing closed-session exemptions under § 19.85(1) require specific showings: •
§ 19.85(1)(f): Requires discussion "would be likely to have a substantial adverse effect upon the reputation" of a person • § 19.85(1)(e): Requires "competitive or bargaining reasons" • § 19.85(1)(g): Limited to legal strategy in "litigation in which [the body] is or is likely to become involved" AB487's proposed § 19.85(1)(i) requires NO such showing - merely that the matter involves "information technology security issues," with no requirement to demonstrate actual harm would result from public discussion.
2. CONSTITUTIONAL CONCERNS 2.1 Wisconsin Constitution Article IV, Section 10 The Wisconsin Constitution, Art. IV, § 10, provides that "the doors of each house shall remain open, except when the public welfare requires secrecy." Wisconsin Statute § 19.81(3) explicitly acknowledges this constitutional provision and declares the legislature's intent "to comply to the fullest extent" with open government requirements. Constitutional Question: Does routine discussion of "information technology security issues" - a term covering everything from password policies to software updates - rise to the level where "public welfare requires secrecy"? The constitutional standard suggests secrecy should be reserved for extraordinary circumstances, not normalized as a routine exemption category.
2
2.2 First Amendment Considerations While the First Amendment does not create an absolute right of public access to government proceedings, courts have recognized that transparency in government is fundamental to democratic self-governance. Restricting public access to discussions about election systems, which directly affect citizens' voting rights, raises heightened scrutiny concerns about the public's ability to monitor the integrity of democratic processes.
3. VAGUENESS AND OVERBREADTH 3.1 Undefined Key Term The bill provides no definition of "information technology security issues." This undefined term could reasonably encompass: • • • • • •
Any discussion of computer systems, networks, or electronic equipment Budget discussions involving IT purchases Vendor selection and contract negotiations for technology Discussions of data retention, backup, or storage policies Any policy involving electronic records or communications Training, staffing, and personnel decisions related to IT
3.2 Amendment AA1-AB487 Expands Scope Dramatically The December 17, 2025 amendment offered by Rep. Gustafson adds proposed § 19.85(1)(j), which extends closed-session authority from just five named entities to "any governmental body" for IT security discussions. This transforms a limited exemption into a statewide blanket exception applicable to thousands of governmental bodies across Wisconsin, from the legislature down to local school boards, town boards, and special districts.
3.3 Contrast with Properly Narrow Exemptions Well-drafted exemptions are narrowly tailored. For example, existing § 19.85(1)(b) permits closed sessions only for "dismissal, demotion, licensing or discipline" of specific employees, not general "personnel matters." Similarly, § 19.85(1)(g) covers only "litigation in which [the body] is or is likely to become involved", not all legal matters. AB487's "information technology security issues" has no such limiting principle.
4. ELECTION TRANSPARENCY CONCERNS 4.1 Wisconsin Elections Commission Coverage AB487 specifically names the Wisconsin Elections Commission as one of the five entities authorized to meet in closed session for IT security discussions. Given that the 3
WEC oversees voting equipment certification, post-election audits, and election system security, this creates a mechanism to conduct these discussions outside public view.
4.2 Public Oversight of Election Systems Wisconsin law currently requires extensive public transparency in election administration: •
Post-election voting equipment audits must be conducted "as part of a public meeting" (WEC Audit Guidelines) • Voting equipment certification decisions are made in public proceedings • Election results, recounts, and canvassing are public processes AB487 could allow WEC to shield discussions of voting machine vulnerabilities, security assessments, vendor relationships, and remediation decisions from public scrutiny precisely the areas where citizens have the greatest interest in transparency.
4.3 Records Exemption Creates Permanent Secrecy Proposed § 19.36(17) creates a public records exemption for "records regarding information technology security issues that are considered in closed session." Unlike a closed meeting (which is temporary), a records exemption creates permanent inaccessibility. Citizens would have no mechanism to ever obtain records of what was discussed, decided, or spent regarding election system security.
5. CONCERNS FROM A CITIZEN'S PERSPECTIVE 5.1 Taxpayer Accountability Technology represents significant public expenditure. Under AB487, citizens may be unable to access information about: • • • • •
How public funds are being spent on IT systems What security vulnerabilities exist in systems they paid for Whether vendors are meeting contractual security obligations What remediation efforts (and costs) are undertaken when problems occur Decision-making processes for selecting and certifying voting equipment
5.2 "Summary" Publication Is Inadequate The bill requires periodic publication of "summaries" with "sufficient alterations... to prevent disclosing confidential, proprietary, and other sensitive information." This is not meaningful transparency, the government decides what to disclose, how to characterize it, and what to redact. There is no mechanism for citizens to verify the accuracy or completeness of these summaries, nor any enforcement mechanism if summaries are inadequate.
4
5.3 Security Through Obscurity Is Poor Policy Cybersecurity experts widely reject "security through obscurity" as a primary defense strategy. Robust security comes from strong systems, not from hiding information. Public discussion of security challenges can actually improve security by engaging stakeholder expertise, ensuring accountability, and preventing complacency.
6. POTENTIAL ABUSE SCENARIOS Without clear definitional boundaries or harm-based requirements, AB487 creates opportunities for abuse: 1. Budget Obfuscation: IT spending decisions could be made in closed session as "security issues," shielding expenditure decisions from taxpayer scrutiny. 2. Vendor Protection: Discussions of vendor performance, contract disputes, or procurement could be characterized as "security issues" to avoid public embarrassment or accountability. 3. Policy Avoidance: Controversial policy decisions with IT components could be shifted to closed sessions to avoid public debate. 4. Election Manipulation Concealment: Problems with voting equipment could be discussed and "resolved" without public knowledge. 5. Whistleblower Suppression: Records exemption could prevent documentation of security concerns raised by employees or contractors from becoming public.
7. Federal Election Law Conflicts First: Federal HAVA 52 U.S.C. § 21112 requires states receiving HAVA funds to maintain "uniform and nondiscriminatory" administrative complaint procedures allowing "any person who believes that there is a violation of any provision of [Title III]... may file a complaint." Argument: If information about voting system security issues is shielded from public access under AB487, citizens may be unable to obtain the information necessary to identify HAVA violations and file complaints. The complaint procedure becomes hollow if the underlying facts are secret. HAVA complaints themselves are treated as public records in most states (e.g., Washington State's HAVA complaint form states: "This complaint is not confidential, and once filed, shall be treated as public record"). AB487's records exemption could conflict with this transparency principle.
5
Second: State Plan Public Notice Requirements 52 U.S.C. § 21004(a)(11) and § 21006 require that state plans - and any "material change" to them - be:
Published in the Federal Register Subject to "public notice and comment"
Argument: If the Wisconsin Elections Commission discusses and makes decisions about election administration procedures (which could constitute "material changes" to Wisconsin's HAVA state plan) in closed sessions, and those records are exempt from disclosure, this could conflict with HAVA's requirement for public transparency in state plan development and modification.
Third: Detection of Discrimination Argument: Section 2 of the VRA (52 U.S.C. § 10301) prohibits voting practices that "result in a denial or abridgement of the right... to vote on account of race or color." If voting system malfunctions or security vulnerabilities disproportionately affect minority communities, shielding that information from public access could:
Make it harder for DOJ to identify potential Section 2 violations Prevent civil rights organizations from gathering evidence for enforcement actions Allow discriminatory impacts to go undetected and unremedied
8. CONCLUSION This is a horrible bill. Assembly Bill 487, particularly with Amendment AA1-AB487, represents a significant departure from Wisconsin's strong tradition of open government. The bill's vague terminology, lack of harm-based requirements, and broad applicability create a new category of government secrecy with minimal safeguards against abuse. The specific inclusion of the Elections Commission raises particular concerns about public oversight of election integrity. Wisconsin's open government laws are built on the principle that "denial of public access generally is contrary to the public interest, and only in an exceptional case may access be denied." AB487 inverts this presumption by creating a broad categorical exemption without requiring any showing that public discussion would cause actual harm. Representatives considering this bill should weigh whether the asserted benefits of secrecy outweigh the significant costs to democratic accountability and citizen oversight, particularly regarding the administration of elections.
6
LEGAL CITATIONS Wisconsin Constitutional and Statutory Provisions: • Wis. Const. Art. IV, § 10 (legislative doors to remain open) • Wis. Stat. § 19.31 (Public Records Law declaration of policy) • Wis. Stat. § 19.35 (Public Records Law access provisions) • Wis. Stat. § 19.36 (Public Records Law limitations on access) • Wis. Stat. § 19.81 (Open Meetings Law declaration of policy) • Wis. Stat. § 19.85 (Open Meetings Law exemptions) • Wis. Stat. § 19.851 (Ethics Commission and Elections Commission closed sessions) Case Law: • State ex rel. Hodge v. Turtle Lake, 180 Wis. 2d 62, 508 N.W.2d 603 (1993) (exemptions strictly construed) • Schill v. Wisconsin Rapids Sch. Dist., 2010 WI 86, 327 Wis. 2d 572 (Wisconsin's strong commitment to transparent government) Legislative Materials: • 2025 Assembly Bill 487 (LRB-3148/1); 2025 Senate Bill 633 (LRB-4704/1) • Assembly Amendment 1 to AB487 (LRBa0686/1) • Wisconsin DOJ Open Meetings Law Compliance Guide (March 2025) • Wisconsin DOJ Public Records Law Compliance Guide (June 2025)
Peter Bernegger President Election Watch, Inc.
7