01The state of AI in government
Government adopted AI faster than it governed it. Across federal, state and local tiers, agencies already use language models to draft correspondence, summarise submissions and triage requests, sometimes through sanctioned pilots, sometimes through whatever browser tab a time-poor officer has open. The difference from the private sector changes everything: when a government system misfires, the consequences land on citizens who cannot take their business elsewhere, and the accountability lands in parliament.
The gap between experimentation and production keeps widening. Most agencies can point to a promising proof of concept. Far fewer can point to an AI system operating on live citizen data with the written sign-off of their privacy, security and legal functions. Pilots stall at the moment they need to touch real records, because that is when the hard questions arrive. What will the model see? Under whose authority? What happens when a parliamentary committee asks how an output was produced?
Meanwhile expectations keep rising. A citizen renewing a licence or applying for support compares the experience with their bank, not with other governments. They expect services to know who they are and to resolve matters in days, not months. Yet agencies carry some of the oldest technology estates in the economy and are being asked to deliver the newest kind of service on top of them.
That tension, between what citizens expect and what agency data can support, is the real subject of enterprise AI in government. It is not a model problem. It is a data and governance problem, and it is solvable with the right infrastructure.
02Why public-sector data is different
Every large organisation has fragmented data. In government, fragmentation is a feature of the system's design, not an accident of history. Five characteristics explain why approaches imported from the private sector keep failing.
Fragmentation is structural. A national government is not one enterprise but hundreds of agencies across three tiers, each with its own legislation, budget and technology estate, and each holding a partial view of the same citizen. Machinery-of-government changes split and merge departments; the systems rarely merge with them. The same person is a taxpayer in one system, a patient in another and a licence holder in a third, under identifiers never designed to meet.
The estates are old. Core registries, payment engines and case management systems in many agencies predate the web. They persist because they work, but they describe the world in schemas designed decades ago, through interfaces built for batch processing rather than conversational AI. Any strategy that begins by replacing them is a decade-long programme before the first benefit lands.
Sharing is limited by law, not preference. Data collected for taxation cannot flow freely into other uses. Secrecy provisions, purpose limitations and privacy principles bind agencies in ways no corporate data team encounters, and inter-agency sharing typically requires legislative authority or formal agreements, not goodwill between CIOs.
Classification adds a second regime. On top of privacy law sits protective security. Each classification level carries its own handling, storage and access requirements, and an AI system that mixes material across classification boundaries is not a productivity tool, it is a security incident.
Trust cannot be rebuilt quickly. Citizens do not volunteer their data to government, they are compelled to provide it. That creates an obligation beyond compliance: one high-profile failure erodes public consent for every data initiative that follows. Agencies are right to be cautious. The question is whether caution has to mean paralysis.
03What governed AI could deliver
The case for solving these constraints is the scale of what becomes possible once agency data can be used safely.
Integrated citizen services stop being a slogan. When systems share meaning, a citizen can tell government something once and have it recognised everywhere the law permits, and staff see one coherent picture instead of six applications.
Casework moves at the speed of the queue, not the backlog. AI that reads, summarises and routes applications, claims and appeals against governed data lets experienced officers spend their judgement on difficult cases rather than the paperwork of easy ones.
Programme integrity improves before payments go out. Errors and improper payments are caught while a claim is in flight, when correction is cheap and dignified, rather than years later through debt recovery.
Regulatory processing accelerates. Licences, permits and registrations are high-volume, document-heavy and rule-bound, exactly the workloads language models handle well when the rules and records they draw on are consistent and access is controlled.
Records start answering questions. Freedom-of-information regimes give citizens a legal right to government records, and AI that searches, classifies and prepares material across governed archives turns an obligation that consumes staff into a service that builds trust.
And policy gets evidence at the pace of events. Analysts advising ministers can interrogate live, governed data across programmes instead of commissioning extracts that arrive after the decision has been made.
04Why initiatives stall
So why do most public-sector AI initiatives still die between pilot and production? Five blockers recur, and none is solved by a better model.
Whole-of-government centralisation is not available. The default private-sector answer to fragmentation is consolidation into one corporate estate. Government cannot pool citizen data across agencies that way: legal limits on sharing, sovereignty obligations and classification boundaries mean citizen data must stay under the legal authority that collected it. Any approach that moves records outside that authority, or into an environment the agency does not control, fails before the diagram is finished. Unification has to happen inside each agency’s own accredited environment, where the law permits.
Accountability demands explainability. Administrative decisions are reviewable by design. Courts, tribunals and ombudsmen can require an agency to explain how a decision was reached, and a decision that cannot be explained cannot be defended. An AI system whose inputs, access authority and reasoning path cannot be reconstructed is unusable for consequential decisions.
Procurement and assurance run on their own clock. Security assessment, privacy impact assessment and procurement rules exist for good reasons, but they were designed for systems that change yearly, not weekly. A pilot built in weeks can take months to assess, and by then the sponsoring executive has often moved on.
Skills are scarce on the inside. Agencies compete for the same engineers as the private sector with tighter salary bands, so deep AI capability tends to sit with vendors. Agencies need architectures they can govern and operate without a permanent bench of specialists.
And the memory of past failures is institutional. Every public servant knows the history of technology programmes that overran their budgets and promises, and Australia's Royal Commission into the Robodebt scheme documented what happens when automation meets citizen data without adequate governance. The lesson agencies drew is the right one: the risk is not using AI, it is using it ungoverned.
05The assurance landscape
Public-sector AI operates inside a lattice of obligations, and that lattice looks different in every country even as its shape stays remarkably constant. The named laws and agencies change from one jurisdiction to the next, but the categories they cover, data protection, AI-specific assurance, protective security and administrative accountability, line up closely. Reading the major regimes side by side is the quickest way to see what any agency has to satisfy.
Data-protection law governs how agencies collect, use, disclose and secure personal information, and every jurisdiction has its own. In the United States the Privacy Act of 1974 controls how federal agencies hold and disclose records retrieved by a person’s identifier. In the European Union the General Data Protection Regulation, Regulation (EU) 2016/679, binds most of the public sector, and the United Kingdom carries the same rules into domestic law through the UK GDPR and the Data Protection Act 2018. In Australia the Privacy Act 1988 and its Australian Privacy Principles do the equivalent work, overseen by the Office of the Australian Information Commissioner. The use and disclosure principles matter most for AI: information collected for one purpose cannot be freely repurposed as model input, and an agency must be able to show what a system used and why.
Public-sector AI assurance frameworks are the newer layer, written specifically for AI. In the United States the National Institute of Standards and Technology publishes the voluntary AI Risk Management Framework (AI RMF 1.0), and the Office of Management and Budget’s memorandum M-24-10 requires federal agencies to name a Chief AI Officer, inventory their AI use cases and apply extra safeguards to rights- and safety-impacting uses. In Canada the Treasury Board’s Directive on Automated Decision-Making sets graduated obligations for systems that make administrative decisions, backed by a mandatory Algorithmic Impact Assessment. In Australia the Digital Transformation Agency’s assurance framework names accountable officials and a common method for assessing use cases against agreed principles. The detail varies by government, but the expectation that a named official can account for each system is becoming universal.
Protective security and information-handling regimes decide where data may live and which systems may touch it. In the United States FedRAMP sets a standardised authorisation that any cloud service holding federal data must pass. In Australia the Protective Security Policy Framework governs how classified and sensitive information is handled, stored and accessed. In the United Kingdom the National Cyber Security Centre, working alongside the Government Digital Service, issues the secure-design and secure-AI guidance that agencies build to. For AI, where data lives and which systems process it are security decisions before they are technical ones.
Sub-national and sectoral regimes add a further layer for the service delivery that happens below the national tier. State privacy statutes in the United States, provincial regimes in Canada, and state and territory legislation in Australia set the terms on which those agencies share and use data, and a multi-jurisdiction initiative must satisfy every participating regime, not just the national one.
The EU AI Act is the direction of travel. Even for agencies well outside Europe, Regulation (EU) 2024/1689 shows where public-sector AI obligations are heading: many government uses, including access to essential public services, are treated as high-risk and carry duties of logging, human oversight, transparency and data governance. Building to that standard now is cheaper than retrofitting to it later.
The common thread across all of these regimes is evidence: an agency must be able to show what its systems did with citizen data and under whose authority. That cannot be met with policy documents alone. It has to be met with infrastructure.
06The control plane approach in government
The blockers share a shape: AI must work across fragmented systems whose data cannot be centralised, at a speed that still carries its assurance evidence. The architecture that resolves this is the enterprise AI control plane: a governance and orchestration layer between an agency's systems and its AI tools, resolving agency data into one governed, stored semantic layer and controlling how AI uses it. Four properties suit the pattern to government.
Governed unification inside the agency’s own environment. A control plane connects to the agency’s own systems of record and builds a governed, unified semantic layer: the fragmented records a single agency holds about a person, scattered across its registries, case files and line-of-business systems, resolved into one understood view where the law permits. Unification happens within each agency and within the legal boundaries of that agency, never by pooling records across agencies. The unified layer is resolved once and stored inside the agency’s own accredited environment, under its existing legal authority, classification posture and access control, with lineage and audit travelling with the data.
Deployment inside the agency's own tenancy. The control plane runs inside the agency's existing cloud environment, not as an external service. No citizen data is transmitted to or processed on systems outside the agency's control, which keeps sovereignty intact and security assessment scoped to infrastructure the agency already governs.
Access control is inherited, not reinvented. Every AI interaction passes through the agency's existing identity and access management: an officer's copilot sees what that officer is cleared to see, nothing more. There is no parallel permission system to drift out of step, and classification boundaries are enforced in the request path, not by convention.
Audit serves accountability by design. Every access, policy decision and output is recorded in an immutable trail. When a minister is asked how a system behaved, or an auditor-general reviews a programme, the evidence already exists at the level of individual interactions. Accountability stops being a reconstruction exercise.
- Every initiative negotiates data access from scratch
- Citizen records copied into project stores and pipelines
- Access rules re-implemented per project, drifting from the source
- Audit reconstructed manually when parliament asks
- One governed semantic layer spans agency systems
- Records unified and stored in the agency’s own environment under existing legal authority
- Every AI interaction inherits agency IAM and classification
- Immutable audit trail produced continuously, inquiry-ready
Fig. 1 · The same agency estate with and without a control plane. The difference is not capability, it is whether governance is a property of the infrastructure.
DataReadyAI implements this pattern as three layers: a semantic normalisation engine (L1), an AI orchestration engine (L2) and a governance and activation layer (L3), deployed inside the agency's own cloud tenancy on Databricks, Snowflake, AWS, Azure or GCP. No enterprise data is transmitted to or processed on external systems, and we are working with organisations across financial services, insurance and government.
07Use cases in depth
Six workloads recur across agencies, each viable because the control plane resolves the constraints that stalled it before.
A single view of the citizen for service delivery
Front-line staff and digital channels draw on one governed picture of the person they serve, resolved once from the systems that legally hold each fragment, stored in the governed layer and kept continuously current. The citizen stops repeating their story, the agency stops deciding on partial information, and access rules keep the single view from ever becoming a single leak.
Casework triage and backlog reduction
Applications, reviews and appeals are read, summarised and routed against governed records: clear-cut cases prepared for rapid decision, complex ones directed to senior officers with context attached. The value is not removing humans from decisions but removing the reading queue between citizens and the humans who decide.
Programme integrity and payment accuracy
Inconsistencies, duplicate claims and eligibility issues surface while a payment is in flight, when the correction is a conversation rather than a debt notice. Because every flag carries its lineage, integrity teams can show exactly why a case was queried, the difference between defensible assurance and automated suspicion.
Regulatory and licensing processing
Permits, registrations and approvals move through document-heavy, rule-bound assessment that language models handle well when rules and records are consistent. A control plane gives the model the governed version of both, and the regulator a complete record of how each assessment was prepared.
Records, FOI and information access
Freedom-of-information requests require agencies to find, assess and prepare records across decades of archives. AI that searches and classifies within the governed layer cuts the effort per request, while the audit trail documents what was searched and what was withheld under which exemption.
Policy intelligence
Policy teams interrogate live, governed data across programmes to see what is happening: uptake, bottlenecks, outcomes. Advice to ministers rests on current evidence with traceable provenance rather than a quarterly extract from a single system.
08Implementation considerations for agencies
Deployment in government succeeds or fails on sequencing. The technology is the same as the private sector's; the order of operations is not.
- Start with one bounded, high-volume workflow. A single casework queue, one licence class, one records series. Bounded scope keeps assessment tractable, and high volume makes the result measurable within a quarter.
- Connect read-only first. The first phase should observe and unify, not write or act. Read-only connection lowers the assessment's risk profile and lets stakeholders watch the governed layer work before any workflow depends on it.
- Bring privacy and security assessors in from week one. Not as a gate at the end but as participants from the start. Assessors who watch the audit trail being produced sign off faster than assessors handed a finished system, and their requirements shape the deployment while shaping is cheap.
- Publish the audit capability internally. Show legal, risk and executive teams the actual trail: what was accessed, by whom, under which policy. Internal transparency converts sceptics because it shows oversight became stronger, not weaker.
- Expand across programmes once the semantic layer exists. The second use case inherits the semantic model, policy machinery and assessment evidence of the first, and lands in a fraction of the time. The economics of a control plane are the economics of reuse.
The anti-pattern is trying to govern the entire estate before allowing any AI consumption. That is the multi-year programme history warns about. Governance infrastructure is what makes it safe to start small and expand on evidence.
This sequencing is how Sydney-founded DataReadyAI deploys: first value in 2 to 3 weeks and production-grade activation in 6 to 8 weeks, starting read-only against the priority systems. Because everything runs inside the agency’s own tenancy, the same pattern fits a FedRAMP-authorised environment in the United States, the EU AI Act’s governance duties, the United Kingdom’s secure-design guidance or Australia’s Protective Security Policy Framework, without moving citizen data outside the authority that holds it. The platform is cloud- and model-agnostic across Databricks, Snowflake, AWS, Azure and GCP, so agencies keep their existing platform commitments and the freedom to change them.
09Frequently asked questions
Where does unified citizen data live?
Inside the agency’s own accredited cloud environment, whether that is a FedRAMP-authorised tenancy in the United States, an equivalently accredited environment in the European Union or United Kingdom, or one assessed under Australia’s Protective Security Policy Framework. The platform connects to the agency’s systems of record and builds a governed, unified semantic layer there, resolved once and stored under the agency’s existing access control, classification posture and legal authority. Nothing is transmitted to or processed on external systems, and every access is recorded in an immutable audit trail.
How does a control plane support ministerial accountability?
Every AI interaction is recorded in an immutable audit trail: what was accessed, under whose authority, which model produced an output and which policy applied. When a minister, a congressional or parliamentary committee, an ombudsman or an auditor-general asks how a system behaved, the evidence already exists rather than being reconstructed after the fact.
Does this replace our existing data platforms?
No. A control plane sits above the systems an agency already runs: registries, case management, warehouses and cloud platforms. It resolves their data once into a governed, unified semantic layer stored inside the agency's own environment, and configurable projections keep feeding existing reporting and downstream tools. The systems of record remain the systems of record.
How long does deployment take in a government environment?
DataReadyAI's typical pattern is first value in 2 to 3 weeks and production-grade activation in 6 to 8 weeks. Deployment sits inside the agency's own cloud tenancy and connections start read-only, so privacy and security assessment can run in parallel rather than gating the start.
10Sources and further reading
- United States, NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0); the Office of Management and Budget’s Memorandum M-24-10 on agency use of AI; FedRAMP; and the Privacy Act of 1974.
- European Union, Regulation (EU) 2024/1689 (the EU Artificial Intelligence Act), which treats many public-sector uses as high-risk, and Regulation (EU) 2016/679 (the General Data Protection Regulation).
- United Kingdom, the Government Digital Service’s Artificial Intelligence Playbook for the UK Government and National Cyber Security Centre AI guidance, under the UK GDPR and Data Protection Act 2018.
- Canada, Treasury Board of Canada Secretariat, Directive on Automated Decision-Making.
- Australia, Office of the Australian Information Commissioner, the Privacy Act 1988 and the Australian Privacy Principles.
- DataReadyAI, Enterprise AI Control Plane: the complete reference guide.