AI for government: data stays in the country, decisions stay with people

Ministries, agencies, municipalities and state enterprises handle huge volumes of requests, documents and directives. We help process them faster — on infrastructure inside your jurisdiction, with local language models, and without taking accountability for decisions away from officials.

  • DeploymentOn-premises · air-gapped
  • ModelsLocal, tuned on your corpus
  • First resultPilot in 4–8 weeks
  • RegionsEurope · Americas · Asia-Pacific
Principles

Four conditions we won't work in the public sector without

These are not options on a price list. They are the baseline for every government project, from a single municipal pilot to a national rollout.

Data sovereignty

Data stays in-country

Citizens' personal data is stored and processed on infrastructure inside the jurisdiction, designed to support local data-protection and localization law: GDPR in the EU, PIPL in China, APPI in Japan, PIPA in Korea, the Privacy Act in Australia, LGPD in Brazil, and federal and state rules in the US.

Isolation

Air-gapped when needed

The platform can run in an isolated network with no internet access, on local language models. Nothing calls out. Updates arrive as signed offline packages.

Accountability

People decide

AI drafts, checks and proposes. Signatures, resolutions and legally binding actions stay with the responsible official. The system enforces this — not a policy memo.

Transparency

Every step on record

Who asked, what the agent answered, which documents it cited, who approved the action and when. The log is open to your auditors and exportable to your SIEM.

Our position

Data stays in the jurisdiction. Decisions stay with officials. Every answer cites its source. Every action has a name next to it.

Jurisdictions

Built for the rules of your jurisdiction

Public bodies answer to stricter rules than companies. Below is what typically matters in each region and how the platform is designed to support it. Your legal team and data-protection officer make the final assessment; we provide the technical documentation they need.

EU

European Union

  • GDPR
  • EU AI Act
  • National public-sector rules
What it means for public bodies

Lawful basis and data minimization, a DPIA for high-risk processing, processor agreements. Under the EU AI Act, public deployers of high-risk systems — for example in access to public services and benefits — must ensure human oversight, keep logs and, for bodies governed by public law, carry out a fundamental-rights impact assessment. People must be told when they talk to an AI.

How we design to support it

Processing in EU infrastructure or on your premises, human sign-off enforced by the platform, full logs, AI disclosure in citizen channels, and a documentation pack for your DPIA and fundamental-rights assessment.

US

United States

  • Federal AI guidance
  • NIST AI RMF
  • State privacy & AI laws
What it means for public bodies

Federal agencies follow government-wide AI governance guidance: inventories of AI use, risk management for rights- and safety-impacting uses, and accountable officials. States and cities add their own privacy, records and AI rules. Cloud services may require an authorization you already hold.

How we design to support it

Deployment inside your authorized environment — your data center or your accredited cloud tenant. Risk documentation mapped to the NIST AI Risk Management Framework, records exportable for retention schedules, and human review for any rights-impacting output.

BR

Brazil and Latin America

  • LGPD
  • ANPD guidance
  • National laws in the region
What it means for public bodies

LGPD has a dedicated chapter for public authorities: processing must serve a public purpose, be transparent and be reported. The regulator can request a data-protection impact report. Other Latin American countries have their own data-protection laws with similar principles.

How we design to support it

In-country deployment, a processing record per use case, Portuguese and Spanish interfaces and speech, and documentation that supports your impact report and your data-protection officer.

JP

Japan

  • APPI
  • Government cloud rules
  • Ministry guidelines
What it means for public bodies

Since the recent amendments, APPI also covers national administrative organs and local governments. Agencies need clear purposes of use, security controls and care with transfers abroad. Cloud procurement may require registered services.

How we design to support it

On-premises or in your approved Japanese cloud environment, local models with native Japanese handling, purpose and access recorded per agent, and no transfer of personal data abroad in sovereign deployments.

KR

Korea

  • PIPA
  • PIPC guidance
  • Public-sector cloud rules
What it means for public bodies

PIPA sets strict rules for public institutions on purpose limitation, safety measures and cross-border transfer. Public-sector cloud use is subject to its own security assurance regime.

How we design to support it

On-premises or air-gapped deployment, Korean-language models and speech, field-level access control and a complete access log that supports your PIPA safety-measure obligations.

CN

China

  • PIPL
  • Data Security Law
  • Generative AI measures
What it means for public bodies

PIPL and the Data Security Law restrict cross-border transfer and require localization of personal information and important data for many operators. Public-facing generative AI services fall under the 2023 interim measures, which can require filing.

How we design to support it

Deployment inside mainland China on local models only — no calls to foreign model APIs. Data, logs and keys stay in-country, and we provide technical documentation to support your filings.

AU

Australia

  • Privacy Act & APPs
  • Policy for responsible AI in government
  • State privacy laws
What it means for public bodies

Commonwealth agencies apply the Australian Privacy Principles and the whole-of-government policy for responsible AI use, which asks for accountable officials and public transparency statements. States and territories add their own privacy laws and security frameworks.

How we design to support it

Deployment in Australian data centers or on your premises, inside the security environment your team has assessed, with logs and documentation that support your transparency statement and privacy impact assessment.

Overview for orientation, not legal advice. We design the platform to support compliance; we do not certify it, and responsibility for the legal assessment remains with your organization.

Sovereign architecture

An AI enclave inside your network, with no way out

In the sovereign setup the whole platform — models, agents, knowledge index and audit log — runs on servers inside your network. It connects to your systems through controlled connectors. It has no route to the internet.

Internet · public model APIsAgency networkAir-gapped AI enclaveNo egressRegistriesDocument managementCase managementStaff · SSO directoryCitizen portal & mailGateway · SSO · policy · maskingAgentsKnowledge indexLocal models · GPUAudit logUpdates · signed offlineEncrypted storage · your keysSecurity operations · SIEMAuditors · oversightone-way exportAir-gapped AI enclave

Local models

Open-weight models run on your GPUs and are tuned on your corpus. Frontier models are optional and only where the law and your policy allow.

No egress

Outbound traffic from the enclave is blocked at the network level, not just in configuration. Telemetry stays inside.

Controlled connectors

Each connector has its own service account with read rights by default. Write access is granted per action and logged.

Your keys

Storage is encrypted with keys held by your organization. BlackGust engineers work on site, under your access rules.

Signed updates

New versions arrive on offline media, are checked for a valid signature and pass your reference tests before release.

Audit export

The audit log streams one way to your security operations center and can be handed to auditors as a read-only copy.

Request lifecycle

One citizen request, from inbox to archive

This is how a typical request moves when the platform is in place. The agent does the routine work; the official keeps the decision and the signature.

Example · illustrative data

  1. 01AI agent

    Received

    A request arrives by portal, email, letter scan or phone. The agent registers it, detects the language and removes duplicates.

    Day 0
  2. 02AI agent

    Classified and routed

    Topic, urgency and responsible unit are proposed with a confidence score. Unclear cases go to a coordinator.

    Minutes
  3. 03Agent + official

    Draft prepared

    The agent drafts a reply with quotes from the relevant law, decree or internal act, each linked to its exact version.

    Day 1
  4. 04Official

    Reviewed and signed

    The official edits, approves or rejects the draft. Above set thresholds, the head of unit signs as well.

    Day 1–3
  5. 05AI agent

    Sent and tracked

    The reply goes out through the original channel. The agent tracks statutory deadlines and warns before they slip.

    Deadline
  6. 06AI agent

    Archived and auditable

    The request, the draft, the edits and every approval are stored together under your retention schedule.

    Retention

What we measure in the pilot

Review timemeasured per request, before and after
Share on timeof requests answered within the statutory deadline
Reworkshare of drafts the official had to rewrite
Use cases

What can be solved in the pilot

Use cases with measurable impact within 4–8 weeks. Each one starts from your real documents and requests, not a demo dataset.

Citizen requests

Classifying requests, identifying the responsible agency, drafting a reply, tracking review deadlines. Works across languages and writing systems, including Chinese, Japanese and Korean.

Review time

Directive tracking

Extracting directives from minutes and documents, assigning owners, sending reminders, a digest of overdue items for leadership.

Share on time

Regulatory base

A legal assistant that searches laws, decrees and internal acts and returns an exact quote with a link to the relevant version.

Time to legal opinion

Leadership analytics

Key indicators across regions and subordinate bodies in one console, with answers to plain-language questions.

Time to answer

Voice line

A multilingual voice agent for public hotlines that answers routine questions and hands complex cases to an operator.

Share without operator

Video analytics

Visitor counts, service-zone occupancy, queues and access control on existing cameras.

Waiting time

Inspections and permits

Pre-checking applications for completeness, comparing them with registry data and preparing the file for the inspector who decides.

Days to decision
Languages

Every language your citizens and staff use

Most AI products are tuned for English first. Quality drops on speech, domain terminology and documents that mix languages and scripts. We tune speech recognition and synthesis to the languages you need and check quality on real requests.

8languages for the interface and agent answers: English, German, French, Spanish, Portuguese, Chinese, Japanese, Korean; others per project
3East Asian writing systems handled natively: Chinese, Japanese, Korean
24/7voice and text agents working without breaks
100%of agent actions recorded in the audit log
Accountability

Who signs what: the human oversight model

Every action in the platform belongs to a role. The agent prepares; named people approve. This table is agreed with you before launch and enforced in configuration.

Typical model; roles and thresholds are set per organization.
ActionAI agentCase officerHead of unitIT & securityAudit & oversight
Citizen requests
Classify and route a requestProposesConfirms or changes——Samples monthly
Draft a replyDrafts, with citationsEdits and signsCo-signs above threshold——
Send a replySends only after signatureReleases———
Legally significant acts
Decision on a benefit, permit or sanctionPrepares the file, flags gapsDecidesApproves where rules require—Reviews
Change a record in a registryCannotChangesApproves bulk changes—Notified
The system itself
Change an agent's permissionsCannot—RequestsApproves and appliesNotified
Release a new agent version——Accepts resultsReleases after reference testsReceives test report
Read the audit log—Own actionsOwn unitFullFull, read-only
Risk register

The risks of AI in government — and what we do about each

A public body should see the risks before it signs. These are the ones we discuss in every diagnostic, with the controls we put in place and who keeps watching them.

R1

Bias and unequal treatment

How it shows upDifferent quality of answers or routing for some groups, languages or regions.

Mitigation
  • Quality tested per language and group on real requests
  • Agents propose, officials decide on anything that affects rights
  • Periodic sample review by audit

Who watchesAudit & data-protection officer

R2

Hallucination

How it shows upA confident answer or a citation that does not exist.

Mitigation
  • Answers only from your indexed sources, with quote and link
  • No source, no answer — the agent says it doesn't know
  • Reference tests block releases that degrade

Who watchesCase officers & IT

R3

Data leakage

How it shows upPersonal data reaching someone without the right, or leaving the jurisdiction.

Mitigation
  • Air-gapped or in-country deployment
  • Access down to rows and fields, inherited from your directory
  • Masking and full access logs

Who watchesIT & security

R4

Manipulation of the agent

How it shows upText in a request or document tries to change the agent's instructions.

Mitigation
  • Input filtering and separation of instructions from content
  • Agents cannot widen their own rights
  • Risky actions always need a human

Who watchesIT & security

R5

Over-reliance

How it shows upOfficials approve drafts without reading them.

Mitigation
  • Sources shown next to every claim
  • Spot checks and rework metrics per user
  • Training for staff at launch

Who watchesHeads of unit

R6

Vendor lock-in

How it shows upThe agency cannot change supplier or model without starting over.

Mitigation
  • Runs on your infrastructure; models can be swapped
  • Data, prompts and logs exportable in open formats
  • Documentation and knowledge transfer to your team

Who watchesCIO & procurement

Procurement & contracts

Three ways to contract with us, and the papers for each

We work in the formats used in public procurement in Europe, the Americas and Asia-Pacific, and help prepare the documentation. We adapt to your rules; your procurement office decides which route applies.

Route 01

Pilot project

Fits when: The budget needs justification, or the use case is new for your organization.

How it runs
  1. Diagnostic, 2–3 weeks, $1,490, credited to the pilot
  2. Pilot on one process, 4–8 weeks, from $9,990
  3. Acceptance against metrics agreed up front
  4. A report you can attach to a larger procurement
Route 02

Competitive tender

Fits when: The scope is known and your rules require open competition.

How it runs
  1. Answers to clarification questions during the tender
  2. Technical proposal mapped to your requirements
  3. Cost breakdown by phase and package
  4. Security and data-protection annexes
Route 03

Framework or direct award

Fits when: Your procurement rules permit it — for example an existing framework, cooperative contract or a below-threshold award.

How it runs
  1. Scope and milestones agreed in a statement of work
  2. Milestone payments with formal acceptance at each stage
  3. Same documentation as in a tender
  4. Only where the law allows; we do not advise on procurement law

Document checklist

What we prepare or help you prepare, by stage.

01 · Before procurement
  • Diagnostic report with process map and business case
  • Technical specification, or help preparing one
  • Market-sounding answers and indicative budget
02 · With the proposal
  • Architecture and security model description
  • Data-flow diagrams and threat model
  • Project schedule with acceptance milestones
  • Your security questionnaire, completed
03 · During delivery
  • Test program and methodology
  • DPIA and impact-assessment input pack
  • User and administrator guides in the required languages
04 · At acceptance
  • A report at the end of each phase
  • Reference test results per agent version
  • Handover documentation and data-deletion procedure
The Sovereign package

How government projects grow into Sovereign

Most public bodies start small and expand only after the pilot proves itself. The Sovereign package is the destination for organization-wide work in an isolated environment.

2–3 weeks

Diagnostic

Processes, data, legal constraints and a ranked list of use cases. $1,490, credited to the pilot.

OutcomeBusiness case and target architecture
4–8 weeks

Pilot

One process, real users, real documents. From $9,990.

OutcomeMeasured impact against agreed metrics
2–4 months

Integration

Connectors to your systems, roles, approvals and audit export in production.

OutcomeAccepted system in your environment
Annual

Sovereign

Organization-wide platform. $490,000/year; GPU hardware and infrastructure priced separately.

OutcomeAI as a running service of your organization

What the Sovereign package includes

Compare packages
  • Organization-wide: unlimited processes and users
  • All modules, including Voice and Vision
  • On-premises or air-gapped deployment
  • Local models fine-tuned on your corpus; frontier models optional
  • A dedicated embedded team of 5+ engineers plus an architect
  • 24/7 support with 1-hour response for critical incidents and a named duty engineer
  • Procurement-ready documentation
FAQ

Questions public-sector buyers ask

Can the platform run with no internet connection at all?

Yes. In the air-gapped setup, models, agents, the knowledge index and the audit log run inside your network with no route out. Updates arrive as signed offline packages. Frontier cloud models are not available in that mode; local models tuned on your corpus take their place.

Is the platform compliant with GDPR, the EU AI Act or our national law?

We design the platform to support compliance — in-country processing, human oversight, logging, access control and deletion — and we provide documentation for your DPIA or impact assessment. We do not certify compliance; the legal assessment stays with your organization and its data-protection officer.

Will AI make decisions about citizens?

No. The agent classifies, drafts and checks. Decisions on benefits, permits, sanctions and any legally binding act are taken and signed by the responsible official. The platform enforces this through roles and approvals; it is not left to good intentions.

Do you hold FedRAMP, IRAP, ISMAP or similar authorizations?

No. We deploy into the environment you have already accredited — your data center or your authorized cloud tenant — and support your assessment with architecture documents, a threat model, a completed questionnaire and cooperation with your penetration testers. See Security.

How long from first meeting to a working pilot?

The diagnostic takes 2–3 weeks and the pilot 4–8 weeks. Procurement time depends on your rules, which is why many agencies start with a pilot that fits their own approval limits.

Which languages are supported?

Eight interface and answer languages out of the box: English, German, French, Spanish, Portuguese, Chinese, Japanese and Korean. Others are added per project, including speech recognition and synthesis tuned on your real requests.

How do we avoid vendor lock-in?

The platform runs on your infrastructure, models can be swapped, and data, prompts, configurations and logs are exportable in open formats. Models fine-tuned on your corpus stay in your environment; ownership terms are fixed in the contract. Your team receives documentation and training throughout.

What happens to our data when the contract ends?

Data is deleted within the agreed period and we issue a deletion certificate. In on-premises and air-gapped setups the data never leaves your servers in the first place.

Where is BlackGust based, and can you work on site?

BlackGust is headquartered in Tashkent. Our forward-deployed engineers work on site with your team at the phases that need it and, in the Sovereign package, as a dedicated embedded team.

What does it cost?

A diagnostic costs $1,490 and is credited to the pilot; pilots start from $9,990. Organization-wide sovereign work is covered by the Sovereign package at $490,000/year, with GPU hardware priced separately. Details are on the pricing page.

Let's discuss your agency's challenge

A meeting with an engineer and the practice lead. We can come to you, sign an NDA first, and bring the security documentation to the first conversation.