Private and on-premises AI · 2 min read

AI agents in state-owned companies: classification to pilot

State-owned companies should classify each system and its data before choosing a model; ownership alone does not make every service a government information system or CII object.

Determine applicable obligations

Legal and security owners should document purpose, data categories, users, integrations and regulated processes. Personal data, government systems, CII and sector rules arise from different conditions.

Classification must distinguish personal data, government information systems, CII and sector obligations because each has different triggers.

Assign governance

Connect the project to a defined organisational objective and name owners for process, data, model and operations, including authority to approve sources, actions, release and shutdown.

Name owners for process, data, model, security and operation, including authority to approve a new source or stop the system.

Choose a bounded pilot

Begin with cited search, drafting or classification with human confirmation. Avoid irreversible actions, critical control and decisions affecting a person as a first use case.

Start with cited retrieval or drafting under human confirmation rather than irreversible actions or decisions affecting an individual.

Accept documented evidence

Require boundaries, component and licence inventory, access matrix, test results, changes, updates, backup, deletion and incident handling. Exact legal controls require case-specific classification and current advice.

Acceptance evidence should include boundaries, licences, permissions, tests, updates, deletion, recovery and incident handling for the classified system.

Evidence and sources

Continue with the underlying material

pommeDeTerre

Need an estimate for your project?

Tell us about the project. We will break it into stages and explain the budget drivers.

View pricing