Government is adopting AI under two forces at once. Programmes such as the IndiaAI mission are expanding access to compute, data and skills. The Digital Personal Data Protection Act, 2023 sets new obligations for how personal data is collected, used and shared. Between them sits the practical question every department faces: how far should an AI agent be allowed to go?
A rule that fits government
Our answer is to set an autonomy level for every agent and to keep public-sector agents low on that scale. Agents observe, suggest and draft; anything that affects a citizen's entitlement, a penalty, a tender award or a payment goes to a named official with the evidence in front of them.
Autonomy in a public-sector squad
Agent designs from our AI & Agentic Engineering practice
| Level | Typical public-sector use |
|---|---|
| Observe | Charter-timeline, fund-flow and litigation watchers |
| Suggest | Grievance triage, dedup flags, inspection ranking, reply drafting |
| Act with approval | Reconciliations and action emails prepared for approval |
| Act within limits | Masking personal data under a fixed policy |
| Autonomous | Not used for decisions about citizens, vendors or money |
Note: Designs, not delivered results.
On the record
Every plan, source, tool call and decision should be logged in a way an auditor, a vigilance officer or an RTI request can use — and a kill switch should let people halt all agents at once.