Point of viewAI in government

Agents prepare, officials decide: governing AI in public services

The IndiaAI mission is expanding public AI capacity and the DPDP Act changes how personal data may be used. For AI that touches citizens, the governing rule is simple: agents prepare the work, a named official decides, and every step is on the record.

6 min read By · Point of view
2023
the year India enacted the Digital Personal Data Protection Act1

Key takeaways

  • AI that affects an entitlement, a penalty or a tender award must leave the decision with an official.
  • Autonomy levels make that rule enforceable: most public-sector agents should observe or suggest.
  • Personal data should be masked before any AI processing, by default.
  • Logs designed for audit and RTI are part of the system, not an afterthought.

Government is adopting AI under two forces at once. Programmes such as the IndiaAI mission are expanding access to compute, data and skills. The Digital Personal Data Protection Act, 2023 sets new obligations for how personal data is collected, used and shared. Between them sits the practical question every department faces: how far should an AI agent be allowed to go?

A rule that fits government

Our answer is to set an autonomy level for every agent and to keep public-sector agents low on that scale. Agents observe, suggest and draft; anything that affects a citizen's entitlement, a penalty, a tender award or a payment goes to a named official with the evidence in front of them.

Exhibit 1

Autonomy in a public-sector squad

Agent designs from our AI & Agentic Engineering practice

LevelTypical public-sector use
ObserveCharter-timeline, fund-flow and litigation watchers
SuggestGrievance triage, dedup flags, inspection ranking, reply drafting
Act with approvalReconciliations and action emails prepared for approval
Act within limitsMasking personal data under a fixed policy
AutonomousNot used for decisions about citizens, vendors or money

Note: Designs, not delivered results.

On the record

Every plan, source, tool call and decision should be logged in a way an auditor, a vigilance officer or an RTI request can use — and a kill switch should let people halt all agents at once.

For executives

What this means for your bank

  1. Set and publish an autonomy level for every agent.
  2. Mask personal data by default.
  3. Design logs for audit and RTI from day one.
  4. Keep a kill switch with people.
Put it to work

How DaasLabs can help

Set up AI and agent governance in our Data Governance, Privacy & DPI service.

Learn more

See how agent governance works.

See governance & controls

Baseline your data and AI maturity.

Take the maturity assessment

Sources

  1. 1
    Digital Personal Data Protection framework (opens in a new tab) Ministry of Electronics and Information Technology
  2. 2
    IndiaAI (opens in a new tab) Government of India

Figures are drawn from the cited public sources. Opinions labelled “DaasLabs point of view” are our own.

Stay informed

Get new the public sector insights in your inbox

New perspectives on AI, data and transformation in the public sector — a few times a month. Browse all insights.