Citizen experience that matches the private sector, on infrastructure the state controls.
Citizens now expect public services to work like the best consumer apps, and governments are racing to deliver: AI assistants, a real digital front door, and services that actually reach people. But citizens cannot opt out of their government, so that experience must run on infrastructure the state controls.
The shifts our research is tracking, named, current, cited.
The European Commission’s Cloud Sovereignty Framework (Oct 2025) scores providers from SEAL-0 to SEAL-4, and the Commission is already steering its own cloud procurement to European sovereign providers. Sovereignty is no longer rhetoric in a tender; it is a grade your next procurement carries.
European Commission →Deloitte finds citizen satisfaction with digital government services runs 21 percentage points behind the private sector, the expectation gap now driving public-sector AI.
Deloitte →The UK's GOV.UK Chat is built on Anthropic's Claude to help citizens navigate more than 80,000 pages of government guidance in plain language. The citizen front door is going conversational, and the states that move first set the expectation for everyone else.
UK GDS (reported) →Capgemini's 2025 eGovernment Benchmark found 43% of national portals already offer automated live support, often AI chatbots. Citizen-facing AI is no longer experimental; the question left is whose infrastructure it answers from.
Capgemini eGovernment Benchmark 2025 →In the public sector, citizen experience is the mandate and sovereignty is the condition: services that match the private sector, run where the state can see and control them.
Citizens now judge public services against the best consumer apps, and the gap is stark: Deloitte finds satisfaction with digital government runs 21 points behind the private sector. The fix is the same AI experience, citizen assistants, a real digital front door, services that reach people, and governments are moving: the UK's GOV.UK Chat, built on Claude, already answers thousands of citizen questions across 80,000 guidance pages.
But citizens cannot opt out of their government, so that experience cannot run on infrastructure the state does not control. Build it sovereign, European, and accountable and the AI Act's heavy public-sector obligations become straightforward: a citizen can be told, in public, why an automated decision was made, because the system is logged and governed inside the perimeter.
We deliver the citizen-experience stack sovereign by default, and pick the right model for each job: citizen assistants and eligibility guidance on European compute, frontier reasoning only on public, non-personal information. Public services that match the private sector, on infrastructure a citizen and a regulator can trust.
| Workload | Placement | Rationale |
|---|---|---|
| Citizen assistants & digital front door | Sovereign | Citizen data held in trust; sovereign by definition. |
| Service access & eligibility guidance | Sovereign | High-risk under Annex III; must be auditable. |
| Translation of public information | Hybrid | Public data on frontier; sovereign post-edit. |
| Internal drafting | Sovereign | Pre-decisional state documents. |
Before any platform decision, one question settles the rest: how much of what your organisation knows can be written down precisely enough for a machine to act on it, and who ends up owning that writing. We run a short engagement to answer it, and it produces working artefacts rather than a report.
Two artefacts come out of this. An operating ontology, the nouns: the entities, relationships, and states your business actually runs on, described once and precisely. And agentic skills, the verbs: the procedures, thresholds, and judgments your best people apply, written down, versioned, and testable instead of retold.
A placement map addressed to the CTO or CIO office: what runs on your compute, what is bought, what is rented, who holds the keys, and what each costs. One test cuts through most of the debate. If a supplier vanished on a Friday, what stops working on Monday, and how long would it take you to replace it?
Where an open-weight model fine-tuned or adapted on your own corpus beats a frontier call, where a small purpose-built model for one narrow task beats both, and where the frontier still earns its fee. Geographic sovereignty falls out of that answer rather than having to be argued for on its own.
A model adapted on your own guidance and decided cases can run entirely inside the estate, which for classified and safeguarding work is the only answer that survives scrutiny.
This is a CTO and CIO office engagement, not a procurement exercise. Your own people have to end up running it, because the moment the encoding is delegated, the thing being encoded quietly stops being yours.
Palantir calls this layer an ontology, and the idea is right: a governed model of your objects, links, and actions that agents can act on. It lives inside their platform. 8090 will design, build, host, and maintain the software around it for you. Both are serious, and both leave the same question open. At the end of it, who owns the layer that holds your judgment? We build the same artefacts in open formats, on compute you control, and hand your CTO the keys.
The same four layers we ship in legal, instantiated for a public body, where the citizen has no option to take their data elsewhere and the standard of proof is therefore higher.
A citizen service assistant that answers from your own published guidance, a casework copilot that drafts within statutory templates, and a records and publication workbench for disclosure, transparency, and archive work.
Statutory guidance, eligibility rules, plain-language standards, and escalation thresholds compiled into skills, so an answer given to a citizen can be traced to the rule it came from and reviewed by the official responsible for it.
Citizen records never reach a third-country provider, by architecture rather than by clause. Every model call is logged, attributable, and inspectable, which is the only form of oversight that survives a public inquiry.
On the body's own infrastructure, on a sovereign cloud tenancy, or on dedicated hardware in the building for classified and safeguarding work that must run with no route out at all.
The application layer here is built for you, not bought. The pattern is the one we already ship, as a product, in legal.
The same software in every posture, so a team can start hosted and end up air-gapped without a migration project. You move along the ladder when you decide to, not when a contract renews.
Your stack stood up on our infrastructure in days and pointed at real work, so it is judged on your matters rather than on a demo. The pilot fee credits against the hardware when you migrate.
Teams that want proof before capital expenditure.
The open-source cores installed on a machine you own, by a script anyone can read first. No account with us, no telemetry, no phone-home. Code flows one way, from us to you, and only when you ask for it.
Small teams, and anyone who wants to inspect the source before trusting it.
An isolated instance per client on sovereign infrastructure, European by default, run, patched, and monitored by us, with the security and backup credentials in your hands rather than ours.
Organisations without an infrastructure team to spare.
Dedicated AI hardware inside your building, with the applications and the open-weight models you choose installed and tested before it ships. It runs with the network unplugged, and it keeps working whatever happens to us.
In government the appliance is often the only acceptable posture: it runs air-gapped, and it keeps running whatever happens to any supplier, including us.
Work that cannot leave the building, ever.
Not promises. Consequences of the architecture: your keys and your data are generated on your machine and stay there, and nothing calls home.
We send a sector-specific brief with workload-by-workload placement guidance and a reference architecture for sovereign deployment.