For government, sovereignty is the whole point
Every other vertical weighs sovereignty against convenience. For the public sector, sovereignty is the mandate, which is why this is the clearest case Rindogatan makes.
A government holds the most consequential data there is, identity, health, justice, benefits, security, in trust for its citizens. Running the AI over that data on infrastructure owned and governed outside the country, outside the Union, is not a procurement detail; it is a transfer of a piece of sovereignty. The Palantir debate across European public services is, at bottom, an argument about exactly this.
Rindogatan's position is unambiguous and on-brand: public-sector AI should be sovereign by default, European by design, and humane by intent, the opposite of a confrontational, opaque, foreign-controlled data platform. And the prize is not abstract: after the Reset, a government can finally give citizens service that matches the private sector, proactive, personal, plain-language, in every language its people speak, on infrastructure the state controls. The capability exists; the only question is the will to choose it.
The public-sector regulatory weather
The AI Act, GDPR, NIS2 and the European data-space agenda all treat public data as something to keep under European control.
Many public services are named high-risk under the AI Act, benefits eligibility, justice, migration, essential services, with the full documentation, oversight, and transparency burden. GDPR governs citizen data tightly, and the public expects more, not less, than the legal minimum. NIS2 designates much of government as critical infrastructure; the European Health Data Space and the broader data-space agenda assume European stewardship of European data.
Taken together, these do not merely permit sovereign public-sector AI, they presuppose it. A citizen-facing system on a third-country API contradicts the entire direction of European public-data policy. Sovereignty here is alignment with the law's intent, not caution against it.
Share of AI workloads by placement, weighted by citizen-data sensitivity and public accountability. A Rindogatan-modelled benchmark, not survey data, public sector tilts the most sovereign of any vertical.
What goes where in public administration
The citizen-data core stays sovereign. A narrow public-data edge can use frontier capability.
At the sovereign end: citizen-service agents and proactive, plain-language communication, case management, benefits and eligibility assessment, public-health analytics, justice and security workloads, and any system touching citizen identity, self-hosted, auditable, accountable to the public. The recommended split is the most sovereign of any vertical, around eighty-five per cent, because the data and the duty both demand it. At the frontier edge: drafting against public legislation, translation of public documents, and research over open data, where no citizen record is involved.
Accountability is the watchword. A public body must be able to explain, in public, why an automated decision was made, trivial on a sovereign, logged, governed system and nearly impossible on an opaque external API. Public scrutiny is a feature of the sovereign architecture, not a threat to it.
“A government that runs citizen services on a foreign API has outsourced a piece of its sovereignty. Public-sector AI is the clearest case we make.”
The public-sector roadmap
Four moves toward AI that holds up to public scrutiny.
Inventory citizen-data AI exposure across departments and classify against the AI Act high-risk tests, treating anything citizen-facing as sovereign-by-default. Stand up sovereign inference on European infrastructure, Stackit and sovereign European infrastructure make this procurable, before scaling any pilot.
Make explainability and public accountability design requirements from day one, and govern placement centrally so no department quietly routes citizen data to a foreign API. The sovereign path is also the publicly defensible one.
- 1. Headline figures are Rindogatan models, directional benchmarks to be calibrated to a specific institution, not survey statistics.
- 2. Partner data points are drawn from publicly published research (e.g. Snowflake's Modern Marketing Data Stack, Databricks' State of Data + AI) and cited for direction only.
- 3. Regulatory references: EU AI Act, Reg. (EU) 2024/1689; GDPR, Reg. (EU) 2016/679; DORA, Reg. (EU) 2022/2554; NIS2, Dir. (EU) 2022/2555.
- 4. Sovereign deployment modelled on European sovereign infrastructure.