Public sector: authority, records, and the citizen who cannot opt out
Shared methods · A shared method; linked tool guides explain the exact steps.
This page covers tools outside your selection. You can still read it. Find matching guides
Government use differs in kind, not degree. Your outputs carry state authority, your citizens cannot choose a competitor, and your files are records.
A company that ships a wrong AI answer loses a customer. An administration that ships one misleads someone who had no choice of provider, about a decision that may bind them. That asymmetry, not any special technology, is why public-sector use has its own rules.
The most complete public rulebook is the UK Government Digital Service's AI Playbook, and it travels well: its principles are about the nature of administration, not about Britain. This page reads it for the person drafting a letter in a Verwaltung, a council office or a ministry, alongside the same product mechanics as everyone else.
Three principles carry most of the weight
The Playbook's ten principles open with "You know what AI is and what its limitations are" — the foundations track, stated as a duty. The two with public-sector teeth:
"You have meaningful human control at the right stages" — with the concrete floor that "humans validate any high-risk decisions influenced by AI". Drafting the letter is delegable; deciding the claim is not.
"You use AI lawfully, ethically and responsibly" — which in government includes obligations private users never meet, like transparency registers for algorithmic tools.
The Playbook is blunt about where the caution binds hardest. A public-facing generated answer "would be prone to hallucination and could lead to someone being misled about a government service, policy or point of law" — the standard confident-error failure, except the error arrives wearing the state's letterhead. And its list of sensitive areas reads like a job description of administration itself: "commercial procurement, recruitment, freedom of information requests, and the processing of claims that require an evidence-based decision".
What is different when the desk is a public one
The output speaks with authority. A citizen cannot discount your letter the way they discount a chatbot. Whatever your internal review habit is for work you cannot fully judge, the published-to-citizens path needs the strict version.
Transparency is a duty, not a virtue. The Playbook's position: "You should be open with the public about where and how algorithms and AI systems are being used", down to labelling: a chatbot response "has been written by an automated AI chatbot". Undisclosed AI drafting in citizen-facing correspondence fails this even where it breaks no statute.
Your conversations may be records. Freedom-of-information and archival law reach working papers. A prompt describing a case, and the draft that came back, can be a disclosable record — which cuts both ways: it argues for keeping the trail and for never putting into a prompt what could not survive disclosure.
Personal data has one-way valves. "AI systems can process personal data, so you need to consider how you protect this personal data" is the Playbook's mild phrasing for a hard rule: case files, health data and benefits histories follow what data may go in under the strictest reading your legal basis allows. A citizen supplied that data under compulsion; that changes what "consent" can justify.
Accountability cannot move. The design goal is to "ensure that people who design and deploy AI systems can be held accountable for their outputs and impacts". "The system decided" has never been an acceptable sentence in administrative law, and a generated draft does not change whose signature sits under the decision.
For EU-based administrations, the AI Act adds the formal layer: public bodies are deployers like any other, and several administrative uses sit in the high-risk annex.
What goes wrong
The unlabelled chatbot. A citizen takes a hallucinated answer about a deadline or entitlement as an official statement, because from where they stand it is one.
Case details in a consumer account. A caseworker pastes a file into a personal chat tool: personal data processed outside any legal basis, on infrastructure procurement never examined.
Drafting sliding into deciding. The generated recommendation gets approved rather than reviewed — automation bias with a stamp. The claim decision was the part the Playbook says a human validates.
The FOI surprise. Prompts and drafts surface in a disclosure request that nobody considered when writing them.
Procurement by default. The tool that arrived inside an office suite becomes the department standard without the vendor questions ever being asked.
How to check it worked
Take one real citizen-facing output your team produced with AI assistance this month and ask three questions of the file: could you show a reviewer which human validated it, would the prompt survive an FOI release, and is the AI's role stated anywhere a citizen could find it? Three yeses is the Playbook working. Any no is specific, fixable, and better found by you than by an ombudsman.
Sources
Something wrong with this page?
Say what you expected and what you got. That is usually the shortest route to a correction, and it goes on the public issue tracker so the fix is visible.