AI your security and procurement teams can actually approve.
Public sector AI projects rarely stall on capability — they stall on the review. Who can access citizen data, under which jurisdiction, with what evidence for the auditor? NeuroCluster is built to answer that question before the review starts, not after a pilot gets blocked.
Why generic AI tools fail public sector review
Ministries, agencies, and public bodies evaluating AI hit the same three review gates regardless of country: data protection (GDPR and national implementations), sector security baselines (the Dutch BIO2, Germany's BSI standards, France's referentiels), and — increasingly — a sovereignty test modelled on the European Commission's SEAL framework.
A consumer-grade AI assistant running on a US-headquartered hyperscaler's API can satisfy none of these on inspection: prompts containing citizen data leave the controlled network, jurisdiction runs through the US CLOUD Act, and the audit trail a reviewer needs is either absent or locked inside the vendor's own systems.
What a governed deployment looks like
NeuroCluster runs AI agents inside a boundary your organization controls — EU-operated shared cloud, a dedicated tenant, or fully on-premises — with the controls public sector review actually checks for:
- Row-level data access: an agent only reaches the records and fields its policy allows, scoped per use case.
- Human oversight by design: actions affecting a citizen's rights, benefits, or status require named approval before execution — recorded with identity and timestamp.
- Deterministic logging: every model call, tool action, and approval is captured automatically, producing the audit trail a reviewer asks for rather than one assembled after the fact.
- European or on-premises infrastructure: no transfer to non-EU-controlled processors as a default architectural property, not a contractual promise layered on top.
Mapped to the frameworks your reviewers use
Instead of a generic "AI governance" pitch, NeuroCluster maps directly onto the specific frameworks a public sector reviewer will cite:
- EU AI Act: classification support, logging, human oversight, and technical documentation for high-risk public sector use cases (employment, essential services, law enforcement).
- SEAL / Cloud Sovereignty Framework: European ownership and an owned technology stack, not a wrapper over a non-EU hyperscaler — the exact gap the Commission's own Cloud III award exposed.
- National security baselines (BIO2, BSI, ANSSI-adjacent frameworks): audit-ready evidence for the ISMS and supplier-review processes these baselines require.
- Algorithm registers and FRIA obligations: deployment snapshots and policy documentation exportable as the artifact these registers ask for, not reconstructed by hand.
A proven pattern: permit processing under strict data classification
A Dutch municipality runs permit processing with governed agents — document analysis and triage by AI, decision authority retained by the caseworker, full audit trail per application. The workflow operates under strict data-classification controls with mandatory human approval before any outbound action.
The approach generalizes beyond municipalities to any public body handling classified or citizen-sensitive data: the pattern is the boundary and the evidence, not the specific use case.
Frequently asked questions
Can government organizations use commercial AI assistants like ChatGPT or Copilot?
It depends on data classification and legal basis, but for citizen personal data and higher security classifications, generic US-hosted SaaS AI tools routinely fail data protection, national security-baseline, and CLOUD Act review. A governed deployment on EU-operated or on-premises infrastructure is the path that clears security and legal review.
How does this relate to the EU's SEAL sovereignty framework?
SEAL (Sovereignty Effectiveness Assurance Level) is the European Commission's scoring system for cloud sovereignty, from SEAL-0 to SEAL-4. NeuroCluster is a European-owned entity operating its own technology stack — the profile that scores at the high end of that scale, rather than a non-EU-controlled platform wrapped in EU branding.
What does the EU AI Act require for public sector AI specifically?
Many public sector use cases — access to essential services, employment decisions, law enforcement — fall under Annex III high-risk categories, requiring logging, human oversight, risk management, and technical documentation. The binding date for these obligations is 2 August 2026.
Can this run fully on our own infrastructure?
Yes. The same platform runs on EU shared cloud, a dedicated tenant, or fully on-premises — including air-gapped environments for classified or critical-infrastructure use cases — with an identical governance and evidence model across all profiles.
How do we start?
A 30-minute readiness assessment: we map your use case, data classification, and oversight requirements, and show what a first governed workflow looks like — including the documentation your reviewers will ask for.
Keep evaluating
The SEAL framework explained
SEAL-0 to SEAL-4, the Cloud III awardees, and how to apply the criteria to any AI vendor.
EU AI Act compliance guide
The full pillar guide: timeline, risk categories, and technical compliance.
Case study: municipality permit processing
Governed agents for permit processing under strict data classification.
AI voor gemeenten (NL)
The Dutch municipality-specific version of this page.
Free FRIA template
Who needs a Fundamental Rights Impact Assessment, and a structured template.