How – Inside the AI OS: running governed agents on your own cluster, liveRegister →
MINISTRIES, AGENCIES & NATIONAL SECURITY BODIES

Sovereign AI for National Government

Ministries and agencies hold the data a state is made of, some of it classified, all of it under a legal basis that names one controller. AI at national scale has to respect both, and it has to run on infrastructure the state controls.

Air-gapped by design

The complete platform runs on classified networks with no outbound connection. Updates arrive through the accredited channel. Clearance is enforced at retrieval.

Controllers stay controllers

Ministries publish governed data products and analysts join them for an authorised question, under a named legal basis, without a central copy.

One stack to accredit

The same platform, governance and audit on the unclassified and the classified side, which is what the security authority and the EU AI Act auditor want to see.

IN PLAIN TERMS

A national government is a federation of controllers, each with a legal basis for its own data and none for the others', and a growing share of that data sits on networks that must never touch the internet. Ministries have run AI pilots on unclassified copies and hit the wall on both counts. The platform gives a ministry, an agency or a cross-government service AI on its own data, in its own perimeter, including disconnected, with the governance a state auditor and the EU AI Act require.

Read this if you're leading digital transformation, IT, security or data at a ministry, a federal or national agency, a statistical office or a national security body, or accountable for its EU AI Act, GDPR and NIS2 obligations.


WHAT THE PLATFORM DOES HERE

For national and federal government, Scrydon is the sovereign AI and data platform that runs models, agents and analytics on ministerial and agency data inside state-controlled infrastructure, including fully air-gapped classified networks, and lets ministries share governed data products without any of them giving up control.

It runs identically in a national sovereign cloud, on government data centres and on disconnected classified networks, so there is one platform to accredit and one governance model from the unclassified service desk to the classified enclave.

THE STATE'S PROBLEM

Data that cannot be pooled, networks that cannot be connected

A national government is a federation of controllers. The tax administration, the social security institution, the housing agency and the health ministry each have a legal basis for their own data and none for the others', so the traditional answer to a cross-cutting policy question, a central data warehouse, either never gets built or gets built without the data that matters. Meanwhile a growing share of the state's most important data sits at RESTRICTED and above, on networks that never touch the internet, where there has been no AI at all, or shadow use on unclassified copies.

Every ministry has by now run a pilot and met the same two walls: the data cannot be pooled, and the network cannot be connected. Behind those stand the security authority that has to accredit whatever runs on classified data, the EU AI Act that asks the state to know and govern every AI system it uses, and a court of audit and a parliament that expect the decision to be explainable. Strategic autonomy is not a slogan here; it is the operating condition.

  • Separate controllers by lawTax, social security, housing and health each have a legal basis for their own data. A central warehouse is either never built or built without the data that matters.

  • Classified networks with no AIRESTRICTED and above never touch the internet, so those networks have had no AI at all, or shadow use on unclassified copies.

  • Shadow AI across ministriesStaff use consumer tools because nothing sanctioned exists. Discovering and governing that is an EU AI Act readiness task in itself.

  • Accreditation and auditEvery deployment has to be assessed by the security authority and explained to the court of audit and parliament.

ON THE PLATFORM

Air-gapped where it must be, federated where it can be

The platform is deployed inside the perimeter that applies: connected in a national sovereign cloud or a government data centre for the unclassified estate, and air-gapped on the classified network, with the same stack in both. On the classified side, open-weight models, retrieval indexes and agents run entirely inside the enclave, updates arrive through the accredited import channel and are recorded, and document clearance markings are enforced at retrieval time so nothing is served above the reader's clearance.

Across ministries, a data space reverses the direction of the warehouse: each controller keeps its data where it is and publishes governed data products whose schema, quality and access policy are described in a shared ontology. A cross-ministry question is a query over those products, executed under an authorisation that names the legal basis, the purpose and the retention period, and logged. Where the law allows only aggregate or pseudonymised results, the product enforces it. Governance, agent identity and the model inventory then produce the evidence the security authority, the EU AI Act and the auditor ask for.

  1. 1

    Deploy in the perimeter

    Connected in a national sovereign cloud or government data centre; disconnected on the classified network, with the same stack.

  2. 2

    Ground in the ministry's own sources

    Open-weight models and retrieval run on the ministry's documents and records, with clearance markings enforced at retrieval time.

  3. 3

    Federate across ministries

    Each controller publishes governed data products into a data space; a cross-ministry question runs under a named legal basis and is logged.

  4. 4

    Govern and evidence

    Policy, identity, audit and the model inventory produce the evidence for the security authority, the EU AI Act and the auditor.

WHY SOVEREIGN

Strategic autonomy is an operating condition, not a slogan

The platform is designed so that no foreign dependency sits in the loop of a national deployment. Models are open-weight and served on state-controlled infrastructure; there is no inference call, licence check or update path outside the perimeter, and the disconnected case is the design case rather than a degraded mode. That is what lets one platform serve the service desk, the policy unit and the classified enclave, and what keeps accreditation to one assessment and one evidence set.

Control is enforced where the data is used. Clearance is metadata on every document and is applied at retrieval, so an analyst with a lower clearance never sees a passage above it, even inside the same network. A cross-ministry query carries its legal basis and is logged against it. Agents act under scoped identities with permissions per system and per action, and every action is attributed. The audit log, policy decisions and model inventory that result are the EU AI Act, GDPR and NIS2 evidence, produced by running the platform, not written for the auditor afterwards.

  • No foreign dependency in the loopOpen-weight models served on state-controlled infrastructure. No inference call, no licence check and no update path outside the perimeter.

  • Clearance at retrievalDocument classification is first-class metadata. An analyst with a lower clearance never sees a passage above it, even inside the same network.

  • Legal basis in the queryA cross-ministry query carries the legal basis, the purpose and the retention period, and the data product enforces aggregate or pseudonymised results where the law requires.

  • Evidence, not a slideThe audit log, policy decisions and model inventory are the accreditation evidence, produced by running the platform, not written afterwards.

Newsletter

Keep an eye on this space

What changed for your sector in European AI sovereignty, and what we learned in the field. A few times a year, no drip campaign.

A few times a year. No drip campaign, unsubscribe in one click. Privacy policy

Use cases

Use cases for national government

Classified networks, cross-ministry analytics and governed AI at state scale.

Back Office Automation

Administration

Challenge

Manual approval processes, procurement delays, and administrative burdens slow down operational readiness and consume valuable personnel hours.

Solution

Automate common approval use cases, procurement requests, and HR processes with intelligent agents that ensure policy compliance.

Read more

Streamlined operations allowing personnel to focus on mission-critical tasks rather than paperwork.

Cross-Agency Benefit Adjudication

Social Services

Challenge

Citizen applications require verification across Tax, Health, and ID agencies, but sharing raw data violates privacy statutes.

Solution

Federated agents query data products across agency domains, returning only 'Yes/No' eligibility proofs based on pre-approved policy code.

Read more

Instant adjudication without creating a central database of citizen data, fully compliant with GDPR and local privacy laws.

Citizen-Developer Case Automation

Digital Services

Challenge

Departments have a backlog of small, repetitive workflows — a permit reminder here, an intake form there — but IT teams cannot build a bespoke agent for every one.

Solution

A governed no-code builder lets policy and operations staff assemble their own AI agents from approved building blocks, with every workflow still subject to the same access controls and audit trail as an engineered agent.

Read more

Dozens of small workflows automated by the teams that own them, without adding to the central engineering backlog or bypassing governance.

Shadow AI Discovery for EU AI Act Readiness

Compliance & Risk

Challenge

Individual teams have quietly adopted their own AI tools and agents, so the organisation cannot produce a complete inventory ahead of EU AI Act high-risk obligations.

Solution

Continuous discovery surfaces every agent and AI tool in use across departments, classifying each against EU AI Act risk categories and routing unsanctioned use into governed alternatives.

Read more

A complete, defensible AI inventory and a measurable reduction in unauthorised tool use ahead of the 2 December 2027 enforcement deadline.

Human-in-the-Loop Policy Exception Handling

Case Escalation

Challenge

Most applications follow a straightforward rule, but the exceptions — a hardship case, an unusual combination of circumstances — need a human decision, and today those cases get lost in the same queue as routine ones with no clear handoff.

Solution

The AI OS routes the routine majority through automated processing while recognising genuine exceptions and handing them to the right official with full context already assembled, then carries the human's decision back into the process automatically.

Read more

Exceptions reach a human reviewer faster and with better context, while the routine majority never needs one at all.

One Citizen Record Across Departments

Master Data

Challenge

Tax, health and licensing systems each hold their own version of "this citizen" or "this business," with different identifiers and slightly different details, so cross-department work means guessing which records actually refer to the same person.

Solution

An ontology defines each citizen and business as a single entity, resolved once across every source system, so departments and agents reason over one consistent identity instead of reconciling mismatched records.

Read more

Cross-department processes start from one agreed identity instead of a manual matching exercise, cutting errors and delay.

FAQ

Frequently asked questions

How do air-gapped AI deployments work for sensitive government data?+
The complete platform, including open-weight models, retrieval indexes, agents and analytics, runs inside the classified network with no outbound connection. Models and software updates arrive through the network's accredited import channel, such as approved media or a data diode, and every update is recorded. Retrieval enforces document clearance markings, so nothing is served above the reader's clearance. See air-gapped deployment and air-gapped AI.
Can ministries analyse data together without a central data warehouse?+
Yes. In a data space each ministry keeps its data where it is and publishes governed data products under its own access policy. A cross-ministry question is a query over those products, executed under a named legal basis and logged, with aggregation or pseudonymisation enforced where the law requires.
How does the platform help with EU AI Act readiness across a government?+
By making AI use visible and governed: shadow AI discovery finds what is already in use, the model inventory and policy engine classify and control it, and logging and human oversight meet the high-risk obligations. The EU AI Act page maps the controls.
Is one platform enough for both the unclassified and the classified side?+
Yes, and that is the point for accreditation: the same stack, governance and audit on both sides means one assessment, one evidence set and no gap between the pilot environment and the network where the work is.
What about a national sovereign cloud or a government data centre?+
The platform runs in a sovereign cloud that meets national requirements, on government data centres, or on-premises, and moves between them without re-architecting.
How is agent access to ministerial systems controlled?+
Agents are first-class identities under a zero-trust identity model, with scoped permissions per system and per action. Every action is attributed and logged, so the auditor can see who or what did what.
Do you partner on tenders and framework contracts?+
Yes, always. We are always looking to partner with primes, integrators and consortia on tenders, RFPs, framework contracts and European programmes, as the sovereign AI and data platform inside a larger bid or as a specialist subcontractor. If you are preparing a bid, talk to us early.

Or write to us

Tell us what you are working on and who should reply. A person reads it and replies within one business day.

We only use these details to reply to you. Privacy policy

Prefer to write? Email hello [at] scrydon.com and we will get back to you.

NEXT STEPS

Keep going

Three routes from here: the rules you will be measured against, the platform these outcomes run on, and the sessions where we walk through them.

Next webinar

How – Inside the AI OS: running governed agents on your own cluster, live

17 Sept 2026, 09:00

Part 2 of the Sovereign AI series, for engineers and architects. No slides after minute five: an agent gets an identity and scoped permissions, calls tools over governed MCP, retrieves from the ontology rather than raw tables, runs inside the sandbox and is stopped when it steps outside policy, and everything lands in the audit trail — then the same stack brought up on a disconnected network. Properties and refusals, shown rather than claimed.

Partners

Building the future of Data & AI together with leading innovators. Learn more.
Delaware logo