Initializing portfolio

000

Aravind.
All articles
AI5 min read

India's Government Is Buying AI That Acts, Not Just Answers

MeitY wants an agentic AI assistant with DigiLocker as its first implementation, an AI platform drafting government tenders, and up to 20 firms to modernise legacy state IT. The accountability framework is arriving second.

AravindChief Technology Officer & Advisor · AI, Cloud & Cybersecurity
India's Government Is Buying AI That Acts, Not Just Answers

The Indian state has spent the last two years putting AI into places where it answers questions. That phase is ending. What replaces it is harder to govern.

From answering to acting

A restricted request for quotation from the National eGovernance Division, the MeitY body behind much of the country's citizen-facing digital plumbing, asks vendors for a reusable "unified AI assistant and bot" platform. The design brief is not a chatbot. It specifies an LLM-driven agentic system that can orchestrate several AI components at once, with DigiLocker as the first implementation.

The reusability is the point. Consent management, analytics and the rest are to be built as components other government bots can pick up, registered on NeGD's common AI Services Platform, with datasets and evaluation assets pushed to AIKosh. This is a template, not a one-off procurement.

The distance between those two things is larger than the vocabulary suggests. A chatbot tells a citizen where to apply for a document. An agent works out what the citizen wants, pulls the relevant records, calls approved government tools and finishes part of the job itself.

Rocky Scopelliti, who wrote The Conscious Code, framed the upside to Moneycontrol in terms of access: a citizen asking in their own language for the benefits they are entitled to, with the system handling the bureaucracy on their behalf. For people shut out by language, literacy or paperwork, that is not a marginal improvement.

It is not one pilot

Procurement is the second front. Cactus Technology Solutions, out of Mumbai, has won the IT ministry's contract to build an AI platform that drafts, reviews and validates government procurement documents.

The efficiency case is easy to make. Government procurement runs on volume, technical specifications and standard clauses, and a model can cut the hours officials spend assembling them. The harder question is where drafting ends. Jameela Sahiba of The Dialogue put the real test plainly: the policy question is not whether these systems are accurate enough, it is whether we are clear about which parts of an administrative process can safely be delegated to a machine and which cannot.

Applied to procurement, that means asking whether the system is generating language or quietly determining specifications, eligibility conditions and evaluation parameters. The official using it may not be able to tell the difference.

Then there is the infrastructure. NICSI is looking to empanel up to 20 technology firms for AI-enabled modernisation of legacy government IT, with ten slots for general vendors and ten reserved for startups and MSMEs. The selected firms would assess ageing applications across ministries, states and PSUs and recommend how to modernise them. MeitY has separately reopened its AI manpower empanelment, after picking TCS, NEC India and four others in the first round, so departments can draw on AI architects and ML engineers without running a fresh tender for every project.

None of this reads like a collection of pilots. It reads like an attempt to make AI a layer sitting across India's existing digital public infrastructure.

The security problem arrives at the same time

The capability that makes an agent useful inside government makes it useful against government. In June, MeitY Secretary S Krishnan circulated a warning about AI-assisted exploitation of digital infrastructure, and CERT-In's accompanying blueprint describes generative models and autonomous agents accelerating reconnaissance, vulnerability discovery, targeted phishing and malware development.

CERT-In's answer is partly to use the same tools. It has operationalised an AI-powered war room and is running dry runs with models that Krishnan said deliver roughly 60 to 70 per cent of the capability of Anthropic's Mythos model. Government organisations have been asked to tighten multi-factor authentication, patching, vulnerability assessment and offline backups. Employees have been advised to keep official and sensitive information out of unapproved external AI platforms.

That last measure is not a ban on generative AI. It draws a boundary around what data may leave.

Where accountability breaks

The interesting failure is not a hallucination. It is the system doing exactly what it was built to do and producing the wrong outcome.

Sahiba's prescription is narrow permissions rather than broad database access: task-specific, time-bound, auditable. A procurement agent should not reach unrelated departmental records because it might one day need them, and should not modify a source database without explicit permission. Tool use and external actions need defined boundaries, particularly where an agent can act without a fresh human instruction at every step.

Scopelliti pushes on consent. A citizen agreeing to let an AI fetch a document from DigiLocker is simple. That same consent cannot be stretched to cover an agent submitting information, making declarations, initiating payments or making choices that affect someone's eligibility or legal position. Government is not a commercial application. These systems mediate the relationship between a citizen and the state.

Salman Waris of TechLegis names the weakness I see in enterprise deployments too: most Indian deployments still treat safety as an uptime and authentication problem rather than an explainability and contestability problem. He also points at sequencing. Government AI assistants sitting on top of DigiLocker and Aadhaar will process exactly the class of personal data the DPDP framework governs, and they are being designed and piloted before the consent-manager and rights-of-erasure machinery is live.

Human-in-the-loop is the working assumption almost everywhere. Agentic design erodes that assumption faster than accountability frameworks are catching up.

Credit where it is due

The NeGD tender is not naive about any of this. It asks for human-in-the-loop review, evaluation covering hallucinations, tool accuracy, multilingual performance and safety, and dashboards tracking agent behaviour and latency. A specification that refuses to treat model accuracy as the only safety measure is further along than most enterprise AI programmes I have reviewed.

Writing safeguards into a tender document and proving they hold in production are different exercises. The second one is where this gets decided.

Source: India is putting AI to work across government. The bigger question is how much power it should have — Moneycontrol

#AI Governance#Agentic AI#MeitY#DigiLocker#CERT-In

Comments

Checking you're human…

Keep reading

Get the next essay first

Checking you're human…

By subscribing you agree to our Privacy Policy. Unsubscribe anytime.