Discussion about digitalising public administration drifts quickly towards the most visible applications — which are also the riskiest. They deserve to be separated clearly.
Three categories, three levels of risk
Internal support, with no direct effect on citizens. Finding a document in an archive, routing correspondence to departments, summarising a case file for the official handling it. An error costs time, not rights. Here the benefit-to-risk ratio is best — and these applications are also the most neglected, because they are not spectacular.
Interaction with citizens, without decisions. Assistants that explain a procedure, help fill in an application or say which documents are needed. The main risk is wrong information. It is managed through cited sources, clear marking of generated answers, and an obvious route to a human.
Decisions or assessments about people. Prioritising applications, assessing a risk, allocating a benefit. Here an error directly affects rights, and the requirements for transparency, contestability and oversight are strictest. Many of these uses fall into the high-risk category of the European regulation.
What is specific to the public sector
There are no \u201ccustomers who leave\u201d. A citizen cannot choose a different supplier for their identity document. The usual market mechanism that corrects a poor service is absent, so the correction has to be built explicitly into the process.
The duty to give reasons. An administrative act must be reasoned. \u201cThe system decided\u201d is not a reason, and an automatically generated justification must reflect the actual decision rather than rationalise it afterwards.
Contestability. There must be a real route for someone to contest and obtain human re-examination. That means process, people and deadlines, not just a button.
Public procurement. The requirements have to be written in advance, in the tender specification. Evaluation, documentation, rights over data, the ability to audit — all must be required from the start, because after signature they cannot appear.
Useful questions before starting
- What concrete problem are we solving, and what does success look like, measurably?
- Who does an error affect, and how can that person find out and contest it?
- What data is needed, and do we have a legal basis for it?
- Who remains responsible for the decision after implementation?
- What do we do if the system fails — is there a working manual route?
- How do we verify, a year from now, that it still works correctly?
A risk rarely discussed
Automated systems create process dependency. Once nobody practises the manual procedure any more, a failure no longer means \u201cwe fall back to the old method\u201d — it means a standstill.
In public administration, the ability to operate in degraded mode is not a luxury. It is a requirement.
