Operational notes Governance

AI in public administration: what AgID's guidelines change

5 min read

Files and documents stacked on an office desk
Public AI procurement becomes a documented procedure, not a trust-based negotiation.

The public consultation on AgID’s guidelines for the development and procurement of artificial intelligence in public administration closed on 11 April 2026. Since then, the two documents have been awaiting the opinions of the Conferenza Unificata (the joint State–Regions–Local Authorities conference) and the Garante Privacy (Italy’s data protection authority): the final version is expected in the second half of 2026 — that is, in these very weeks. For anyone selling technology to public administration, or building it in-house, the window to prepare is closing before the rules become binding on every administration.

Two documents, one objective

With Determination No. 43/2026 of 10 March, AgID (the Agency for Digital Italy) put out for consultation two distinct but complementary texts, envisaged by the Three-Year Plan for IT in Public Administration 2024-2026 and adopted under Article 71 of the Digital Administration Code: the Guidelines for the development of AI systems in public administration and the Guidelines for AI procurement in public administration. These are not a duplicate of the EU AI Act. They are the operational layer that is missing today: how to design an AI system in-house, and how to buy one from an external supplier without ending up in litigation, or with a system nobody can manage any more.

Procurement as leverage, not formality

The procurement document introduces a metric rarely seen elsewhere in Italian public administration: LCOAI, the Levelised Cost of Artificial Intelligence, which weighs a system’s total cost across its entire life cycle against the output it actually produces. No longer the price at signature, but what it genuinely costs to keep that system running for years. The guidelines provide a standardised technical specification template with eight annexes and a worked numerical example, designed for administrations that have often never assessed an AI bid against technical criteria of their own.

Suppliers are asked for more: verifiable technical documentation, demonstrated compliance with the EU AI Act based on the system’s risk level, a genuine AI Bill of Materials — the list of components, models and datasets that make up the solution — and an explicit exit strategy, to guarantee the administration data portability and contract reversibility. Anyone selling AI systems to public administration, including integrators who today simply resell a third party’s model, will need to start producing this documentation before it becomes a tender requirement.

In-house development: four levels of autonomy

The development document is aimed at administrations building AI systems internally, often with small teams and no prior experience. It introduces four levels of autonomy to classify how much a system decides on its own as against how much remains under direct human control, a modular logical architecture, and a seven-phase development model, with risk-classification checklists and impact-assessment forms to be completed before release. These are tools built for whoever has to answer to an inspection, not just for whoever writes the code: they trace decisions, not just features.

The point that cannot be waived: human responsibility

Both documents translate into concrete procedures a principle already set out in Italian Law 132/2025: AI in public administration operates in an instrumental, supporting function, while responsibility for the decision and the procedure always remains with the person. This is not a stylistic clause. It is the criterion that separates a compliant system from one that, in the event of a dispute, exposes the official who adopted it. It is the same principle we build our operational AI pipeline on: the agent proposes and executes, the critical action stays under traceable human control, whatever the sector.

What changes for those selling to public administration

For a private supplier — including companies that today work with regulated sectors such as defence or public healthcare — the practical effect is that procurement stops being a race to the lowest price and becomes a documentary check. Anyone who does not already have an AI Act compliance record, an up-to-date AI Bill of Materials and a reversibility clause in their standard contracts will start at a disadvantage as soon as the guidelines become final. This also applies to those operating outside public administration in the strict sense, because the same criteria of transparency and reversibility are becoming the standard that large private clients demand from their technology suppliers.

What to do

  1. Take stock of the AI systems already in use or out to tender, within your own administration or at the public-sector clients you serve.
  2. Prepare the documentation now: AI Act compliance record, AI Bill of Materials, impact assessment — before they become binding tender requirements.
  3. Review contracts in progress: check that a written exit strategy exists, with data portability and no technical lock-in.
  4. Put in writing who decides: the human-control principle must be assigned to an identifiable person, not left implicit.
  5. Follow the process: opinion of the Garante Privacy, opinion of the Conferenza Unificata, publication of the final version. Update specifications as soon as it is out.

Do you sell technology to public administration, or are you adopting it in-house, and want to arrive ready for the final version of AgID’s guidelines? Half an hour with one of our experts to work out what to prepare before they become binding.

Sources