ArchitecturePublic Sector
A reference architecture for a citizen-facing government AI assistant
A citizen-facing assistant earns trust by answering only from official guidance, saying when it does not know, and passing people to a caseworker or an existing online service once a question becomes personal. This reference design covers the scope rules, the content and retrieval layers, handover, model hosting, accessibility and records, and how to test the assistant before and after launch.
On this page
- What a government assistant should and should not do
- Reference architecture for a citizen-facing assistant
- Treating published guidance as the assistant's source of truth
- Handing a conversation over to a caseworker
- Model hosting options for a public-facing assistant
- Accessibility and inclusion requirements for a public chatbot
- Logging, retention and information requests for chatbot transcripts
- Testing a government assistant before and after launch
- Questions and answers
- Sources
What a government assistant should and should not do
Settle scope before choosing any technology. Each rule removes a class of failure that prompt tuning cannot fix.
- If
The question is about published rules, deadlines or how a service works.
ThenAnswer from official guidance, quote the relevant passage and link to the page.
Grounded, cited answers can be checked by the user and tested by the service team.
- If
The person wants to apply, pay, book or report something.
ThenHand off to the existing online transaction rather than rebuilding it inside the chat.
Transactions already have validation, identity checks and records that a chat would duplicate badly.
- If
The answer depends on the person's own circumstances, such as eligibility or the progress of their case.
ThenExplain the general rule, then route to the official eligibility checker or a caseworker with the conversation attached.
The assistant has no authority to decide entitlement, and implying otherwise creates false expectations.
- If
A message suggests risk to someone's safety, abuse or a crisis.
ThenShow a fixed, pre-approved response with emergency and specialist contacts, and offer an immediate human route.
Generated text is the wrong tool where wording has been agreed with safeguarding specialists.
Reference architecture for a citizen-facing assistant
- Accessible channels
A chat component on the service's own pages that works with screen readers and keyboards, beside phone and in-person routes.
- Dialogue and policy rules
Classifies each message and decides whether to answer, look something up, refuse or hand over.
- Retrieval and citation
Finds passages in approved content and passes only those, with their links, to the model.
- Structured lookups
Facts such as collection days or opening hours fetched from systems of record, never generated.
- Language model, onshore
Writes the answer from retrieved passages, hosted to match the sensitivity of the data it sees.
- Approved content store
Published guidance with owners, review dates and expiry, re-indexed whenever pages change.
- Handover to caseworkers
Creates a case or callback with a conversation summary in the existing case system.
- Logs, tests and records
Redacted transcripts, test results and wrong-answer reports, kept under the retention schedule.
Treating published guidance as the assistant's source of truth
The assistant can only be as accurate as the content it retrieves. Index pages the organisation publishes and maintains, such as service guidance, policies, fees and forms, and leave out internal drafts, staff notes and forum posts. Each passage should carry its URL, review date and owning team, so a wrong answer can be traced to a page and corrected there.
When retrieval finds two pages that disagree, fix the content rather than telling the model which to prefer. Give seasonal guidance an expiry date, re-index on every publish, and send content owners a regular list of questions the assistant could not answer: those gaps usually show where the website itself is unclear.
Handing a conversation over to a caseworker
- Resident
Starts with a general question on the council or agency website.
- Assistant
Answers general questions and recognises when one becomes personal.
- Content retrieval
Returns passages and links from approved guidance only.
- Case system
The existing system of record, where the request is logged and prioritised.
- Caseworker
Model hosting options for a public-facing assistant
| Consideration | Commercial model API | Managed model in an in-country cloud region | Open-weight model on infrastructure you control |
|---|---|---|---|
| Where prompts are processed | Depends on the provider's regions and terms; may be abroad | In the chosen national region, under the provider's terms | Wherever you host it, including onshore sovereign facilities |
| Who can see prompts | The provider, under its retention and abuse-monitoring terms | The cloud provider under contract; retention is usually configurable | Your operators and their contracted suppliers only |
| Model updates | Provider-controlled; old versions retire on its timetable | Chosen from a catalogue, still subject to retirement dates | You decide when to change, and must patch and re-test yourself |
| Operating effort | Lowest | Moderate | Highest: capacity, monitoring and security are yours |
| Usually fits | Prototypes over public content only | Most information assistants that see incidental personal data | Services handling sensitive data or bound by strict sovereignty rules |
Check the contract rather than the defaults: retention, training use and data location are negotiable with some providers and fixed with others.
Accessibility and inclusion requirements for a public chatbot
Logging, retention and information requests for chatbot transcripts
Transcripts help with evaluation and complaints, but people type personal details into any text box. Redact identifiers at capture, keep raw transcripts apart from analytics, restrict access, and set retention in the organisation's records schedule rather than the supplier's defaults. Information held by a UK public authority, chat logs included, can be requested under the Freedom of Information Act 2000, so decide in advance how transcripts would be searched and which exemptions might apply6.
Tell people they are talking to an AI system. Article 50 of the EU AI Act requires systems that interact directly with people to make this clear unless it is obvious, and those duties have applied since 2 August 202657. In UK central government a public-facing assistant also needs an algorithmic transparency record9; the transparency and impact assessment guide explains what to publish, and the government's AI Playbook is a useful companion for UK teams2.
Testing a government assistant before and after launch
Evaluation continues after launch; see also LLM evaluation sets.
Build a test set from real demand
Draw questions from site search, contact-centre categories and complaints, including misspellings and other languages, with the expected answer and source page for each.
Agree acceptance criteria with the service owner
Set the share of correct, cited answers required and the categories, such as fees or safeguarding, where any error blocks launch.
Red-team the edges
Try out-of-scope requests, attempts to override instructions, requests for advice beyond published policy and abusive messages.
Run a private beta with assisted-digital users
Include screen-reader users, people with limited English and people who rarely go online, observed by user researchers.
Trace every wrong answer in live service
Offer a simple way to flag a wrong answer, review flags weekly and trace each to content, retrieval or the model.
Re-test on every change
Re-run the full test set whenever the model, instructions or content index change, and before updating any published record.
Questions and answers
Should a government assistant use a public LLM API?
It can for prototypes over public content, but check where prompts are processed, how long the provider keeps them and whether they are used for training. A live service will receive personal details, even unprompted, so it usually needs contractual retention controls and in-country processing, or a model on infrastructure you control. Decide by the data the assistant will see, not by the model's benchmark scores.
How do we stop a government chatbot inventing policy?
Restrict answers to passages retrieved from approved content, require a source link for every factual statement, and refuse when retrieval finds nothing relevant. Test refusals as carefully as answers. Much invented policy comes from gaps or contradictions in the content itself, so send unanswered questions to content owners and fix the pages rather than adding more instructions.
What must a public body publish about its AI assistant?
At minimum, tell users they are talking to AI, cover the assistant in the accessibility statement and privacy notice, and explain how to reach a person. UK central government bodies in scope also publish an algorithmic transparency record. Publishing the assistant's scope, its content sources and how to report a wrong answer builds trust even where it is not required.
Can a government assistant answer in languages other than English?
Yes, but be explicit about how. Answers drawn from officially translated pages are the most reliable. Machine-translating answers widens access but can distort legal or financial terms, so label translated answers, link the original page and test the languages your residents use most. Keep phone and interpreter routes visible.
Sources
- Understanding accessibility requirements for public sector bodies — GOV.UK · checked 10 October 2026
- Artificial Intelligence Playbook for the UK Government — Government Digital Service · checked 10 October 2026
- Section508.gov: accessibility requirements for US federal agencies — US General Services Administration · checked 10 October 2026
- Directive (EU) 2016/2102 on the accessibility of the websites and mobile applications of public sector bodies — EUR-Lex · checked 10 October 2026
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 50 — EUR-Lex · checked 10 October 2026
- Freedom of Information Act 2000 — legislation.gov.uk · checked 10 October 2026
- EU AI Act Omnibus Agreement: postponed high-risk deadlines and other key changes — Gibson Dunn · checked 10 October 2026
- Web Content Accessibility Guidelines (WCAG) 2.2 — W3C · checked 10 October 2026
- Algorithmic Transparency Recording Standard (ATRS): mandatory scope and exemptions policy — GOV.UK · checked 10 October 2026