All Insights

Policy & Regulation

Ontologies in the public sector — how formal models make compliance verifiable

Public authorities and municipalities need AI that not only works but stays traceable. We show how ontology-based architectures pull compliance requirements from GDPR and the EU AI Act directly into the system structure — and why exactly that makes the difference between a pilot and production.

23 April 20268 min readBy Leonardo Bornhäusser

In the public sector, "works in the demo" is the weakest quality criterion. What counts is: verifiable, documentable, with clear accountability. This is exactly where ontological architectures play to their strength — they turn implicit assumptions into explicit contracts that an auditor can read.

Where authorities concretely hit the wall

We regularly see three patterns in mandates: first, shared terms are missing between specialist procedures — the same "applicant" is one thing at the social-welfare office and another at the building-permit office. Second, data provenance is not systematically captured — who makes decisions on the basis of which source? Third, pilots run into the sand because the Annex IV documentation is meant to be caught up only at the end, and then becomes "too expensive".

What an ontology structurally changes here

Once the core domain is formally modeled, clear rules apply: which entities exist, which relationships are allowed, which roles may perform which operation. These contracts move into the system structure instead of loose documents. Audit requirements become a consequence of the architecture, not an additional attachment.

Compliance becomes a by-product of clean modeling. Once the ontology is in place, GDPR disclosure, Annex IV documentation and data provenance fall out almost automatically.

Three concrete levers — without giving away IP

First lever: roles and permissions are anchored in the model, not in the UI layer. Second lever: data sources are named entities — we know at any time where a statement comes from. Third lever: decisions are versioned objects with assumption and outcome fields. All of this consists of methodical design decisions, not magic. The concrete implementation per mandate remains — unsurprisingly — confidential.

Why now is the right time

The Annex IV obligations of the EU AI Act tighten noticeably in 2026/2027, while GDPR audits in public administration become more systematic in parallel. Whoever starts now with a small, clean domain ontology has done the homework in two years. Whoever is still pilot-hopping will have to catch it up under time pressure — more expensive and worse.

We work with municipalities, state authorities and larger corporates on exactly these base structures. If this is an open question in your organization, write to us — we say early whether a mandate makes sense or whether a different approach would be cheaper for you.

OntologiePublic SectorEU AI ActComplianceGovernance