Solutions/By industry/Government and Public Sector
For government and public sector

Deny-by-default enforcement for

Public agencies deploy AI against FedRAMP, FISMA, FOIA, and data sovereignty constraints all at once, and the January 2026 CISA incident showed what happens when governance relies on individual discretion. Igris provides the enforcement layer: deny-by-default policies that admit only approved providers, content guards that catch sensitive designations, and an audit trail that satisfies FOIA and FISMA at the same time.

USE CASE 01
01
Access Control

Citizen Service AI Chatbot

piideny-by-defaultcompliance
Problem

A government chatbot for tax inquiries, benefits status, and permit applications receives citizen personal identifiers as a matter of operational routine: social security numbers, tax IDs, residential addresses, and in some cases healthcare, disability status, and immigration-adjacent details. The data protection risk: citizen PII transmitted to a commercial LLM provider that is not FedRAMP-authorized violates FISMA security requirements for federal systems, constitutes a GDPR Article 5 breach for EU-connected citizens, and violates DPDP Act 2023 obligations for Indian citizens. The EU AI Act classifies AI systems used in government services affecting citizens' access to public benefits under Annex III as high-risk, with documentation and human oversight obligations applying from August 2026. The accountability risk is structural: government chatbot interactions with citizens are government records subject to FOIA disclosure requests. Policy guidance did not prevent the CISA FOUO incident. Only technical enforcement does.

Igris Solution

Guard applies PII redaction policies to every citizen message before it reaches the LLM, stripping social security numbers, tax IDs, residential addresses, and immigration-related identifiers automatically. A deny-by-default policy on every government chatbot connection means only explicitly approved, FedRAMP-authorized providers are permitted to receive prompts — any model or provider not on the allowlist is blocked at the gateway layer regardless of how the integration is configured or updated. Tenant isolation between department connections ensures that a citizen interaction with the tax service cannot appear in any context accessible to the benefits service or the permits office. The Igris audit trail creates a complete, timestamped record of every citizen interaction, every redaction event, and every policy enforcement action — the FOIA-ready record the agency needs and the FISMA continuous monitoring evidence the CISO requires.

Outcome

Citizen PII is protected by technical enforcement before it reaches any external provider. Only FedRAMP-authorized models are reachable, enforced at the gateway regardless of future integration changes. Every citizen interaction is on record, FOIA-queryable, and timestamped. When an oversight body asks how citizen data was handled in the government AI channel, the audit trail provides the documented answer.

USE CASE 02
02
Content Guard

Internal Document Processing

contentdeny-by-defaultaudit
Problem

Government employees using LLMs to summarise policy documents, draft ministerial responses, and analyse legislative text are doing at scale precisely what the CISA Acting Director did in January 2026: routing sensitive government content through a commercial AI provider without a technical control to stop it. Controlled Unclassified Information, FOUO designations, law enforcement sensitive markings, and pre-decisional deliberative content are present in the documents that staff interact with daily. When any of this material reaches a commercial LLM provider without documented controls, the agency has violated FISMA security requirements, created a records management problem under FOIA, and in EU government contexts, breached GDPR data minimisation obligations. The EU AI Act's Annex III classification of AI used in public administration as high-risk adds documentation and oversight obligations from August 2026.

Igris Solution

Guard content guards detect classified and sensitive document markers — CUI designations, FOUO headers, law enforcement sensitive patterns, and agency-specific sensitivity taxonomies configured as custom detection patterns — blocking sensitive material before any prompt leaves the network. An allowed model list on every staff-facing connection restricts AI tool access to FedRAMP-authorized providers only, enforcing the procurement requirement FISMA mandates. Igris Lens tracks AI spend per department connection, giving budget officers the per-department cost visibility government appropriations accounting requires. Department budget caps prevent any single unit from exceeding its allocation. The full audit trail records every document interaction, every content detection event, every policy enforcement action, and every model used.

Outcome

Sensitive government documents are protected by a technical detection control at the prompt layer — not by policy memos, training programmes, or individual discretion. Only FedRAMP-authorized providers receive staff prompts. Per-department spend is visible and bounded. The audit trail satisfies FOIA accountability requirements and FISMA oversight obligations simultaneously.

USE CASE 03
03
Agent Governance

AI-Assisted Benefits and Social Services Case Management

piimcpaudit
Problem

Government agencies using AI to assist with welfare, disability, and housing benefits processing handle data that combines financial vulnerability indicators, health and disability status, family composition, and immigration-adjacent information. The EU AI Act explicitly classifies AI systems used in social benefits eligibility determinations under Annex III as high-risk, with mandatory documentation, human oversight, and audit trail requirements from August 2026. FISMA security controls apply to every vendor interaction. GDPR Article 9 applies to health or disability data in EU citizens' benefits assessments, and DPDP Act 2023 applies for Indian government social services platforms. An AI-assisted eligibility determination that cannot be documented, explained, or attributed to a specific model and policy set is not just a compliance failure — it is a citizen rights problem.

Igris Solution

Guard applies PII redaction to every benefits assessment prompt, stripping financial account details, health and disability identifiers, and family composition data not required for the specific inference task. The deny-by-default policy restricts model access to FedRAMP-authorized or government-approved providers only. Sentinel governs every tool call the benefits AI agent makes, enforcing an allowlist that restricts which citizen records and databases the agent can access for each specific case. The audit trail records every eligibility interaction, every redaction event, and every agent action — the EU AI Act high-risk documentation and FISMA oversight evidence assembled automatically.

Outcome

Benefits AI operates with documented governance controls on every citizen interaction. EU AI Act high-risk system documentation exists for every eligibility determination the AI informed. FISMA continuous monitoring requirements are met by the audit trail. When a citizen challenges a determination and requests to know how AI was involved in their case, the governance log provides the documented answer.

USE CASE 04
04
Content Guard

AI FOIA Response and Records Management

contentdeny-by-defaultaudit
Problem

Records offices using LLMs to assist with FOIA response workflows — searching repositories, identifying responsive records, flagging exemption candidates, and drafting redaction rationale — are processing the very data that FOIA governs and FISMA protects. A review pipeline that sends unredacted government documents to a commercial LLM to help identify exemptions has transmitted sensitive material to an external provider before any exemption determination is made. For documents containing citizen personal data, law enforcement sensitive markings, or pre-decisional deliberative content, that is the exposure the agency was trying to prevent. GDPR and DPDP Act obligations apply to any citizen personal data in the documents being reviewed.

Igris Solution

Guard applies content detection policies to FOIA review prompts, catching sensitive markings, personal data patterns, and law enforcement sensitive designations before any document content reaches the LLM provider. The allowed model list restricts FOIA processing to FedRAMP-authorized providers. The audit trail records every document processed, every detection event, and every policy action — creating the internal processing record that supports public transparency obligations, oversight accountability, and the agency's own FOIA compliance documentation.

Outcome

FOIA response AI assists records officers without exposing unredacted sensitive documents to unapproved providers. The processing audit trail supports internal accountability and public transparency requirements. When a requestor challenges the agency's document handling, the governance log documents how every record in the review set was processed.

See Igris for Government and Public Sector

Enforce AI governance, do not rely on discretion

See how agencies restrict AI to FedRAMP-authorized providers, block CUI and FOUO content, and keep FOIA-ready audit records.