As part of the Government AI Campus, Apolitical is publishing a series of articles featuring leaders from the 2026 Government AI 100, a list recognising public servants around the world who are pioneering AI adoption, capacity building and regulation.
Apolitical spoke with Evelyn Grass, Head of Division for Artificial Intelligence at Germany's Federal Ministry for Digital Transformation and Government Modernisation. Working across national, European and international AI governance, she helps shape Germany's approach to AI policy, from implementing the EU AI Act to engaging in global discussions on the future of responsible AI.
You began your career in antitrust law before moving into digital and AI policy. How do you think that your legal background has shaped the way that you approach AI governance?
Well, I'm currently heading the Unit on Artificial Intelligence in the newly established Federal Ministry of Digital Transformation and Government Modernisation in the German government. My background as a former antitrust lawyer is important here because it gives me first-hand experience of how companies work with European regulation in practice.
For my team, it's really important to have a strong economic perspective on the things we're doing and to understand what matters to businesses when it comes to regulation. What you really need is clear, practice-oriented guidance, and to ensure regulation enables innovation and business use cases rather than restricting or hindering them.
As one of the leads on the EU AI Act at a national level, what do you think governments most commonly underestimate about what it actually takes to put major AI regulation into practice?
Firstly, regulating AI is a real challenge because it’s such a new and fast-moving technology, particularly when you compare it with our legislative processes. For example, the EU AI Act was proposed in April 2021 and we finished negotiations in February 2024. But since then, there have already been lots of further developments.
Secondly, we don't know exactly what will happen when it comes to the technology's development. Experts have different views on where the technology is heading, so you have to think in scenarios. For example, I find the International AI Safety Report a really valuable tool because it describes several scenarios that could arise.
Thirdly, regulation is about addressing risks linked to the technology, but experts often disagree on what those risks are. You have outstanding experts like Yoshua Bengio on the one hand, who always underline that there are enormous risks linked to the technology. Yet on the other hand, you have someone like Yann LeCun saying large language models don’t have any existential risks. So this is something you have to deal with as a regulator and find the right balance.
“Finally, what businesses always look for is legal certainty. They want to have a clear legal framework that they can really count on. But with a fast-moving technology like this, you’ll also need to adapt it every once in a while. So the key is to make some really targeted amendments, but not create an absolute shift in the way we address AI regulation”.
The recent amendments to the EU AI Act by the AI Omnibus package are a good example of this. They were designed to address issues like overburdening companies while also tackling newly emerging risks such as sexualised deepfakes. In the end, I think we had a lot of success. But it was a challenge to achieve everything within a very short timeline while also ensuring there were thoughtful discussions and that people had enough time to prepare for these conversations.
Many governments are currently developing, and in some cases revising, their national AI strategies. Based on your experiences, what’s one piece of advice you would give them when revising their national strategies?
When it comes to an AI strategy, I would say you have to bear in mind that the AI technology is moving very, very fast. Any AI strategy should reflect this. I think it’s less helpful to draft a very rigid strategy that acts as a fixed foundation for years. Instead, you should find a process that allows more flexibility, like thinking in scenarios and following a more agile process.
That's increasingly how we're approaching AI in Germany, particularly in the newly established Ministry for Digital Transformation and Government Modernisation. Rather than relying on a single long-term plan, we're working through a range of projects at once. We often pursue several approaches to the same policy goal, test different solutions and then adjust course based on what we learn. A major focus is ensuring that public administration acts as a role model in AI adoption. We see AI as an opportunity to modernise the state, make government more efficient and flexible and use public procurement to help strengthen the wider AI ecosystem.
“One example is the Deutschland Stack, a programme to develop a suite of digital and AI tools for public administration. It brings together German and European startups to build practical solutions that government bodies can use, while also helping to strengthen domestic and European AI capabilities”.
Alongside this, we're supporting projects on foundation models and frontier AI, both nationally and with international partners, and reviewing areas of the legal framework such as copyright and data protection. Ultimately, the goal is to keep multiple workstreams moving at the same time and retain the flexibility to adapt as the technology evolves.
I know that you represent Germany in forums like the OECD, where there are countries with very different priorities all at the same table. What does it take to build meaningful international consensus and collaboration on the way that AI is governed?
When you look at the AI technology, it doesn’t know borders. AI models, AI tools and AI systems come along with huge opportunities for all societies, all governments and all countries. For example, cancer treatment or tackling climate change. But at the same time, there are major risks linked to this technology that affect all of us as well. Like the risk of biochemical weapons, the loss of control issue, and the misuse by bad actors or cyber threats.
“I already mentioned the International AI Safety Report, but I think it’s an amazing product in this respect. It has been drafted by more than 100 independent experts from more than 30 countries of the world, and they really achieved a consensus on what they were writing. I always refer to this report because it really shows we are sitting, to some extent, in the same boat”.
I also think we can learn from each other. When I attend OECD meetings, I always learn a lot from what other jurisdictions are doing and the policy approaches they’re taking. So even if it’s not complete consensus, there are still lessons that you can take from all of those other countries.
From what you’ve seen in Germany and the international forums that you’ve sit in, what capability gaps most commonly hold governments back from adopting AI responsibly? And what’s actually worked to help you address that?
Well, I think that largely depends on what kind of country you’re looking at. For example, when you’re a country from the Global South, you’ll have very different challenges to a country like Germany. I’d distinguish between government-specific challenges and then challenges that every institution faces when trying to adopt AI.
When it comes to government-related challenges, the key issue is that we’re dealing with confidential data and documents. So we can’t just make use of tools like ChatGPT or Anthropic’s Claude for our work. We need sovereign, secure structures. In Germany, we’re addressing this by building our own generative AI platform for public administration called KIPiTZ (Künstliche Intelligenz Platform für IT-Lösungen). It covers all sorts of use cases, from summarising documents and analysing huge amounts of data to translation work. It’s run on-premises so that it’s secure, and it’s been developed specifically for the German public administration. But it includes mainly open source models and can be linked to other models as well in a safe and secure way.
We’ve also created a marketplace where public authorities can share AI tools and use cases with one another. The idea is to make it easier for organisations to learn from each other, see what’s working elsewhere and accelerate adoption across government.
Beyond the technology itself, AI literacy remains a major challenge. You have to train people and help them understand how to use these tools effectively. We have training programmes for civil servants, but it’s also a leadership challenge. A big part of our work is encouraging teams to share experiences, learn from one another and continually improve how they use AI in their daily work.
How long did it take you to build KIPiTZ?
We really started from the very beginning when ChatGPT was published. We discussed how we could create something similar for the German government. Of course, it took quite some time. First of all, we created a version which could only be used with public data. Now it’s able to run on confidential data, which is a huge step forward.
Could you share an example of an AI initiative that you think genuinely advanced public value? What made the approach work and what can other governments take from it?
So we’ve set up a really interesting initiative called ‘Project Spark’. It’s an innovation partnership focused on using agentic AI to accelerate complex planning and approval processes. The AI helps structure and speed up these processes, but the final decision always remains with the responsible public authority.
One of the things we wanted to demonstrate was that agentic AI can work effectively in a highly regulated, rules-based environment. In fact, the existing rulebook proved helpful because it provided clear parameters for the AI system to operate within. We made the project open source so that other governments can learn from it and adapt it to their own needs. Beyond improving administrative processes, it has also helped create wider public value by speeding up procedures that matter to citizens and businesses.
“We also established an Agentic AI Hub that brings together startups and public authorities. Government organisations can share challenges they are trying to solve, while startups develop and test potential solutions. This has helped foster collaboration across local, regional and federal government and strengthened the wider AI ecosystem in Germany”.
Finally, what excites you most about governments using AI, but also what concerns you?
What excites me most about AI in government is its potential to help public administrations work in a more modern, efficient and informed way. We tend to talk about AI hallucinating or creating false information, but actually, what I see in my daily work is that we are far better informed and can analyse a huge amount of data by using AI.
For example, as a unit responsible for AI regulation, we receive a huge volume of position papers and stakeholder submissions. Previously, there was simply no chance to read and digest them all. But now, it's possible! This allows us to analyse stakeholder input in a much better way, reflect on it and use it to make more informed decisions.
When it comes to concerns, for democratic countries based on the rule of law, I think what is mostly needed is a clear legal framework defining the limitations and setting clear requirements for when, and to what extent, state institutions should make use of AI. That is the basis for creating trust and ensuring these technologies are used responsibly. For Germany, as for other European Member States, the AI Act is of such importance because it provides exactly the basis for these rules and limitations.
Make sure to share your own thoughts with the author by leaving a comment below

Log in or sign up to continue the conversation