Organizations everywhere are under high pressure to show that they are adopting AI. Governments are no different. There is a hunt for AI use cases across public organizations, and tools like Apolitical’s government AI navigator can serve as inspiration.
While these initiatives are promising, the challenge, as usual, lies with implementation.
In fact, if the issue was just about finding a service that can leverage AI, governments don’t need to look further: they can just deploy AI in citizen services. AI enables 24/7 availability, increasingly agentic capabilities to resolve transactions end-to-end (and not clunky rules-based chatbots or limited FAQ answer tools), and rapidly evolving voice models that can increase accessibility for those less comfortable with digital interfaces and in a wide range of languages.
If the value is so clear, what then is stopping governments from adopting AI?
In Europe, part of the answer lies with how the EU is trying to deal with a legitimate concern: ensure AI can be trusted.
Europe may be regulating the wrong end of trust in AI
Last June, the EU published a Code of Practice on Transparency of AI-generated Content. This detailed 38-page document establishes a set of “voluntary” commitments that AI system providers and deployers can make to fulfill their transparency obligations under Article 50 of the AI Act. I added the quotes to the word voluntary because, while not signing the Code does not make a company non-compliant, those that don’t sign by the July 27 deadline will have to prove compliance with Article 50 on their own, with more scrutiny from market surveillance authorities, and none of the predictability that signing the Code affords.
Without getting too much into the weeds, the Code establishes two layers of transparency. An invisible one: watermarks and digitally signed metadata embedded in AI-generated content. And a visible one: an “AI” icon for deep fakes and for AI-generated or modified text published on matters of public interest.
The goal of the Code is the right one: increase trust in AI-generated content. I just think that it’s the wrong tool to achieve it. Even worse, it can do more harm than good, including slowing down adoption of useful AI tools.
I base my assessment on three main reasons:
First, this scheme rests on an assumption: that people are concerned with the (AI) origins of the content. This may be true in some cases, but I suspect that, in general, people are more worried about whether the content is accurate and trustworthy, regardless of which tool was used to create it. If this were the case, why not put the focus - and the responsibility and associated costs - on proving accuracy (when it matters) rather than provenance?
Second, it imposes a huge burden on AI providers and deployers. This will particularly affect smaller companies with lower resources. Yes, the Code of Practice contains some wording on proportionality for SMEs. But what is the point of adding any cost if it is just based on an assumption (people will be running detection tools on the content they consume, or checking the “AI” icon where it appears) that is likely misguided?
By the way, if the EU’s experience with cookies is evidence of anything, we should expect people to ignore the icon soon enough.
And third, it also imposes a heavy burden on governments. How realistic is it that supervisory bodies will be monitoring all AI-generated content (even if watermarks are machine-readable)? By the way, they will be monitoring whether the content has the “AI generated” label, not the actual potential harm: whether it is inaccurate, misleading or harmful. And it is also limited for key AI-generated content. The Code recognizes that reliable marking and detection may be technically limited for short text outputs, including outputs below a specified threshold. That limitation is particularly consequential for AI-powered conversational public services, where many responses are brief.
Instead, use procurement as an authentication tool
I doubt people or organizations will care about the AI watermark. Even if they do, what they really will demand is accuracy and trustworthiness.
Existing laws already address many downstream harms: fraud, impersonation, defamation, consumer deception and unlawful uses of personal data. I don’t think an AI icon will increase protections against those harms, while it will, for sure, raise the costs of developing and adopting AI tools. The critical question then is whether universal provenance requirements are the most proportionate intervention for every context, especially where governments can impose direct contractual accountability on the systems they procure.
I understand why the government would want to ensure that all the AI generated content that it uses in its services is trustworthy. Rightly so. The bar for trust in government should be higher than for any private organization.
But here I think governments have a better tool than demanding AI watermarks or the signing of the Code of Practice from their providers.
All the AI products and services that governments purchase will be subject to procurement and contracting. Why not add responsibility assurances for the accuracy and trustworthiness of all the content created in those services? This shifts the focus to the real goal - accuracy and trust - and puts the onus on the providers to ensure that they meet that purpose. AI providers can then be creative on how to achieve the goal. In practice, this could mean accuracy service levels, liability for harmful errors, and a mandatory human escalation channel. These measures will likely be more sophisticated, and perhaps even costlier for AI companies at times. Crucially, they will be much more effective than adding an icon or a watermark to a large chunk of their output.
This also aligns incentives. Contrary to a supervisory board needing to review massive amounts of AI-generated content, each government entity procuring an AI technology has a clear goal of ensuring that accuracy standards are met for its service. The AI provider or deployer will also want to deliver the services and meet the requirements to avoid being penalized and renew the contract.
Interestingly, the Code already concedes this logic: the labelling obligation for AI-generated text disappears when someone assumes editorial responsibility for its publication. Accountability substitutes for disclosure. Incorporating it into procurement simply extends that principle to a service in a way that can be enforced through a contractual relationship.
The EU should keep the goal, but change the tool
The EU’s common approach is to regulate at the layer that is easiest to legislate — upstream with the AI providers — rather than intervene at the point where harm actually occurs. It is a policy approach that may seem elegant on paper, but is expensive for the compliant, and mostly irrelevant to the wrong-doers.
It can also be self-defeating. The Commission’s AI Continent Action Plan exists because European companies and governments trail badly in actually using AI. Demanding use with one hand while adding ineffective burdens with the other just takes Europe further away from AI adoption without increasing citizens’ protection.
Unless it shifts its approach, on August 2, Europe will likely increase transparency but slow down progress in AI. But if they use procurement smartly, European governments can still show how to use procurement to buy AI that they can trust.
This article was originally published in the Datapolis substack.
Log in or sign up to continue the conversation