05Public sector
AI agents in the public sector: the record before the signature
A program owner who has to approve an AI agent needs to be able to say what it was allowed to do, and show it. TrustGate gives a record of what each agent was cleared to do, made before the action ran.
It is not an authorization to operate, a certification or a compliance opinion.
What the approving official needs
- What the agent is allowed to do, and what it is not.
- Which actions need a person.
- A record, made before the action, that the agent did not write.
- A plain answer when a result cannot be confirmed.
TrustGate returns a signed allow, deny or escalate decision before the action runs, for actions that go through it. The receipt binds the agent, action, target and exact arguments that were evaluated.
Unknown is an answer
An outcome we cannot confirm is reported as unknown, never as success. TrustGate reports 'could not check' separately from 'checked and found nothing'.
The responsibility stays with the organization
The UK Information Commissioner's Office writes that agents “are not and should not be considered as legal entities, even if organisations using agentic AI may seek to blame it for errors.”
54% of organizations have no defined approach to limit AI agent access, or rely on predefined human access, according to a Gartner survey of 297 cybersecurity leaders in the second quarter of 2026.
What this is not
- Not an authorization to operate, an accreditation or a certification.
- Not a compliance, legal or audit opinion.
- Not a lock. Signatures prove and detect. They do not prevent.
How a program starts
Bring the mission workflow and the official who needs a record before they sign. We start with 1 workflow.
Quick answers
Does TrustGate give an authorization to operate?
No. TrustGate is not an authorization to operate, an accreditation or a certification. It produces a record of what an agent was cleared to do.
What does a public-sector program owner get from TrustGate?
A record of what each agent was cleared to do, made before the action ran and not written by the agent. TrustGate returns a signed allow, deny or escalate decision before the action runs, for actions that go through it.
Sources
Each source was read on October 2, 2026. Wording in quotation marks is exact; the rest is paraphrase.
- UK Information Commissioner's Office, Tech Futures: Agentic AI, data protection and privacy risks · UK Information Commissioner's Office · No publication date shown on the page
- Gartner press release on CISO actions for the end of 2026 · Gartner · 2026-09-30