ua roadmap
!images129c5bfb-ec63-4c28-9d08-905ded46248f-01_309_310_187_2375.jpg
Building the Agentic State in Ukraine
Roadmap from Vision to Implementation
March 2026
Lead Author | Dmytro Ovcharenko
Co-Authors Danylo Tsvok, Luukas IIves, Manuel Kilian, Simone Maria Parazzoli
Contributor Ott Velsberg, Marco Daglio
PUBLIC BETA. This document is a public beta, representing an early iteration with further versions to follow. Feedback is welcome, including suggestions on scope and requests to clarify unclear concepts or descriptions. Please send your comments to roadmap@agenticstate.orq.
The Agentic State
Table of Contents
Executive Summary ….. 1
Introduction ….. 2
How To Use this Document ….. 2
The Case of Ukraine ….. 3
Part 1: What Ukraine Is Building ….. 6
A New Government Operating Model ….. 6
Values as Architectural Constraints ….. 6
Architecture: Thin Orchestrators on Shared Infrastructure ….. 7
Ukraine’s Technical Implementation Through the Lenses of the 12 Layers of the Agentic State ….. 7
Part 1a — Implementation Layers: Building the ‘Hands, Face, and Voice’ of Government ….. 7
Public Service Design and UX — Public-facing Agent (Layer 1) ….. 9
Internal Workflows — Internal Agent (Layer 2) ….. 13
Regulatory Compliance and Supervision - Compliance Agent (Layer 4) ….. 16
Part 1b - Enablement Layers: The Government’s Nervous System and Skeleton ….. 18
The Technical Foundations: Building a Government’s ‘Nervous System’ ….. 18
Technology Stack - An Agentic GovStack (Layer 9) ….. 20
Data & Privacy — Data Governance Components and Practices (Layer 8) ….. 24
Cyber Security — Zero Trust Architecture (Layer 10) ….. 29
The Institutional Foundations: Building an Agentic Government’s Skeleton ….. 31
Agentic Governance - Accountability, and Oversight (Layer 7) ….. 31
People, Culture, and Leadership — Who Leads, Who Decides, Who Is Accountable (Layer 12) ….. 35
Part 2: How Ukraine Is Building and Operating the Agentic State ….. 41
Ukraine’s Theory of Change ….. 41
Use-Case Selection and Piloting ….. 44
Phased Deployment Roadmap ….. 47
Conclusion ….. 53
Authors, Supporters, and Contacts ….. 54
Executive Summary
Since 2019, Ukraine has executed one of the most ambitious public sector digital transformations in the world, leaping from 102nd to 5th in the UN eGovernment ranking. The primary enabler is the Diia platform, now used by 23 million citizens. Ukraine has now set its ambition to go further: to turn its Digital State into an Agentic State - a new government operating model where AI agents anticipate citizen needs, coordinate across agencies, and act to deliver outcomes.
In October 2025, The Agentic State published a Vision Paper introducing a framework of twelve layers for rethinking government in the era of agentic AI. That framework gave governments a way to think about the Agentic State as a serious possibility. What it could not do was show how to reach it. This document picks up exactly there: a roadmap that bridges vision and execution, using Ukraine - today among the most frontier governments in the world on this agenda - as the primary case.
The document is organised in two parts. Part 1 describes what Ukraine is building: a public-facing agent (Diia.AI), a civil servant agent helping government employees navigate regulation, draft decisions, and build new agentic solutions, and a compliance agent shifting regulation from periodic audits to continuous risk monitoring. It then covers the technical foundations - including data, compute, and interoperability — and the governance and institutional architecture needed to run it all. Part 2 describes how Ukraine is building: its theory of change, how use cases are selected and evaluated, and a phased deployment roadmap running from shared foundations and pilots, through production-grade scaling, to the full vision of proactive cross-agency service delivery.
This document is a peek into the future of government. Ukraine is among the most ambitious and impactful governments in the world, and this roadmap reflects the thinking of its leadership at the frontier and beyond it. It is an attempt to cope with technological, administrative, and political uncertainty. Hence, the plans described here will evolve, specific components will change, and the technology itself is moving faster than any document can track. But the value of sharing this now is significant. The problem statements and categories of work are durable even as the solutions evolve, and we believe this roadmap will prove genuinely useful to governments worldwide working through the same transition.
This document is a public beta representing a snapshot of Ukraine’s thinking at time of publication. Given rapid progress in the broader field of agentic AI, it is not only possible but certain that many elements described here will change. Feedback is welcome at roadmap@agenticstate.orq.
The Agentic State
Introduction
How To Use this Document
In October 2025, The Agentic State published a Vision Paper with a comprehensive framework for rethinking government in the era of agentic AI. At its core was an architecture of twelve layers - six implementation layers ( $1-6$ ), where agentic capabilities deliver direct value to citizens, businesses, and government operations, and six enablement layers (7-12), the structural foundations that must be in place for those capabilities to work reliably and accountably.
That framework gave governments a way to think about the Agentic State as a serious possibility. What it could not do was show how to reach it, and build one. The hardest part of any transformation is not the vision but the transition from concept to reality - the specific decisions, trade-offs, and sequencing choices that turn architecture into a working system.
This document picks up exactly there. It uses the same
!images129c5bfb-ec63-4c28-9d08-905ded46248f-04_709_1369_742_1327.jpg
twelve-layer framework as its organising structure and fills each layer with the lived experience of a government that is putting it into practice: Ukraine, which in early 2026 is among the most ambitious countries moving from a digital state to an Agentic State.
The document is composed of two parts:
- Part 1 describes what Ukraine is building - the functionalities, architecture, attributes, and governance structure of the Agentic State as Ukraine is envisioning and beginning to implement.
- Part 2 describes how Ukraine is approaching the transformation - the theory of change, maturity models, and sequencing of decisions as it moves from vision to implementation.
The Agentic State
To allow readers to move between Ukraine’s specific choices and the broader questions they raise, the content across both parts is organised into two columns:
The right column presents Ukraine’s direct experience: the architecture, governance structures, sequencing decisions, and technical choices that Ukraine is making as it builds its Agentic State.
The left column steps back and asks the broader questions that underlie those decisions. These are intended as a mental dialogue for government leaders in other countries - an invitation to reflect on the same issues in their own context, placing direct experience into a larger frame and allowing for adaptation.
The Case of Ukraine
From Digital State to Agentic State
Since 2019, Ukraine has undertaken one of the most ambitious public sector digital transformations worldwide, leaping from 102nd to 5th in the UN eGovernment ranking. The primary enabler is the Diia platform and ecosystem. With 23 million users - the majority of the adult population - citizens hold a secure mobile-ID and interact with the state through digital channels. Underlying this is a unified backbone of identity, data, and payment rails, giving Ukraine something most countries lack: a single, interoperable infrastructure layer on which new services can be built without starting from scratch. Chief Digital Transformation Officers (CDTOs) coordinate technology strategy across every ministry and public agency.
Ukraine has now set the ambition to turn its Digital State into an Agentic State. Its National AI Strategy (2026) defines this plainly: a paradigm where “AI agents contribute to automating the entire cycle of public service delivery - from perceiving a citizen’s need to reasoning through a solution and acting to provide the service.” This is not simply a technology upgrade bolted onto existing processes, but rather the development of a new operating model for the government itself.
A digital state is reactive: the citizen identifies what they need, finds the right agency, fills in the right form, and follows up. An Agentic State is proactive: grounded in clear legal basis, consent, and institutional accountability, the government anticipates needs, coordinates across agencies, and acts on their behalf within clear boundaries. What makes this a new operating model possible is a deep transition: a shift from efficiency to architecture. Digitisation made existing processes faster. The Agentic State redesigns the processes themselves - how services are composed, how agencies coordinate, and how the system as a whole learns and adapts.
The Agentic State
The push toward the Agentic State was initiated under the leadership of Mykhailo Fedorov, who as Deputy Prime Minister and Minister of Digital Transformation from 2019 to January 2026, built the Diia ecosystem and first articulated the vision of an agentic AI-driven government. The work now continues under Oleksandr Bornyakov, who served as Deputy Minister at the Ministry of Digital Transformation since its founding and became Acting Minister of Digital Transformation in January 2026.
“AI agents represent the cutting edge of AI, fundamentally changing the way services are accessed globally. The future lies with Agentic States, and Ukraine is boldly advancing toward this format — where a single user request leads directly to results.”
Mykhailo Fedorov, Minister of Defence, former Minister of Digital Transformation, Ukraine
In late 2025, Ukraine launched Diia.AI, the first national AI assistant to deliver user-specific public services via a chat interface. Agentic AI is also being used to speed up permitting (see box). These are the first steps toward implementing the ambitious roadmap described on these pages.
Diia.AI
Diia.AI is the intelligent AI layer built on top of Ukraine’s Diia portal and mobile application, forming a core part of the country’s “Agentic State” vision. It includes the Diia Assistant (a citizen-facing concierge service) and Diia.Engine (a low-code platform with built-in AI modules), operating on a hybrid architecture that keeps personally identifiable information on-premise while using cloud infrastructure (Google Vertex AI) for LLM inference.
The Challenge
Ukraine has demonstrated it can build and deploy digital services at speed and scale. The deeper challenge is that the administrative model itself — how services are designed, how budgets are allocated, how decisions are made, how accountability is structured - was built for a world where each institution owns its domain end-to-end. Ministries were never designed to share infrastructure, cross-agency orchestration or real time coordination. Overcoming this does not only mean connecting databases. It requires building shared institutional capacity and the governance to sustain it. Ensuring that Ukraine constructs not just the technical plumbing but the organisational architecture that allows AI applications to function as a coherent system, rather than a collection of isolated pilots, is central.
The Agentic State
Why Now?
Three factors make this the right moment for Ukraine to move. Two are structural and apply to any government considering this transition. The third is uniquely Ukrainian.
1. The underlying AI technology has caught up with the ambition. Large language models can now interpret citizen requests, reason about which services are relevant, and coordinate multi-step workflows. What Ukraine’s Diia platform achieved through careful engineering and integration can now be extended through agents that work across the system.
2. Ukraine’s wartime context has created both necessity and political permission for rapid transformation. The normal bureaucratic resistance to change is weaker when the alternative is institutional dysfunction during an existential crisis. Decisions that would take years in peacetime can happen in months.
3. The open-source AI ecosystem has matured to the point where governments can build on shared infrastructure rather than being locked into proprietary vendor solutions. Standardised frameworks and open protocols now exist for orchestration, interoperability, and agent communication - reducing the risk of building something that cannot evolve and giving governments genuine architectural choice rather than dependency on a single vendor’s roadmap.
Moving now carries the risk of building something that does not yet work as intended. But waiting carries a greater risk: that the accumulation of incompatible pilot projects and ad hoc decisions creates constraints such as fragmentation, duplicated investments, uneven service quality or AI systems that cannot scale.
Disclaimer. The roadmap is a snapshot of Ukraine’s thinking at time of publication. Given rapid progress in the broader field of Agentic AI, it is not only possible but certain that many elements described here will change. Conversely, the problem statements are expected to remain. Put differently, the terrain may shift, but the need for a map to navigate the terrain will remain. This document helps refine the scale and layers needed to construct a map that is useful in navigating the terrain.
The Agentic State
Part 1: What Ukraine Is Building
A New Government Operating Model
Going from digital state to Agentic State means more than adding AI to existing services. It means a new operating model for government, one that changes not just the technology but how services are designed, how agencies coordinate, and how the system as a whole learns and adapts.
In practice, this means three shifts. For citizens, services become proactive and hyper-personalised - anticipating needs rather than waiting to be asked. A citizen who reports a situation once (“my house was damaged in a missile attack”) has the system coordinate emergency housing, insurance claims, building permits, and social support across agencies without needing to know which ministry handles what. For civil servants, AI tools provide accurate, sourced answers to complex regulatory and procedural questions in seconds rather than hours, freeing them for the high-value judgment work that automation cannot replace. And for government as a whole, standardised, modular, interoperable platforms make new services dramatically faster and cheaper to build - strengthening the possibilities to learn and improve, and compressing what once took years into weeks.
Values as Architectural Constraints
These operational shifts are bounded by four values that determine what gets built and how:
4. Human centricity: Automation complements human decision-making; it does not replace it. A human appeal to any automated decision is designed to be always available and readily communicated. Civil servants are freed to take care of complex cases, not made redundant.
5. Transparency: Agentic services operate with radical transparency - open data, open procedures, auditable decisions. Through automation and simplification, government bodies improve service quality without growing in headcount.
6. Fluid economy: The government acts as a platform. Businesses benefit from minimal friction in their interactions with the state. Digital public infrastructure underpins marketplaces where private sector services plug into government workflows.
7. Resilience: Public services are designed for resilience, rapid detection, containment, continuity, and recovery under severe cyber stress. New services can be launched in days in response to unforeseen crises or opportunities - a capability pressure-tested through years of wartime operations.
Architecture: Thin Orchestrators on Shared Infrastructure
Beneath these values sits a structural principle: centralised enablement paired with decentralised initiative. Core AI infrastructure, standards, and governance are coordinated centrally. Individual ministries and local administrations retain the autonomy to build AI solutions tailored to their mandates. This creates the speed, coherence, and ownership needed for implementation at scale.
The critical architectural discipline is this: applications in the implementation layer are thin orchestrators, not thick applications. They do not contain their own siloed business logic or private databases. Instead, they draw from shared infrastructure - a common orchestration layer, a unified knowledge base, a sovereign data mesh - so that every new service reinforces the coherence of the whole rather than creating a new monolithic silo.
Ukraine’s Technical Implementation Through the Lenses of the 12 Layers of the Agentic State
The sections that follow describe Ukraine’s implementation layer by layer, using the Agentic State framework as the organising structure. The twelve layers are grouped into two categories: The six implementation layers (Part 1a), where agentic capabilities deliver direct, visible value to users, and six enablement layers (Part 1b), which comprise the infrastructure and governance foundations that these services depend on.
Ukraine is building across these layers through three parallel interfaces for citizens, civil servants, and businesses - which are where the architecture takes concrete form. Not all layers are equally mature at this stage; some are well advanced, others are in early development, and some are not yet in scope. What follows reflects the state of play in early 2026,
The Agentic State in Ukraine
!images129c5bfb-ec63-4c28-9d08-905ded46248f-09_961_1072_657_1617.jpg
!images129c5bfb-ec63-4c28-9d08-905ded46248f-09_232_1072_1649_1617.jpg
The Agentic State
describing the immediate next steps that Ukraine intends to take as well as its broader ambitions.
Part 1 a - Implementation Layers: Building the ‘Hands, Face, and Voice’ of Government
The Agentic State architectural framework defines six implementation layers (Layers 1-6). These are where the transformation becomes visible - the ‘hands, face, and voice’ of the new government operating model. They cover public service design and user experience (1), government workflows (2), policy- and rule-making (3), regulatory compliance and supervision (4), crisis response (5), and public procurement (6).
In this document, we present Ukraine’s current implementation efforts on Layers 1, 2, and 4. However, it’s important to note that the organising logic behind Ukraine’s work is not strictly the layers themselves but user groups — citizens, civil servants, and businesses — reflecting the country’s experience building Diia as a user-first platform.
The Implementation Layer - the user-facing surface of the Agentic State - is structured around three types of agents. The first is the public-facing agent: the conversational interface through which citizens and businesses access government services, replacing fragmented portals and manual processes with a
Implementation Layer
The user-facing surface of the Agentic State
!images129c5bfb-ec63-4c28-9d08-905ded46248f-11_654_1425_1151_255.jpg
single, intelligent point of contact. The second is the
internal agent: a secure AI platform embedded in civil servants’ workflows, helping them navigate regulation, process casework, draft decisions, but also prototype and develop new agentic solutions. The third is the compliance agent: a tool that allows businesses to submit proofs of regulatory compliance, and regulators to monitor them in real time - shifting supervision from periodic, document-heavy audits to continuous, automated verification. These three agent models are not independent products; they are the user-facing expression of the same underlying efforts on the Enabling Layers, drawing on the same registry, the same data mesh, and the same communication protocols.
Public Service Design and UX - Public-facing Agent (Layer 1)
This section focuses on the user-facing agentic interface, the conversational front door to the government, which in Ukraine is Diia.Al, an agentic end-user agent built within the broader Diia ecosystem. It is here that the Agentic State becomes most tangible - where citizens and businesses can describe a situation in natural language and have the system coordinate the response across agencies.
Underlying Questions and Key Themes
How do citizens and businesses interact with government?
Ukraine’s Approach
Public-facing Agent (Diia.AI)
What it is: Diia.ai is the government’s single conversational front door for the public. The Diia.AI agent is embedded into the existing Diia app and portal and relies on existing infrastructure and components, such as authentication and data exchange.
Architecture: A single, multimodal agent acts as the main interface for citizens and businesses to access services. The end-user agent functions as a master orchestrator and trusted user interface. Based on a citizen’s natural language request (e.g., “My house was damaged in a missile attack, what help can I get?”), the Diia.AI agent queries the Agentic GovStack (Layer 9) to discover and coordinate a sequence of specialised back-end agents (e.g., an emergency housing agent, an insurance claim agent, or a building permit agent) to fulfill the request, providing a single, seamless and auditable experience to the user.
Technical Realisation:
- Front-End: A conversational chat interface is already live on the Diia portal, launched in September 2025 as one of the first national AI assistants integrated into a government service channel with both informational and transactional services. Voice interaction and deeper mobile integration represent the next layer of the roadmap.
- Cognitive Engine: Diia.AI currently uses an LLM with a privacy-preserving architecture: personal data is stripped before any request reaches the model, with only the anonymised intent passed to the LLM and
The Agentic State
How do agents enable proactive or eventdriven services?
re-personalised locally within Diia’s protected systems. The longer-term ambition is a fine-tuned, sovereign or national-language model to further strengthen cultural and linguistic accuracy.
- Back-End Integration: Today, the agent operates through two core components - the Liquio low-code platform (which underpins the Diia portal and provides a standardised service layer that AI can call) and the Model Context Protocol (MCP), which defines available services, required parameters, and expected outputs, allowing the assistant to act rather than merely advise. Currently this enables services such as income statements and obtaining verified information about entrepreneurial status, tax group, real estate or land, and pension and insurance records. The forward vision is to extend this via the GovStack Orchestration Layer, enabling the agent to coordinate workflows across multiple ministries - for example, routing a business licence request across Commerce, Tax, and Health & Safety - as new registries and agencies are connected.
Ukraine’s Diia.AI is being built in two modes.
- Mode 1: Reactive (current). Citizens describe their situation in natural language (“How do I get a certificate of no criminal record”). The system interprets the intent, routes to the appropriate back-end agents, and orchestrates the response.
- Mode 2: Proactive (in development). The system monitors life events registered in government databases and initiates relevant service offers without waiting for the citizen to ask.
Diia will be proactive in two ways. The first one - event-triggered proactiveness - is valuable but not distinctively agentic. For instance, when a birth is registered, automatically offering the “Yemalyatko” baby bonus or surfacing childcare subsidies are offered through a deterministic process: one event, one predefined response. Diia can and will do this — but it isn’t the ceiling.
The second way is where agentic infrastructure becomes irreplaceable: pattern-based proactiveness that requires reasoning across multiple signals over time. No single event triggers it; the insight emerges from the combination. For example:
The Agentic State
- Income vulnerability detection. The system detects a sustained dip in a citizen’s declared income across tax records. No single threshold was crossed, no form was filed — but the pattern suggests financial stress. The agent proactively asks whether she might benefit from available support programs, and if so, initiates the application on her behalf.
- Cross-agency distress signals. Multiple contacts with different government agencies - social services, housing authority, employment office - are registered within a short window. No single agency sees the full picture. The agent surfaces the pattern and offers the citizen a single dedicated support session to understand and address their situation holistically.
- Regulatory exposure mapping. A new regulation is passed affecting a specific business category. Rather than publishing a notice, the agent identifies which registered businesses are affected based on their activity profile, assesses what actions are required, and proactively walks each business owner through their specific obligations.
This is the category of proactiveness that justifies the infrastructure investment, and that legacy, siloed systems structurally cannot deliver.
Safeguards: Proactive outreach requires explicit consent management, clear distinction between government services and commercial offers, and transparency about why a particular offer is being made. The agent must disclose that the citizen is interacting with an AI system, and every proactive suggestion must be traceable to a specific life event and a specific policy basis. At any point, citizens need to be empowered to escalate to a human official - ensuring that agentic automation never becomes a barrier to human accountability. More information on this is discussed in the Agentic Governance section.
How do public and private service offerings interact in the Agentic State? What is the platform role of the Agentic State?
Government as a Platform
Ukraine is building Diia.Al not only as a government services portal but as a platform on which both public and private services can operate. The citizen experiences a single conversation, behind which multiple agents negotiate across government and commercial systems via MCP, with Diia.AI mediating identity, consent, and
The Agentic State
data exchange. Citizens choose which services to connect, and Diia mediates interactions using data they have verified and authorised — much like connecting a third-party tool to a personal account.
The system uses a multi-agent architecture where Diia.Al acts as orchestrator. A proxy agent interprets the citizen’s intent and determines which services - government and commercial - are relevant. Register agents communicate with government databases (via MCP servers on the register side, MCP clients on the Diia.AI side) to retrieve authenticated citizen data. Business agents communicate with external service providers (banks, marketplaces, insurance companies) via the same MCP protocol.
In the scenario of a citizen applying for unemployment benefit and retraining, the citizen registers as unemployed through Diia. Then, this triggers a coordinated flow across public and private actors:
8. Eligibility verification: Rather than asking the citizen to gather payslips and employment records, the agent pulls verified income and employment history directly from their bank and employer (with consent), completing means-testing automatically.
9. Benefit activation: The relevant state benefit is calculated and initiated without a separate application.
10. Retraining entitlement: The citizen is informed of their retraining entitlement and shown accredited private training providers whose programmes match their skills profile.
11. Enrolment: The citizen selects a programme; their verified identity and employment history are shared with the provider, and enrolment is confirmed within the same conversation.
The government’s role throughout is infrastructural: defining accreditation standards, mediating consent, and holding the canonical identity and registry layer. The value it captures is systemic: Iower delivery costs, higher uptake of entitlements, and reduced fraud through verified identity.
As the platform matures, this architecture could extend further - to surface commercial offers from businesses in the context of relevant life events, creating a high-intent marketplace built on verified identity. This would represent a meaningful revenue opportunity for government. The design principles for such an extension -
The Agentic State
how to preserve trust, ensure transparency, and keep commercial and public service logics clearly distinct are something Ukraine will need to work through as deployment scales.
For the technical perspective on this - in particular the GovStack orchestration and interoperability layer, the technical infrastructure that enables agent-to-agent and agent-to-legacy communication - see the section on The Technical Foundations (in particular Layer 9: Technology Stack).
The Agentic State
Internal Workflows - Internal Agent (Layer 2)
The citizen-facing interface gets the visibility, but an important segment of the transformation happens behind the scenes - in how civil servants work day to day and how ministries build and deploy AI tools internally. This layer covers Ukraine’s approach to equipping government employees with AI-powered tools and, critically, to providing a single governed platform on which all government organisations can build, discover, and reuse agentic services and components.
Underlying Questions and Key Themes
How do you manage the back-office agentification of government?
Ukraine’s Approach
The Internal Government Agent
Ukraine is planning to build a platform that supports the development and operation of agents for internal workflows. This will include both agents that assist civil servants in human-in-the loop workflows and agents that execute fully-automated workflows.
What it is: Ukraine is planning to develop a secure AI assistant for civil servants to help with drafting documents, summarising complex reports, and retrieving information accurately, but also empowering them to build and deploy new services. An environment where a policy officer or agency team can obtain verified information but also prototype and launch new public-facing solutions already pre-wired to the right APIs, design frameworks, and integration protocols, lowering the barriers to in-house development.
Architecture: The platform will be a secure interface that uses a domain-adapted, fine-tuned LLM to provide instant, accurate, and citation-backed answers to complex procedural and legal questions. For example, a policy officer could ask, “What are the exact legal requirements for a public consultation on a new environmental regulation?” and receive a complete, sourced answer in seconds. Access control and audit logging are integral to this system to meet transparency and accountability standards. Moreover, the platform will also expose a governed development layer: pre-approved components, MCP-compatible service templates, and Diia design system scaffolding, so that new services built within the platform are interoperable
The Agentic State
with the broader public platform by default. The same policy officer can also build the consultation service itself, with identity verification, consent management, and registry integrations already in place.
Technical Realisation:
- Interface: A secure web interface and plugins for standard government office software, alongside a development environment with governed access to government APIs and service templates.
- Cognitive Engine: This will also run on the sovereign LLM but will be fine-tuned on a separate, secure dataset of internal, non-classified government documents.
- Information Retrieval: Primary consumer will be the primary user of the GovKnowledge API, allowing it to provide civil servants with instant, accurate, and citation-backed answers to legal and procedural questions.
- Build Layer: Pre-configured integration scaffolding - MCP server templates, Diia design system components, registry connectors - so that services built within the platform inherit compliance, interoperability, and security requirements without bespoke engineering effort for each deployment.Ukraine is planning to build a comprehensive AI platform for all government organisations that unifies the current fragmented landscape of independent AI tools into a single governed environment.
The platform serves three tiers of users:
- Domain Experts (No-Code). Non-technical users - lawyers, policy analysts, educators - can create Al assistants, agents, workflows tailored to their specific domain and tasks by providing instructions and connecting knowledge sources. A lawyer working on EU integration, for example, can build an assistant that translates EU directives, identifies corresponding Ukrainian legislation, and performs comparative analysis - without writing code.
- Technical Business Analysts (Low-Code). Product owners and business analysts who understand their workflows deeply can visually decompose business processes into automated flows — defining start and end states, adding conditional logic, connecting to registers, and inserting AI-powered review
The Agentic State
steps. This is closer to process automation than simple chatbots: it enables the “agentification” of complex multi-step government procedures.
- Developers (Full Code). Software engineers can build agents programmatically, create custom MCP tools, and integrate them into the platform via well-defined contracts. This tier enables the most sophisticated use cases - cross-registry orchestration, real-time data processing, and novel agent architectures.
Because the platform controls the underlying infrastructure of identity verification, registry access, audit logging, and compliance checks, it can offer creative freedom at the application layer while enforcing security and consistency at the foundation. Without this, the risks are real: shadow automation, inconsistent prompts, uncontrolled access to registers, and weak accountability when something fails. A government-managed platform mitigates these by making the guardrails architectural rather than relying on individual compliance with policy. These assistants can be published to an internal marketplace, allowing colleagues across other ministries with similar needs to discover and reuse them.
For the technical perspective on this - in particular the GovStack orchestration and interoperability layer, the technical infrastructure that enables agent-to-agent and agent-to-legacy communication - see the section on The Technical Foundations (in particular Layer 9: Technology Stack).
Regulatory Compliance and Supervision - Compliance Agent (Layer 4)
Regulation is one of the areas where agentic AI has the potential to change not just how government operates, but the fundamental relationship between the state and businesses it oversees. This layer addresses how Ukraine is rethinking compliance - moving from periodic, manual auditing toward continuous, automated assurance where both the regulator and the regulated entity deploy agents.
Underlying Questions and Key Themes
How does regulatory compliance change when both the regulated entity and the regulator adopt agents?
Ukraine’s Approach
Agentic Compliance (The Compliance Agent for Businesses)
What it is: Ukraine is planning to develop a system for continuous, automated regulatory monitoring that shifts the burden from periodic reporting to real-time assurance. This system transforms regulation from a model of periodic, manual auditing to one of continuous, automated assurance. The model is best suited to narrowly scoped, high-volume, low-discretion obligations - tax filings, emissions thresholds, licence renewals where compliance can be expressed as verifiable conditions. Where supervision requires interpretation, context, or discretionary judgment, human regulators remain essential. The aim is to free their capacity for exactly those cases.
Architecture: This is a distributed privacy preserving system based on verifiable trust. Regulations are translated into “Rules as Code” and published by the government. Businesses run a lightweight, open-source “Firm-Side Agent” that generates cryptographic proofs of compliance based on these rules while preserving commercial confidentiality. A “Regulator Dashboard” then monitors these proofs in real-time, using AI to flag anomalies for human review and intervention.
Technical Realisation:
- “Rules as Code”: For a pilot sector (e.g., environmental reporting or business licensing), a dedicated team will translate key regulations into a machine-readable format.
- Firm-Side Agents: The government supports the development and diffusion of lightweight, open-source “compliance agents” that businesses can run on their own systems. These agents read
The Agentic State
the “rules as code” and can generate cryptographic proofs of compliance without revealing sensitive commercial data.
- Regulator-Side Dashboard: The Regulator Dashboard will be the government-side interface through which compliance officers monitor the continuous stream of proofs submitted by firm-side agents. Rather than reviewing every submission, regulators work in a “management by exception” mode: AI flags statistical anomalies — unusual patterns in proof frequency, deviations from sector benchmarks, or gaps in expected submissions - and surfaces them for human review. The dashboard does not expose underlying business data; it operates entirely on proofs, preserving commercial confidentiality while giving regulators a real-time view of systemic compliance health across an entire sector. This shifts the regulator’s role from periodic auditor to continuous risk monitor, allowing investigative capacity to be concentrated where it is actually needed.
Part 1 b - Enablement Layers: The Government’s Nervous System and Skeleton
The Agentic State framework defines six enablement layers (Layers 7-12). They cover agent governance, accountability, safety and redress (7), data and privacy (8), the technology stack (9), cybersecurity and resilience (10), public finance and buying agents (11), and people, culture, and leadership (12). If the implementation layers are the hands, face, and voice of the Agentic State, the enablement layers are its nervous system and skeleton - the structure that holds everything together.
Ukraine is working across all six enablement layers, but the layers are at different stages of maturity. The sections that follow focus on those where thinking and implementation are most advanced. For the sake of coherence, the sections that follow group them into two sets: first, the technical foundations - the technology stack (Layer 9), combined with data and privacy (Layer 8) and cybersecurity and resilience (Layer 10); and second, the institutional foundations - agent governance, accountability, safety and redress (Layer 7), and people, culture, and leadership (Layer 12).
The Technical Foundations: Building a Government’s ‘Nervous System’
Getting the technical foundations right from the start matters more than it might seem. Every architectural decision taken early - how data is structured, how systems communicate, how security is enforced - shapes what is possible later. Governments that skip this step and build applications first inevitably hard-wire choices that become legacy constraints within years, sometimes months, especially given the speed at which AI technology is evolving. The purpose of these layers is to ensure that Ukraine’s agentic applications are built on shared, open, and secure foundations that can evolve with the technology rather than against it.
In building the infrastructure for an Agentic State, Ukraine can rely on existing legacy govtech infrastructures that are already broadly adopted, performant and quite modern. This facilitates the deployment of new infrastructures on top.
Disclaimer: The following pages describe a model for the architecture and core components of Ukraine’s Agentic GovStack. These functionalities will be deployed progressively, but specific components and their relations will evolve with deployment practice.
The Agentic State
Underlying Questions and Key Themes
What is the overall architectural approach to deploying the Agentic State?
Why is an open, composable approach essential for government?
Ukraine’s Approach
Overall Architectural Design
Agentic applications are architecturally different from traditional software. A conventional government IT system can be self-contained: its logic, data access, and integrations are bundled within the application itself. An agent, by contrast, must dynamically discover services, invoke tools across organisational boundaries, and compose capabilities at runtime rather than at design time.
Consequently, the defining architectural principle of the agentic state is that domain-specific services applications act as thin orchestrators, not thick applications: they contain no siloed business logic or private databases of their own, but are instead built as expert consumers of common infrastructure. Their intelligence lies in how they assemble and sequence capabilities that already exist in the shared layer. When a new service is built in this manner, it strengthens rather than fragments the overall architecture - every integration point it establishes becomes available to subsequent services at no additional cost.
The common infrastructure for operating agentic services will be developed as the Agentic GovStack - a shared, modular set of building blocks that governments can reuse across services instead of rebuilding the same foundations each time.
The traditional approach to large-scale government IT - commissioning a single prime vendor to build everything - is poorly suited to the pace at which AI is evolving. New models, tools, and capabilities are emerging continuously; locking into one company’s closed stack would mean inheriting its roadmap, its pricing, and its limitations, with no ability to integrate better components as they appear.
Ukraine’s approach is instead composable by design: rather than a monolithic system, the agentic GovStack is built from interoperable components that can each be upgraded, replaced, or extended independently. This requires shared standards and protocols to ensure everything connects - but it means the government is never dependent on any single vendor and can always adopt what works best.
The Agentic State
Technology Stack - An Agentic GovStack (Layer 9)
This layer describes the shared technical infrastructure that Ukraine’s agentic applications will be built on: the orchestration layer, the compute fabric, and the standards that hold them together - recognising that architectural decisions taken early on shape how systems communicate, where models run, and how agents discover each other shapes what is possible later.
Ukraine is programming to develop this nervous system as comprised of five interconnected components:
- an overarching GovStack Orchestration Layer that routes all communication between agents and services;
- a Unified GovKnowledge API serving as the single source of truth for laws, regulations, and public information;
- an Agent Registry cataloguing all trusted government agents and their capabilities;
- a Data Mesh providing secure, standardised access to data; and
- a Hybrid Compute Fabric managing workloads across sovereign and public cloud infrastructure.
Together, these components form the shared foundation on which every citizen-facing service, internal government tool, and compliance system described in this document operates.
The Agentic GovStack
!images129c5bfb-ec63-4c28-9d08-905ded46248f-24_1013_1458_625_1233.jpg
The Agentic State
Underlying Questions and Key Themes
How do agents collaborate securely across ministries?
Ukraine’s Approach
The GovStack Orchestration and Interoperability Layers
What it is: A central software layer that allows different AI agents and legacy government systems to communicate securely and efficiently. It acts simultaneously as a universal translator, a secure routing system, and an enforcement point for government-wide standards. Without it, every new agent would need bespoke integrations with every other system; with it, any authorised agent can communicate with any other through a single, governed channel.
Architecture: The layer is built around two complementary components. An API Gateway serves as the single entry and exit point for all inter-service communication - managing authentication, authorisation, rate limiting, and traffic monitoring across the entire government stack. A Service Mesh sits beneath this, handling service-to-service communication within the infrastructure: load balancing, encrypted transit, circuit breaking, and observability. Together they ensure that no agent communicates outside governed channels, and that every interaction is logged, auditable, and recoverable.
Technical Realisation:
- Deployment: Procure or build a centralised API Gateway and Service Mesh. This platform will manage, secure, and monitor all traffic between government services.
- Standardisation: Mandate a single, government-wide Agent Communication Protocol (ACP) based on open standards (e.g. MCP, A2A). Every new AI service, whether built in-house or procured, must use this protocol. Compliance is enforced at the Gateway: non-compliant services cannot connect. This prevents vendor lock-in and ensures that the interoperability of the whole is not hostage to any single procurement decision.
The Agentic State
- Observability: All traffic through the layer is logged to a centralised audit store, providing the traceability foundation required by the governance framework and enabling real-time anomaly detection across the agent network.
How do agents and orchestrators find other agents and know how to engage with them?
The Agent Registry
What it is: A central, machine-readable directory of every authorised government agent - the “Yellow Pages” of the agentic state. It is the mechanism through which agents discover each other, verify each other’s identity, and understand each other’s capabilities without relying on bespoke bilateral agreements. Just as the Data Mesh makes data discoverable across the government stack, the Agent Registry makes intelligence and capability discoverable.
Architecture: The Registry is a structured database of agent profiles. Each agent profile contains a verified identity (cryptographic certificate), a capability manifest (what the agent can do, what inputs it accepts, what outputs it produces), an authorisation scope (which data it is permitted to access, which actions it is permitted to take), and an operational status. When an orchestrator needs to route a citizen request - say, a business licence application that spans Commerce, Tax, and Health & Safety - it queries the Registry to discover the relevant agents, verify their current authorisation, and confirm their availability before passing the request. No hard-coded dependencies; the architecture is discoverable and dynamic by design.
Technical Realisation:
- Registration: Every agent deployed on government infrastructure - whether built centrally, locally or procured - must be registered before it can operate. Registration requires a capability manifest, a defined authorisation scope approved by the relevant data steward, and a cryptographic identity issued by the government PKI.
- Verification: Agents querying the Registry receive cryptographically signed capability attestations, allowing them to verify that they are communicating with an authorised counterpart and not a spoofed or deprecated service.
The Agentic State
Where do AI models run - and how do you balance sovereignty, cost, and scalability?
- Governance: The Registry is the operational expression of the agent governance framework. Agents whose authorisation scope changes, whose certificates expire, or which are flagged by the oversight function can be suspended or revoked centrally, immediately preventing them from participating in any orchestrated workflow across the stack.
The Sovereign Compute Core & Hybrid Cloud Fabric
What it is: The physical and cloud infrastructure where the AI models and agents run. The model balances security needs with the need for scalability.
Technical Realisation:
- On-Premise Sovereign Core: A high-performance, on-premise compute cluster (e.g., using NVIDIA DGX systems or similar) to run the most sensitive workloads. This can include the training of sovereign or national-language LLMs and agents handling classified data or sensitive personal data.
- Cloud Fabric: A multi-cloud strategy with primary providers (e.g., Microsoft Azure, Google Cloud, AWS) for scalable, non-sensitive workloads, development, and bursting capacity.
- Unified Management: A platform (e.g., a Kubernetes-based solution like NVIDIA AI Enterprise) to manage this hybrid environment as a single entity. This allows developers to deploy an agent without worrying if it’s running on the on-premise cluster or in the cloud, providing maximum flexibility.
The Agentic State
Data & Privacy - Data Governance Components and Practices (Layer 8)
Agents are only as good as the data they can access. This layer addresses how Ukraine is making authoritative government data scattered across dozens of ministries and legacy systems - discoverable, trustworthy, and usable by AI agents, while maintaining appropriate governance and privacy controls.
Underlying Questions and Key Themes
How do agents access
authoritative information on current laws and processes?
Ukraine’s Approach
The GovKnowledge API
What it is: A single, secure API endpoint that serves as the canonical source of truth for all versioned laws, regulations, public FAQs, and procedural guidance. Rather than each agent or service maintaining its own copy of legal text - inevitably creating versioning chaos and incorrect citations - every agent in the government stack queries the same authoritative source. When a regulation changes, it updates once, centrally, and every dependent system immediately references the current version.
Architecture: The Knowledge Base is structured as a versioned, citation-addressable repository. Every law, regulation, and procedural document is ingested in machine-readable format, annotated with metadata (enacting authority, effective date, amendment history), and exposed through a standardised API. Queries can retrieve specific provisions by citation, search by semantic meaning, or request the full regulatory context for a given action. Critically, the API returns not just text but provenance: every response includes the authoritative source, version number, and effective date, ensuring that agent-generated advice is auditable back to its legal basis.
Technical ingestion pipeline: Establish a workflow where newly enacted or amended regulations are converted to machine-readable format (structured XML or JSON) and uploaded to the repository with full version control. Initial focus on high-frequency domains (tax, business licensing, social benefits) before expanding to the full legal corpus.
The Agentic State
How do agents find the data they need across hundreds of separate ministry systems?
The Data Mesh
What it is: A distributed data architecture that allows authorised agents to discover and access data from across government without needing to know where it is physically stored. It shifts from a centralised data warehouse model to a federated model where each ministry exposes its key datasets as secure, standardised “data products” on a shared mesh. An agent querying for a citizen’s tax status doesn’t need to know which system holds it; the mesh is the means for discovery and retrieval.
Architecture: The Data Mesh operates on the principle of domain-oriented data ownership. Each ministry remains the steward of its own data but commits to exposing it through standardised interfaces that the mesh can route to. A data catalog sits at the centre, maintaining a machine-readable index of available data products, their schemas, their access policies, and their operational status. When an agent requests data, it queries the catalog, which returns the appropriate endpoint and access credential. The data never leaves its source system without explicit authorisation; the mesh mediates discovery and permissioned access, not storage.
Technical Realisation:
- Data product standards: Define government-wide schemas and API contracts for common data types (identity, address, legal entity) so that consuming agents can rely on consistent structure regardless of which ministry provides the underlying data.
- Data catalog: Build or procure a federated data catalog that indexes all available data products, their schemas, access policies, and SLAs. The catalog becomes the discovery layer that agents query before making data requests.
- Access control: Integrate the mesh with the government identity and authorisation infrastructure so that every data request is authenticated, logged, and subject to the access policies defined by the data steward. The Data Mesh does not bypass data governance - it operationalises it at scale.
- Organisational structure: Appoint a Chief Data Officer (CDO) in each ministry responsible for identifying core datasets (citizen registry, business registry, tax records, land cadastre) and exposing them as standardised data products on the mesh.
The Agentic State
What data governance capabilities are prerequisites for an Agentic State?
Data Governance and the AI Data Lifecycle
Governing data in the Agentic State is not the same as governing data for traditional IT systems. The risks are different and so are the obligations. Ukraine’s approach establishes governance not as a compliance layer added on top of technical systems, but as a set of constraints built into the architecture itself.
The foundational principle is data sovereignty by design. Ukraine operates a three-tier classification system that determines how data is handled: public data can be processed on cloud infrastructure; sensitive personal data must be masked before it leaves sovereign systems; and restricted data - covering document verification, health records, and defence - is processed exclusively on sovereign infrastructure, with state secrets air-gapped entirely.
For workloads that involve cloud models, a four-stage pipeline ensures no citizen data reaches an external system in identifiable form. When personally identifiable information is detected, it is replaced with deterministic tokens held in volatile memory on sovereign infrastructure; the anonymised prompt is sent to the cloud model; tokens are then rehydrated with real data before the citizen sees the result. This significantly limits what an attacker could obtain in the event of a breach at the cloud provider. It does not eliminate all privacy risks: inference and re-identification remain possible, and must be managed through data classification, minimisation, contractual controls with providers, logging, and legal restrictions on downstream processing.
The Feature-Training-Inference (FTI) architecture structures the AI data lifecycle into three pipelines, each with distinct governance requirements. Feature pipelines are where raw data is transformed into AI-ready inputs: this is where anonymisation is applied, data quality is enforced, and automated bias checks run. Training pipelines carry additional obligations around intellectual property clearance, version control, and full lineage tracking for any dataset used to train or fine-tune a model. Inference pipelines - the live, session-level data flowing through deployed agents — are governed by strict access controls and automatic expiry, ensuring that no query data persists beyond its immediate use.
The Agentic State
How can the government ensure quality in data creation?
How can governments ensure AI models perform well linguistically and culturally?
The quality of these pipelines depends ultimately on the quality of the data flowing through them. For Al applications in public administration, the most critical input is not raw data but labelled data - cases where the correct decision, and the reasoning behind it, has been recorded in a form a model can learn from.
Ukraine’s approach to data quality is the Golden Dataset Protocol, which treats training data creation not as a technical annotation task but as a process of extracting institutional expertise from senior civil servants. For each service domain, a small group of specialists — typically three to five people with deep experience handling edge cases and legal grey zones - are recruited to annotate historical cases in structured workshops. The case mix is deliberate: the majority are standard, but a significant share are ambiguous or contested, and a small proportion are adversarial — errors, fraud attempts, or poor-quality submissions. For complex agent tasks, experts do not simply label outcomes; they record their reasoning, producing an auditable decision trace that allows an agent to explain not just what it decided but why.
Where experts disagree - which is common on edge cases - Ukraine treats the disagreement as a signal rather than noise. A structured arbitration process produces a single rule, which frequently results in clarifying an underlying regulation or internal procedure before any model is trained. Cases with high expert disagreement also directly inform the safety thresholds that govern when an agent escalates a decision rather than resolving it autonomously. The result is a dataset that is representative, consistent, clean, and reasoned and whose quality directly determines the public value of the service built on top of it.
Building Sovereign National Multimodal Corpuses
To achieve cultural and linguistic autonomy, Ukraine is moving beyond simple text collection to building National Multimodal Corpuses. These include text, audio, and image data designed to train new modalities that “think and speak Ukrainian.” These corpuses are built using a National Data Description Standard. Every data point is enriched with metadata regarding its origin, licensing, and quality score. This structured approach allows Ukraine to create a National Benchmark Systems (UaBench) that evaluates not just accuracy, but also the cultural and ethical alignment of the resulting models.
The Agentic State
Data Architecture as a Prerequisite
A single Conceptual Data Model unifies the Open Data portal, agency information systems, and the national data portal. By implementing Metadata Management in a central repository, Ukraine ensures that every AI agent in the ecosystem understands the context and lineage of the data it uses.
Cyber Security - Zero Trust Architecture (Layer 10)
When thousands of autonomous agents communicate across ministerial boundaries, the security model must change fundamentally. This layer describes how Ukraine is applying Zero Trust principles to an agentic environment - where the entities requesting access are not only human users but also agents acting on their behalf.
Underlying Questions and Key Themes
What security architecture is required when autonomous agents communicate across government?
Ukraine’s Approach
Security by Design: The Zero Trust Mandate for an Agentic State
Ukraine is preparing for an ecosystem where thousands of autonomous agents are constantly interacting and accessing data across ministerial boundaries. The traditional “castle-and-moat” security model is obsolete. The only viable security architecture for the Agentic State is Zero Trust.
The core approach is simple but absolute: never trust, always verify. This security model is not an add-on; it must be woven into the very fabric of the foundational architecture. To operationalise this approach, Ukraine is developing two principles.
Principle 1: Assume Breach & Verify Explicitly. The system must be designed with the assumption that an attacker is already inside the network. Therefore, no implicit trust is granted to any agent or user, regardless of their location. Every single request - from an AI agent in one ministry requesting data from another, to a citizen interacting with a government portal - must be independently and cryptographically authenticated and authorised before it is granted.
Principle 2: Enforce Least Privilege for All Agents. Every AI agent must be granted the absolute minimum set of permissions required to perform its specific, documented function. An agent designed to check the public opening hours of a government office should have zero ability to access citizen data. An agent handling a tax return should have no ability to interact with the motor vehicle registry. This granular control must be natively enforced by the platform, for instance through policy-as-code mechanisms and runtime enforcement gates, which ensures that even if a single agent is compromised, the potential damage is strictly contained.
The Agentic State
The Institutional Foundations: Building an Agentic Government’s Skeleton
The technical foundations are necessary but not sufficient. Without clear governance, accountability structures, and the right people in place, even the best-designed infrastructure will fail in practice. These layers address the institutional side of the Agentic State: how agents are governed and held accountable (Layer 7), and how the leadership, skills, and organisational culture required to sustain the transformation are built and maintained (Layer 12).
Agentic Governance - Accountability, and Oversight (Layer 7)
As governments deploy AI agents that interact with citizens, make recommendations, and coordinate across agencies, a fundamental question arises: who is responsible when an agent acts? This section addresses how Ukraine is building the governance structures to ensure that every agent operating within the Agentic State is registered, auditable, and subject to clear lines of accountability and oversight - including mechanisms for citizens to challenge and seek redress for automated decisions.
| --- | --- |
|---|---|
| How do you maintain human oversight and accountability? | The Human-Centric Agentic State: Trust, Quality, and Accountability An Agentic State is only as strong as its weakest hallucination. To move from “experimental tools” to “trusted public services,” Ukraine is implementing a robust framework of Human-AI Alignment. This ensures that autonomous agents do not operate in an institutional black box, but are subject to continuous human monitoring, technical tracing, and clear legal accountability. |
| How do you validate an agentic solution before building it? | Human Validation Before Development A core principle of Ukraine’s oversight architecture is that human judgment must validate an agentic service concept before any model is built — not after. Ukraine operationalises this through a “Wizard of Oz” methodology. During the design phase, test users interact with what appears to be an AI agent - a chat interface on the Diia portal - but responses are generated by a human operator working behind the scenes. The operator follows a strict script simulating only the capabilities the future agent will actually have: the same |
| Level 0 | Isolated LLM, no tools. Text transformation only (translation, summarisation) |
| --- | --- |
|---|---|
| Level 1 | LLM + retrieval/tools. Informational Q&A: “Where is my passport application?” “What is my tax debt?” The agent searches and formats; it does not plan. Standard for most government chatbots. |
| Level 2 | LLM + tools + planning. Transactional services requiring multi-step reasoning. This is the ePermit level: the agent decomposes a citizen’s situation, checks conditions across registries, and generates a personalised response. |
| Level 3 | Multi-agent orchestration. Cross-ministry life situations where specialised agents coordinate: a veteran returning from service needs health assessments, social benefits, and retraining programmes handled by different agencies. This is the “Agentic State” target - not yet the operating reality. |
| Level 4 | Self-evolving agents. Experimental, sandbox only. |