Public-sector AI adoption becomes harder at the moment it becomes useful. Drafting assistance and internal search can save time, but the same tools can expose sensitive information, produce unreliable outputs or blur accountability if they are inserted into administrative processes without clear controls.
NÚKIB's June guidance for Czech authorities is therefore timely. It treats AI as an operational technology that needs rules, not as a novelty that can be left to individual employee judgement.
The state has a different risk profile from a startup
A public authority handles personal information, statutory decisions and systems that citizens may have no practical alternative to using. That changes the acceptable risk threshold. A hallucinated marketing caption is inconvenient; an unsupported claim inside an administrative workflow can be consequential.
The useful governance model is proportionate rather than prohibitive. Low-risk assistance can be enabled with approved tools and data rules, while higher-risk uses need human review, auditability, procurement controls and a clear owner for the decision process.
Security and AI governance are converging
NÚKIB's involvement also reflects a broader trend. AI governance is increasingly inseparable from cybersecurity because models interact with data stores, identity systems, external services and software supply chains.
That matters for Czech technology suppliers selling into government. Product capability alone will not be enough. Vendors will increasingly need to explain data location, access controls, model dependencies, incident handling and how customers can review or constrain automated outputs.
The next phase is procurement discipline
Guidance is only the first layer. Public bodies also need procurement practices that distinguish between generic AI claims and systems that can be operated safely over several years. NÚKIB's separate June work on ICT procurement points in the same direction.
For Czechia, getting this right could create a useful domestic reference market for trustworthy AI. Getting it wrong would produce the familiar public-sector pattern of fragmented pilots, unclear ownership and expensive technology that never becomes dependable infrastructure.