Solution case studyAIP113
LLM governance and personal data protection compliance for AI initiatives in local government

Solution case studies are scenarios based on common industry problem patterns. They do not refer to any client and are not MarkasDev project portfolio items. Our client portfolio is published separately.
Industry context
Regional agencies and state-owned enterprises run digital public services. Growing volume means manual ways of working no longer keep up.
Constraints
- Shadow AI on personal devices
- Many different AI vendors
- No data classification for prompts
- Change management for field staff
Approach
Diagnose
Audit the AI use-case inventory, data classification, and control gaps.
Deliver
Build an AI gateway, prompt policies, data loss prevention, logging, and use-case approval.
Operate
Periodic access reviews, red teaming, and vendor reassessment.
High-level architecture
UsersAI gateway (authorisation, DLP, budget)model providersaudit and evaluation store.
Typical outcomes
Less shadow AI; approved use cases with clear ownership.
Typical or expected outcomes, not claims about MarkasDev project results.Common questions
Should we block ChatGPT entirely?
Providing an approved route plus training works better.
Does this replace legal review?
No. It complements legal and compliance policy.