Proposal · DigitalDifficulty mediumReading time: 8 min
A server and downloadable models are within reach; the real work is the regulation, the impact assessment and training.
An artificial intelligence that does not take the data out
Municipal offices handle sensitive data every day: incomes, health conditions, family situations, ongoing proceedings. An assistant based on a language model can save hours on drafts, summaries, archive searches and translations. But if that model runs on the servers of a foreign vendor, every question carries citizens’ data with it. The proposal is to use open models, run on a machine owned by the Municipality, for supporting tasks and never for decisions.
The idea in brief
- AI is already coming into the offices through the back door: texts with citizens’ data pasted into free assistants running on foreign servers, with no contract and no legal basis.
- The proposal: a server with graphics cards in the town hall, open-weights language models and the institution’s documents as the knowledge base. No data leaves the institution.
- Four uses, all supporting and never decision-making, as Law 132/2025 requires: summarising acts, searching the archive, preparing drafts, translating at the counter.
- Limits written into a regulation before the machine is switched on, mandatory training and a six-month trial in two offices.
The starting point
AI is already in the offices, through the back door
No resolution is needed for a clerk to paste a text into a free web assistant to summarise or correct it. It happens in every office, public and private, and nobody governs it. If the text contains a citizen’s name, their income or a social services report, that data has just been transferred to a company outside the European Union, with no contract, no legal basis and without the person concerned knowing.
The Italian Data Protection Authority has already shown where the problem lies. In January 2025 it blocked the DeepSeek app in Italy because users’ data ended up on servers in China with no clarity about purposes and retention. In 2023 it had suspended ChatGPT and in 2024 it charged OpenAI with processing data without a legal basis. For a municipality, which is the data controller, the question is not whether to use artificial intelligence, but where the data goes while it does.
Meanwhile the Italian administrations that move often choose the opposite road: in June 2026 Rome presented the new assistant of its portal, developed with Microsoft and a vendor of management systems. It works, but the data and the dependency sit elsewhere.
The rule
What the law says
Law 132 of 23 September 2025, Italy’s first law on artificial intelligence, devotes article 14 to public administration. AI is to be used to increase efficiency and shorten proceedings, while guaranteeing that its workings can be known and its use traced. But its role is instrumental and supporting: a person remains solely responsible for the decisions and proceedings in which AI was used. Administrations must also adopt technical, organisational and training measures for responsible use.
The European regulation on artificial intelligence (AI Act) adds two things that matter for a municipality. Since 2 February 2025 anyone using AI systems must ensure their staff have a sufficient level of literacy. And systems used by public authorities to assess people’s eligibility for benefits and services, such as grants, housing or exemptions, are classified as high-risk, with obligations of registration, a fundamental rights impact assessment and information to the people concerned. An assistant that helps write and search is not high-risk; it becomes so the moment it enters the decision about who is entitled to what. This proposal stops before that.
The data protection regulation applies as always: if the model runs at a vendor, that vendor is a processor and a binding contract is needed; if the data leaves the Union, the safeguards of chapter V are needed; in any case an impact assessment is needed. If the model runs on a server owned by the Municipality, no data leaves the institution: the risk perimeter shrinks to that of any other internal system. The AgID guidelines on adopting AI in public administration, in consultation since February 2025, ask the same thing in positive terms: classify systems by risk, keep human oversight, prefer open and verifiable solutions.
The proposal
One server, open models, supporting tasks
A machine in the town hall
A server with one or two graphics cards of 24 or 48 gigabytes of memory is enough to run models of 8 to 30 billion parameters for dozens of users, and with 48 gigabytes one reaches 70-billion models. It is a one-off purchase, in the order of a professional workstation, against a per-user monthly subscription that cloud assistants charge for every employee, forever. The exact quote must be based on the number of users; the order of magnitude is that of a company car.
Open-weights models
In 2026 the models that can be downloaded and used freely are many and good: EuroLLM, trained on the twenty-four official languages of the Union; Apertus, Swiss and fully documented; Minerva, Italian; the Llama, Mistral and Gemma families and the Chinese DeepSeek and Qwen. The last two have changed the picture: in public benchmarks their largest models come close to the frontier models of OpenAI and Anthropic on many tasks, from writing to reasoning, and the gap has shrunk to a few points; it remains on the most complex tasks. And there is a difference that matters for a municipality: the Data Protection Authority blocked the DeepSeek app because it sent data to China, but the model’s weights, downloaded and run on a server in the town hall, send nothing to anyone. They run with free tools such as Ollama or llama.cpp and are used from a multi-user web interface such as Open WebUI. No licence, no data leaving, and the model is swapped when a better one comes out.
The Municipality’s documents as the base
The model is not retrained: regulations, resolutions, decisions and pages of the website are indexed and retrieved at the time of the question, with the technique known as RAG. Every answer cites the document it comes from. It is the most effective way to contain made-up answers, and it makes the assistant useful from day one.
Four uses, all supporting
Summarising a resolution or a file before a meeting. Searching the register and the archive with a question in plain language instead of a keyword. Preparing the draft recitals of an act, with the procedure and the applicable rules, leaving reasoning and decision to whoever signs. Translating and simplifying answers for the counters, where citizens speak many languages. These are the tasks article 14 allows and that German and French administrations already entrust to their assistants.
What the assistant does not do
It does not decide who is entitled to a grant, to housing, to an exemption. It does not write the reasoning of a decision. It does not answer citizens without a person having read the answer. It does not receive data not needed for the task. These limits must be written into an internal regulation before the machine is switched on, not after.
Reuse before development
Baden-Württemberg published its assistant as free software precisely so that other bodies can reuse it; France did the same with the Albert platform. Before having anything developed, the Municipality assesses these tools, as article 68 of the Digital Administration Code already requires for every software purchase. Whatever the Municipality adapts, it releases in turn.
Training and someone in charge
Staff literacy is a European obligation in force and the Italian law requires training measures. A short training cycle for everyone, a longer one for those who will use the assistant every day, and the Digital Transition Officer, together with the Data Protection Officer, governing the trial: six months in two offices, then the decision whether to extend.
Who has done it
Administrations that keep their models in-house
Baden-Württemberg, F13 assistant · since 2023, open source since July 2025
Chat, document summaries and search through records for all the state’s employees, run in the regional data centre.
Model-independent: the underlying model can be swapped without redoing the rest. Published on openCode so that other bodies can reuse it; Saarland is already trying it.
Schleswig-Holstein, LLMoin assistant · 2026
Assistant built into the workstation of a thousand employees, run by the public consortium Dataport.
It replaced a proprietary model with an open-weights model of 120 billion parameters.
France, Albert (DINUM) · since 2024
The State’s assistant on open Llama and Mistral models, tested at France services counters to answer citizens about their files.
Code published; the model access platform is open source and reusable.
Canton of Ticino, with the Swiss model Apertus · 2025-2026
Secure translations in the cantonal administration with a fully open model, in 8 and 70 billion parameter versions.
First public deployment of Apertus. An Italian-language case, seventy kilometres from Saronno.
Sapienza University, Minerva model · 2024
First family of models trained from scratch on Italian, up to 7 billion parameters, under a permissive licence.
Downloadable in a format that runs on an office computer with a graphics card.
In Italy the national social security institute INPS has a three-year plan for generative AI and uses an internal tool to make its texts more readable; the City of Florence adopted a strategic plan for AI and an assistant on its portal in thirteen languages. At the time of writing no Italian municipality is known to declare that it runs its models locally. Saronno could be the first on record.
From the point of view of a resident
What changes at the counter
A quicker answer about a file, because the person answering found the right resolution in a minute instead of an afternoon. A letter from the Municipality written in plain language. A form explained in their own language to someone who arrived recently. And the certainty, written in a regulation and verifiable, that their data did not end up on a server on the other side of the world to obtain all this.
Honesty
What can go wrong
- Made-up answers. Every language model can produce false statements in a confident tone. Mandatory citation of the source and human reading of every text before it goes out are the two defences, and neither is optional.
- Local is not magic. A server in the town hall must be updated, protected and maintained: without a technical contact and a maintenance contract it becomes a risk, not a guarantee. The data does not leave, but inside it must be protected like everything else.
- Quality: the gap has shrunk, not vanished.The largest open models, such as DeepSeek and Qwen, are now close to the best cloud models, but they need tens of gigabytes of graphics memory to run; those of 8 or 30 billion parameters, within reach of a municipal server, remain a step below. For summarising, searching and translating they are more than enough; on the most complex tasks the difference shows. It is a conscious trade: a little capability in exchange for control over the data.
- The temptation to expand. Once the assistant works, someone will propose using it to process grant applications. That is where the AI Act’s high-risk rules and the ban on automated decisions kick in: the internal regulation must say so first.
- The costs are estimates. No figure on this page concerns Saronno. The number of users, the choice of model and the hardware quotes are for the competent office; the page gives orders of magnitude and sources.
Useful links
- Legge 23 settembre 2025, n. 132: disposizioni e deleghe in materia di intelligenza artificiale
Official Gazette no. 223 of 25 September 2025
Art. 14: AI in public administration is instrumental and supporting, a person remains solely responsible for the decision.
- Legge 132/2025 e uso dell’IA nella pubblica amministrazione: la guida
Agenda Digitale
A practical reading of art. 14: which phases of a proceeding may use AI and which may not.
- Regolamento (UE) 2024/1689 sull’intelligenza artificiale (AI Act)
Official Journal of the European Union, EUR-Lex
Literacy (art. 4), obligations of public deployers (arts. 26 and 27), high-risk systems.
- AI Act, allegato III: sistemi di IA ad alto rischio
artificialintelligenceact.eu
Point 5: assessment of eligibility for public benefits and services by public authorities.
- Linee guida per l’adozione dell’intelligenza artificiale nella pubblica amministrazione
AgID, public consultation February-March 2025
Principles, risk classification, human oversight, preference for open solutions.
- Strategia italiana per l’intelligenza artificiale 2024-2026
AgID
Public administration as one of the four areas of intervention.
- Intelligenza artificiale: il Garante blocca DeepSeek
AI4Business, January 2025
Urgent measure of 30 January 2025: users’ data on servers in China.
- ChatGPT: il Garante privacy sanziona OpenAI
Italian Data Protection Authority, 20 December 2024
Data processing without a legal basis. The fine was later overturned by the Court of Rome; the investigation stands.
- Decalogo per la realizzazione di servizi sanitari nazionali attraverso sistemi di intelligenza artificiale
Italian Data Protection Authority, 2023
Transparency, human oversight, non-discrimination and impact assessment as core principles.
- KI-Assistenz F13 wird zur Open-Source-Software
State Ministry of Baden-Württemberg, 23 July 2025
The state’s assistant, run in the regional data centre, released as free software for reuse.
- LLMoin e F13: l’IA nel servizio pubblico tedesco spiegata
Punkt am Ende, February 2026
Schleswig-Holstein’s assistant on an open-weights model, run by Dataport.
- Albert API
DINUM, Direction interministérielle du numérique
The French State’s assistant on open models, with an open source platform.
- Apertus: a fully open, transparent, multilingual language model
ETH Zurich, 2 September 2025
Swiss public model with 8 and 70 billion parameters, with documented data and methods.
- Canton Ticino, Artificialy e CSCS portano Apertus nella pubblica amministrazione
Corriere del Ticino
Secure translations in the cantonal administration: an Italian-language case.
- Minerva 7B: la nuova frontiera dei modelli linguistici italiani
FAIR Foundation and Sapienza University of Rome
Italian model trained from scratch, runnable locally.
- DeepSeek-V3.1 e DeepSeek-R1, pesi e schede dei modelli
DeepSeek, Hugging Face (MIT licence)
Chinese open models with results close to the frontier models in public benchmarks; the weights run locally.
- Qwen3, la famiglia di modelli aperti di Alibaba
Qwen, Hugging Face (Apache 2.0 licence)
Models from a few to hundreds of billions of parameters, with versions suited to a municipal server.
- EuroLLM-22B
EuroLLM team, Hugging Face, December 2025
Open model for the twenty-four official languages of the Union, with public weights and data.
- Ollama VRAM requirements for local LLMs
localllm.in
Graphics memory needed for models of 8, 14 and 70 billion parameters.
- Julia 2.5, il nuovo assistente virtuale di Roma Capitale
RomaToday, June 2026
Counterexample: a municipal assistant developed with Microsoft and a vendor of management systems.
- Il piano per l’intelligenza artificiale del Comune di Firenze
Il Signor Sotto
Strategic plan 2026-2028 and a portal assistant in thirteen languages.
- DOT, il nuovo assistente virtuale per aziende e intermediari
INPS, June 2025
Generative AI in a large Italian public body.