Skip to content
Giacomo Ravetta · PoliticsItaliano
Illustration: Artificial intelligence in the town hall, with the data staying in the town hall

Proposal · DigitalDifficulty mediumReading time: 8 min

A server and downloadable models are within reach; the real work is the regulation, the impact assessment and training.

An artificial intelligence that does not take the data out

Municipal offices handle sensitive data every day: incomes, health conditions, family situations, ongoing proceedings. An assistant based on a language model can save hours on drafts, summaries, archive searches and translations. But if that model runs on the servers of a foreign vendor, every question carries citizens’ data with it. The proposal is to use open models, run on a machine owned by the Municipality, for supporting tasks and never for decisions.

The idea in brief

  • AI is already coming into the offices through the back door: texts with citizens’ data pasted into free assistants running on foreign servers, with no contract and no legal basis.
  • The proposal: a server with graphics cards in the town hall, open-weights language models and the institution’s documents as the knowledge base. No data leaves the institution.
  • Four uses, all supporting and never decision-making, as Law 132/2025 requires: summarising acts, searching the archive, preparing drafts, translating at the counter.
  • Limits written into a regulation before the machine is switched on, mandatory training and a six-month trial in two offices.

The starting point

AI is already in the offices, through the back door

No resolution is needed for a clerk to paste a text into a free web assistant to summarise or correct it. It happens in every office, public and private, and nobody governs it. If the text contains a citizen’s name, their income or a social services report, that data has just been transferred to a company outside the European Union, with no contract, no legal basis and without the person concerned knowing.

The Italian Data Protection Authority has already shown where the problem lies. In January 2025 it blocked the DeepSeek app in Italy because users’ data ended up on servers in China with no clarity about purposes and retention. In 2023 it had suspended ChatGPT and in 2024 it charged OpenAI with processing data without a legal basis. For a municipality, which is the data controller, the question is not whether to use artificial intelligence, but where the data goes while it does.

Meanwhile the Italian administrations that move often choose the opposite road: in June 2026 Rome presented the new assistant of its portal, developed with Microsoft and a vendor of management systems. It works, but the data and the dependency sit elsewhere.

The rule

What the law says

Law 132 of 23 September 2025, Italy’s first law on artificial intelligence, devotes article 14 to public administration. AI is to be used to increase efficiency and shorten proceedings, while guaranteeing that its workings can be known and its use traced. But its role is instrumental and supporting: a person remains solely responsible for the decisions and proceedings in which AI was used. Administrations must also adopt technical, organisational and training measures for responsible use.

The European regulation on artificial intelligence (AI Act) adds two things that matter for a municipality. Since 2 February 2025 anyone using AI systems must ensure their staff have a sufficient level of literacy. And systems used by public authorities to assess people’s eligibility for benefits and services, such as grants, housing or exemptions, are classified as high-risk, with obligations of registration, a fundamental rights impact assessment and information to the people concerned. An assistant that helps write and search is not high-risk; it becomes so the moment it enters the decision about who is entitled to what. This proposal stops before that.

The data protection regulation applies as always: if the model runs at a vendor, that vendor is a processor and a binding contract is needed; if the data leaves the Union, the safeguards of chapter V are needed; in any case an impact assessment is needed. If the model runs on a server owned by the Municipality, no data leaves the institution: the risk perimeter shrinks to that of any other internal system. The AgID guidelines on adopting AI in public administration, in consultation since February 2025, ask the same thing in positive terms: classify systems by risk, keep human oversight, prefer open and verifiable solutions.

The proposal

One server, open models, supporting tasks

  1. A machine in the town hall

    A server with one or two graphics cards of 24 or 48 gigabytes of memory is enough to run models of 8 to 30 billion parameters for dozens of users, and with 48 gigabytes one reaches 70-billion models. It is a one-off purchase, in the order of a professional workstation, against a per-user monthly subscription that cloud assistants charge for every employee, forever. The exact quote must be based on the number of users; the order of magnitude is that of a company car.

  2. Open-weights models

    In 2026 the models that can be downloaded and used freely are many and good: EuroLLM, trained on the twenty-four official languages of the Union; Apertus, Swiss and fully documented; Minerva, Italian; the Llama, Mistral and Gemma families and the Chinese DeepSeek and Qwen. The last two have changed the picture: in public benchmarks their largest models come close to the frontier models of OpenAI and Anthropic on many tasks, from writing to reasoning, and the gap has shrunk to a few points; it remains on the most complex tasks. And there is a difference that matters for a municipality: the Data Protection Authority blocked the DeepSeek app because it sent data to China, but the model’s weights, downloaded and run on a server in the town hall, send nothing to anyone. They run with free tools such as Ollama or llama.cpp and are used from a multi-user web interface such as Open WebUI. No licence, no data leaving, and the model is swapped when a better one comes out.

  3. The Municipality’s documents as the base

    The model is not retrained: regulations, resolutions, decisions and pages of the website are indexed and retrieved at the time of the question, with the technique known as RAG. Every answer cites the document it comes from. It is the most effective way to contain made-up answers, and it makes the assistant useful from day one.

  4. Four uses, all supporting

    Summarising a resolution or a file before a meeting. Searching the register and the archive with a question in plain language instead of a keyword. Preparing the draft recitals of an act, with the procedure and the applicable rules, leaving reasoning and decision to whoever signs. Translating and simplifying answers for the counters, where citizens speak many languages. These are the tasks article 14 allows and that German and French administrations already entrust to their assistants.

  5. What the assistant does not do

    It does not decide who is entitled to a grant, to housing, to an exemption. It does not write the reasoning of a decision. It does not answer citizens without a person having read the answer. It does not receive data not needed for the task. These limits must be written into an internal regulation before the machine is switched on, not after.

  6. Reuse before development

    Baden-Württemberg published its assistant as free software precisely so that other bodies can reuse it; France did the same with the Albert platform. Before having anything developed, the Municipality assesses these tools, as article 68 of the Digital Administration Code already requires for every software purchase. Whatever the Municipality adapts, it releases in turn.

  7. Training and someone in charge

    Staff literacy is a European obligation in force and the Italian law requires training measures. A short training cycle for everyone, a longer one for those who will use the assistant every day, and the Digital Transition Officer, together with the Data Protection Officer, governing the trial: six months in two offices, then the decision whether to extend.

Who has done it

Administrations that keep their models in-house

  • Baden-Württemberg, F13 assistant · since 2023, open source since July 2025

    Chat, document summaries and search through records for all the state’s employees, run in the regional data centre.

    Model-independent: the underlying model can be swapped without redoing the rest. Published on openCode so that other bodies can reuse it; Saarland is already trying it.

  • Schleswig-Holstein, LLMoin assistant · 2026

    Assistant built into the workstation of a thousand employees, run by the public consortium Dataport.

    It replaced a proprietary model with an open-weights model of 120 billion parameters.

  • France, Albert (DINUM) · since 2024

    The State’s assistant on open Llama and Mistral models, tested at France services counters to answer citizens about their files.

    Code published; the model access platform is open source and reusable.

  • Canton of Ticino, with the Swiss model Apertus · 2025-2026

    Secure translations in the cantonal administration with a fully open model, in 8 and 70 billion parameter versions.

    First public deployment of Apertus. An Italian-language case, seventy kilometres from Saronno.

  • Sapienza University, Minerva model · 2024

    First family of models trained from scratch on Italian, up to 7 billion parameters, under a permissive licence.

    Downloadable in a format that runs on an office computer with a graphics card.

In Italy the national social security institute INPS has a three-year plan for generative AI and uses an internal tool to make its texts more readable; the City of Florence adopted a strategic plan for AI and an assistant on its portal in thirteen languages. At the time of writing no Italian municipality is known to declare that it runs its models locally. Saronno could be the first on record.

From the point of view of a resident

What changes at the counter

A quicker answer about a file, because the person answering found the right resolution in a minute instead of an afternoon. A letter from the Municipality written in plain language. A form explained in their own language to someone who arrived recently. And the certainty, written in a regulation and verifiable, that their data did not end up on a server on the other side of the world to obtain all this.

Honesty

What can go wrong

  • Made-up answers. Every language model can produce false statements in a confident tone. Mandatory citation of the source and human reading of every text before it goes out are the two defences, and neither is optional.
  • Local is not magic. A server in the town hall must be updated, protected and maintained: without a technical contact and a maintenance contract it becomes a risk, not a guarantee. The data does not leave, but inside it must be protected like everything else.
  • Quality: the gap has shrunk, not vanished.The largest open models, such as DeepSeek and Qwen, are now close to the best cloud models, but they need tens of gigabytes of graphics memory to run; those of 8 or 30 billion parameters, within reach of a municipal server, remain a step below. For summarising, searching and translating they are more than enough; on the most complex tasks the difference shows. It is a conscious trade: a little capability in exchange for control over the data.
  • The temptation to expand. Once the assistant works, someone will propose using it to process grant applications. That is where the AI Act’s high-risk rules and the ban on automated decisions kick in: the internal regulation must say so first.
  • The costs are estimates. No figure on this page concerns Saronno. The number of users, the choice of model and the hardware quotes are for the competent office; the page gives orders of magnitude and sources.

Useful links