Governance & Audit
Public Disclosure: How Much Should You Publish?
· 10 minute read
Citizens deserve to know an agent is in the path. They do not deserve your system prompt, and you do not deserve to hide the human gate. Publish the middle.
Two departments answered the same newspaper questionnaire in the same week. The first said it used no AI, though a helpdesk agent had been drafting replies for four months. The second published its entire system prompt, retrieval policy, and a week's worth of redacted chats on a microsite. By Friday the first department was accused of secrecy. By Friday the second was watching coaching forums replay the prompt and fish for wording that unlocked a softer eligibility hint. Both thought they had done transparency. Both had done the wrong amount.
This is an opinionated map of how much an Indian public institution should publish about official agents. The opinion is that you publish existence, purpose, data classes, the human gate, and the redress path. You do not publish material that lets people game a live decision, or material that is someone else's personal data. You never publish a lie that you use no AI when you do.
It is not legal advice. RTI will be decided on the Act you already have, including exemptions you must apply carefully. DPDP will govern what you owe a Data Principal about processing. The India AI Governance Guidelines of 5 November 2025 may urge transparency; they do not write your disclosure notice. Counsel still reads the live text.
The middle path: a public card, not a dump
For each live workflow, a public card of one or two screens is enough. Name the service in ordinary language. Say an official digital assistant helps draft or retrieve. Say which human still decides. Say what the assistant is not allowed to do — sanction, mark, pay, reject without an officer. Say how to complain about the decision, not about the model in the abstract.
That card belongs next to the service, not only in a PDF on the IT wing's page. People meet the agent on a portal or a helpdesk. That is where the sentence must stand.
A department-wide register extract can sit on the website as well: list of live workflows, owners, dates. It is the public cousin of the internal register. It should be boring and true.
What you should not publish
Live system prompts that encode eligibility heuristics, fraud tells, or exam-integrity checks. Publishing those is not accountability. It is a coaching manual.
Retrieval sets that include unpublished drafts, legal advice, or third-party commercial data.
Traces, chats or embeddings that identify a citizen or student, even if you think you have redacted names. Quasi-identifiers on a campus are easy.
Network diagrams, jump-box paths, and the SoD matrix in enough detail to target the combined-duty account you have not yet split.
A claim of accuracy percentages you cannot reproduce. Invented GMV or '92 percent satisfaction' is not transparency. It is a new lie.
| Object | Public by default | On request / exempt / never public |
|---|---|---|
| Existence and purpose of the workflow | Yes, in the service card | Hiding it is the worst option |
| Human gate and redress path | Yes | Do not hide a missing gate behind an exemption |
| Model brand and hosting posture (on-prem / which estate) | Usually yes at a coarse level | Exact rack diagrams and patch levels stay inside |
| System prompt and fraud heuristics | No | Summarise the rule; do not hand over the tell |
| A particular citizen's trace | No | The Principal may have rights; the public does not |
| Aggregated quality notes without identifiers | Sometimes | Only if the number is real and the sample is described |
RTI is not your communications plan
A well-written public card reduces bad RTI. It does not replace RTI. When a request comes, apply the Act you have. Do not invent an 'AI exemption'. Do not release another person's file because the word transparency was in a speech.
Decision records that already exist as notes, sanction orders and rejection letters remain the primary public-facing artefacts. The agent's draft is usually an internal paper. Whether a particular draft is disclosable is a facts-and-exemptions question, not a slogan.
If your only record is a vanished unofficial chat, RTI will hurt whether you are a transparency maximalist or a minimalist. Disclosure policy cannot repair amnesia.
DPDP notices are not press notes
A Data Principal notice, when the operational duties apply, is a legal artefact with a purpose and a contact. It is not a blog post about innovation. Do not merge the two into a single fluffy paragraph that fails both jobs.
MeitY notified the Act and Rules on 13 November 2025. Most remaining operational duties apply from 13 May 2027. Build the notice pack now if the agent already processes personal data. Do not wait for the date to decide what you are willing to say.
Guidelines that urge transparency do not let you publish personal traces to look modern.
The lie of 'we do not use AI'
Departments say this because they fear the next headline, or because they think only a branded chatbot counts. Drafting assistants, unofficial staff paste, and ranking tools in a spreadsheet all count as something you may have to explain. If an official agent is in the path, say so. If unofficial tools are the real path, fix that before you write a denial.
Over-disclosure of prompts and under-disclosure of existence are both ways to lose. Existence is the cheap, honest sentence. Start there.
Objections you will hear — and what to do with them
These are the lines that stall the file. Answer them in the room, then put the answer in the note. A spoken answer without paper will be forgotten by the next officer.
If we admit we use AI, every rejection will be blamed on the model.
They will be blamed anyway when the prose sounds unlike the section. Name the human gate. Make the officer the author of the decision. Hiding the assistant makes the first leak look like a conspiracy.
Transparency means open-sourcing the prompt.
No. Transparency means a citizen can know the system exists, what it is for, who decides, and how to complain. Open-sourcing a live eligibility prompt is a different, usually bad, idea.
Legal says publish nothing until there is a circular.
You already publish how to apply for a scheme. Adding one sentence about an official assistant is not a new species of disclosure. Waiting for a circular is how the newspaper writes it first.
We will publish everything and let exemptions sort RTI later.
That dumps personal data and gaming material. Sorting later is how you create the next incident. Sort now.
A 10-day public-card sprint
Do one workflow, not a portal redesign. Put the card where the citizen already stands.
- Days 1–3: draft the card: existence, purpose, data class in ordinary words, human gate, redress, what the agent must not do.
- Days 4–6: legal and DPO mark-up. Remove numbers you cannot defend. Remove prompt text if someone pasted it in.
- Days 7–8: publish next to the service. Add a boring line to the department register page.
- Days 9–10: brief the helpdesk on how to answer 'did a machine decide this?'. The answer is the card, not a shrug.
How this shows up in the file
Keep the public card, the internal fuller register, and a note on what you will refuse to publish and why. When RTI arrives, you start from that note rather than from panic.
If the public card is more optimistic than the internal register, you have a disclosure incident already.
This article is informational field guidance for Indian public institutions, not legal, procurement, security-accreditation, academic-regulation or engineering advice. Confirm against the current Gazette, DPDP text and Rules, CERT-In direction, India AI Governance Guidelines, UGC/AICTE/NAAC notices, NEP documents, GFR, departmental manual and your counsel before you file it. Guidelines are not statute. Circulars move.
How this survives CAG, RTI or the Board
“Public Disclosure: How Much Should You Publish?” is not a workshop slide. A P6 Compliance/DPO will have to reconstruct a decision after the officer who clicked approve has been transferred. Write the artefact that lets a stranger replay the case: the log fields, the approval, the override, the register row.
Citizens deserve to know an agent is in the path. They do not deserve your system prompt, and you do not deserve to hide the human gate. Publish the middle. India AI Governance Guidelines (November 2025) are guidelines, not a statute. DPDP still allocates fiduciary duty. Delegation of Financial Powers still allocates who may spend. Do not hide those instruments behind the word governance.
If you cannot show who acted, on which purpose, with which data class, and who could have refused, you do not have accountability. You have a chatbot with a charter PDF.
- Name the owner of “AI transparency disclosure government” inside the department, not the vendor.
- Keep CERT-In-relevant logs in India for the required period.
- Store overrides with a reason an auditor can read.
- Put the workflow on the AI register before it touches a citizen.
Close this loop before the next CAB
Put “Public Disclosure: How Much Should You Publish?” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P6 Compliance/DPO, not “the vendor.”
Revisit the item when the model, the GeM term, the region, or the SI changes. “AI transparency disclosure government” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.
Questions this usually raises
- Must we publish the model name?
- A coarse hosting posture and the fact of an official assistant matter more than a brand. You may publish a family name if it does not help an attacker. Do not publish it as a substitute for the human-gate sentence.
- Does RTI force us to release system prompts?
- Not automatically. Apply the live Act and exemptions with counsel. Many prompts will mix internal deliberative material, security, and third-party content. Do not use that as a reason to hide the agent's existence.
- Should we publish accuracy statistics?
- Only if you can describe the sample, the period, and the definition of a hit. Invented percentages are worse than silence.
- Do the 2025 AI Governance Guidelines require a public register?
- They are guidelines. Read the live document. Do not invent a statutory public-register duty in their name. A public extract is still good practice.
- What do we say if staff used unofficial tools?
- Do not deny official policy you have not enforced. Internally, inventory and replace. Publicly, do not volunteer a confession that names citizens. Take counsel on any specific incident.
Sources
- Prcept AI — platform and sovereignty
- Right to Information Act, 2005 (India Code)
- Digital Personal Data Protection Act, 2023 (India Code)
- India AI Governance Guidelines (PIB document, November 2025)
- Comptroller and Auditor General of India
- Ministry of Electronics and Information Technology
- Department of Administrative Reforms — Central Secretariat Manual of Office Procedure