AI, Platforms, and Retained Authority
AI is an operational tool, not an institutional objective
Artificial intelligence is affecting diplomatic work unevenly. In many foreign ministries in 2026, its practical use remains concentrated in drafting, translation, search, summarisation, monitoring, transcription, knowledge retrieval, and administrative support.
Some use cases will reduce routine workload. Others will produce bland or inaccurate output, require more senior review than manual work, or create unacceptable data and accountability risks. A ministry may decide to stop a use case after testing. That decision can demonstrate institutional maturity.
The report therefore does not treat AI adoption as evidence of readiness. It asks whether the use creates demonstrable value and whether the surrounding institution retains enough authority to govern the responsibility.
Identity
Can the institution prove who acted, and on whose authority?
Traceability
Can the decision path, including automated steps, be reconstructed?
Continuity
Does the function survive a supplier, contract or platform change?
Exit capacity
Can the institution leave with its data, records and working knowledge?
Human oversight
Is a named official accountable for the output before it is used?
Five elements of equal weight, applied as a module inside the Capability Framework. The test is not a certification and does not clear a system for use.
NoteDiplomats.Digital synthesis. Passing the test does not certify a system; it records the conditions an institution has retained.
Useful, restricted, and abandoned use cases
| Possible outcome | Institutional meaning |
|---|---|
| Use with proportionate safeguards | The use case saves time or improves access, and the ministry can preserve evidence, data boundaries, review, accountability, and continuity. |
| Restrict or redesign | The tool is potentially useful, but the data, consequence, source quality, or workflow requires stronger limits or a different system. |
| Stop or abandon | The use case creates more review work, unreliable output, unacceptable exposure, or dependency without sufficient value. |
The objective is not to maximise the number of AI-enabled workflows. It is to make responsible decisions about where the tool supports diplomatic work and where it should not be used.
Where AI enters the Conversion Chain
AI can influence every stage:
| Stage | Possible contribution | Possible risk |
|---|---|---|
| Signal | Detect recurring topics, translate material, group public enquiries. | Visibility bias, excessive alerts, or automated inference treated as fact. |
| Verification | Compare records, search sources, identify inconsistencies. | Invented sources, source laundering, overconfidence in detection scores. |
| Interpretation | Organise evidence and surface recurring patterns. | Context loss, flattened disagreement, culturally weak framing. |
| Prioritisation | Summarise consequence and generate options. | The system's framing shapes attention before officials inspect the evidence. |
| Escalation | Prepare concise briefings and decision formats. | Uncertainty disappears from a fluent summary. |
| Coordination | Translate and distribute agreed material. | Different systems or prompts produce inconsistent guidance across missions. |
| Action | Draft statements, guidance, or technical requests. | Official identity carries output that was not adequately reviewed. |
| Learning | Search records and compare recurring friction. | The institution stores lessons inside a proprietary system it cannot later access. |
Human oversight should therefore mean more than a person approving the final sentence. It includes deciding whether AI should be used, choosing the system and data, inspecting and challenging output, returning to the source evidence, identifying accountability, restricting use, stopping the process, and preserving a record of how the result was produced.
A proportional governance model
The greater the consequence, sensitivity, uncertainty, or irreversibility of the task, the stronger the evidence traceability, human authority, and institutional oversight required.
| Use category | Examples | Minimum control |
|---|---|---|
| Low consequence | Grammar, formatting, non-sensitive brainstorming, routine public-information drafting. | Approved tool, basic human review, no sensitive data. |
| Moderate consequence | Translation, document summarisation, research support, internal knowledge retrieval. | Source access, data rules, reviewer accountability, correction route. |
| High consequence | Political assessment, crisis briefing, hostile-activity analysis, consular or security recommendation. | Original-source review, explicit uncertainty, independent human verification, decision traceability, senior accountability. |
| Restricted or prohibited | Classified material in unapproved systems, automated public attribution, unsupervised decision-making, sensitive personal data without authority. | Do not use unless a separately authorised and assured environment exists. |
The AI Use Register
A simple register can make institutional use visible without creating an enterprise bureaucracy. It should record: - the use case and institutional purpose - the approved system and provider - the data category and sensitivity - the expected value - the required human review - source and uncertainty requirements - the accountable owner - known limitations and incidents - continuity and fallback - review date and decision to continue, restrict, redesign, or stop
The register should be proportionate. It is not intended to document every spell-check or routine grammar correction. It should focus on meaningful institutional use and consequential workflows.
Platforms and infrastructure
AI is one part of a wider dependency environment. Foreign ministries rely on social platforms, cloud services, telecommunications, identity systems, software providers, content-delivery networks, data centres, cables, satellite connectivity, and external analytical services.
External capability can be necessary and beneficial. Sovereign control does not require every system to be built or hosted internally. It requires the ministry to understand and govern the dependency.
The practical questions include: - Where is institutional data stored and processed? - Which jurisdiction and contract govern it? - Can records, logs, contacts, and institutional knowledge be exported in usable form? - What happens if access is withdrawn or the service fails? - Can the ministry replace the provider within an acceptable time? - Are staff skills and workflows becoming dependent on one proprietary system? - Does the institution retain control of official identity and authentication? - Can consequential output be reconstructed?
The Retained Authority Test
The Retained Authority Test is a module within the Capability Framework. It does not certify that an external system is 'sovereignty-safe'. It asks whether the ministry preserves enough institutional control to govern the responsibility.
1. Identity
Does the institution retain control of the official identity through which the state communicates and acts? Who controls accounts, credentials, authentication, naming, and the ability to recover or revoke access?
2. Traceability
Can the ministry reconstruct the sources, data, system contribution, human review, authority, and decision behind a consequential output or action?
3. Continuity
Can the responsibility continue when the primary person, provider, platform, account, system, or connection becomes unavailable?
4. Exit capacity
Can the institution export records, preserve knowledge, change provider, return to an internal or alternative process, and terminate the dependency without unacceptable loss?
5. Human oversight
Do accountable officials retain the ability to approve, challenge, restrict, correct, pause, stop, and assume responsibility for the work?
| Test | Minimum evidence |
|---|---|
| Identity | Institutionally controlled credentials, recovery, role-based access, and account continuity. |
| Traceability | Source access, logs, decision records, and clear attribution of human and system contributions. |
| Continuity | Fallback process, substitute access, tested recovery, and usable records. |
| Exit capacity | Portability, contract provisions, replacement plan, and retained internal knowledge. |
| Human oversight | Named accountability, review proportional to consequence, challenge rights, and stop authority. |
External advisers and institutional trust
Any external adviser, research partner, provider, or platform creates legitimate questions for a foreign ministry. Independence alone is not reassurance. Institutions need to know who funds the organisation, what relationships and conflicts exist, what information it receives, how data is handled, who is accountable, and what happens when the engagement ends.
Diplomats.Digital should therefore apply the same retained-authority principles to its own work. Public research and institutional support should disclose methodology, funding relationships, conflicts, data boundaries, correction routes, and the limits of access.
The appropriate public claim is not that implementation is automatically 'sovereignty-safe'. It is that the method is designed to preserve institutionally controlled implementation and retained authority, subject to the ministry's own legal, security, political, and operational assessment.
When governance becomes bureaucratic drag
AI governance can create unnecessary burden when every low-risk use requires senior approval, when registers capture trivial activity, when documentation becomes a substitute for evaluation, or when a committee continues after the underlying use case has been abandoned.
A proportionate model should ask whether the control reduces a real risk and whether the process remains usable. Governance that officials bypass because it is unrealistic creates less authority, not more.
A minimum leadership test
-
Which AI and external-system uses create demonstrable institutional value?
-
Which uses create more review work or risk than benefit?
-
Which data and decisions must remain inside a more controlled environment?
-
Can officials inspect the sources and challenge the output?
-
Can the ministry continue the work without the tool?
-
Who can stop the use case?
-
Can the institution change provider without losing identity, records, or knowledge?
The central proposition
Digital and AI-supported capability becomes institutionally useful when the ministry can benefit from external systems without losing evidence, accountability, continuity, identity, professional judgment, or the authority to stop.
Evidence and citation record · 12 sourcesClose evidence and citation record
Evidence and citation record
Source IDs follow the Technical and Evidence Annex citation map. Conceptual models developed by Diplomats.Digital are analytical propositions, not externally validated standards.
- OECD2026Digital Government Outlook 2026
Cited in this section as S05 in the Technical and Evidence Annex citation map.
- UNESCORecommendation on the Ethics of Artificial Intelligence
Cited in this section as S07 in the Technical and Evidence Annex citation map.
- Source2026International AI Safety Report 2026
Cited in this section as S08 in the Technical and Evidence Annex citation map.
- Stanford Institute for Human-Centered AI2026AI Index Report 2026
Cited in this section as S09 in the Technical and Evidence Annex citation map.
- United NationsGlobal Digital Compact
Cited in this section as S10 in the Technical and Evidence Annex citation map.
- UK ParliamentScience diplomacy: Sovereignty — strategy — and the global race
Cited in this section as S11 in the Technical and Evidence Annex citation map.
- Creative CommonsLicence overview
Cited in this section as S31 in the Technical and Evidence Annex citation map.
- Creative CommonsCC BY 4.0
Cited in this section as S32 in the Technical and Evidence Annex citation map.
- Creative CommonsCC BY-NC-SA 4.0
Cited in this section as S33 in the Technical and Evidence Annex citation map.
- Creative CommonsCC BY-NC-ND 4.0
Cited in this section as S34 in the Technical and Evidence Annex citation map.
- Diplomats.DigitalBuilding Sovereign Diplomatic Capabilities / Retained Authority Test
Cited in this section as S35 in the Technical and Evidence Annex citation map.
- Diplomats.DigitalResources and institutional tools
Cited in this section as S36 in the Technical and Evidence Annex citation map.
Source status: Citation records and publication links were checked for Edition 1.0 at publication. Subsequent corrections are recorded through the version history.
Suggested citation
Diplomats.Digital (2026). State of Digital Diplomacy 2026: From Communication to Capability. Edition 1.0. Section: AI, Platforms, and Retained Authority.