Governance-by-Design for Experience Infrastructure

SCS Brief · Baseline principles for privacy-native systems, auditability and human agency, written for public and civic partners · Oct 4, 2026

In civic infrastructure, the person is the principal. An AI agent that coordinates on someone's behalf should act only on a mandate that person gave, leave a ledger they and an oversight body can read, and stop when anyone affected pulls the brake. Personal data should never sit in the same agent as untrusted input and a way out.

This brief sets out those four baseline principles for public and civic partners: municipalities, regions, cultural institutions and the companies that serve them. Each principle comes with what a partner can require in procurement and how to check it. The evidence behind them is set out in a forthcoming companion paper from Deriss Research, Rogue by Consensus.

1. Why now

AI agents are moving from answering questions to acting: booking, messaging, matching people and coordinating events across calendars, inboxes and public services. Once an agent holds keys to other systems, a breach no longer needs a hacker inside the network. It needs one poisoned input, or two agents whose combined actions add up to something neither was meant to do.

The 2026 record shows this is no longer theoretical:

Civic systems raise the stakes. They hold data about residents who never chose the vendor, and public trust lost to one incident takes years to rebuild. Governance therefore has to be designed in from the start, not added after a breach.

2. Four baseline principles

Each principle turns a security mechanism from the research into a right the person can see and a requirement a partner can write into a contract.

The test for all four is the same: an honest agent loses almost nothing, because its actions match its mandate. A rogue one has to break a visible rule to act, and breaking the rule is the signal.

3. Alignment with GDPR and the EU AI Act

The four principles put into practice duties that already exist in European law. Governance-by-Design is the AI-agent counterpart of GDPR's data protection by design.

Timing matters for public partners. The Digital Omnibus, in force since 27 July 2026, moved most high-risk duties to 2 December 2027 (Annex III) and 2 August 2028 (Annex I) (Gibson Dunn https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/). Public bodies that deploy high-risk systems will also owe a fundamental-rights impact assessment (Art. 27). Whether a given civic coordination tool counts as high-risk depends on its use; building to these principles now means the answer does not change the design. This is not legal advice; partners should confirm classification with their own counsel.

4. How SCS applies it

Experience OS is being built to these Governance-by-Design principles, and Stockholm is where they are tested. It is a voice-first, privacy-native coordination layer, currently in private alpha. It works with people's calendars and messages on their behalf, which makes it exactly the kind of agent these principles exist for. We hold ourselves to the same test we ask partners to apply.

Nothing is described as live until it can be shown to a partner. European by design; Stockholm is where it is proven.

5. For partners: what to ask any AI vendor

Partners can use these ten questions in procurement, whoever the supplier is, SCS included:

Next step. SCS invites public and civic partners in Stockholm to test these principles with us https://www.socialcapitalstockholm.com/contact on a real coordination use case, and to tell us where they fall short.

Sources

References and links are citations, not affiliations or endorsements.