Rising submission and surveillance volume against fixed headcount — with a hard constraint that no document may leave the agency's environment.
Sovereign AI workflows for a government health agency, built from reusable modules inside the Government Commercial Cloud and extended one work package at a time.
Submission and surveillance volume was rising against a fixed headcount — the familiar shape of the problem across health authorities everywhere. What made this engagement different was the hard constraint sitting underneath it: no document, no extracted field, no model call could leave the agency's own environment at any point, including for inference. That rules out most commercial AI tooling by default, not because the capability is wrong but because the delivery model is — a hosted API the agency doesn't control is a transfer the moment a document touches it, regardless of what the vendor's privacy policy says.
A sovereign cloud deployment inside the agency's own Government Commercial Cloud tenancy in Singapore — dedicated infrastructure, in-country processing including inference, administrative access held within the agency's own jurisdiction. That rules out the usual shortcut of calling out to a third-party model endpoint for the hard parts and keeping only the orchestration local: inference had to run on infrastructure the agency controls, not infrastructure it merely trusts. See sovereign cloud for government AI for what that topology actually commits to beyond where data sits at rest, and Singapore's AI in Healthcare Guidelines for the sectoral expectations a deployment like this sits alongside.
Four work packages on one shared module base, standing up one at a time rather than as a single large programme. WP1 — document extraction and structuring, live — turns incoming submissions into structured records an officer can search and compare rather than re-reading PDFs by hand. WP2 — compliance and quality verification, live — checks completeness and cross-references claims against supplied evidence, producing a screening report an officer confirms rather than a decision the system makes. WP3 — multilingual health-product advertisement surveillance, in build — extends automated screening from sampling to full population coverage. WP4 — grounded product-information retrieval for pharmacovigilance, in build — surfaces the specific approved product information a safety case needs, with the source attached. The two live work packages run in production today handling real submission volume; WP3 and WP4 are in active build against the same module registry, not a separate roadmap.
The design boundary is the same one described in automating regulatory submission review: the system locates, extracts and flags; the officer decides. WP2's compliance checks produce a screening report with every flagged discrepancy traceable to the specific requirement and the specific submitted content it was checked against — an officer confirms the screening rather than re-deriving it, which is what actually makes a completeness check faster without weakening it. Every action any module takes is logged at the point it happens, to an immutable record, matching the standard set out in audit trail requirements for AI systems — the same discipline a government inspector would expect of the agency's own internal controls. For the human-in-the-loop boundary itself — which steps an officer must confirm versus which the system is trusted to execute outright — the governing principle is the one described in human-in-the-loop design for healthcare AI, applied here to a regulator's workflow rather than a clinician's.
A private, in-country deployment with no external data sharing, including during inference. Officers keep the decision; the workflow does the reading and the cross-referencing. Each new work package stands up faster than the one before it, because WP3 and WP4 configure the same registered extraction, compliance-check and retrieval modules WP1 and WP2 already proved out, rather than building new ones from nothing — the gap between WP1 and WP2 going live and WP3 and WP4 entering build was months, not another full procurement cycle.
The agency's own staff operate all four work packages inside their own cloud tenancy. document_extraction · compliance_check · grounded_retrieval · audit_trail — plus a proven sovereign deployment pattern the agency can point its next work package at directly.
This deployment is also what Regulatory document automation is built from — the same extraction, compliance-check, and audit-trail modules run on the sponsor side of the same transaction. See the Government & regulators page for the fuller breakdown of this deployment.
See the Government & regulators solution →Client names, references, and full results available under NDA.
Our proprietary AI orchestration platform for healthcare: one engine, a registry of reusable task modules and domain agents, and a governed knowledge base — deployed inside your walls and run by your team.