AMENAZA ROBOTO
Inteligencia Artificial en el Estado
Alone against AI
ChatGPT, Gemini, Claude, and Copilot assist public officials with their daily tasks. Out of the 24 agencies surveyed, only four reported having a formal policy governing the use of these tools. In most cases, each official decides—without clear guidelines—which government-held data can be provided to AI.

By: Gabriel Farías y Miguel Ángel Dobrich.
Legal advisor: Matías Jackson.
Translation: Alexandra Waddell.

September 4, 2026

This investigation was produced in partnership with the Pulitzer's AI Accountability Network .
A police report, medical record or a criminal record is just a copy-and-paste away from a generative artificial intelligence service that processes the data outside of the country. From that point on, how that data is handled depends on the terms of service: where the information is processed, how long it is stored, who can access it and if the service provider can use it to improve or train their models. These conditions vary according to the type of account and the contract.

To understand what control the State maintains over the information officials are putting into these tools, Amenaza Roboto asked 24 government agencies to report which tools they use, what data they upload, and what measures they implement. With the responses, we created the Generative AI Governance Index, which compares how much each agency knows about this use, how it's being regulated, and what is being done to protect citizen’s data.

The Uruguayan constitution and the Law on the Protection of Personal Data and Habeas Data Action (N.º 18.331) establish duties of accountability, confidentiality, and security. In turn, the Code of Ethics for Public Service (Ley N.º 19.823) requires public servants to maintain confidentiality regarding matters and information that come to their knowledge by virtue of their position, when legally required to do so. This general framework defines obligations, but its day-to-day application requires more concrete decisions to be made.

Since the end of 2022, the public launch of ChatGPT—and, in the following months, other generative AI assistants from Anthropic, Google, and Microsoft—the digital landscape in which public servants perform their duties has changed. These tools can edit, summarize, and reorder documents that a user uploads to the system. The problem emerges when public servants bring personal data or confidential information to the chat. What can be copied into a chat? What account should be used? How is the exchange registered? What conditions are service providers imposing?

In 2023, The Agency for Electronic Government and the Information and Knowledge Society (AGESIC) of Uruguay began creating the first technical guide for the use of generative artificial intelligence by the State. In 2024, it recommended the development of protocols and technical guides. Through a survey, Amenaza Roboto found that, in 2026, four of the 24 government agencies reported a documented review of admissible data. The measures, however, varied in scope. ANCAP sent us their policy for classification, tagging, and data management approved in 2018, before the public availability of generative assistants, and the document contains no reference to artificial intelligence. The Central Bank of Uruguay (BCU) shared a resolution that classifies information to manage public access requests, but establishes no rules for their use in artificial intelligence systems nor defines what may or may not be uploaded to an AI assistant. Neither the Banco de Previsión Social (Uruguayan social security bank or BPS) nor AGESIC provided the classifications they reported using.

The most common measures are individual in nature, such as training for civil servants, while institutional controls and responsibilities are less frequently mentioned. One agency reported monitoring or preventing data breaches. Nine said that AI governance was assigned to a specific person or department. Three provided the contact information of a designated person in charge; none documented the assignment through an administrative act.

The data comes from the 24 requests for access to public information. Nineteen agencies provided information between late May and July 2026. Four invoked exceptions outlined in the Law of Access to Public Information (N.º 18.381) and the Ministry of the Interior let the legal deadline expire without response.

Generative AI Governance Index

Percentage scored out of the index's 15 possible points

Rank
Agencies
Score

Percentages rounded to the nearest whole number. Tied agencies share a rank.

Agencies that did not provide information are included in the index at 0%, with the reason indicated.

Source: responses and documents submitted by the agencies in response to the public information access request.

AI use is known or assumed in the majority of agencies

Nine agencies admitted to having knowledge that its officials use generative AI assistants: ANCAP, ANDE, ANII, BPS, BCU, Ceibal, MIDES, the Ministry of the Environment, and UTEC. Another six (MEC, MTOP, MVOT, OPP, OSE y UDELAR) indicated that they assumed it was being used. AGESIC, the MEF, and the MSP responded that they had not yet assessed its use.

The fourth option of the survey, “We know that use does not occur,” was not selected by any agency. The Office of the President responded with prose, giving us insufficient information as to which of the four categories they belonged.
AGESIC plays a unique role: It coordinates the National Strategy of Artificial Intelligence 2024-2030 and develops guidelines for the rest of the government. However, it responded that it had not yet determined whether its own employees use these tools. It added that the recommendations currently being drafted would include that assessment.

Incomplete data use and classification policies

Article 24 of the Uruguayan constitution establishes that State agencies are civilly liable for damages caused to third parties during the execution of public services. A person gives their information to the State to file a police report, receive medical care, apply for retirement, or fulfill a legal obligation. They give this information to the institution, beyond the public servant who processes the request.

With regard to the databases they manage, public entities are responsible for data processing. Articles 10 and 12 of the Law on the Protection of Personal Data and Habeas Data Action (N.º 18.331) require them to adopt security and confidentiality measures and hold them liable for violations. Articles 13 and 14 recognize every person’s right to know the purpose of the use of their data, its potential recipients, any international transfers, and what data the institution retains about them. To account for this processing, the agency must determine what information left its system, where it went, and when.

Matías Jackson, a lawyer who specializes in information systems and legal counsel for this investigation, noted that Article 31 of the Law on Access to Public Information (N.º 18.381) considers it a serious offense to allow unjustified access to restricted or confidential information and to misuse information in the custody of a public official or to which the official gained access for official purposes. “Beyond the general mandate of confidentiality, and depending on the type of information used in the tool, the official could be subject to sanctions and the government held liable for his or her actions,” he explained.

Having written rules would translate this general duty into specific instructions: It would determine what can and cannot be written into these tools, which account must be used, and what the consequences are for failing to comply with those conditions. It would establish the same criteria to all public officials, identify the authority that approved it, and permit revisions when tools or provider terms change. Until that criteria becomes final, each official interprets the limit based on the case they are handling.

The survey identified two instruments. A policy or set of guidelines governs the conduct of the public employee: It specifies the tasks for which an AI assistant can be used, which account to use, and under what conditions. A data classification system governs the material: It establishes how to handle information that is public, private, confidential, personal, or protected by professional secrecy. An organization may have one in place while waiting for the other.

Four organizations—BPS, Ceibal, BCU, and UDELAR—announced a formal policy approved by their leadership. UDELAR responded that its Central Governing Council approved guiding principles for the use of artificial intelligence as well as a roadmap on May 26, 2026, clarifying in the same response that it does not yet have “specific and comprehensive institutional instructions or guidelines” on the use of these tools: the resolution tasked a working group with developing them. UTEC reported a department-level set of instructions, and eight others indicated that they were drafting a document. Regarding admissible data, four reported a documented classification system, eight provided general guidelines, and five cited criteria yet to be defined. Two responses were open to interpretation.
Documented classification
Yes
No
Policy or guideline
Yes
Both instruments
2
BPS · BCU
Usage rules only
3
Ceibal · UDELAR · UTEC
No
Classification only
2
AGESIC · ANCAP
None
12
ANDE · ANII · MEC · MEF · MIDES · Ministry of Environment · MSP · MTOP · MVOT · OPP · OSE · Office of the President

19 responses out of 24 agencies · Drafts in progress and general guidance do not count as documents.

The responses left other conditions open: server location, applicable jurisdiction, retention period, and authorized users. This information is necessary to trace data transfers to third parties and to exercise the rights provided for under Law N.º 18.331.

In July 2026, when the final responses were received, specific rules were still pending adoption.

Provided documents do not define what can be uploaded to AI

A review of the documents shows that declaring a classification on its own is not sufficient to establish what information can be entered into an artificial intelligence assistant.

AGESIC stated that it had a documented classification, but it did not attach it. In its response, it referred to the Personal Data Protection and Access to Public Information laws. Those regulations establish general obligations for the State as a whole, but do not specify what information may be entered into an AI assistant.

ANCAP attached its Classification, Tagging, and Data Processing Policy, approved in 2018. The policy organizes information by category and sets general conditions for its storage and circulation. Its approval predates generative AI assistants and contains no specific references to artificial intelligence, user accounts, or permissible data in a chat.

To support its classification policy, the BCU cited Resolution D-182-2023, which classifies information as restricted, confidential, or secret for the purpose of processing requests for access to public information. The resolution does not regulate data processing in artificial intelligence assistants nor does it establish what may be entered into them. To further back up the formal policy it declared, the agency identified a protocol for cloud service usage, approved March 6, 2026, and classified as restricted. Since its content was not provided, the investigation could not verify if its rules apply to generative assistants. BCU stated that its institutional policy on artificial intelligence is currently being drafted.

The BPS stated that it applies a documented classification system and attached an Information Security Policy for Artificial Intelligence, which regulates the use of these tools. Its institutional origin is supported by the letterhead, the regulatory framework, the internal responsibilities it assigns, and its inclusion in the official record. The document does not specify a date or the act that approved it, which limits its traceability but does not prevent it from being recognized as an agency policy. Data classification, which was addressed separately, was not included in the provided files; therefore, its scope and any potential references to artificial intelligence could not be verified. On this matter, the agency responded that “current regulations regarding the processing and protection of personal data apply”—the same general reference provided by AGESIC.

Ceibal stated that it has general guidelines and attached an internal set of ten guidelines for its employees. The document requires the use of the corporate environment with the institutional account; prohibits the entry of passwords, access credentials, proprietary source code, financial data, strategic documents, and personal information of students, faculty, and staff; and requires the prior anonymization of bulk data. These rules directly specify what information should not be shared with AI assistants. However, the Decalogue lacks a letterhead, date, version number, or identification of the authority that approved it; therefore, while it constitutes a written instruction, it does not allow for verification of its institutional approval.

The institutional alternative is a function of the office software

Eight agencies stated that they offer an institutional LLM alternative: a tool contracted or managed by the institution itself, with corporate terms and conditions different from those of a personal account. Seven identified which tool they use, and in five of those cases, they rely solely on Microsoft or Google services; the Central Bank added licenses for ChatGPT and Ceibal contracted Claude. The OPP checked the option but left the tool name blank: This is the only statement that does not identify any product and the only one that did not count toward the score.
Agency Declared tool Provider

The form did not explicitly require the contract: its absence does not prove one doesn't exist, but no response allows verifying the guarantee it invokes.

OPP checked the box but left the tool field blank: it is the only one of the eight that does not identify any product, which is why it does not count toward the score.

In several agencies, artificial intelligence was included as part of the email, storage and office suite software packages already contracted. ANCAP explained that it was aware of the use because it held licenses for Copilot Chat and Microsoft 365 Copilot. The former became available in November 2023 for accounts on its corporate domain. UTEC reported using Gemini for Google Workspace. Ceibal noted that Gemini and NotebookLM were available to the entire organization, while Copilot and Claude were used for specific projects.

The BCU described the most diverse setup: on-premises models, ChatGPT and Microsoft 365 Copilot licenses, and an interface for Azure OpenAI. It was also the only agency that reported having models installed on its own infrastructure, capable of processing queries within its environment.

These agencies attribute the use of these alternatives to corporate confidentiality and data protection requirements. UTEC, for example, cited its agreement with Google to use Gemini for Google Workspace. Since the full contracts were not included in the responses, the investigation could only verify the conditions described by each agency.

A corporate account may offer better terms than a free version, but it does not replace the rules governing what information can be uploaded to the tool.

Training is emphasized over monitoring

Providing an institutional tool does not guarantee that employees will use it: They may also resort to personal accounts or other services. The survey also asked about monitoring and blocking. The former allows for the detection or logging of data transfers; the latter prevents them. Their presence or absence indicates the agency’s capacity to monitor or intervene in such exchanges.

Eight agencies reported having an institutional tool, and four reported having a way to report incidents. The BPS reported a measure for monitoring or preventing data leaks. However, it provided few details about that control. No agency reported implementing technical domain blocking.

Training is more widespread. Eleven agencies reported training activities on the responsible use of artificial intelligence. Four described these as formal, recurring programs; the others, as one-time sessions.

The general pattern shows that adoption relies primarily on individual behavior. An agency may provide an account and train an employee, but the traceability of what that employee uploads is much less developed.
THE OVERALL PATTERN SHOWS COMPLIANCE DEPENDS MAINLY ON INDIVIDUAL CONDUCT
Those responsible hold no formal designation

Nine agencies reported that AI governance was assigned to a specific person or department. Three identified a responsible official: ANDE and the BCU provided the person’s name; UTEC specified the position and contact information. The other six referred to a committee, a department, a working group, or internal teams. The form requested five pieces of information—position, name, reporting line, time commitment, and public contact information—in addition to the administrative act formalizing the role.

Nine declared officials, none with a formal administrative act

The five fields the form requested about the AI governance official, plus the administrative act appointing them

Agency Position Name Reporting unit Time allocation Contact Administrative act
BCU One person ✕
ANDE One person ✕ ✕
UTEC A unit with a director ✕ ✕ ✕
ANII A unit, plus a representative to AGESIC ✕ ✕ ✕ ✕
AGESIC An internal committee ✕ ✕ ✕ ✕ ✕ ✕
ANCAP A working group ✕ ✕ ✕ ✕ ✕ ✕
BPS A department ✕ ✕ ✕ ✕ ✕ ✕
Ceibal Teams and committees ✕ ✕ ✕ ✕ ✕ ✕
MIDES A unit, without formal designation ✕ ✕ ✕ ✕ ✕ ✕

Filled circle: reported. Empty circle: reported partially or indirectly. Cross: not reported.

BCU is the only one that completes all five fields: 20 hours per month for the inventory of 17 AI projects and systems it declared.

ANDE identified engineer Nathalie Deppen, head of the Information Technology Department, and provided her email address. UTEC identified the director of the Digital Transformation Center, which reports to the General Secretariat, and provided the department’s contact information. The Central Bank filled out all five fields: it identified the Information Technology manager, Virginia Barboza, who reports to the general manager, with an average time commitment of 20 hours per month.

The same organization reported 17 projects and AI systems in use, multiple of which are linked to the financial institutions it supervises. The role is assigned an average workload equivalent to about two and a half workdays per month.

The administrative role serves a purpose distinct from the name or title: It documents responsibility, defines authority, and ensures that the assignment survives changes in leadership. Nine responses left this accreditation pending.

Agencies have no verifiable information due to confidentiality or lack of response

ANTEL, the State Insurance Bank, the Ministry of Defense, and UTE invoked various exceptions under the Law on Access to Public Information (No. 18,381). The Ministry of the Interior allowed the deadline set forth in Article 15 to expire. In the index, all five received a score of zero because they did not provide information that would substantiate rules or measures. This result reflects an absence of verifiable information; it does not demonstrate that the institutions lack the necessary capabilities.

The five agencies that did not report

Four invoked exceptions under Law No. 18.381; one did not respond at all

Agency What they invoked Provision The problem
ANTEL Confidentiality classification predating the request Law 18.381 Does not substantiate the concrete harm that answering this request would cause
BSE Generic, prior confidentiality classification, cited by email Law 18.381 The classification was not issued for this specific information
Ministry of Defense Confidentiality classification created because of the request Law 18.381 The classification was created after the request it was meant to answer
UTE Unavailable information and risk-based confidentiality Arts. 14 and 9(E) Argues that answering would require producing information it does not have
Ministry of the Interior Nothing: did not respond — Silence is not an exception provided for by the law

None of them were scored: not knowing what measures they adopted is not the same as knowing they adopted none.

ANTEL and the BSE cited confidentiality grounds established prior to the request. Their responses provided general justifications, with little elaboration on the specific harm associated with this request. The Ministry of Defense issued a confidentiality ruling based on the request itself. UTE argued that completing the form would require producing information not contained in its records and also invoked a reservation regarding its risk management policies.

In the case of the Ministry of the Interior, the expiration of the deadline enables the action provided for in Article 18 of Law N.º 18.381, under which a judge may order the disclosure of the information.

AI Governance Index results

The AI Governance Index summarizes each agency’s stated and documented capacity to govern the use of generative artificial intelligence by its employees: determining whether such use occurs, establishing rules, and adopting measures to implement them. The scoring system was defined before the requests were sent. The six questions analyzed allow for a maximum of 15 points per agency: two for awareness of its use, five for written rules, and eight for measures adopted. The index does not measure legal compliance or the practical effectiveness of these measures, which require a separate evaluation.

The 24 agencies surveyed scored a total of 92 out of a possible 360 points, or 26%.
The breakdown tells the story more clearly: Awareness of its use accounted for 50% of the available points; written rules, 27%; and measures adopted, 19%.

2026 AI Governance Index: 92 out of 360 possible points

Each chip represents one possible point in one of the six questions analyzed. Hover over any chip to see what it's worth and what it means.

Awareness: whether the agency knows its staff use them
Written rules: usage policy and permissible data
Measures adopted: controls, accountable person, and training
Awareness /2 Written rules /5 Measures adopted /8 Total
confirmation /2 policy /3 data /2 controls /4 accountable /2 training /2 /15
BPS
12
Ceibal
11
ANCAP
10
BCU
✕✕
8
UTEC
8
ANDE
7
ANII
✕✕
6
MIDES
✕✕✕✕
6
UDELAR
✕✕✕✕
✕✕
6
AGESIC
✕✕
✕✕✕✕
4
Ministry of Environment
✕✕✕✕
✕✕
✕✕
4
OPP
✕✕✕✕
✕✕
✕✕
3
MTOP
✕✕✕
✕✕✕✕
✕✕
✕✕
2
MVOT
✕✕
✕✕✕✕
✕✕
✕✕
2
MEC
✕✕✕
✕✕
✕✕✕✕
✕✕
✕✕
1
MEF
✕✕
✕✕✕
✕✕
✕✕✕✕
✕✕
1
OSE
✕✕✕
✕✕
✕✕✕✕
✕✕
✕✕
1
MSP
✕✕
✕✕✕
✕✕
✕✕✕✕
✕✕
✕✕
0
Office of the President
✕✕
✕✕✕
✕✕
✕✕✕✕
✕✕
✕✕
0
ANTEL
✕✕
✕✕✕
✕✕
✕✕✕✕
✕✕
✕✕
0
UTE
✕✕
✕✕✕
✕✕
✕✕✕✕
✕✕
✕✕
0
BSE
✕✕
✕✕✕
✕✕
✕✕✕✕
✕✕
✕✕
0
Ministry of Defense
✕✕
✕✕✕
✕✕
✕✕✕✕
✕✕
✕✕
0
Ministry of the Interior
✕✕
✕✕✕
✕✕
✕✕✕✕
✕✕
✕✕
0
All 24 agencies·awareness 50 %·rules 27 %·measures 19 %·average 26 %

Grey chips fill in the maximum possible; the red cross marks questions scored zero.

The BPS leads the table with 12 points, followed by Ceibal with 11 and ANCAP with 10. The BCU and UTEC scored 8. Seven agencies scored zero. The MSP responded with a forward-looking approach: It proposed developing an internal policy and conducting a survey, providing little information on the rules or measures in effect at the time of the survey. The Office of the President of the Republic responded outside the form, with a general note that does not clarify what actions it is taking.

Artificial intelligence already has users, providers, and tools within the government. Governance lags behind: The responses show a greater ability to acknowledge its use than to set limits, track data flow, and identify who is accountable for those decisions.

What happens when a file is uploaded to an AI assistant?

Uploading a file to a generative AI service such as ChatCPT or Claude doesn’t imply that it will be made public or that the provider will use it to train a model. But it does mean that content is processed on a third party’s infrastructure. If a file contains personal data or information that is confidential, restricted, or protected by professional secrecy, the agency needs to know who is processing it, where, for how long, and with what level of access.

Training a model involves processing large quantities of examples to adjust the internal parameters and learn patterns that it then uses when generating responses. It does not mean saving every document as a directly searchable file. However, if the provider uses the interaction for training, there is a possibility that the model will memorize fragments of the document and reproduce them in future responses. This is not an automatic consequence nor the expected behavior, but it is a risk recognized by the National Institute of Standards and Technology.

Training and storage are separate issues: A provider may not use the record for training and yet still retain the file, message, or interaction log for a certain period of time.

The Personal Data Protection and Habeas Data Act (N.º 18.331) requires security and confidentiality measures and regulates international transfers. The URCDP, Uruguay’s regulatory body for data protection, recommends that contracts with third-party providers define the parties’ obligations, as well as the location and retention periods.

The terms also vary by account. OpenAI, Anthropic, and Google follow the same model: The content from their personal services—ChatGPT Free/Plus, Claude Free/Pro/Max, Gemini Free/Pro/Ultra—can be used to improve models based on each user’s settings, which is not the default behavior in their enterprise products (API, Business or Enterprise plans, Workspace). Anthropic adds a caveat: even with training disabled, conversations flagged for security reasons or reported as feedback may still be used. Microsoft, for its part, notes that interactions with Copilot under enterprise protection are logged and retained for auditing purposes, though they are not used to train the models. Therefore, the fact that a provider does not train its models using the data does not, by itself, solve the problem: The organization must still monitor which account each user operates under and be able to trace the flow of information.
For more details on this research, see the Amenaza Roboto repository at GitHub. There you will find the methodology and supporting documentation for the article.
Amenaza Roboto