← All RFCs
RFC-MA-2026Concept Paper

Request for Comments

Public Infrastructure Framework for Private Agents: An AI Agent for Every Massachusetts Resident

A Concept Paper on Open Civic Agentic Infrastructure

Authors: Santiago Garcés  ·  Gabriela Torres  ·  Ashish Bhatia  ·  Ramesh Raskar

Executive Summary

AI agents present a unique opportunity to simplify the experience of people interacting with complex organizations. Finding information, initiating requests, scheduling, following up — across multiple systems, departments, etc. Agentic systems could save time and frustration, especially for people who already suffer from challenges accessing resources they need to thrive. We need new types of infrastructure that enable the accessibility that comes with agentic systems, without compromising on privacy and individual liberty.

This paper does not claim to have built this infrastructure. It argues that the need for it is urgent, that the building blocks already exist in Massachusetts, and that this Commonwealth, and the City of Boston, home to the first public library, the first subway, the first phone call — is the right place to build it first. We propose not a government-run agent for every citizen, but a public infrastructure layer that guarantees every resident the ability to access their civic life through an AI agent without corporate capture of their most intimate data.

1 — Why This Needs to Exist

AI agents are already interacting with government infrastructure: scraping websites, querying data portals, automating form submissions. That shift is happening whether cities plan for it or not. Two forces are converging that make action urgent now.

First, civic access is still deeply broken. Navigating government services requires time, language fluency, digital literacy, and persistence that many residents, especially those who need services most, simply don't have. A parent of five living in a housing authority, earning $17,000 a year, with no reliable internet, should not have to navigate a dozen portals to schedule after-school programs. They are exactly the person who would benefit most from a convenient, trustworthy AI interface, and exactly the person least likely to be able to afford one privately.

Second, whoever builds the agents will own the data. We lost the data war in the social media era, our photos, locations, and social graphs are now controlled by platforms that extract value from them. Agents will be more intimate than any social media platform. They will know our health, our finances, our family situations, our civic status. If a private platform becomes the universal agent layer for Massachusetts residents, the data generated by the most vulnerable residents will be the most exploited.

“Massachusetts has a narrow window to set the rules of this game before the game sets itself.”

2 — What We Mean — and What We Don't

This is not a proposal for the government to provide an agent for every citizen. That framing would generate justified skepticism: the cost associated with provisioning tools at this scale, the risks to privacy and individual liberty, and the ability to stay competitive with a rapidly changing landscape would all be challenging.

What we are proposing is a public infrastructure layer: a governed, secure, open set of protocols and interfaces that ensures any agent: built by Anthropic, Google, a Boston startup, or a Dorchester neighborhood organization, can interact with civic services in a reliable, privacy-preserving, authenticated way, and that every resident has access to this layer regardless of whether they can afford a $40/month AI subscription.

The right framing, as Boston's CIO has put it, is the right to access civic services through an AI agent without corporate capture. The government's role is to be the rule-setter and infrastructure provider — not the monopolist, not the product.

3 — A Motivating Use Case: Maria

Maria is a Portuguese-speaking mother of three in East Boston. She wants to open a food truck. She earns just enough that she cannot afford a premium AI subscription, but she has a smartphone and an email address.

She asks her agent — accessed through a free public interface, or through whatever AI tool she uses — “O que preciso para abrir um food truck em Boston?” [What do I need to open a food truck in Boston?]

Her agent authenticates through Boston Home (the city's OAuth provider), queries the Open Data MCP server, identifies the Active Food Establishment Licenses and Building Permits datasets, discovers that property_id links them, estimates the inspections typically required for her business type, pre-fills the relevant forms, tracks her application status, and alerts her to renewal deadlines. All in Portuguese. All without Maria needing to know which department handles which permit, or what SQL is.

Without this infrastructure, this journey takes weeks of phone calls. With it, an afternoon. The agent doesn't make the decision for her — it removes the friction that has always made civic participation a privilege of the time-rich.

4 — The Core Problem: Who Owns the Agent Owns the Data

In the social media era, we didn't fully understand that the platform that hosts your social graph owns your social graph. By the time we understood it, it was too late.

Agents will be more intimate. They will mediate our relationship with our government, our employers, our healthcare providers, our schools. The platform that runs your agent will know more about you than any social network ever did; it will synthesize your personal and external data for you, will recommend you different decision paths as well as act on your behalf either autonomously or in a delegated fashion.

Three risks follow directly:

Data capture

The past is a good indicator of the future: AI platforms have already sucked up all publicly available data to train their frontier models. They will continue to look for more differentiated data to build future intelligence. If a private platform becomes the universal agent layer, residents' civic data — benefits status, permit history, service requests, health interactions — becomes proprietary training data and a commercial asset.

Walled gardens

If the dominant agent platform doesn't interoperate with government systems, residents face a forced choice between civic access and platform loyalty. Portability — the ability to change your LLM provider, your cloud provider, your agent interface, without losing access to your civic life — must be a guaranteed right, not a feature.

Equity inversion

Free agent services will monetize data and usage patterns. Paid services will protect privacy. This means the poorest residents, who most need AI assistance with complex civic navigation, will be the most exposed. Privacy must be a right, not a luxury — and government has both the motivation and the purchasing power to buy it for those who cannot.

5 — What's Already Being Built

Massachusetts is further ahead than most places realize. Several building blocks are already in place or in active development:

Boston's Open Context MCP Server

To Boston's knowledge, the first public MCP server built by a city government, connected to the open data portal. Already open-source. Any city can deploy it. A CIO in Anchorage, Alaska is already querying Boston's live data because the server is publicly accessible.

Boston Home

A city-level OAuth identity provider, currently in development, that will allow federated authentication — a resident's MIT email, Google account, or city-issued credential can all authenticate with the same city infrastructure. This is the foundation for delegating access to agents.

my.mass.gov

The state-level identity verification layer, more focused on benefits-level verification than the city's non-repudiation approach, but potentially federable with Boston Home into a unified Commonwealth identity layer.

City of Boston Data Commons

Emerging infrastructure for unlocking datasets, providing training resources, and exchanging computing credits — the foundation for a sovereign AI resource layer that doesn't depend entirely on private cloud providers.

Neighborhood Agent in Dorchester

A community-built agent using retrieval-augmented generation over community meeting notes — a grassroots demonstration that the demand exists and the tools are accessible.

Nanda at MIT Media Lab

Research on agentic coordination protocols, citizen-scale agent architecture, and the governance frameworks required — now applied to India's national citizen agent project and directly informing this effort.

6 — The Architecture We're Proposing

This is not a finished blueprint. It is a proposed direction for working groups to develop. The core insight is that most of the infrastructure already exists — what is missing is the middle layer that connects it.

6.1 The Four Layers of the Agent Ecosystem

Drawing from national agent architecture proposed by Nanda and adapting for Massachusetts:

Layer 1 — Government / City Agents

Authenticated MCP servers representing city and state departments. High authentication and security requirements. Boston's Open Context is Layer 1.

Layer 2 — Business / Institutional Agents

Agents representing MBTA, hospitals, universities, insurers, employers. Must be certified ("Know Your Agent" — KYA) by city or state authority. Fraudulent impersonation of MBTA or a housing authority is a real threat; certification is the defense.

Layer 3 — Resident Agents

Personal agents acting on behalf of individual residents. Delegated access from the resident's identity. Multiple agents allowed; portability guaranteed. Any provider can build them as long as they comply with the civic interface protocols.

Layer 4 — Unregulated Layer

Innovation space. Someone wants to build a Red Sox agent or a neighborhood restaurant guide agent? Fine. No certification required because no civic authority is claimed. This is where the ecosystem breathes.

The government's role is to define and enforce the protocols that govern Layers 1–3, and to stay entirely out of Layer 4.

6.2 Identity as 80% of the Solution

The single most important thing Massachusetts can do is solve identity. OAuth plus a verified email address solves 80–90% of the authentication challenge. Boston Home, federated with my.mass.gov, establishes the foundation: the government asserts that this agent is acting for this resident, for this purpose, within this scope — without needing to run the agent or know what the agent is doing beyond which tools it called.

The key architectural question now being explored in Boston: should agents have their own independent identity (like separate email addresses, with narrowly scoped permissions), or only delegated access from the resident's credential? Independent agent identities offer better security through smaller attack surfaces. Delegated access is simpler. Both approaches need further design — this is a working group question.

Government already has a construct for this: delegated acts. Only certain people can update a vendor's bank information. Only a licensed architect can pull certain permits. Extending this logic to digital agents acting on behalf of residents is a natural evolution of existing infrastructure, not a new invention.

6.3 MCP as the Governed Interface

An MCP server does not require the city to run the agent or know what the resident is asking. It only exposes which tool was called and what was returned. This is the minimal viable privacy surface: the city provides a governed, monitored, secure interface to civic data and services, without surveilling the resident's intent or conversation.

This resolves the core tension: the government needs to know that legitimate agents are accessing legitimate services. It does not need to know why.

6.4 The Evolution of City-Resident Interfaces

Phase 1 (Now)

Read-only access to public resources — open data, city websites, service information.

Phase 2 (Near-term)

Agents can submit information to the city — service requests, permit applications, form submissions.

Phase 3 (Future)

Full AI-to-AI orchestration — city systems and external tools coordinate autonomously on behalf of residents, with human confirmation for high-stakes actions.

Boston is building Phase 1 now and designing for Phase 2. Phase 3 requires governance and trust infrastructure that doesn't yet exist — but designing for it today avoids rebuilding everything tomorrow.

6.5 The Full Stack

Residents access civic life through two parallel interfaces: human interfaces (web apps, mobile apps, portals) and AI agentic interfaces (MCP services). Both sit above a shared digital public infrastructure layer — identity (Boston Home / my.mass.gov), payments, enterprise data products, documents, AI-powered translation. That layer rests on core government applications: permitting, CRM, benefits, 311.

The agentic interface is a new front door to infrastructure the Commonwealth already operates and owns.

7 — What Is In Scope — and What Is Not

In Scope

Civic services. The things government already provides — permits, benefits, service requests, public records, program enrollment, scheduling, transportation information, vital records, housing services. The goal is to make these things as easy to access through an agent as they are for someone who has time, language fluency, and digital literacy.

Out of Scope

Everything else. Entertainment, food, shopping, personal finance, social life. The private market will build agents for those things, and will likely build them better than any government-adjacent project ever could. Mission creep — a civic agent that becomes a general-purpose life assistant — is a governance and trust failure waiting to happen.

The discipline of staying close to civic services is what makes this trustworthy, fundable, and politically viable.

8 — Equity: Privacy as a Right, Not a Luxury

Today, if you use a free AI service, you are the product. Your conversations train the model. If you can afford $40/month, your data is private. This is not an acceptable structure for civic infrastructure.

Boston is already acting on this: providing free broadband to every housing authority and bus resident. The same logic extends to AI. For residents who make $17,000 a year and interact with government through publicly-funded services, the government has both the motivation and the purchasing power to buy their privacy — to procure AI access on terms that protect their data rather than monetize it.

“This is not charity. It is the same logic that produced public libraries, public schools, and public broadband: some infrastructure is too important to leave entirely to market pricing.”

The AI skills gap is the other equity dimension. MassTech's workforce development work — including the proposed living guide to AI skills that updates dynamically as the job market shifts — is essential context. Access to the infrastructure is necessary but not sufficient; residents also need the confidence and capability to use it.

9 — Why It Must Remain Open: No Walled Gardens

The single most important architectural principle is portability. A resident's civic identity, their agent history, their delegated permissions — none of these should be locked to a specific AI provider, cloud platform, or application store.

If Google releases an agent that works brilliantly with Boston's MCP layer, residents should be able to use it. If a better option emerges six months later, they should be able to switch without losing anything. The protocol is public. The infrastructure is public. The agent is the resident's.

This means: open standards for agent-to-government interaction; no exclusive contracts that give one provider privileged access to government MCP servers; and a governance body that maintains the protocol stack as a public good, not a vendor product.

The comparison to payments is exact: UPI in India works because the protocol is public and any compliant application can use it. BHIM (the government reference implementation) establishes the baseline and proves it works. Private players build on top. No one owns the rails.

10 — Other Efforts Around the World

India's Doot / Agent One

A national-scale architecture giving every citizen a personal AI agent built on Aadhaar, DigiLocker, and UPI. The same MIT team working on this Massachusetts effort participated in the design of the Indian framework. Key lessons: trust infrastructure must be designed before the agent is deployed; governance requires a body analogous to NPCI for UPI; equity requires edge-first compute for low-connectivity populations.

City of Milan

Currently developing a comparable civic agent layer, with ProjectNANDA team's collaboration beginning.

Australia, Caribbean Nations

Active government explorations of citizen agent infrastructure, each motivated by the same dual concern: improve civic service delivery, and prevent private platform capture of citizen data.

Estonia's Proactive Services Model

Government initiates contact when residents become eligible for services, rather than waiting for residents to navigate to them — the logical endpoint of the agentic vision, where the agent doesn't just answer questions but surfaces entitlements proactively.

Dorchester Neighborhood Agent

Already being built, using retrieval-augmented generation over community meeting notes to answer neighborhood-specific civic questions. A grassroots proof-of-concept for what's possible with minimal infrastructure.

Massachusetts is not behind. It is at the frontier — and it has the academic institutions, the government will, and the civic culture to set the standard others follow.

11 — Open Questions and Working Groups

This paper does not resolve these questions. It proposes that working groups be formed to develop answers over the next twelve months.

Working Group 1

Identity & Authentication

What does the schema for a civic agent identity look like? Should agents have independent identities or delegated access? How does Boston Home federate with my.mass.gov? What attributes — preferred language, service scope, delegated permissions — should be portable across providers?

Working Group 2

Civic Services Interface

What services should be exposed through MCP in Phase 2 (submission, not just read)? What are the security and liability requirements for each service category? How do we handle non-determinism and cascading failures when agents interact with deterministic government systems?

Working Group 3

Equity, Privacy & Access

How does the Commonwealth use its procurement power to buy privacy for residents who cannot afford it? What is the public option for AI access — and what should it cover? How does the workforce development living guide stay current as AI transforms the labor market?

Working Group 4

Governance & Policy

What body governs the civic agent protocol stack? What is KYA (Know Your Agent) certification, who issues it, and what does it require? How do we handle adversarial agents, fraudulent impersonation, and the deepfake threat to civic services?

12 — Conclusion

Every Massachusetts resident will have an AI agent. The only question is whether that agent will be built on open infrastructure they control, or proprietary infrastructure that controls them.

Boston has already built the first piece. Nanda at MIT Media Lab has mapped the architecture. MassTech is building the data layer. The identity infrastructure is under development. The governance conversation is starting now.

We are not at the beginning of a long road. We are at the moment when the road forks — and the choice we make in the next eighteen months will determine which path Massachusetts, and the cities and states watching it, will follow.

Boston has done this before. The first public library. The first subway. The first phone call. Not because someone had a complete plan, but because someone decided the need was real enough to start.

“The need is real.”

About the Contributors

Santiago Garcés is the Chief Information Officer for the City of Boston. He focuses on deploying generative AI in city operations, writing some of the first municipal AI guidelines in the U.S.

Gabriela Torres is the Director of AI Innovation Ecosystem Development at Mass Tech, a role under the Massachusetts Tech Collaborative, where she helps integrate the state's AI innovation ecosystem.

Ashish Bhatia is a Product Manager with 23 years of experience in Product and AI Solutions at Microsoft and Amazon.

Ramesh Raskar is an Associate Professor at MIT and the founding architect of ProjectNANDA, pioneering research at the intersection of machine learning and agentic web infrastructure.

This concept paper was developed collaboratively by the City of Boston, Nanda Research team at MIT Media Lab, Foundation for Agentic Networks (FAN) that hosts the open source repositories for ProjectNANDA, MassTech AI Hub, and members of the Massachusetts civic technology community. It is a living document. Comments, contributions, and working group interest can be directed to: OET@boston.gov (Office of Emerging Technologies for Boston).

Use Cases

  • Parking permit for a Macy's furniture delivery
  • Zillow helps you register for a homestead exemption