Skip to content

Every agency wants the same thing right now: a helpful, always-on AI assistant the public can use. The hesitation is never about whether generative AI is useful. It’s about trust. Can we put a chatbot in front of citizens without leaking sensitive data, inventing answers, or creating a compliance problem no one can defend in an audit?

That hesitation just became more urgent. With Amazon Q Business closing to new customers after July 30, 2026, teams that were counting on a quick managed chatbot need a new path. One that doesn’t trade speed for control. AWS has recommended Amazon Quick as the successor for many enterprise scenarios, but agencies building public-facing assistants with anonymous access and custom integrations require a different conversation.

That distinction matters. Public AI assistants introduce unique requirements that go beyond simply replacing one chatbot with another. Citizens shouldn’t need to log in. Sensitive information must be protected before it reaches the model. Every response should be grounded in approved agency content and traceable to its source. And the entire solution needs to operate within an agency’s authorized security boundary while standing up to security, privacy, and audit scrutiny.

The good news is that the pattern that holds up in federal environments is already well understood. We call it Federal-Safe AI, and it’s a public GenAI assistant that runs inside an agency’s authorized security boundary. 

The Pattern, in Plain Terms 

The design principle is simple: the model comes to the data and the data never leaves.

In practical terms: 

  • Simple public access. A lightweight web widget the public can use without needing to login, with rate limiting to keep automated abuse out.
  • Sensitive data is protected in both directions. The knowledge base holds only approved public content, but members of the public routinely type things into a chat box that an agency never asked for, including personal and health information. Before anything reaches the model, personal (PII) and health information (PHI) are masked and every interaction is audit-logged.
  • The AI stays inside the authorized environment. The assistant runs on Amazon Bedrock, Amazon’s managed AI service, within a FedRAMP Certified, Class C (Moderate) cloud environment. It answers questions using only agency-approved content rather than information from the open internet. Built-in guardrails help keep responses accurate, appropriate, and on topic, while agency data never leaves the authorized security boundary.
  • Every answer points back to a real source. The assistant answers from vetted source material and shows its work, rather than generating open-ended text on its own.

The result is an assistant that reads only what it should, answers only from what it’s given, and keeps every byte in-boundary with no data egress. 

Questions Every Agency Should Ask 

The questions an Information System Security Officer (ISSO) or an Inspector General (IG) will ask are predictable and this pattern answers them before they’re asked: 

  • Where does the data go? Nowhere. It stays in-boundary, with no egress.
  • Can it leak PII/PHI? Masking on the way in, guardrails on the way out, logging throughout.
  • Can it hallucinate? Answers are grounded in a curated knowledge base and cited.
  • Is it authorized-ready? It rides an existing FedRAMP Certified, Class C (Moderate) service footprint rather than inventing a new one.

That’s the difference between a demo and something an agency can put in production. 

Start Small. Learn Fast. 

Agencies don’t need a year-long program to prove this. A Phase-1 pilot can stand up in a contractor-owned cloud account, reading only public content, decoupled from the credentialing and integration steps that slow everything down. That lets a team show a working, in-boundary assistant while the government-side items clear in parallel. Momentum without cutting corners. 

The Takeaway 

As the managed-chatbot landscape shifts, the agencies that win won’t be the ones who move first. They’ll be the ones who can show a public assistant that’s grounded, guard railed, and fully in-boundary. 

RIVA is already applying these principles across federal civilian programs, helping agencies build secure AI capabilities while protecting the AI artifacts that power them, including prompt files, MCP server configurations, and agent instruction files. It’s practical experience that informs how we design, deploy, and govern AI for government.

 At RIVA, we help agencies deploy AI they can trustsecure, governed, explainable, and designed for long-term mission success. 

If you’d like to talk through what this looks like for your agency, reach out to Moe Chizari, Director of AI Practice, at mchizari@rivasolutionsinc.com