Step 01
Free assessment
A session with the IT department, the business unit and the security lead: which corpora can be used without risk, which data is ruled out from the start, and which use would show a visible effect within the first quarter.

Sector — Public sector
AI in Morocco's public administrations and institutions: citizen services, case processing, public procurement. Law 05-20 and DGSSI framework.
In brief
A Moroccan public administration or institution deploying generative AI must work within a demanding security framework: Law 05-20 on cybersecurity, the national directive led by the DGSSI, and, for a number of entities, the status of a vital-importance infrastructure. In practice, this points towards sovereign hosting. The use cases remain plentiful: citizen reception, case processing, regulatory research and public procurement.
Moroccan public administration holds an asset few companies possess: a vast, structured and public documentary corpus. Statutes, circulars, procedures, administrative case law, instruction files. It also carries a symmetrical handicap: that corpus is hard to navigate, even for its own officers, and citizens give up before they find what they came for.
The Digital Morocco 2030 strategy sets the course — public services that are digital, accessible and efficient. Generative AI is one of its most direct levers: it turns an opaque corpus into a comprehensible answer, in French as well as Arabic. But in the public sector it can only do so under one non-negotiable condition: that you know exactly where the data sits and who can access it. That is the starting point of every public engagement we run, never the conclusion.
Updated 14 July 2026
Sector stakes in Morocco
Law 05-20 on cybersecurity and the framework led by the DGSSI structure the obligations of administrations, public institutions and operators of vital importance: governance of information-system security, system accreditation, control over service providers, and requirements on the localisation and protection of sensitive data. An AI service wired into public information systems does not escape this regime. For entities classified as vitally important the bar is higher still, and in most cases it leads to hosting the processing within a controlled perimeter on national territory.
Two further obligations sit on top of this base, specific to public authority. The protection of citizens' personal data falls under Law 09-08 and the CNDP, with particular sensitivity when files touch civil status, social welfare or health. And above all, accountability: an administrative decision must be reasoned, a reply to a citizen must commit the administration, and an act must be attributable to a named officer. An AI system that produces an answer that is untraced, unsourced and unverified is incompatible with these principles — not because the technology would be poor, but because responsibility itself cannot be delegated to a machine.
Security governance, system accreditation, control over service providers: an AI service connected to public systems falls within this perimeter and must be reviewed accordingly.
Classified entities are subject to reinforced requirements. In practice, this means processing hosted within a controlled national perimeter, with no dependence on an external service.
An administrative decision is reasoned and attributed to an officer. AI prepares, informs and drafts a proposal — it never decides and it signs nothing.
Citizens must be served in Arabic as well as French. A public system that handles only one language excludes part of the very population it is meant to serve.
Use cases
Every use case links to the Hunter BI offer that delivers it. We claim no result figures until they are measured at your organisation.
Sovereignty
Elsewhere, sovereignty is a trade-off. Here it is, more often than not, a prerequisite. An administration that entrusted citizen files, civil-status data or instruction documents to a service hosted beyond its control would hand a third party part of the command the national framework asks it precisely to exercise. This is not about distrust of a vendor: it is about competence — in the legal sense of the word — and about the ability to answer to the supervising authority, the DGSSI or the CNDP.
Open models change the equation. They now make it possible to deploy — on public infrastructure or with a qualified host in Morocco — assistants whose quality is more than enough for administrative work: document search, assisted drafting, file structuring, answers in Arabic and French. The data does not leave, the logs stay with you, and the system can be accredited like any other component of the information system. And the day an officer, a citizen or an audit body asks what the machine did and what it relied on, the answer exists.
Where to start
In the public sector the first project must be beyond reproach: a scope with no personal data, immediate usefulness for officers, and a security case worked out from the very start.
Step 01
A session with the IT department, the business unit and the security lead: which corpora can be used without risk, which data is ruled out from the start, and which use would show a visible effect within the first quarter.
Step 02
Start on texts and procedures that are already public: the usefulness is real, the risk is nil, and the accreditation case is built on a concrete example rather than on assumptions.
Step 03
Once the base is accredited and officers are trained, the scope extends to case processing and internal data, within a sovereign architecture, with supervision and periodic review.
It depends entirely on the data being processed and the status of the entity. For content that is already public, the question is open. For citizen data, instruction documents or sensitive systems — all the more so in an entity of vital importance — the national cybersecurity framework points to controlled hosting on national territory. This analysis is done with your security lead before any tool decision.
It can prepare a draft; it can neither decide nor sign. The reasoning behind a decision commits the administration and its author: it must be checked, completed and owned by an authorised officer. Our public deployments are built to make this step unavoidable, logging who validated what and from which sources.
By testing it, not assuming it. Recent models handle Modern Standard Arabic at a usable level, but quality varies widely by model, domain and register. We evaluate on your own texts and your own citizen questions before recommending a model — a public deployment that fails in Arabic is a deployment that has failed.
By breaking it down. An assessment, then a scoped pilot, then a deployment: this sequence fits public-procurement rules well and avoids committing a substantial budget to an unproven solution. We help technical teams specify what needs specifying — reversibility, localisation, logging, data ownership — without locking the contract to a single vendor.
A free scoping session with a Hunter BI consultant: your data, your regulatory framework, the use cases worth launching first — and the ones better set aside.