From scattered experimentation to strategic adoption: what Europe tells us about generative AI in the public sector

Generative artificial intelligence (generative AI or GenAI) has already entered European public administrations. Not in an orderly and planned way, but often through informal practices: public servants using commercial tools to write, summarize, translate or program, often without formal approval or established guidelines. This phenomenon, which the report calls “shadow use or shadow AI" is today one of the most relevant governance challenges in the public sector.

The Joint Research Centre (JRC) of the European Commission has just published the report «The adoption of Generative AI in EU public administrations: exploring individual behaviors and organizational approaches» (Mikalef, Medaglia, Tangi and Rodriguez Müller, 2026), one of the thineres structured analyses of how generative AI is being adopted in European administrations. The study is based on the analysis of eight case studies built from 31 interviews with managers and experts from seven countries and the European Commission itself. Catalonia appears as one of the cases and the director of the AOC, Miquel Estapé, was one of the people interviewed.

Two complementary perspectives

The report analyzes the adoption of generative AI from two mutually influencing perspectives:

  • Individual use: how public servants perceive and use these tools in their day to day lives.
  • Organizational assimilation: how administrations decide to make technology accessible, govern it and integrate it into their processes.

Two administrations can choose the same assimilation model and, nevertheless, their teams use the same management tools.eres very different. That's why we need to look at both dimensions at the same time.

On an individual scale: three persistent tensions

Based on the interviews, the report identifies three tensions that run through the way public staff interpret generative AI:

  1. Empowerment and dependence. Generative AI is seen as a cognitive assistant that increases productivity and facilitates access to knowledge. At the same time, concerns about over-reliance, skill erosion and loss of analytical depth are emerging. One interviewee summed it up frankly: he admits to having become more dependent on the tool than he would like to admit.
  2. Innovation and control. It is adopted to gain efficiency and improve decision-making, but implementation clashes with governance requirements, risk management and organizational inertia. There is often a gap between expectations and the value actually perceived in practice.
  3. Exploration and regulation. Staff explore new tools that promise efficiency and creativity, but operate within strict frameworks of data protection and accountability. The result is a continuous negotiation between experimentation and compliance.

It is particularly relevant to note that, when internal tools are not intuitive or functional enough, staff tend to resort to external commercial tools, with the implications this has for data protection, security and regulatory compliance.

A four-stage maturity model

One of the most useful contributions of the report is a four-stage model of value creation, designed as a strategic tool rather than a linear path that everyone must follow to the end:

  • Exploratory see the potential. Ad hoc, individual use, with commercial tools and simple tasks. The main value is awareness.
  • Service structure use and generate trust. Safe environments, training and usage guidelines are introduced. The value is efficiency in routine tasks.
  • transformer redesign work and services. Generative AI is integrated into workflows and systems (RAG, agents). The value is the increased capabilities for complex tasks.
  • reflective institutional learning and integration into the ecosystem. The administration systematically evaluates its use, with feedback loops and adaptive governance.

The report is clear on one important point: Not all administrations, nor all units within the same administration, must reach the final stage. Each organization can choose the assimilation strategy according to its infrastructure, its competencies, the sensitivity of the data and the nature of its tasks.

Catalonia, among the reference administrations

The report describes Catalonia as one of the most digitally advanced European regionsIt highlights that it has created data platforms, algorithmic governance frameworks and inter-administrative platforms that support a responsible approach to AI for both public services and the economy.

The study also highlights pilot projects aimed at internal secure generative AI environments and sandboxes deployed with strict safeguards that ensure compliance with the GDPR, the national AI guide and the European AI Regulation, while improving the mechanisms for cataloguing, quality and risk classification of algorithmic systems. In the words of the report, this work demonstrates Catalonia's ambition to combine rapid experimentation with robust organizational and regulatory safeguards.

Three areas for action

The report closes with a set of operational recommendations grouped into three priority areas:

  1. Building an interoperable generative AI infrastructure. Establish secure environments by design, easy to use and compatible with European regulations, and develop shared frameworks for data governance and reliable documentary corpora.
  2. Strengthen governance and operational preparedness. Institutionalize AI governance bodies, standardize integration frameworks in workflows, and introduce training programs that keep human oversight and judgment at the center.
  3. Accelerate the creation of public value and innovation. Prioritize high-value use cases through structured pilots in environments with graduated risk levels, and promote collaboration between administrations by sharing prompts, templates, governance models, and evaluation results.

What does this mean for the Catalan administration?

Many of the report's recommendations connect directly with the raison d'être of a consortium like the AOC: provide shared digital infrastructure and services that avoid duplication of efforts and allow smaller administrations to access capabilities that they would be unlikely to develop on their own.

The report precisely points out that an approach supraorganizational of data governance can foster interoperability, ensure consistency between systems, and facilitate the deployment of AI assistants across administrations without having to rebuild the underlying data pipelines each time. It also points out that centralized models at regional or national levels can reduce technical duplication and democratize access to quality AI capabilities, suggesting that a hybrid, multi-level governance model may be most appropriate.

This is, to a large extent, the conversation we have ahead of us: how we move from scattered experimentation, and shadow use that is difficult to govern, towards a strategic, safe and sovereign assimilation of generative AI, aligned with public values ​​and the European regulatory framework.

A final reflection

The report's basic conclusion is that The success of generative AI adoption depends not so much on technological availability as on the ability to align individual practices with organizational structures. Bridging this gap is what will allow generative AI to provide sustainable public value, while maintaining trust, accountability and institutional consistency.


Full report: Mikalef, P., Medaglia, R., Tangi, L. and Rodriguez Müller, AP (2026), The adoption of Generative AI in EU public administrations: exploring individual behaviors and organizational approaches, Publications Office of the European Union, Luxembourg.

Available at: JRC Publications Repository (JRC147095)

Published in