To the content

Agentic AI Enterprise Platform for Controlled and Secure AI Agent Operations

Challenge
NEU
Current phase
Ends on: 03.12.2026
  1. Call and submissions
    Current phase: 25.08.2026 - 03.12.2026
  2. Queries begins on 04.12.2026
  3. Jury evaluation begins on 07.12.2026
  4. Announcement of the winners from 04.01.2027
Online since 24.08.2026

Challenge

Austro Control GmbH (ACG) operates in a safety-critical environment with high demands on reliability, traceability, data protection and compliance. At the same time, relevant project, technical and company knowledge is distributed in different filings and work contexts and is therefore not always immediately available for decisions, coordination and operational activities. This makes collaboration and the consistent use of existing knowledge more difficult. At the same time, the need for AI-supported automation is growing in the specialist departments.

The challenge is to use an AI-supported enterprise platform in such a way that it makes knowledge usable, supports complex workflows and relieves employees without compromising data protection, information security, data sovereignty or traceability. In particular, this requires controlled handling of sensitive company and personal data when using external AI models or cloud-based components. What is needed is a trusted, long-term platform that meets the needs of enterprise operations and avoids siloed point solutions and uncontrolled shadow environments.

The market for AI is developing very dynamically and is very fragmented. The company is therefore looking for a holistic solution for agentic AI for a safety-critical enterprise environment that

  • enables the organization-wide deployment of AI agents,
  • supports clear roles and approval processes (human in the loop),
  • allows secure integration into existing systems,
  • ensures traceable control of the agents,
  • protects sensitive data,
  • is sufficiently scalable for different application areas.

The following exemplary use cases illustrate the range of possible challenges and the requirements that develop from them. A solution does not have to cover the cases presented in full. However, providers should explain which use cases can be implemented with their solution and which extensions would be required for this.

Use Case 1: Support of internal IT support
An AI agent supports ACG's internal IT support in processing requests from different areas of the company. New enquiries are received via the ticket system or by e-mail. The agent classifies the request and researches additional information in the digital work environment, in technical documentation, in system and operational information as well as in support cases that have already been resolved. The data required for this is distributed in structured ticket data, e-mails, office documents, wiki pages and technical logs and is subject to different access authorizations. The agent summarizes the facts, recognizes missing information, compares possible solutions with existing documentation and previous cases and adds to the ticket. In the case of security-critical systems, user accounts or authorizations, he only creates a comprehensible proposal for action. Changes are only made after review and approval by authorized IT employees. Sources used, processing steps and approvals are logged in full.

Use Case 2: Review and Preparation of Incoming Invoices
An AI agent helps ACG process incoming invoices. Invoices arrive by e-mail or via a central document repository. The agent reads relevant information, compares it with purchase orders, contracts, and supplier data, and assigns the invoice to the responsible organizational unit or cost center. The required information is distributed in PDF files, e-mails, ERP or accounting systems, contract documents and approval workflows and is subject to different access authorizations.
The agent detects missing or contradictory information, marks deviations and prepares the invoice for technical and commercial review. He forwards any queries or necessary approvals to the responsible employees. He does not carry out bookings, master data changes or payments independently, but only after checking and approval by authorized persons. Sources used, check steps, deviations and approvals are logged in full.

Use Case 3: Planning and Documentation of Technical Infrastructure
An AI agent supports ACG in the planning, documentation and further development of technical infrastructures. Relevant information about systems, networks, components and their dependencies is managed in a central system database (single source of truth). Supplementary data is available in technical documentation, ticket systems, project documents and other specialist applications. The systems are connected to each other via interfaces and are subject to different access and security requirements. Employees describe their concerns in natural language, such as planning an infrastructure change, expanding a system, or analyzing technical dependencies. The agent interprets the request, retrieves the necessary information from the connected systems and translates the input into the appropriate data structures, processes and workflows. In doing so, it takes into account technical standards, architectural specifications, role models as well as existing release and governance processes. The agent creates proposed actions, documentation, or change requests and merges information from different data sources. Changes to productive or safety-critical systems are only carried out after testing and approval by authorized employees. Data sources used, processing steps and approvals are fully logged and documented in a comprehensible manner. In addition, there can be work steps where defined changes can be carried out by the AI agent without further ado – but of course only with Human in the loop.

Question

How can an existing or market-oriented enterprise solution for agentic AI be adapted and deployed to meet the requirements of the ACG in a secure, scalable and governance-compliant manner?

Desired result

The goal is the secure, scalable and rule-compliant use of agentic AI in everyday work. The challenge is intended to identify suitable central enterprise platforms for AI agents. To classify the initial situation and as a basis for the preparation of the submissions, ACG provides relevant framework information:

  • Existing system landscape and relevant applications: ACG's existing IT and system landscape includes Microsoft-based work environments, document and information management systems, security and monitoring solutions, and specialized specialist applications. The applications are provided both cloud-based and on-premise. Information on systems, networks, infrastructure components and their dependencies is partly managed via central technical data platforms (as a single source of truth). In addition, there are guidelines and governance requirements for the use of AI systems and the use of company data.
  • Available computing and infrastructure resources: Preference is given to operating models that meet high requirements for information security, data protection and data sovereignty. Both on-premise approaches and hosted solutions within the EU or EEA are generally possible with ACG.
  • Volume of documents and data to be processed: Organization-wide deployment and a variety of different use cases, workflows, and AI agents. It can be assumed that the database and documents will grow continuously. The platform is said to be scalable in the long term in terms of data volume, number of users and number of parallel agent processes.
  • Type of documents and data to be processed: Support common corporate and office formats and, in the future, also enable the integration of specialized technical data formats. The information to be processed can come from documents, knowledge databases, e-mails, ticket systems, business applications, infrastructure and operational data, and other structured and unstructured data sources. The main working languages are German and English
  • Expected number of users: The solution will initially be designed for up to 500 users and support different role, authorization and governance concepts. At the same time, it is intended to enable a later expansion to additional specialist areas and use cases.
  • Integration requirements: Standardized and secure interfaces to existing company, information, security and specialist systems. The solution should make data and functions usable in a controlled manner, be able to integrate different AI models and support traceable logging and auditability of all relevant agent activities.

The focus is on the integration of a suitable solution into a complex, security-critical IT and system landscape. This includes high-availability enterprise systems, Microsoft-based work environments, document and information management systems, and solutions for monitoring, security, and compliance (see above). The platform must therefore be able to be integrated into existing internal and external systems via secure and standardized interfaces and meet particularly high requirements for availability, information security and regulatory compliance.

The platform is intended to enable the traceable and compliant use of AI agents over their entire life cycle – from the identification of suitable use cases to implementation and operation to governance and further development. Secure interfaces are intended to make company data usable in a controlled and contextual manner. Employees should be able to configure agents using natural language and use them across departments in operational, administrative or customer-related scenarios. This allows repetitive or time-consuming processes to be supported or automated, and contextual help can be provided directly in the work process.

We are looking for available or market-oriented enterprise platforms and technical components that can be adapted and integrated to the requirements of the ACG. Modular or hybrid approaches are possible as long as they are based on a demonstrable technical basis and the provider is responsible for configuration, further development and integration. A complete in-house development by ACG is not planned. The solution should already cover essential requirements and be able to be transferred to pilot operation quickly and in a structured manner through configuration, standardized extensions or targeted adjustments. Supplementary architectural and implementation proposals are welcome if they are linked to a concrete technical solution; purely generic concepts or consulting services without a testable solution module are excluded. The level of maturity, reference implementations, the need for adaptation and the effort required for pilot operation must be presented in a comprehensible manner.

Core requirements for submitted solutions:

  • Orchestration and coordination of multiple AI agents by agents along defined roles, workflows, and approval processes
  • Flexible integration of different AI models and providers to limit technical and economic dependencies
  • Policy-based inspection and release or block inputs, contextual information, and agent results prior to further processing by an AI model; the control authority should be able to be connected to existing data loss prevention and other security systems
  • GDPR-compliant processing of personal and sensitive data and consideration of the EU AI Regulation
  • Role-based access control and connection to existing authorization concepts
  • Protection against uncontrolled reuse of inputs, documents, prompts or metadata
  • Traceable information on data processing, storage location and data flows (logging and auditability of agent activities)
  • Human release and control points for critical agent actions
  • Ability to integrate with existing enterprise and security systems

Desirable features:

  • Preferred solutions: On-premise, private cloud, and EU/EEA-based operating models
  • Scalability to multiple disciplines and use cases
  • Multi-client capability or differentiated use by different organizational units
  • Low-code/no-code configuration of agents by business units
  • Accessibility according to EN 301 549 and WCAG
  • Existing compliance or security credentials, e.g. B. ISO 27001, SOC 2, or equivalent evidence
  • Local emergency operation or defined fallback mechanisms
  • Monitoring, versioning, and lifecycle management for agents and workflows

Non-goals:

  • Isolated or purely application-specific individual solutions without platform character, extensibility and organization-wide scalability
  • Chatbot-only or assistance solutions without agentic workflow functionality
  • Pure consulting activities without a concrete technical solution approach
  • Solutions without secure, standardized integration options for existing enterprise and security systems
  • Solutions that require a complete in-house development or the permanent development of essential platform functions by ACG

The points mentioned describe possible solution directions and framework conditions, but do not represent a binding technical or architectural requirement. The submission must explain in a comprehensible manner which points the solution already fulfils and how the others can be achieved.

Call for submissions

Present your approach to the secure and scalable use of agentic AI. The focus is on market-oriented solutions, testable platform components or resilient architectural approaches for cross-system workflows in which AI agents securely merge and process information from heterogeneous sources and prepare or execute further steps within defined roles and releases. IMPORTANT: The challenge is intended to explore the market; the points mentioned are for orientation and evaluation purposes and do not constitute a conclusive technical specification.

Description:
Submit a brief description of your approach to the solution. In particular, describe the technical architecture, security and data protection concept, integration capability, governance mechanisms, possible use cases, as well as operation and further development. Clearly explain which components of your solution are already available as standard, what configurations or customizations would be required for ACG, and what services would need to be provided by the vendor, implementation partner, or ACG. In addition, describe how updating, operation, maintenance and further development can be organized in the long term.Be transparent about the one-time, ongoing, and/or usage-based costs of your solution. In particular, consider implementation, integration, operation, licenses, maintenance, support, computing power, and the use of AI models. Explain the cost development as usage increases, the scope of standard and custom components, and the flexibility to switch AI models or vendors. Where concrete quantity structures are missing, comprehensible assumptions, cost scales or example scenarios must be used. Please prepare the costs in a form that is comprehensible for management decisions and not exclusively on the basis of technical key figures, such as tokens. Give examples of the costs incurred for typical use cases or workflows and the measures envisaged to optimize costs. In addition, we ask for a brief assessment of the expected benefit, for example through time savings, increased efficiency or quality improvements. In addition, references, pilot examples or a proposal for a first pilot project can be cited. Optionally, the article can use this or a comparable example process to illustrate how AI agents can structure, accelerate and securely support complex processes.

Summary of added value:
Get to the heart of decisive advantages! What makes your solution particularly innovative? What distinguishes them? Application examples, references and a realistic project process help with the evaluation.
Optionally, you can also attach a file. This file is intended to complement the texts of the form fields, but not to replace and repeat! Use the file attachment, e.g. for graphics.

Confidential information (only for project managers):
This information can be submitted confidentially via the platform. In this text field, you can enter further information that you want to share exclusively with the project owners. Alternatively, it is possible to send a PDF by e-mail to the moderators of the challenge.

IMPORTANT NOTE: Submissions in the consortium (e.g. AI provider, IT security provider and integrator) are possible. Keep it short (guideline: maximum 10-12 presentation slides or 4-5 A4 pages). We are exploring the market with the challenge. It is therefore not necessary to prepare designs or feasibility studies specially prepared for this occasion.

The deadline for submissions is December 4, 2026, at 11:59 p.m.!

Benefits of the challenge and further project development

With this challenge, Austro Control gets an overview of solutions and potential partners. For companies, this means that participation in the challenge puts you on the radar of the public contracting authority. Your submission will remain visible as your business card for other interested parties even after the challenge has ended. They are positioning themselves for further public sector purchasing projects.

This creates sensitivity and understanding on the part of the public client for suitable innovations. This is important so that the public contracting authority can take innovative approaches into account in any purchasing project under the Federal Procurement Act after the market survey.

Notice of the sponsor under public procurement law:
It is stated that Austro Control, as a public contracting authority, is subject to the Federal Procurement Act. The market survey in question expressly does not constitute a procurement transaction within the meaning of the BVergG in the current version, but is intended as a form of an IÖB market survey merely as a preliminary stage for future procurement under the application of any internal procurement guidelines and the BVergG.

As part of this market exploration, Austro Control would like to get to know new solutions in order to be able to take innovative approaches into account in future projects. Participation in this process does not give rise to a legal entitlement to participate in further awarding/procurement processes.

Do you have the right solution?
Then submit!

Questions about the challenge

Any questions? Post it! The moderator will check, research and publish your question together with the answer. This way, all possible participants receive the same information.

Strong partners stand behind the Austrian Competence Centre for Innovation Procurement

An initiative of:

In cooperation with:

Cookies

We use cookies to make sure we give you the best experience on our website.

Find out more under "Collection of access data, log files and cookies" in our Privacy Policy.

To the main navigation