ENSI — European Nexus for Strategic Intelligence. The principles of civic value; the companion piece “Eight Plays for the Civic Apps” turns them into action.
It is the middle of the night and a system fails — one that thousands of town halls quietly depend on to register births, issue permits and pay benefits. Somewhere a crisis coordinator is woken up and asked three questions: what depends on this system, who is affected, and who is responsible for fixing it? Today the honest answer to all three is we don’t know yet. The knowledge exists, scattered across registers, contracts and the heads of people who are asleep. Nobody has ever assembled it into something a person can look at.
Now picture the same coordinator opening a map of the state, switching off the failed system and watching the cascade spread across towns, services and people — with the responsible authorities named and the latest signals flowing in. Nothing in that picture is science fiction. The software to draw it was built by a very small team in a few weeks. What is missing is not the code. It is the data that only the state holds, the office that would own the tool, and the permission to use it when it matters.
That gap — between what a very small team can now build for the public and what actually reaches the public — is the subject of this piece. The working apps have already proven the leverage: a governed sales workforce, a voice agent that makes the calls, a video editor that cuts by meaning, a research engine that writes audited reports. A studio of one or two people now ships what used to take a company.
The civic apps are where that leverage should matter most: a state you can see through, claims you can check, public argument you can follow, priorities you can weigh, charters for how AI must treat people, knowledge in languages the market ignores. They are also exactly the apps that stall. Not because they are harder to build — the same hands built both — but because they need things code cannot produce: data the state holds, a mandate from someone who will use them, a publisher who signs, an audience, and money that does not come from the people they serve.
The civic apps in this body of work cover the whole range. Mapa státu makes the Czech administration a graph anyone can question, and the Resilience map shows what falls when one system fails. Lhari verifies public claims on a strict budget, DemocracyWatch measures democratic health and ends every measurement in an action, Bohemie measures what goes right in the country as well as what goes wrong, and Future of Politics finds the decisive issues no institution owns. MeetViz and Noeverse turn long public argument into cited maps, while the ENSI research engine and Hyperthesis produce audited evidence on any question. Hard Frontier and Climate Lab rank where talent and money would do the most good. Aether and the Agent-Driven Meetup form the people who will build and steward all of this, audhd.cz carries health literacy into Czech, and the Sentience Accord, AGI Standards and Agentic Safety set rules for AI itself.
Together they are a first sketch of software for a self-governing society — and a precise map of where such software gets stuck. This piece sets out the principles that explain both: what makes an app civic, how its value should be counted, why it stalls, and what a builder has to do differently to create value for society rather than merely to ship. The companion piece, Eight Plays for the Civic Apps, turns the principles into concrete moves.
The principles in brief
Leverage is not value. Shipping proves nothing; value exists only when something changes for people outside the team.
Building became cheap; proving did not. The collapse in the cost of building makes proof the scarce and decisive part of civic work.
Public value is a product feature. It has to be named before the first line of code and instrumented from the first day.
The beneficiary is not the buyer. In a civic app, the person who gains and the person who pays are different — so satisfaction stops being evidence.
Civic errors land on other people. When a civic app is wrong, the cost falls on someone who never chose it, which makes it the most governed software a builder makes.
Civic apps need legitimacy before they need users. A commercial app needs a customer’s yes; a civic app needs data, a mandate, a signature and trust.
Price is not value. What people pay is the easiest value to count and the least informative about society.
Free is not worthless. Free civic tools are counted as zero only because of how accounts are kept, and their worth can be measured.
Public means governed, not just open. Purpose, governance and accountability make something public — not the label.
Count only what actually changed. Every claimed outcome must be reduced by what would have happened anyway, who else caused it, what it displaced and how fast it fades.
The last mile is institutional, not technical. Civic apps stall on five barriers — data, mandate, signature, distribution and money — none of them code.
Keep a value ledger, and publish the failures. Evidence recorded from day one, including what went wrong, is the only proof that is believed.
Fund without capture. Every source of money must be tested against one question: does it buy control over what the app says or whom it watches?
Build less, finish more. A few civic apps carried all the way prove more than many more starts.
1. Leverage is not value
The first thing a builder of AI-native software discovers is leverage. A single person, directing agents, can now produce what used to need a department: a research desk, a sales team, a map of the state, a charter. It is intoxicating, and it tempts every builder into the same mistake — treating the thing built as the thing achieved.
For commercial software the mistake corrects itself, because a customer either pays or does not. For civic software nothing corrects it. A map of the state can be live, elegant and technically impressive while changing nothing about how any crisis is handled. A fact-checking engine can process thousands of claims without a single one being corrected by the person who made it. A course can be published without anyone becoming more capable.
So the first principle is the one every other rests on: value for society exists only when something changes for people outside the team, and when that change can be shown to someone who has no reason to take the builders’ word for it. Everything a civic builder does — what to build, whom to partner with, what to measure, when to stop — follows from taking that sentence seriously.
2. Building became cheap; proving did not
For most of history, building and proving cost roughly the same order of effort. An institution that spent a year building a public service also spent that year gathering partners, users and evidence, and the two happened together. AI has broken that balance. A civic app that once would have taken an institution a year can now be built in a month — but showing that it helped still takes the same partners, the same patience and the same honest counting it always did.
When one side of a balance collapses, the other side becomes the bottleneck. In civic work, proof is now the scarce and decisive part. The builders who create real value for society will not be the fastest builders; they will be the ones who treat proof as part of the product rather than as an afterthought, and who are willing to spend more of their time on partners and evidence than on features.
The trap is obvious and common. When building is cheap and proving is expensive, it is always easier to build the next thing than to prove the last one. A portfolio of many impressive civic starts can be, in terms of value for society, worth less than one modest app carried all the way.
3. Public value is a product feature
If proof is the bottleneck, it cannot be bolted on at the end. Public value has to be designed like any other feature: named before the first line of code, instrumented from the first day, and verified like any other claim the app makes.
Naming it first means stating the outcome, not the output. Not “a dependency graph of the state” but “fewer single points of failure that nobody knew about”. Not “a fact-checking engine” but “public claims that get corrected”. Not “a course” but “people who can direct and govern agent systems”. Instrumenting it means that the app records, from the start, the evidence that the outcome is happening. Verifying it means someone outside the team can check.
The good news is that the habits which make agentic software trustworthy are exactly the habits a credible account of public value needs: never citing a source that was not fetched, never trusting a model’s own verdict, logging every action and its cost, and writing down honestly what went wrong. Pointed at outcomes, those habits become a value ledger. Pointed only at outputs, they produce impressive artefacts that nobody outside the team has used.
4. The beneficiary is not the buyer
In ordinary software the user and the customer are the same person, or at least on the same side. A civic app breaks that symmetry. The people who gain from a map of the state’s dependencies are the citizens whose services keep running; the people who would pay for it, if anyone does, are a ministry or a foundation. The people who gain from a fact-checked political debate are voters; the people who fund it are donors or a newsroom.
That split has a deep consequence: the buyer’s satisfaction stops being evidence of value. A ministry can love a tool that citizens never benefit from; a foundation can fund a project that serves its own agenda more than the public. Whenever the beneficiary and the buyer differ, something else has to take the place of the customer’s verdict — the voice of the people affected, and evidence of what changed for them.
Civic value is also collective. A sales tool creates value for one firm at a time; a civic app creates value that is shared and often invisible to any single person — a failure that did not happen, a false claim that did not spread, a debate that became easier to follow. Nobody experiences all of it, so nobody can vouch for it alone, which is why it has to be measured deliberately.
5. Civic errors land on other people
When a sales agent misjudges a lead, the operator loses a little time. When a civic agent misjudges a politician’s claim, a named person is harmed in public. When a health-literacy site gets a fact wrong, a reader who trusted it pays the price. When a map of the state shows a dependency that does not exist, a crisis staff may act on it.
In civic apps the cost of error falls on people who never chose the tool. That single fact changes how such apps must be built. They have to be the most carefully governed software a builder makes: every claim tied to its source, every model output checked by something that cannot be persuaded, every consequential action waiting for a person who will answer for it, and every correction made as visibly as the original mistake.
The paradox is that civic apps are usually built with fewer resources than commercial ones, yet they need more governance. The way out is to reuse the governance machinery the commercial apps already built — the gates, the checks, the ledgers — rather than skipping it because the civic app has no budget.
6. Civic apps need legitimacy before they need users
A commercial app needs a customer’s yes. A civic app needs something closer to permission: data that only the state holds, a mandate from an institution that will use it, a publisher who will sign what it says, and trust from people who disagree with each other. Without these, even a brilliant civic app cannot be used for the purpose it was built for.
This reverses the usual startup order. A commercial builder finds users first and worries about legitimacy later, if ever. A civic builder has to secure legitimacy first, because users will not come — and should not come — to a tool that no institution stands behind. The first partner of a civic app is therefore not its first user but its first institution: the working group, the committee, the clinic, the newsroom, the council.
Every technology revolution has lived through this stage. Railways needed charters and medicine needed licences before they could be woven into public life. AI has closed the capability gap faster than any technology before it, which is why the gap in legitimacy is now wider than ever — and why civic builders have to spend so much of their effort on it.
7. Price is not value
The first kind of value is the easiest to count: what people pay. Subscriptions to a sales workforce or a video editor are value by revealed preference — someone looked at the price and said yes. That makes it real and easy to measure, and also the least informative about society.
A product can be paid for and do harm, or be free and do great good. The economist Mariana Mazzucato has spent a career arguing against the habit of confusing price with value, and civic apps are the clearest case of why she is right: the most valuable of them may never charge anyone. A map of the state, a verified evidence pack for a parliament, a health guide in a small language — none of these would score well if revenue were the measure.
For a civic builder, the practical lesson is to stop apologising for the absence of revenue and start measuring what the app is actually for. Revenue can fund the work; it cannot prove its value.
8. Free is not worthless
The state map, the Czech ADHD and autism site, the research libraries and the charter are all free, and all counted as zero by standard accounts. That zero is an artefact of the accounting, not a fact about the world. It means only that nobody paid, not that nobody gained.
Economists have learned to price free digital goods by asking users what they would have to be paid to give them up, and the answers turn out to be large. The same method works for civic apps. A short, honest choice question put to the people who use a tool — what would it take for you to lose this? — is often the first real evidence that it matters to them, and it costs almost nothing to collect.
The deeper point is that a civic builder should never accept “it’s free, so we can’t measure it”. Free goods have value; the task is to find the method that reveals it, and to report it with the same honesty as any other number.
9. Public means governed, not just open
Some value is collective: a state that understands its own dependencies, a debate grounded in checked claims, a public that knows which issues nobody is responsible for. This is public value, and it is the value civic apps exist to create. But it has a condition that builders often miss. Mazzucato’s work on public value makes the point directly: calling something public infrastructure does not make it public. Purpose, governance and accountability do.
A state map gated to one working group is useful to that group; it becomes public value only when its data, its rules and its purpose are public, and when the public can hold someone responsible for it. A fact-checking engine run by a private team becomes a public good only when its methods are published, its errors are corrected in the open and its verdicts are signed by someone accountable. Open code is not enough; open governance is what counts.
This is why civic apps, even when they are built by a private studio, have to be designed to be handed over — to an institution, a commons or a public body — with their data, procedures and rules intact. An app that can never leave its builders’ hands can be useful, but it can never be fully public.
10. Count only what actually changed
The hardest and most important kind of value is change for people, net of what would have happened anyway. The discipline of social return on investment gives the method. Its seven principles — involve the people affected, understand what changes, value the things that matter, include only what is material, do not over-claim, be transparent, verify the result — are best read not as an audit but as design rules for a civic app.
Its four adjustments are where honesty lives. Every claimed outcome must be reduced by what would have happened anyway, by who else helped cause it, by what it displaced, and by how quickly it fades. A civic app that claims to have prevented an outage must ask whether the outage would have been prevented without it, whether someone else deserves the credit, and whether the fix will still hold next year. An app that claims to have corrected a false claim must ask whether the correction would have happened through ordinary journalism.
These questions are uncomfortable because they shrink the numbers. That is exactly why they matter. A civic app that reports small, honest numbers will be believed; one that reports large, unadjusted ones will not, and should not be.
11. The last mile is institutional, not technical
The same builders, with the same tools, reliably put AI deep into commercial products long before they put it into public ones. The reasons are never technical. Five barriers recur, and naming them precisely is the first step to getting past them.
The first is data that does not exist or is not released: the resilience map has to label its cascades “simulated” because no register records which operator runs which system for which authority, and an app with nothing true to work on can only perform. The second is no mandate: a civic app can have enthusiastic users and still have no owner inside the institution it serves, and output without an addressee is a report nobody asked for. The third is no one who signs: a design in which an agent publishes that a named politician lied, with no human gate, is technically sound and institutionally unsafe. The fourth is no distribution: nobody searches for a map of their state’s dependencies until the night they need one. The fifth is no money: most civic apps are funded by their builders’ time, a subsidy with a hard ceiling that is reached precisely when an app becomes useful.
The principle behind the five is simple: the last mile of a civic app runs through institutions, not through code. Every hour spent on features when the blocking barrier is a mandate or a dataset is an hour spent in the wrong place.
12. Keep a value ledger, and publish the failures
Public value that is not measured is not believed, and value measured once, by hand, at the end is rarely believed either. The answer is a value ledger that every civic app writes to from its first day. It records the inputs (people’s time, the cost of models and cloud), the outputs, who used them and how, the outcomes the app exists to cause, the honest adjustments to each outcome, and who verified it against what evidence.
Agentic software already produces most of what such a ledger needs: event logs, per-call cost records, evidence ledgers, quality checks and audit trails. The work is to join them and point them at outcomes. The rigour should match the stakes — a simple comparison where one is cheap, a forecast and later evaluation where outcomes are hard to randomise, plain outcome tracking where money is the wrong measure.
And the ledger must include the failures. A civic app that reports its own drop-off and its own mistakes honestly will be believed when it reports its gains; one that reports only gains will be believed by no one who matters.
13. Fund without capture
Commercial apps fund themselves. Civic apps must be funded by someone who is not the beneficiary, and every such funder is a potential source of pressure on what the app says or whom it watches. That is the real risk of civic funding: not that there is too little money, but that the money comes with invisible strings.
Several sources can be used without surrendering the mission. The working apps can pay for the shared engine that every civic app runs on. Institutions can commission evidence on the condition that it is published by default after a short embargo. Funders can pay per outcome rather than per activity, which the value ledger makes possible. Public bodies can pay for deploying and supporting an open public good rather than for licences. And a community of members can pay a modest fee while contributing the review, editing and code that civic apps need.
Every source must pass the same test: does it give the funder control over what the app says or whom it watches? If the answer is yes, it is capture, not funding — and no amount of money is worth it.
14. Build less, finish more
Cheap building makes it rational to start many things; a studio can hold a sales product, a map of the state and a charter at the same time. But value for society is decided at the other end, in the slow and unglamorous work of carrying one app across the last mile — securing the data, the mandate, the signature, the audience and the funding, and proving what changed.
So the final principle is a discipline rather than a discovery: build less, finish more. Pick the few civic apps with the strongest pull, name the outcome before the feature, measure from the first day, let a person sign what the public is told, and publish what happens, including what went wrong.
That is the last principle of social return — verify the result — applied to software that is meant to serve everyone. The companion piece, Eight Plays for the Civic Apps, sets out which apps to carry first and how.
Building for the public
The working apps have shown that a tiny team can build almost anything. The civic apps are where that should matter most, and where it has not yet landed — because the last mile runs through data, mandates, signatures, audiences and money, and none of those can be generated by a model.
That is not a reason for pessimism. It is a map. Every barrier on it has a known way through: a partner who holds the data, an institution that wants the tool, an editor who will sign, a meeting that already happens, a funder who pays for outcomes without buying the verdict. What it requires is a change of habit — from starting to finishing, from outputs to outcomes, from building for the public to building with it.
This piece draws on the Metamatics Ventures and ENSI NGO apps and on ENSI’s research library on measuring social and public value, digital public infrastructure and civic technology.



