MeitY's National e-Governance Division has narrowed the field for a government agentic AI platform to two bidders: CoRover and Kyndryl, with DigiLocker as the first use case. The shortlist follows an 18 September notice, according to Moneycontrol. Cactus Communications and NEC did not advance.

That is the shipped part. The unresolved part is what NeGD actually evaluated, what the winning vendor must build in four months, and how the platform escalates a citizen request when the agent should not handle it alone.

What was shortlisted

The reported field is small: two vendors for a platform meant to be used across government departments. DigiLocker is the MVP. That choice is revealing. DigiLocker is not a generic chatbot surface. It is a document wallet tied to issuer-verified records, consent, and sharing.

An agentic layer on top of DigiLocker would need to do more than retrieve a PDF. It would need to understand which document a citizen is asking for, confirm consent, fetch the record from the right issuer, and either complete a permitted action or route the request to a human officer. That is the ask/do/escalate framework in practice: ask for missing context, do the bounded task, escalate when identity, entitlement, or law is unclear.

What the timeline requires

The procurement timeline reported is four months to build and twelve months of operations and maintenance. Four months is aggressive for a platform that touches identity documents. A narrow DigiLocker workflow can be built in that window if the application programming interfaces are stable and the scope stays fixed. A general-purpose government agent across departments cannot.

The O&M phase is where the real cost sits. Agentic systems drift when issuer formats change, when consent rules are updated, or when a model starts producing plausible but wrong next steps. A twelve-month maintenance contract should include monitoring, incident response, and a way to disable an action without taking down the whole service.

The evaluation gap

Moneycontrol reported the shortlist, but the notice as described does not publish scoring weights, audit-log requirements, or how the platform will comply with the Digital Personal Data Protection Act. Those are not procurement footnotes. They determine whether the system can be audited after a citizen says a document was accessed without consent.

For a department, the useful questions are concrete. Can the agent show which document it read, under whose consent, and for what purpose? Can it stop before sharing data with a third party? Can a human officer see the agent's reasoning trail when a request is escalated? If those answers are not in the contract, the MVP may still demo well while leaving the hard accountability work for later.

What MeitY requires this month

For September, the requirement is procedural. NeGD needs to finish evaluation and move to award without widening the scope beyond what the shortlisted vendors can deliver. MeitY has separately been pushing domestic AI evaluations; Ashwini Vaishnaw said LLM funding evaluations are at the final stage, according to TechShots. That work is about model quality. Agentic procurement is about operational reliability.

The two tests are different. A model can score well on a benchmark and still fail a DigiLocker workflow if it cannot handle an expired document, a name mismatch, or a consent withdrawal. The shortlist is a signal that MeitY wants to move from pilots to production. The next signal is whether the contract makes escalation and auditability measurable.

Until then, the public record has two names, one MVP, and a clock. CoRover and Kyndryl have qualified. The harder question is what happens when the agent is asked to do something it should not.