Eleven systems hold up the government. Eight are written in languages nobody hires for
How do we modernise a critical legacy government system without replacing it?
Figures and rules on this page apply to
United States
Working somewhere else? The shape of the problem usually travels. The deadlines do not.
What this looks like
A caseworker needs one answer: has this claim already been paid. The system of record knows, but it answers through a nightly batch, so the answer arrives tomorrow. In the meantime somebody keeps a spreadsheet of what the batch has not told them yet. That spreadsheet becomes the real system, and nobody wrote it down as one.
The numbers
Every figure here is someone else’s. Check them.
- 11federal legacy systems GAO names as most in need of modernisation, out of 69 reviewed
- 8 of 11use outdated programming languages
- 7 of 11run with known cybersecurity vulnerabilities
- 4 of 11run on hardware or software the vendor no longer supports
- 3 of 10modernisations from GAO's 2019 list completed as of February 2025
Why it happens
It is not a people problem.
The reason these systems survive is that they work. They were built for a job and they still do that job. The cost of being wrong about replacing one is measured in benefits not paid. So every modernisation becomes a programme, every programme becomes a multi-year commitment, and the thing that would have helped this quarter never gets built. Six of GAO's original ten are still waiting after six years.
Why your current software has not fixed it
Because it was never built to.
A replacement programme and an operational fix are different kinds of work with different risk profiles, and the procurement route only really supports the first. A large integrator is structurally aimed at the replacement, because that is where the contract value is. Nobody is paid to build the small reading layer that would give a caseworker today's answer today. It does not look like transformation, so it cannot be sold as it. That is a market shape, not incompetence.
Intelligence, plumbed in
A copybook and a scanned form are both readable without retyping.
The build is a read-only layer over the system of record. Then a one-way extract out of it, and a form a citizen can finish on a phone. Underneath it: a connector, one agreed meaning per field, and a test set scored on your own records.
How we make AI survive real data-
Connectors -
A semantic layer -
Evals you can check
However hard, whatever it is
This system is one example. Bring the whole estate.
One system, one agency, one published review. If your estate has forty of these and no list, building the list is where we would start.
-
01 We sit with you
Days where the work happens, not a workshop in a meeting room. We watch the job get done and write down the shortcuts nobody wrote down.
-
02 We read everything
Your data, your rules, your vendors and their documentation, and the published research on your sector. We report what is actually in there.
-
03 We break it to first principles
Not which tool fixes this. What is actually causing it, taken apart until we reach the piece that cannot be divided further.
-
04 Then we build
Weeks, not quarters. By this point we are not guessing what to build, and guessing is the thing that makes projects long.
What we build
Specific enough to argue with.
Four mechanisms, not four features. Each one is a thing that happens on its own, every day, whether or not anyone remembers to run it.
-
A read-only layer over the system of record that answers the questions a caseworker actually asks, without changing a single line of the mainframe.
-
A one-way extract out of the legacy system, on a schedule you control. The data joins to anything else without opening a path back in.
-
The queue the desk works from: oldest case first, with age, owner and what it waits on. Not a screen that shows the newest.
-
A public-facing form a citizen can finish on a phone in one sitting, which writes into the legacy system through the route it already supports.
How you would know it worked
Numbers in your own reporting, not ours.
- Time from a citizen's question to a defensible answer, measured at the desk rather than in the batch window.
- Number of shadow spreadsheets still in use after six months, which should fall to nothing.
- Backlog age at the ninetieth percentile, not the average, because the average hides the cases that become complaints.
Straight answers
Where a model is involved, it is scored against your own records first. Accuracy per source, not one flattering average.
The questions this raises
-
Are you going to touch the mainframe?
No. We read it, through an interface it already exposes, and we write nothing into it that you have not approved in advance. The mainframe outliving the layer we build is a normal and fine outcome.
-
We are mid-way through a replacement programme. Does this compete with it?
Usually it helps it. The layer gives you a working picture of what is really in the data. That is the most useful input to a migration, and the thing most programmes discover late.
-
Can this run inside our own network with no internet?
Yes. Air-gapped, on-premise, with the model running on your own hardware if inference is involved. No data leaves the network and there is no cloud call to make.
-
What about accessibility and records retention?
Built in from the start, because retrofitting either one is far more expensive. We work to WCAG 2.2 AA and we design retention against your own schedule, not a default.
Where the figures come from
We did not make these up, and you should not take our word for them.
An old system with no documented way in
The old system is what costs money, and the new one gets the bill.
It runs, it is correct, and the person who knew how it worked has retired. Everything new has to negotiate with it, and each negotiation is bespoke. The cost is charged to whatever is being built, rather than to the thing causing it.
Two estates here, and the pattern is not limited to the public sector. Any system old enough to be load-bearing qualifies.Name the system nobody will touch.
A mainframe you cannot replace is still a mainframe you can read.
The build is a read-only layer over the system of record. Then a one-way extract out of it, and a form a citizen can finish on a phone.
See everything we build-
Software -
Hardware -
Ways of working -
Whole ventures
Is this happening to you? Tell us the size of it.
Twenty minutes. We will tell you honestly whether the numbers justify doing anything about it.