Skip to content

Insights

Thinking on urban intelligence.

Field notes on how AI-enabled infrastructure actually gets built, funded, and defended in India — written from the ground up.

DeploymentClarivill Perspectives · 7 min read

Why smart city projects fail at the last mile

There is a moment in every smart city programme that never makes it into the case study. It happens around month five. The platform demo went beautifully. The command centre renders are on everyone's desktop. And somewhere in a mid-sized town, a two-man crew is standing next to a half-dug pit because the road-cutting permission that was “practically approved” three weeks ago is sitting under a paperweight in an office that closes at four.

Nobody budgets for the paperweight. Everybody pays for it.

We come out of the construction and government-works world, and the thing that strikes us about India's smart city decade is how familiar its failures look. The technology press writes about AI accuracy and platform architecture. But talk to anyone who has actually delivered one of these programmes and they will tell you the schedule was never lost in the data centre. It was lost in trenches, transformers, and tehsil offices.

Where the eighteen months actually go

A typical corridor-scale programme today asks for thousands of cameras, a few hundred smart poles, and a command centre — delivered in about eighteen months, with liquidated damages ticking at half a percent of contract value per week of delay. Read that clause again. On a ₹250 crore contract, a month of slippage costs more than most subcontractors earn on the entire job.

Now walk the critical path. The AI models can be trained in parallel. The applications can be integrated in parallel. The command centre is one building. But the field network — the part that turns a platform into a city system — is thousands of small serial dependencies: a foundation that needs curing time, a power connection that needs a utility's field officer to show up with a meter, a fibre route that crosses a road owned by a different department than the footpath next to it. Each dependency is trivial. Ten thousand of them, spread across dozens of towns, is the project.

The schedule was never lost in the data centre. It was lost in trenches, transformers, and tehsil offices.

And here is the uncomfortable part: the companies best equipped to build the platform are, almost by definition, worst equipped to manage those dependencies. A brilliant integration team in a metro office cannot make a lineman appear in a small town on a Tuesday. That is not a criticism. It is a division of labour that the industry keeps pretending doesn't exist — and then rediscovers, at LD rates, on every project.

The retrofit trap

The current generation of programmes adds a wrinkle the first smart cities never faced: retrofitting. It sounds cheaper on paper — the camera is already on the pole, just make it intelligent. In practice, “existing infrastructure” means five different camera brands installed across eight years by six vendors, half of them out of warranty, connected by cabling of unknowable provenance. The edge device is the easy part. Discovering what you are actually retrofitting is a survey discipline, and the projects that skip it end up doing the survey anyway — during commissioning, at night, under a deadline.

Our rule of thumb from the EPC world applies directly: the cost of knowing site conditions before you price is one-tenth the cost of learning them after you mobilise.

Maintenance is where reputations are made

Go-live gets the ribbon. The next ten years get the citizens. A surveillance network is judged not on the day it is inaugurated but on the Tuesday afternoon, four years later, when a camera at a market junction has been dead for a week and an incident happens under it. Modern contracts understand this — availability clauses now carry per-camera, per-day penalties — but the industry still treats operations as an afterthought staffed by whoever is cheapest locally.

We would argue the opposite: the field operations force is the product. A platform without uptime is a screensaver. The programmes that age well are the ones where somebody designed the maintenance organisation — spares depots, response geography, technician training — with the same seriousness as the network architecture. Usually nobody did, because the maintenance decade was priced in an afternoon during bid week.

What we would change

Three things, none of them glamorous. First, treat permissions and right-of-way as an engineering discipline with its own schedule, owner, and risk register — not as a miscellaneous line someone's cousin will sort out. Second, price the field survey properly and do it before the design is frozen, because every assumption that survives contact with a real street is a small miracle. Third, design the operations organisation at bid stage and name the people who will run it, because the vendor who plans for year seven is the vendor who is still trusted in year seven.

None of this is a technology insight. That is precisely the point. India is about to extend AI-enabled governance from a hundred cities to thousands of towns, and the constraint will not be model accuracy. It will be the last mile — the layer where software meets soil. The winners of the next decade will be the ones who respect it.

EconomicsClarivill Perspectives · 8 min read

The self-funding city: AI and municipal revenue

For ten years, India's smart cities ran on a simple financial logic: the Centre paid. The Smart Cities Mission moved roughly ₹1.6 lakh crore through a hundred cities, and when the Mission formally wound down in 2025, it left behind an obvious question that nobody in the sector likes saying out loud. There are more than four thousand urban local bodies in this country. Who pays for the other 4,700?

The most interesting answer we have seen is emerging quietly in tier-2 India, and it inverts the entire model: the city borrows, and the AI repays the loan.

How the arithmetic works

Start with an unglamorous fact. A typical Indian municipality collects perhaps 55 to 60 percent of the property tax it is owed. Trade licence compliance in smaller towns can run below half. This is not because officials are idle — it is because the records are two decades stale, the building on the ground is twice the size of the building in the register, and nobody has the staff to reconcile a hundred thousand properties by hand.

This is, awkwardly for the sceptics, exactly the kind of problem machine learning is genuinely good at. Overlay satellite imagery on the property register and under-assessment stops hiding. Cross-reference water connections against property records and unbilled usage surfaces. Match trade activity visible on a commercial street against the licence database and the gap prices itself. None of this is exotic AI. It is diligent reconciliation at a scale no human establishment could staff.

Now do the sums. Take a corridor of 26 towns with a combined tax base where realisation improves from 58 percent to even 75 percent over five years. The incremental revenue, compounded across property tax, trade licences, advertisement fees, and enforcement, is comfortably enough to service the debt on a ₹250 crore platform. Add the direct revenue the infrastructure itself earns — advertisement on digital displays, EV charging, licensed data — and the debt-service maths gets easier still.

The city borrows, and the AI repays the loan. If the model proves out, it is the funding template for the 4,700 towns the Mission never reached.

The contracts being written around this model are fascinating documents. Vendors are no longer paid merely to make systems work; meaningful retention amounts are now released only when revenue outcomes are demonstrated. Quarterly reporting includes debt-service coverage ratios — a lender's metric, sitting in a technology contract. The vendor has been made a stakeholder in the municipality's balance sheet. We think this is, on balance, healthy. It is also unforgiving.

The honest caveats

Anyone selling this model without caveats is selling something else. Three deserve naming.

First, the AI finds the revenue; humans still collect it. An algorithm can put a list of five hundred under-assessed properties on a commissioner's desk. It cannot serve the notices, survive the appeals, or absorb the local politics of reassessment. Programmes that model collection improvements without modelling the enforcement capacity of a small-town revenue department are writing fiction with spreadsheets.

Second, the sector has been burned by AI theatre before. There are well-documented cases of expensive urban AI systems that demonstrated beautifully and then produced remarkably few genuine outcomes in production. The gap between a curated demo and a monsoon-season deployment across mixed camera stock is where credibility goes to die. Buyers have learned this, which is exactly why the retention clauses exist.

Third, a decade is a long time. Loan-term contracts bind vendor and municipality together for ten years, through elections, transfers, and technology cycles. The financial engineering is only as durable as the institutional arrangements around it — the escrows, the certifying agencies, the governance committees. The paperwork matters as much as the models.

Why it matters anyway

With all those caveats, we still think this is the most important structural idea in Indian urban technology right now. Grant funding reached a hundred cities in a decade. A repayable model that pays for itself out of better governance can, in principle, reach every town with a tax register — no central scheme required. The first corridors running this model are, in effect, running the experiment for everyone else. If their coverage ratios hold up over the first three or four years, every state finance department in the country will notice, and the replication will not be linear.

Our own conviction, coming from the execution side, is simple: the model works if the system works, and the system works if it is deployed honestly and maintained relentlessly. Revenue intelligence is a promise made in a boardroom and kept on a street. We know which half of that sentence we were built for.

SecurityClarivill Perspectives · 7 min read

OT security is the next frontier for Indian infrastructure

Ask a city's IT team where their network ends and they will point at a firewall. Ask us, and we will point at a grey cabinet bolted to a pole on a service road — the kind with a hasp lock, a passive splitter, an edge computer, and, increasingly, a route into systems that matter.

India is wiring its physical infrastructure to central platforms at extraordinary speed. Cameras by the tens of thousands. Water networks with SCADA telemetry. Streetlights with remote control. Traffic signals taking instructions from optimisation engines. Every one of these is a triumph of integration, and every one of them moves the attack surface out of the data centre and onto the street, where it sits behind a padlock in the sun.

IT security and OT security are different disciplines

The information-security world has spent thirty years learning to protect data — confidentiality first, patch aggressively, assume the endpoint is replaceable. Operational technology inverts nearly all of it. In OT, availability comes first: you cannot reboot a water treatment process to apply a patch. Equipment lives for fifteen years, not three. Protocols were designed in an era when “security” meant the door to the pump house was locked. And the endpoint is not replaceable — it is a pump, a signal, a valve.

Urban AI programmes now weld these two worlds together. A camera network is IT until it feeds an enforcement system. A streetlight is a lamp until 400 of them share a management platform with the same credentials. A smart pole is street furniture until you notice it carries a public Wi-Fi radio, an EV charger, and an edge computer on the same internal switch. Convergence is the whole point of these programmes — and convergence is precisely what traditional security models were never built for.

The attack surface has moved from the data centre to a grey cabinet on a service road, behind a hasp lock, in the sun.

What the field teaches you

Spend time around physical infrastructure and you develop instincts that do not come from certification courses. Some of what we would put in every threat model:

The cabinet is the perimeter. Network diagrams show trust boundaries as neat lines. On the ground, the boundary is a metal door that a contractor's helper props open on a hot afternoon. Physical access discipline — keyed hierarchies, tamper alarms that someone actually responds to, port hygiene inside field enclosures — does more for real security than another appliance in the data centre.

The maintenance chain is an attack path. Over a ten-year O&M term, hundreds of technicians will legitimately touch field devices. Every laptop that plugs into a roadside switch, every firmware file carried on a pen drive, every default password left on a replaced camera is part of the security posture. Vendor ecosystems, not vendors, get breached.

Legacy is forever. Retrofit programmes inherit devices whose firmware ended support years ago. The honest answer is rarely replacement — budgets do not allow it — but segmentation: assume the old device is compromised, wall it off, and monitor what it talks to. Zero trust is usually described as an architecture. In a retrofitted city it is closer to a survival attitude.

Detection beats prevention at street scale. You will not harden ten thousand endpoints across two dozen towns to perfection. You can, however, know within minutes when one of them starts behaving strangely — a camera that suddenly speaks to an address it never has, a controller that chatters at 3 a.m. The regulatory direction agrees: India's incident-reporting mandates now measure response in hours, which is only achievable if monitoring reaches the edge.

The market is about to demand this

Look at the tender documents being issued for city platforms today: zero-trust architecture requirements, 24×7 security operations, empanelled auditor certifications before go-live, breach notification measured in single-digit hours, penalty structures for classification breaches. The procurement world has, to its credit, written ambitious security obligations into contracts. What the market lacks is the delivery capability to honour them at the street layer — the discipline that connects a SIEM dashboard in a command centre to the padlock on a junction cabinet in a mandal town.

That gap is where we believe the next serious infrastructure-security practice in India will be built: not another firewall reseller, but a capability that treats the cabinet, the technician, the firmware, and the SOC as one continuous system. It is unglamorous, physical, procedural work. Which is to say — it is exactly the kind of work that decides whether all the glamorous work survives contact with the real world.