Practical AI for rail and public transport operators, their suppliers, and the consultancies that serve them

Many organisations in rail and public transport have run an AI pilot that never left the demo. We help teams find where these tools are useful, run structured first experiments, and take what works into production. What we build runs on your own hardware, in a hardened European cloud, or with a model provider of your choice; privacy, security, and verification are settled first.

Your organisation:

a rail or public transport operator

Most of the work is knowing where AI is reliable in production

We help operators find where AI would hold up in maintenance, operations, asset management, or procurement, and run the first experiments on their own material. What they learn becomes a responsible AI strategy and its governance.

Example deployment

A simplified view of what the system does with your documents. Tap a row to see how.

MAINTENANCEWO-2841 · unit 407
  • Fault history, 14 entriessummarised · cited
  • Maintenance manual, §7.3check sequence
  • Release to serviceengineer signs

14 depot reports summarised; each line cites its report and date.

The check sequence quoted from the manual in its own wording, page cited.

The system drafts; the engineer decides and signs. Nothing is released automatically.

  1. Unclear which AI ideas would survive daily operations

  2. Data protection stops pilots at the security review

  3. Confident answers without sources

  4. Experiments in several departments but no overall AI strategy

Swipe for more, tap a step.

How we help

Unclear which AI ideas would survive daily operations

We start from your processes, not from the tools, and rank where AI holds up: fault histories, maintenance records, asset registers, procurement files.

How we help

Data protection stops pilots at the security review

Deployment is decided first: your own hardware, a hardened European cloud tenant, or a provider under contract, so the security review can say yes before the pilot starts.

How we help

Confident answers without sources

Every claim is checked against its source and cited; assessments are labelled as assessments. Your engineers see what is fact and what is judgement.

How we help

Experiments in several departments but no overall AI strategy

What the first experiments teach becomes a responsible AI strategy and the governance that goes with it, written for your board and your works council.

a supplier or rail-adjacent SME

Most hours go into bids, compliance matrices, and conformity documentation

Those documents are the work our systems were built for: reading, matching, and drafting with every statement traced to its source, on infrastructure chosen to meet your customers' audit requirements. We build the systems around your processes, or train your team to build them.

Example deployment

A simplified view of what the system does with your documents. Tap a row to see how.

COMPLIANCE MATRIX212 requirements
  • R-041Retrofit on all 14 vehiclescompliant
  • R-042First vehicle back within 14 monthspartial
  • R-044Availability ≥ 98.5 %, defined twiceAvailability, defined twiceopen

Compliant: matched to product specification §2.1; the source page is one click away.

Partial: first vehicle at month 15 in our plan; flagged for the bid manager.

Open: availability defined in Annex C §2 and ITT Vol. 2 §6.2, differently. Raised as a clarification question.

  1. Bids absorb weeks of engineering time

  2. Compliance matrices, line by line

  3. Your customers audit your cybersecurity

  4. Conformity evidence for the Cyber Resilience Act

Swipe for more, tap a step.

How we help

Bids absorb weeks of engineering time

Tender OS reads and qualifies the documents within minutes rather than days; the Agentic Bid Builder drafts the response with every statement sourced.

How we help

Compliance matrices, line by line

Requirements are extracted, matched to your product, and cited to the page; contradictions between volumes are flagged as clarification questions.

How we help

Your customers audit your cybersecurity

A hardened European cloud tenant, or your own hardware, that stands up to their questions: inference, storage, and compute in locations you can show them.

How we help

Conformity evidence for the Cyber Resilience Act

Documentation drafted by agents and reviewed by someone who has run OT-cybersecurity roadmaps for the same kind of company.

a consultancy serving rail

Your rail clients are asking about AI

We work with rail-focused consultancies in two ways: directly, so that your own team uses these tools in its delivery and advises from experience; and jointly, on client engagements where the advice needs a production system behind it. Where client material cannot leave your premises, the system can run entirely on your own hardware.

Example deployment

A simplified view of what the system does with your documents. Tap a row to see how.

LOCAL-ONLY ASSISTANTnothing leaves the building

YOUR OFFICE:

  • client files
  • local model
  • cited answer

Client files stay on your servers; indexed locally, never uploaded.

An open-weight model running on your own hardware.

Every answer quotes the client file and the page it came from.

  1. Clients ask about AI before you have used it

  2. Client material cannot leave the building

  3. Advice that needs a system behind it

  4. A team that does not know what to trust

Swipe for more, tap a step.

How we help

Clients ask about AI before you have used it

Hands-on sessions on your own delivery work and your own documents, so that you advise from experience rather than from reading.

How we help

Client material cannot leave the building

A local-only assistant on your own hardware: files are indexed on your servers, nothing is uploaded, and nothing reaches a third party.

How we help

Advice that needs a system behind it

We work alongside you on the client engagement, building the system while you lead the advisory work, under whichever arrangement suits the client.

How we help

A team that does not know what to trust

Verification and labelling are built into the tools your consultants use, so every number and quote carries its source.

  • Systems in production in a hardened European cloud; deployable on your own hardware
  • 2,500+ pages of tender documentation processed
  • Tenders in more than six countries
  • Client documents are never used to train a model
  • LiveSystems in production in a hardened European cloud; deployable on your own hardware
  • No trainingClient documents are never used to train a model
  • 2,500+pages of tender documentation processed
  • 7+countries in which tenders were processed

Three ways of working together

Which one fits depends less on the size of the organisation than on where it is with AI today. A short assessment shows which.

Assess

The AI Readiness Assessment: one to two weeks. Where each department stands, which processes are worth automating or training for, where to run the systems, and what has to be true before go-live.

What you get →

Enable

Hands-on sessions on your own documents: where your organisation stands with AI, where current models help with your kind of work and where they do not, how to check an output before acting on it, and how to build the first internal tools without a data-science team.

Training formats →

Build

Agentic systems designed and built around your existing processes, inside your team. Verification, access control, hardening, and data residency are decided at the start; the deployment — local, hybrid, or cloud — follows your constraints.

How we build →

Why pilots tend to stall, and what production requires

The model is rarely the problem. Pilots stall on questions that were reasonable to postpone during a demo and impossible to postpone afterwards.

  1. Pilot

    Where the documents go. Which model runs where, under whose contract, and what it retains. Until this is written down, the security review cannot say yes.

  2. Security review

    What checks the answer. A confident answer is not evidence. Production needs a traceable source for every claim and a label on every judgement.

  3. Verified

    Who looks after it. Prompts drift and edge cases accumulate. Production needs a named owner and a small routine.

  4. In daily use

    Whether it fits the working day. A tool that slows the work for a month is abandoned. We build the system into the existing workflow.

The pilot-to-production checklist →

The two questions we are asked most about AI in production

How do we know the output is not invented?

All language models make errors. Checking is therefore built into the system rather than left to the reader: every claim is checked back against the original document, adjacent text is re-read in the document's own language, and assessments are labelled as assessments rather than presented as facts.

How the verification layer works →
Extracted claimfact · verbatim

Series retrofit of the onboard signalling equipment shall be completed for all 14 vehicles within 26 months of contract award.

ITT Vol. 2 · §4.3.1 · p. 87 · R-043

Adjacent text, re-read in the original

„Das erste nachgerüstete Fahrzeug ist spätestens im 14. Monat nach Auftragsvergabe wieder in Betrieb zu nehmen; die Serien-Nachrüstung erfolgt in Losen von jeweils zwei Fahrzeugen.“

Assessmentassessment · not verbatim

Two vehicles out of service at any time between month 14 and month 26. Read the availability clause in Annex C §2 against this.

One requirement from a tender, as the verification layer returns it: the claim quoted, its source cited, the surrounding text re-read in German, and the assessment kept apart from the fact.

Is our data kept confidential?

That depends on the sensitivity of the material. There are four ways to deploy, from nothing leaving your building to a frontier model outside Europe, and hybrids of them. We help you choose, and build to that choice.

Where your data goes →
Most sensitiveHow sensitive is the material?Least sensitive

Many organisations settle on a hybrid: sensitive material on the first two, everything else on the last two, with the same verification layer across all of them.

  1. Client material cannot leave the building

    On your own hardware

    For organisations whose material may not leave the premises, or that have a no-cloud policy.

    Where the model runs
    On servers you own, inside your network
    What leaves your network
    Nothing
    Used to train a third-party model?
    No; nothing reaches a third party
    • Nothing leaves your network
    • Full control of access, logging, and retention
    • Works without any internet connection
    • You provide and run the hardware
    • Smaller, local models only
  2. Customers audit your cybersecurity

    Hardened European cloud

    For suppliers and operators whose customers or auditors check their security, and who need stronger models than local hardware allows.

    Where the model runs
    In a dedicated EU tenant, hardened and operated with you
    What leaves your network
    Encrypted documents, to your EU tenant only
    Used to train a third-party model?
    No; a private tenant, under a contract that excludes training
    • Inference, storage, and compute inside the EU, under your contract
    • Built for customer security audits
    • Stronger models than local hardware
    • Encrypted documents leave your network
    • A tenant to harden and keep hardened
  3. Lower-sensitivity drafting and research

    European model provider

    For teams working with lower-sensitivity material who want the strongest models with the least setup.

    Where the model runs
    At a European provider, under a no-training contract
    What leaves your network
    Prompts and the documents you choose to send
    Used to train a third-party model?
    No, excluded by contract
    • Fastest to start; the strongest models
    • No training on your data, by contract
    • No infrastructure to run
    • Prompts and documents go to a third party
    • Only where sensitivity allows
  4. Non-sensitive material; the strongest model is the priority

    Non-European frontier model

    For teams that need the strongest available models on non-sensitive material and can accept data leaving the EU.

    Where the model runs
    At a US or other non-EU provider, usually under a business agreement
    What leaves your network
    Prompts and documents, outside the EU
    Used to train a third-party model?
    Not on business tiers; depends on the contract and its jurisdiction
    • The strongest models available
    • The widest tooling and integrations
    • Data leaves the EU, into another legal jurisdiction
    • Confidentiality rests on the provider's terms

Why industry experience matters more than the model

General-purpose AI tools are easy to buy and hard to put to use. What makes a system usable is knowing the process it sits in — what a compliance matrix is for, why an availability clause defined twice is a warning sign, and which document the engineer opens first. These systems were built with that knowledge.

  1. FindTenderSourceFinding tenders
  2. QualifyTender OSReading and qualifying them
  3. DraftAgentic Bid BuilderDrafting responses
  4. RememberTender WikipediaKeeping institutional knowledge answerable
  5. ComplyCRA agentsProducing conformity documentation
  1. FindTenderSourceFinding tenders
  2. QualifyTender OSReading and qualifying them
  3. DraftAgentic Bid BuilderDrafting responses
  4. RememberTender WikipediaKeeping institutional knowledge answerable
  5. ComplyCRA agentsProducing conformity documentation

Hover or tap a system to see an example.Tap a system to see an example.

TenderSourceFeed · new this week
3 matches
  • Onboard signalling retrofit, 14 light-rail vehiclesVerkehrsbetriebe Talmark · deadline 14 Nov 2026 · est. € 18.5 Mmatches your profile
  • Depot maintenance framework, four yearsStadtbahn Weidental · deadline 28 Oct 2026 · est. € 6.2 Mmatches your profile
  • Passenger information displays, 62 stopsRegionalbahn Lindmark · deadline 5 Dec 2026 · est. € 3.9 Mmatches your profile
Tender OSLight-rail onboard signalling retrofit — 14 vehicles
qualified
IDRequirement · sourceStatus
R-041Retrofit of onboard signalling on all 14 light-rail vehiclesITT Vol. 2 · §4.1compliant
R-042First retrofitted vehicle back in service within 14 months of awardITT Vol. 2 · §4.3partial
R-043Series retrofit completed for all vehicles within 26 months of awardITT Vol. 2 · §4.3.1 · p. 87compliant
R-044Fleet availability of at least 98.5 % during the retrofit periodAnnex C · §2 — also defined in ITT Vol. 2 · §6.2, differentlyopen
IDRequirement · sourceStatus
R-042First retrofitted vehicle back in service within 14 monthsITT Vol. 2 · §4.3partial
R-043Series retrofit completed within 26 months of awardITT Vol. 2 · §4.3.1 · p. 87compliant
R-044Fleet availability ≥ 98.5 % during the retrofitAnnex C · §2 — also in ITT Vol. 2 · §6.2, differentlyopen
Agentic Bid BuilderCriterion B.2 · Retrofit programme and fleet availability
draft · for review
Draft answer

The retrofit is delivered in lots of two vehicles, so that no more than two are out of service at any time [Method statement · §2.1]. The first vehicle returns to service in month 15 and the series is completed within 26 months of award [ITT Vol. 2 · §4.3]; availability against the timetabled requirement is held at 98.6 % throughout the programme.

2 sourcesBid manager to confirm month 15 against R-042 before release.
Tender WikipediaQuestion · bid team
answered · cited
QuestionWhat did we quote for depot tooling last time?
Answer

€ 412,000 in the Talmark light-rail bid and € 386,500 in the Weidental depot framework. Both included the wheel-lathe adapter set; neither included operator training.

  • Price schedule v3 · 12 Mar 2025
  • Commercial annex B · 30 Sep 2024
CRA agentsConformity evidence · OBU-400 onboard unit
3 of 5 evidenced
Secure-by-default configurationProduct security guide · §3.2evidenced
Vulnerability handling processPSIRT policy v2.1 · §4evidenced
SBOM availabilityBuild manifest, release 4.3 — export pendingopen

The Agentic Bid Stack — five systems in production covering the rail bid lifecycle, from finding tenders to conformity documentation.

A bid managed with these tools, inside a client's team — a complete overview within a day of publication; a spare-parts calculator from five hundred pages in under an hour; penalty exposure across three regimes as a model the managing director could adjust.

Local, hybrid, or cloud — the same verification layer runs on your own hardware, in a hardened European cloud, with a European or non-European model provider, or in a hybrid of them. The architecture follows the sensitivity of the material, not the reverse.

The systems and the cases →

What stays with people

Much of what makes an organisation work is not written down anywhere: how decisions are taken, which customer needs a call rather than an email, and what the last incident taught the depot. A model has no access to that, nor does it know your pricing strategy or your safety case.

Modern AI is also uneven — very strong at some tasks and unreliable at others that look similar. Part of using it well is building the reflex to test, keeping domain experts in the loop, and deciding on evidence rather than instinct where not to use it at all.

Organisations that treat AI as something that augments their people's intelligence and judgement get more out of it than those that try to replace either. The starting point is knowing where the limits are, including the ones that will not move.

Raphael Santos Cavalcanti
Portrait generated with AI from photographs of Raphael Santos Cavalcanti.

Nova Mobility Consulting is led by Raphael Santos Cavalcanti, based in Mainz, Germany. He brings fifteen years in rail and public transport across Europe, Asia, North America, and South America — project and bid management, strategy, engineering and product, and business development — and has more recently built the systems on this page.

About Nova Mobility →

Start with a 30-minute call

The booking form asks three questions so that both sides can judge early whether there is a basis for further work.

Book a call

The pilot-to-production checklist

What has to be true before an AI pilot enters daily operations.

Get the checklist →