Your sector, in the FAQ

Retail, industry and energy, answered in full.

The questions asked where the work sits in operations, the supply chain and the estate rather than inside a regulated process.

questions in this group, each answered in full
12
pages the answers are written on, every one linked
2
questions across the whole FAQ
316

12 questions on retail, industry and energy, answered by Tenhaw, a UK AI consultancy and AI delivery partner based in London. Nothing here is a summary: each answer is the exact text from the page that owns it, and every group links back to that page for the context around it.

6 questions

Retail, Consumer and Media

Answered on Retail, Consumer and Media, and rendered here in the same words.

Read the page these answers live on →

Where do retailers get the fastest return from AI agents?

In high-volume, reversible-decision workflows: merchandising and demand signals, supply chain exception handling, customer service triage with human resolution, and content production at volume. These have short feedback loops, contained risk, and produce measurable results inside a single trading cycle.

Does UK consumer law apply to product descriptions written by AI?

Yes. The unfair commercial practices rules apply to the trader, not to the author, so a misleading description is a misleading description whether a copywriter or a model produced it. The rules in the Digital Markets, Competition and Consumers Act apply to practices from 6 April 2025, and the CMA can now decide for itself that they have been broken rather than going to court first, with penalties of up to 10% of global turnover and the power to direct redress. The practical design response is to ground every factual claim about a product in a field in a system of record, and to hold anything the model asserts that cannot be matched to one. The same logic covers price display, where mandatory fees have to appear in the total up front, and reviews, where presenting incentivised reviews as genuine is a banned practice.

Do we need a DPIA for an AI agent that uses customer data?

Almost always, and more importantly you need it more than once. A DPIA is required where processing is likely to result in high risk, which covers most personalisation, profiling and large-scale use of customer data. The failure we see is not a missing DPIA, it is a DPIA completed for a narrow pilot and never revisited when the agent's autonomy widened, which is the change that altered the risk. Two other things tend to get missed: a retrieval corpus needs its own retention and deletion behaviour, because honouring a deletion request in the database and not in the index is not honouring it, and a decision with significant effect on a person needs a real route to human intervention and to contest the outcome. Tenhaw is not your DPO and does not give legal advice here.

Who owns the rights to content generated by an AI model?

It depends on the tool's terms, the licences behind its training data and the warranties you were able to negotiate, and UK law still has no broad commercial text-and-data-mining exception to fall back on: the government's copyright and AI report of 18 March 2026 dropped a broad exception with an opt-out as its preferred approach and said it would gather further evidence instead. The engineering answer is more useful than the legal one: record provenance at the moment of generation, which tool, which version, which inputs, which licence, and keep it with the asset. Most rights problems in media are discovered eighteen months later, and the difference between an hour of work and a month of work is whether anyone can say where the asset came from.

How do you run an AI programme around peak trading?

By treating the change freeze as a design constraint from the start. Delivery is sequenced so that pilots ship and stabilise before freeze, the freeze period is used for adoption, measurement and operating-model work that requires no deployment, and the next build window is planned against the trading calendar rather than a generic quarterly plan.

What is different about frontline versus head office AI adoption?

Almost everything. Head office knowledge workers adopt tools that make their own work easier and have discretion over how they work. Frontline staff work to fixed processes, often on shared devices, with little discretion and immediate customer pressure. The two require separate adoption designs, separate measurement, and usually separate sequencing.

6 questions

Industrial, Energy and Infrastructure

Answered on Industrial, Energy and Infrastructure, and rendered here in the same words.

Read the page these answers live on →

Where do industrial businesses get value from AI agents?

In engineering knowledge work rather than operational decisioning: retrieval across decades of technical documentation, simulation and scenario modelling that amplifies scarce specialist time, capital project reporting across distributed programmes, and compliance evidence gathering. Operational decisions in industrial settings are usually too consequential and too hard to reverse for early agentic autonomy.

Can an AI agent be part of a safety case?

Not comfortably, and it is the wrong place to start. A safety case argues, with evidence, that risks are reduced so far as is reasonably practicable, and that argument depends on the behaviour of the system being characterised. A system whose output is not reproducible is difficult to argue for, and a model your supplier updates on their release schedule breaks the argument silently. The realistic pattern is to keep agents on the analysis side of the boundary, make the boundary explicit so that crossing it is somebody's decision rather than a drift, require a management-of-change gate before a pilot touches anything safety-relevant, and pin model versions under change control your safety function owns. Tenhaw employs no safety engineers and does not write or assess safety cases.

Does NIS2 apply to AI systems in industrial operations?

NIS2 does not regulate AI as such. It regulates the security and resilience of the entities in scope, and since October 2024 it has covered more sectors, put accountability on management bodies and added supply chain security and fast incident reporting. An agent inside an operator's estate is in scope the way any other system is, and in OT the specific question is segmentation: the boundary between corporate IT and the control domain exists to stop things reaching across it, and an agent is a new actor asking to cross. UK operators of essential services face the same questions through the NIS Regulations and the NCSC's Cyber Assessment Framework, with IEC 62443 as the engineering standard underneath. Design answers first: what identity does the agent hold, what can it read, and can it write anything at all.

What do ISO/IEC 42001 and the NIST AI RMF actually require?

ISO/IEC 42001 is a certifiable management system for AI: policy, roles, risk assessment, controls and evidence that they operate. The NIST AI Risk Management Framework is voluntary and organised around four functions, govern, map, measure and manage, with a generative AI profile alongside it. Neither is law, and both are increasingly what procurement and insurers ask about. The failure mode is adopting either as a document rather than as controls, so the register and the running system drift apart. Building the inventory, the evaluation records and the ownership trail during delivery costs a fraction of reconstructing them in a remediation programme. Tenhaw is not certified to ISO/IEC 42001. It is under assessment, and the security page says where that stands.

How do you run agentic transformation across distributed engineering teams?

By designing for asynchronous operation from the start. Tenhaw ran exactly this at Anglo American across the UK, Australia and the USA, building an agile blueprint lightweight enough that specialists onboarded fast, throughput data feeding simulation, and outcome-based milestones rather than project plans, so progress remained legible without synchronous coordination.

Has Tenhaw worked in heavy industry?

Yes. Tenhaw set up and ran the Data, Simulation and DevOps teams behind Anglo American's hydrogen-powered mining programme, work that underpinned a £40bn business case and spun out as First Mode. Tenhaw also made global delivery predictable at Yondr across data centre operations in the UK, US and Singapore.

All sectors

The rest of the FAQ

316 questions, grouped by subject

Every question answered anywhere on tenhaw.com sits in one of 39 groups. This is one of them.

All 316questions, and every group →

Still have a question?

A 30-minute discovery call with James Rooney. Bring the question this page did not answer. You'll leave with a rough scope whether you engage us or not.

30 minutesWith James personallyNo obligation

Most organisations start with a fixed-price Agent-Readiness Audit · £30k–£90k · 6–8 weeks