Your sector, in the FAQ

Retail, industry and energy, answered in full.

The questions asked where the work sits in operations, the supply chain and the estate rather than inside a regulated process.
questions in this group, each answered in full
36
pages the answers are written on, every one linked
2
questions across the whole FAQ
1424

36 questions on retail, industry and energy, answered by Tenhaw, a UK AI consultancy and AI delivery partner based in London. Nothing here is a summary: each answer is the exact text from the page that owns it, and every group links back to that page for the context around it.

On this page
18 questions

Retail, Consumer and Media

Answered on Retail, Consumer and Media, and rendered here in the same words.

Read the page these answers live on →

Where do retailers get the fastest return from AI agents?

In high-volume, reversible-decision workflows: merchandising and demand signals, supply chain exception handling, customer service triage with human resolution, and content production at volume. These have short feedback loops, contained risk, and produce measurable results inside a single trading cycle.

Does UK consumer law apply to product descriptions written by AI?

Yes. The unfair commercial practices rules apply to the trader, not to the author, so a misleading description is a misleading description whether a copywriter or a model produced it. The rules in the Digital Markets, Competition and Consumers Act apply to practices from 6 April 2025, and the CMA can now decide for itself that they have been broken rather than going to court first, with penalties of up to 10% of global turnover and the power to direct redress. The practical design response is to ground every factual claim about a product in a field in a system of record, and to hold anything the model asserts that cannot be matched to one. The same logic covers price display, where mandatory fees have to appear in the total up front, and reviews, where presenting incentivised reviews as genuine is a banned practice.

Do we need a DPIA for an AI agent that uses customer data?

Almost always, and you need it more than once. A DPIA is required where processing is likely to result in high risk, which covers most personalisation, profiling and large-scale use of customer data. The failure we see is not a missing DPIA, it is one completed for a narrow pilot and never revisited when autonomy widened, which is the change that altered the risk. Two other things get missed. A retrieval corpus needs its own retention and deletion behaviour, because honouring a deletion request in the database and not in the index is not honouring it. And a decision with significant effect on a person needs a real route to human intervention and to contest the outcome. Tenhaw is not your DPO and gives no legal advice here.

Who owns the rights to content generated by an AI model?

It depends on the tool's terms, the licences behind its training data and the warranties you were able to negotiate. UK law still has no broad commercial text-and-data-mining exception to fall back on, and the government's copyright and AI report of 18 March 2026 dropped a broad exception with an opt-out as its preferred approach, saying it would gather further evidence instead. The engineering answer is more useful than the legal one, so record provenance at the moment of generation, which tool, which version, which inputs, which licence, and keep it with the asset. Most rights problems in media are discovered eighteen months later, and the difference between an hour of work and a month of work is whether anyone can say where the asset came from.

How do you run an AI programme around peak trading?

By treating the change freeze as a design constraint from the start. Delivery is sequenced so that pilots ship and stabilise before freeze, the freeze period is used for adoption, measurement and operating-model work that requires no deployment, and the next build window is planned against the trading calendar rather than a generic quarterly plan.

What is different about frontline versus head office AI adoption?

Almost everything. Head office knowledge workers adopt tools that make their own work easier and have discretion over how they work. Frontline staff work to fixed processes, often on shared devices, with little discretion and immediate customer pressure. The two require separate adoption designs, separate measurement, and usually separate sequencing.

Can we use AI to summarise customer reviews?

Yes, and the control that matters is knowing which reviews fed the summary. Presenting fake or incentivised reviews as genuine is a banned practice under the unfair commercial practices rules, and the trader carries a duty to take reasonable steps to stop them appearing, so a summariser that quietly folds incentivised reviews into a headline average produces a number nobody can defend. Build it so every claim the summary makes traces back to reviews you can identify, and hold anything the model asserts that the underlying reviews do not support. We test the claim path rather than the tone. Where puffery ends and a misleading claim begins is your legal team's call, not ours.

Can we let an AI agent run pricing and promotions on its own?

Only behind a rules layer it cannot talk its way around. The total price including mandatory fees has to be presented up front rather than assembled during checkout. Price display is regulated in its own right, so a promotion agent that splits a mandatory fee off the headline price has produced a misleading practice on the trader's behalf. Since 6 April 2025 the CMA decides for itself whether consumer law has been infringed rather than litigating first, with penalties of up to 10% of global turnover, or £300,000 if that is greater, and the power to direct redress. Put the pricing rules in code the agent cannot override, and test what the display claims rather than how it reads.

Can we use past order data to train a recommendation model?

Not automatically. UK GDPR asks for a lawful basis and a purpose the data was actually collected for, and data gathered to fulfil an order was not obviously collected to train a recommendation model, which is where retail personalisation gets uncomfortable. That does not make it impossible, it makes purpose and lawful basis inputs to the design rather than a gate at the end. The Data (Use and Access) Act 2025 reworked parts of the regime, and it is the ICO's guidance rather than the headlines that a DPO holds a programme to. Our default in pilots is synthetic or mocked data, which takes the hardest approval out of the fastest-moving phase. We work to what your DPO decides.

Which retailers and media brands has Tenhaw worked with?

On the retail side, under the Tenhaw banner: five agile teams coordinated through YOOX NET-A-PORTER's £1bn e-commerce re-platform, the mobile app and integration squads at Greggs made predictable and trusted again with data showing that clearing tech debt sped delivery up, and three newly merged teams at Colart turned into one unit that shipped an e-commerce site. On the media side, James Rooney ran the visual rebrand team on the Discovery+ and Eurosport launch, six teams against a date the CEO had already announced, and held delivery roles at Sky. That work was delivery transformation rather than agentic build, and we label it that way because the two are not the same claim.

What does a retail AI operating model look like in practice?

A retail AI operating model comes down to four choices: which workflows agents touch, where the human sits in each one, how the build is sequenced against the trading calendar, and who owns what an agent says to a customer. The last one is the trap. Anything an agent generates that reaches a customer is a commercial practice by the trader, so the claim path belongs in the design rather than in a review at the end. The other structural point is that head office and store or contact-centre operations are two different transformations, and running them as one programme is a reliable way to fail at both. Peak freezes make sequencing a design constraint, not a scheduling detail.

Why do AI demand forecasts go wrong around promotions?

Because seasonal and promotional data makes naive forecasting agents unreliable, and retail history is mostly seasons and promotions. The model reads a promotional spike as demand rather than as a lever somebody pulled, then carries that shape into a week when nobody is pulling it. The version that works feeds the promotional calendar and price changes in as explicit inputs instead of leaving the agent to infer them, and keeps a buyer between the recommendation and the purchase order. Merchandising and demand signals are still one of the fastest places in retail to get a return, because the decisions are frequent and reversible. What fails is giving the forecast to an agent and the promotional calendar to nobody.

Can agents take on supply chain exception handling?

Yes, and it is one of the first places we would look, because that is variance humans currently absorb by hand and the volume is high enough to show a result inside one trading cycle. Every time, the agent assembles the exception, a late shipment, a short delivery, a substitution, pulls the related records and the history, proposes a resolution and hands a person a decision instead of a search. Two boundaries hold. It does not commit money or change a customer's order on its own, and anything it produces that reaches the customer, a revised delivery promise included, is a commercial practice by the trader and needs grounding in a system of record.

How do you stop a customer-facing agent becoming a PR incident?

By putting the boundary in a different place from where you would put it in the back office. Get a customer interaction wrong in retail and it is a social media post the same afternoon, which is a different risk profile from mislabelling an invoice, so the agent drafts and a person resolves rather than the other way round. Start where a mistake is recoverable: triage, summarisation, routing, and internal drafting that a colleague sends. Widen autonomy only where the evidence from the narrow version supports it. The failure mode is rarely a rude reply. It is a confident factual assertion about a product, a price or a delivery date that nobody checked.

How do retailers justify AI spend when margins are thin?

By buying it in pieces small enough to prove themselves inside a trading cycle. The commercial case for agents is strongest where margins are thinnest, which is also where the appetite for multi-year consultancy spend is lowest, so the shape of the spend has to match. An agentic proof of concept is £20k–£55k fixed over 2–4 weeks. The AI readiness audit is £44,000 fixed over four weeks and ends in working prototypes, and a recommendation to stop is a valid outcome. After that, engagements are retainer-shaped rather than milestone-shaped, and a month that delivers no measurable value gets reported as a failed month. That is the honest version of return inside a trading cycle.

Can AI take over the manual reporting from stores and field teams?

Yes, and it is usually the least contentious place to start, because what gets replaced is manual consolidation rather than judgement. Store and field reporting in most retailers is someone pulling figures out of several systems by hand every week, which is high volume, low risk and easy to check, because the numbers already exist to reconcile against. The design work is not the model. It is deciding what the report is for, cutting the fields nobody acts on, and giving the frontline something back rather than only feeding head office. Adoption is the risk here rather than the build. A store team will use a report that saves them an evening and ignore one written for head office.

Is agentic AI in retail an IT project or a trading one?

A trading one with engineering inside it. If IT owns it, you get something merchandising did not ask for, store operations cannot use, and a frontline half of the programme that quietly never happens. The sponsor should be whoever owns the trading outcome, with the merchandising or category lead, whoever runs stores or the contact centre, brand or legal for the line between puffery and a misleading claim, and your DPO in the design sessions rather than in the approval queue. Engineering reports into that group instead of running alongside it. If nobody in the room can approve a change to a customer-facing message, the wrong people are in the room.

Does the Online Safety Act apply to AI features in our app?

Yes, if the app has user-to-user features, and the duties Ofcom enforces do not change because a model wrote the content. Reviews, comments, community feeds and anything an agent generates or promotes into them are part of the system being assessed, so putting an agent on that surface belongs in the assessment before it ships rather than after. The duties expect proportionate systems rather than reactive takedown, which is an argument for emitting the evidence trail as the system runs instead of reconstructing it later. Where an agent supports that work the customer-facing boundary still holds, so it can gather and prioritise while a person owns any decision that lands on someone. We build the mechanism, not the legal position.

If the sources do not answer it, a call will.

Talk it through
18 questions

Industrial, Energy and Infrastructure

Answered on Industrial, Energy and Infrastructure, and rendered here in the same words.

Read the page these answers live on →

Where do industrial businesses get value from AI agents?

In engineering knowledge work rather than operational decisioning: retrieval across decades of technical documentation, simulation and scenario modelling that amplifies scarce specialist time, capital project reporting across distributed programmes, and compliance evidence gathering. Operational decisions in industrial settings are usually too consequential and too hard to reverse for early agentic autonomy.

Can an AI agent be part of a safety case?

Not comfortably, and it is the wrong place to start. A safety case argues, with evidence, that risks are reduced so far as is reasonably practicable, and that argument depends on the behaviour of the system being characterised. A system whose output is not reproducible is difficult to argue for, and a model your supplier updates on their release schedule breaks the argument silently. The realistic pattern is to keep agents on the analysis side of the boundary, make the boundary explicit so that crossing it is somebody's decision rather than a drift, require a management-of-change gate before a pilot touches anything safety-relevant, and pin model versions under change control your safety function owns. Tenhaw employs no safety engineers and does not write or assess safety cases.

Does NIS2 apply to AI systems in industrial operations?

NIS2 does not regulate AI as such. It regulates the security and resilience of entities in scope, and since October 2024 has covered more sectors, put accountability on management bodies and added supply chain security and fast incident reporting. An agent in an operator's estate is in scope like any other system. In OT the question is segmentation, and the boundary between corporate IT and the control domain exists to stop things reaching across it. An agent is a new actor asking to cross. UK operators of essential services face the same questions through the NIS Regulations and the NCSC's Cyber Assessment Framework, with IEC 62443 the engineering standard underneath. Design answers first: what identity does the agent hold, what can it read, and can it write anything at all.

What do ISO/IEC 42001 and the NIST AI RMF actually require?

ISO/IEC 42001 is a certifiable management system for AI: policy, roles, risk assessment, controls and evidence that they operate. The NIST AI Risk Management Framework is voluntary and organised around four functions, govern, map, measure and manage, with a generative AI profile alongside it. Neither is law, and both are increasingly what procurement and insurers ask about. The failure mode is adopting either as a document rather than as controls, so the register and the running system drift apart. Building the inventory, the evaluation records and the ownership trail during delivery costs a fraction of reconstructing them in a remediation programme. Tenhaw is not certified to ISO/IEC 42001. It is under assessment, and the security page says where that stands.

How do you run agentic transformation across distributed engineering teams?

By designing for asynchronous operation from the start. Tenhaw ran exactly this at Anglo American across the UK, Australia and the USA, building an agile blueprint lightweight enough that specialists onboarded fast, throughput data feeding simulation, and outcome-based milestones rather than project plans, so progress remained legible without synchronous coordination.

Has Tenhaw worked in heavy industry?

Yes. Tenhaw set up and ran the Data, Simulation and DevOps teams behind Anglo American's hydrogen-powered mining programme, work that underpinned a £40bn business case and spun out as First Mode. Tenhaw also made global delivery predictable at Yondr across data centre operations in the UK, US and Singapore.

Can an AI pilot use data from our plant historian?

Usually yes, provided it is scoped as an integration across the IT and OT boundary rather than as an analytics project. The failure we see is a pilot pulling historian data to a cloud model endpoint by a route the security function never approved, because nobody treated the agent as a new actor crossing a boundary built to stop exactly that. Our defaults are read-only access, a dedicated non-human identity with a tested revocation path rather than a shared service account, and no write path into the control domain unless your OT security function designs it. Early work runs against mocked services or synthetic data, so the hardest approval is not blocking the fastest-moving phase.

Our bottleneck is a handful of senior specialists. Can agents help?

That is the first place we look in this sector. Deep domain expertise sits with a small number of highly qualified people whose time is the actual constraint on the business, so an agent that amplifies scarce expertise is worth far more than one automating work you have plenty of. In practice that means simulation and scenario modelling, so a specialist can explore ten scenarios rather than two, and analysis prepared to the point where their judgement is the only thing still required. Expect scepticism from those same people, and expect it to be well-founded. You earn it with evidence on their own problems.

Our technical documentation is on-premise and unstructured. Can agents use it?

Yes, and it is usually where we would start here. Engineering knowledge retrieval across decades of technical documentation is the first place we look, because that material holds hard-won judgement that is otherwise locked in a filing system. Unstructured is normal and manageable. Tenhaw deploys on client infrastructure under your policies, with UK data residency by default, so on-premise is not a blocker either, and the documents never need to leave your estate to become retrievable. What the constraint really changes is sequencing. Expect early effort to go into access and structure before the impressive demos appear, and plan for it.

How do you show AI value when capital cycles run in years?

By separating the asset business case from the workflow business case. Capital cycles mean the case for the asset itself is measured in years, and nothing about agentic AI changes that. The workflows around the asset move on much shorter cycles. Capital project reporting consolidated across distributed programmes, compliance evidence gathering where the audit trail is the deliverable, and engineering knowledge retrieval all return value on the cadence of the work rather than the asset lifecycle. Engagements here are retainer-shaped rather than milestone-shaped, and Tenhaw reports measurable value every month, counting a month that delivers none as a failed month. That keeps a long programme honest while the asset case takes its own time.

Can an agent write anything into our control system?

Not by default, and not unless your OT security function designs the path itself. Our default is read-only across the IT and OT boundary, with no write path into the control domain, because that segmentation exists precisely to stop things reaching across it. An agent is a new actor asking to cross, so it gets a dedicated non-human identity with a tested revocation path rather than a shared service account, and its activity can be told apart from a person's afterwards. It is also where the value is not. In this sector the return sits in the analysis that informs decisions rather than in the decisions themselves, and anything informing a safety-relevant judgement needs a management-of-change gate before the pilot.

What happens if the model gets updated after we sign off a workflow?

Treat it as a change, because that is what it is. A supplier updating a model is a change whether or not anyone in your organisation initiated it, and any change to a safety-related system triggers management of change and reassessment. The awkward part is that the update lands on the supplier's release schedule rather than yours, so our default is pinned model versions with change control your safety function owns. An update then becomes a decision you take on your own timetable rather than an event you discover. We also keep evaluation results as records alongside the runs that produced them, so moving version gives you a measured before and after rather than a difference of opinion.

How do we stop an AI tool drifting into safety-critical use?

Name the boundary, and make crossing it somebody's decision. A tool arrives as decision support, becomes the thing operators actually rely on, and no management-of-change assessment is ever triggered because nothing in the control system changed. That is how the line gets crossed, by drift rather than by decision. So we write down which human judgement the workflow informs, design the point where a person is required rather than leave it to a line in the training pack, and treat any use that starts informing a safety-relevant judgement as a management-of-change gate before it goes further. Our contribution is seeing that line coming and bringing your safety function in before it is crossed.

Which teams need to be in the room: OT security, safety or engineering?

All three, at different moments, and the order matters. Engineering leads, because the value in this sector is engineering knowledge work: retrieval across technical documentation, simulation that amplifies scarce specialist time, capital project reporting across distributed programmes. OT security joins while the work is still a design, rather than after it has quietly become an integration that nobody scoped as one, since we ask what identity an agent holds and what it can reach before we ask what it can do. Your safety function is needed where a workflow informs a safety-relevant judgement, and that is the moment to stop and involve them, not the month after the pilot.

Can agents take the coordination load off teams in three time zones?

Yes, and it is a real source of value here. Engineering and delivery teams spread across three continents make asynchronous working a necessity rather than a preference, and the cost of that shows up as waiting when a question asked at five in London is answered tomorrow. Agentic workflows that assume a synchronous team in one time zone do not survive contact with that reality. So we design so that no step needs a particular person awake, and put agents on the assembly work in between, keeping the written record current so the next time zone starts from something. Tenhaw made global delivery predictable at Yondr across the UK, US and Singapore, though that was delivery discipline rather than agents.

Can an agent pull capital project reporting together across a programme?

Yes, and it is one of the first places we look in this sector. Consolidating capital project reporting across distributed programmes is knowledge work, where the inputs are trackers, documents and reports in different formats from teams in different time zones, and the effort goes into assembling a consistent picture rather than deciding anything. That makes it good agentic territory, because a person still reviews the output, and it is the same person who would otherwise have assembled it by hand. It also stays well clear of the control domain, so it can move at its own pace while the safety-adjacent conversation takes as long as it needs to take.

Can agents assemble compliance evidence across sites and systems?

Yes, and it is often the soundest first workflow here, because the audit trail is the deliverable rather than a by-product. The work is finding, citing and assembling evidence that already exists across systems and sites, which is retrieval with a paper trail attached, and a person still signs. Two design points carry it. Every item cites the source it came from, so an assessor can follow it back rather than take the summary on trust. And the model version and the run that produced each answer are kept as records, so the same question can be reconstructed months later. It also never reaches across the boundary into the control domain.

Our specialists have no spare time. How much of it will you need?

Less than a project would take, and in short structured blocks rather than a standing commitment. We design around sessions to set the problem, judge outputs and correct them, with the long stretches of work happening without your specialists in the room. Early work runs against mocked services or synthetic data, so their time is not spent unblocking approvals during the fastest-moving phase. We pair with your permanent engineers as we build, with measured skill transfer, because the point is to leave capability behind rather than a dependency on us. The AI Readiness Audit works the same way: four weeks, £44,000 fixed, sitting with the people who do the work rather than issuing a survey.

All sectors

If the sources do not answer it, a call will.

Talk it through
The rest of the FAQ

1424 questions, grouped by subject

Every question answered anywhere on tenhaw.com sits in one of 51 groups. This is one of them.

All 1424questions, and every group →

Or ask the question directly and skip the categories.

Talk it through
book a call

Still have a question?

A 30-minute discovery call with James Rooney. Bring the question this page did not answer. You'll leave with a rough scope whether you engage us or not.

most start with a fixed-price AI Readiness Audit · £44,000 · 4 weeks · working prototypes

// pick a slot · cal.com/tenhaw/professional-servicesLIVE CALENDAR

Calendar not loading? Open it on cal.com or email hello@tenhaw.com.